Creating a Policy
- 1. Select Approver
- 2. Choose Strategy
- 3. Add Steps
- Manager: The request goes to the requester’s manager for approval.
- Application Admins: The request goes directly to the assigned application admins responsible for that app.
- Business Owner: The request goes to the owner of the requested app.
- Individual User: The request goes to a specific user. Only users who are in your Slack workspace can be picked, because approval requests are delivered as Slack messages.
Assigning the Policy to Apps
Go to Settings → Policies, open the policy you want to use, and assign the apps that should follow it. If no dedicated policy is chosen for an app, the Default policy applies.Handling Out-of-Office Approvers
- If an approver is unavailable, an AccessOwl Org Admin can override approvals on their behalf by opening the access request in the admin interface.
- The system audit log will show who performed the override and which user it was done on behalf of.
When an Approver is Offboarded
Approval steps point at a role (such as Business Owner or Application Admins), not at a specific person. If the person holding that role is offboarded, the step does not break and the request never falls back to the offboarded person’s manager. Instead, the role itself is reassigned - see Handling Role Changes for how AccessOwl reassigns the Business Owner and Application Admin roles. Requests that were already in flight keep the approvers they were created with. An AccessOwl Org Admin can approve those requests on the offboarded person’s behalf from the admin interface, and the audit log records who acted and on whose behalf.Best Practices
Keep It Simple
Use Auto-Approve for Low-Risk Apps
FAQ
Can someone who is not in Slack be a user or an approver?
Can someone who is not in Slack be a user or an approver?
Can we set a time-based or temporary approval window (e.g., access for two weeks)?
Can we set a time-based or temporary approval window (e.g., access for two weeks)?
Does AccessOwl provide automated escalation if an approver doesn’t respond for a certain number of days?
Does AccessOwl provide automated escalation if an approver doesn’t respond for a certain number of days?
Can we apply different approval policies to different user groups or roles automatically?
Can we apply different approval policies to different user groups or roles automatically?
Can I apply a policy to all applications at once?
Can I apply a policy to all applications at once?
- App-level policies apply to standard access requests for a specific application (e.g., “Critical Applications” policy assigned to Slack).
- Entitlement-level policies apply to requests for a specific permission type (e.g., “Elevated Access” policy assigned to elevated permissions), regardless of which app. These policies do not need any apps assigned to them.
What happens when both an app-level and entitlement-level policy could apply to the same request?
What happens when both an app-level and entitlement-level policy could apply to the same request?
Is there a way to lock a policy so even admins can’t override it?
Is there a way to lock a policy so even admins can’t override it?
Can an app be assigned to more than one approval policy?
Can an app be assigned to more than one approval policy?
Why does an approver in my chain not match the current policy or Business Owner?
Why does an approver in my chain not match the current policy or Business Owner?

