Restricting exception approvers
By default, exception approvers can also make approval decisions about requests in which they are themselves requester (UID_PersonInserted) or recipient (UID_PersonOrdered). To prevent this, you can specify the desired behavior in the following configuration parameter and in the approval step:
-
QER | ComplianceCheck | DisableSelfExceptionGranting configuration parameter
-
QER | ITShop | PersonOrderedNoDecideCompliance configuration parameter
-
QER | ITShop | PersonInsertedNoDecideCompliance configuration parameter
-
Approval by affected employee option in the approval step for finding exception approvers
If the requester or approver is not allowed to grant approval exceptions, their main identity and all sub identities are removed from the circle of exception approvers.
Summary of configuration options
Requesters can grant exception approval for their own requests, if:
- PersonInsertedNoDecideCompliance configuration parameter is not set.
Recipients can grant exception approval for their own requests, if:
Requesters cannot grant exception approval, if:
Recipients cannot grant exception approval, if:
Related topics
Setting up exception approver restrictions
To prevent recipients of request becoming exception approvers
This configuration parameter takes effect:
-
When requests are granted approval exception.
-
During cyclical rule checking. For more information about cyclical rule checking, see the One Identity Manager Compliance Rules Administration Guide.
- OR -
-
In the Designer, enable the QER | ITShop | PersonOrderedNoDecideCompliance configuration parameter.
This configuration parameter takes effect:
To prevent requesters becoming exception approvers
-
In the Designer, set the QER | ITShop | PersonInsertedNoDecideCompliance configuration parameter.
This configuration parameter takes effect:
For individual approval workflows, you can allow exceptions to the general rule in the PersonInsertedNoDecide and PersonOrderedNoDecide configuration parameters. Use these options if the requester or recipient of requests is allowed to grant themselves exception approval only for certain requests.
To allow request recipients or requesters to become exception approvers in certain cases
Related topics
Explicit exception approval
If the QER | ComplianceCheck | EnableITSettingsForRule configuration parameter is set, properties can be added to compliance rules that are taken into account when rule checking requests.
Use the Explicit exception approval IT Shop property to specify whether the reoccurring rule violation should be presented for exception approval or whether an existing exception approval can be reused.
Table 46: Permitted values
Enabled |
A known rule violation must always be presented for exception approval, even if there is an exception approval from a previous violation of the rule. |
Not set |
A known rule violation is not presented again for exception approval if there is an exception approval from a previous violation of the rule. This exception approval is reused and the known rule violation is automatically granted exception. |
If several rules are violated by a request and Explicit exception approval is set for one of the rules, the request is presented for approval to all exception approvers for this rule.
Rules that have Explicit exception approval set result in a renewed exception approval if:
In case (a), the request for the IT Shop customer is presented to the exception approver. If the request is approved, case (b) applies to the next request. In case (b), every request for the IT Shop customer must be decided by the violation approver, even when the request itself does not result in a rule violation. The result you achieve is that assignments for employees who have been granted an exception, are verified and reapproved for every new request.
For more detailed information about exception approvals, see the One Identity Manager Compliance Rules Administration Guide.
Rule checking for requests with self-service
Self-service (SB approval procedure) is always defined as a one-step procedure. That means you cannot set up more approval steps in addition to a self-service approval step.
To realize compliance checking for requests with self-service