Introduction
Approval groups can be used to manually group a bunch of Core Identity into a group that than can be configured as an approval group for a Role or a Resource. If another Core Identity will be added to such a role or resource, the members of the approval groups get notified and they are asked to either approve or decline the assignment.
Properties
When adding an approval group to a role or a resource, you are presented with the following properties:
All members must approve
This means that every single member of the approval group must approve the role application. If at least one member vetoes, the role will not be assigned. If the option is not activated, the approval of one member of the approval group is sufficient.
Approve automatic assignments
This means that roles that are automatically assigned to a core identity due to its employment should be checked again manually by members of the Approval Group.
Approve manual assignments
Means that roles that have been manually assigned to a core identity are to be checked again manually by members of the Approval Group.