Learn how to configure required reviewers for access requests.
All resources and groups in Opal can be requestable with configurable approval options and reviewers. Use this guide to learn how admins can configure the reviewers of access requests.
Reviewers: Users who can review and approve access requests
Admins: Users who can manage the full configuration of policies for resources and groups
You can manage owners from the Inventory > Owners tab. There, you can find the following settings for reviewers:
Reviewer Escalation Policy:
Notify everyone: As the default option, Opal notifies all required reviewers at once. Opal requires just one approval from all required reviewers to complete the request.
Reviewer escalation policy: Once configured, Opal creates an explicit escalation order. In this example, Opal notifies the first reviewer. After the escalation time has passed, Opal notifies the next reviewer, and so on.
Linked reviewer Slack channel: Opal creates a channel that receives a message for every access request.
Source group: Opal keeps the user list for this owner synchronized with a group of your choice. You can still edit the escalation path in the Users tab, but you can’t add or remove users from this owner directly.
Access reviews that require owner approval will fail when owner groups are empty. To receive notifications about empty owner groups, enable Error notification setting in Configuration > Organization Settings > Advanced.
For resources and groups, the Request Configuration section gives admins an overview of the approval logic. You can create multiple request configurations if you want to apply different approval logic for different requesting users, groups, or roles.
To send users notifications when they are approved for resources or groups, check the Include custom notification text with approvals checkbox in the request configuration or template, then specify a custom message.
Service Users can be assigned as request reviewers to automate approvals based on dynamic conditions. This can be integrated with your own tooling to evaluate if users are compliant with your access policies, such as if security training is complete or if the user is in their authorized work location.When assigning a service user to a request, an automation is configured for that service user. An automation consists of:
When the automation is triggered. For access requests, use Assigned to request.
Then the action that is taken. For access requests, use Send webhook.
Endpoint that a webhook is sent to. The webhook handler must be able to make Opal API calls to provide an approve, deny, or comment decision.
HMAC Secret that is used to sign the webhook payload.