Skip to main content
The following settings are available from a resource’s Edit page. Use them to customize who can edit resources and how resources appear to end users in the catalog.

Resource admins

Owners can be used as Admins of a resource, allowing you to decentralize access management. Both Owners and Opal Admins can manage the configuration of approval and additional security settings from a resource’s Edit page.

Allow requests

To allow end users to request access to your resource, expand the Request configuration section and ensure Allow requests is enabled. See Security settings to learn how to further customize request flows.

Allow request extensions

Allow end users to extend access from the catalog by toggling Allow request extensions in a request configuration, then select a duration. The additional duration is added to the original request expiration time. End users can request extensions from the Opal UI or in Slack.

Visibility

Every resource and group has a visibility setting. This is a “hard” visibility setting: a user who doesn’t have access, isn’t an admin, and isn’t in a group that’s been granted visibility cannot see the resources or groups in their catalog. Visibility enables you to hide resources from anyone who doesn’t have access, or restrict requests to certain groups.
  • No visibility restrictions: This resource/group is visible to all employees.
  • Restrict to groups: Only users in certain groups, admins, and users who have direct access to this item can see the item.
2262
You can set Import Visibility at the app level. This creates a default Visibility setting for all resources that are imported from the app. Setting visibility at the app level does not change visibility settings for resources that have already been imported.
2262 2262

Security settings

Some resources are more sensitive than others. You can apply the following settings to your critical resources:
  1. Require MFA to approve requests (and make connections): Requires MFA to approve requests via web and Slack. In addition, for certain resources, Opal will also require MFA before end users can connect to the resource.
  2. Maximum duration: Enforces the maximum amount of time a resource or group can be requested for
  3. Recommended duration: Shows the recommended duration as the default option in both Slack and web
  4. Require support ticket: Requires a support ticket to create a request
  5. Custom fields: Create a standard set of questions for employees to answer before submitting an access request
2262

1. Require MFA to approve requests

If MFA to approve requests is enabled, Opal triggers an MFA prompt before reviewers can approve requests in Slack and web. This protects sensitive resources and validates the approver’s identity. For some resources, Opal can be used to generate short-lived credentials via CLI or web. If MFA is enabled for these resources, end users must validate their identities before connecting to the resource.

2. Maximum duration

Set a maximum duration to enforce timebound access. If it’s unset, duration defaults to the organization-wide maximum duration if present, and indefinite access otherwise. If a recommended duration is selected, it shows as the default duration on access requests, but employees can still specify other durations.

4. Require support ticket

If this is enabled, then a support ticket must be submitted with an access request. This will enable an access request to be dynamically revoked if the support ticket has been completed. This enables a strong security posture as you can revoke access based on the completion of an activity. You can only attach tickets that are assigned to you.
If both a time duration and support ticket is enabled, then Opal will take the event that comes first.

5. Custom fields

Admins can customize questions for employees to answer before submitting an access request to a given resource.
  1. To create custom fields, Admins must first go to Templates under the in the left-hand bar and click on + Custom Access Request
Create a custom access request template
  1. After creating the template, admins can set up custom fields by clicking on Add Block.
Add a block to a custom access request template Field options include the following types:
  • Short Answer: Short text fields
  • Paragraph: Longer text fields
  • Checkbox: A binary selection
  • Multiple Choice: A dropdown selection that only allows one choice
  • Multi-select: A dropdown selection that allows multiple choices
  • Callout: A customizable message that will be shown when a user requests access to a certain group or role
Each form field block will allow you to customize it in different ways. You can configure an individual item to require an input by using the toggle on the bottom right of the block, and you can rearrange the order of blocks by clicking and dragging the three dots on the top left. Mark a custom field as required You will see how your fields look like and behave on the right side of the screen, under the Form Preview section. Form preview for a custom access request template Once you are done, you can save the template with the Save Changes button on the bottom right of the screen. In addition, you can revert the template to its last saved state using the button next to it.
  1. Once the template has been created and saved, you can attach your Custom Field template to a resource under the Custom fields section:
Attach a custom field template to a resource Your fields should now appear when a user requests access to this resource: Custom fields on an access request We support direct links to apps in our catalog so that users can launch that app or resource immediately. By default, users can navigate to the link to the app or resource regardless of their access. If you want to hide this link, you may do so in Configuration > Settings > Access Requests > Hide launch links for users without access. You may input a custom launch URL in the catalog at the app level for applications we do not natively populate or to override the standard link. To do so, navigate to the application, click Edit on the top right and input your custom Launch URL.
Last modified on August 31, 2026