Prerequisites
- You must be an Opal Admin, or an Admin of the resource or group you’re configuring.
- The stage you add escalation to must use Any logic. Escalation can’t be added to a stage that requires All reviewers to approve. See Approval flow.
How escalation works
When you add escalation to a stage, Opal adds an Escalation stage directly after it. The escalation stage contains the original stage’s reviewers plus the owners and users you escalate to.- If any original reviewer responds before the timer expires, the request proceeds normally and the escalation stage is satisfied at the same time. Nothing extra happens.
- If nobody responds before the timer expires, the request advances to the escalation stage, and the escalated reviewers are notified.
- The original reviewers stay on the escalation stage, so they can still approve after escalation. Escalation widens the pool of people who can act; it doesn’t take the request away from anyone.
Escalation only widens the pool of reviewers. It never grants access on its own—a request that nobody acts on still expires the way it normally would.
Configure escalation
- Go to the resource or group’s Edit page and expand Request Configuration.
-
In the Approval Flow section, find the stage you want to add a timer to and select Escalate if no response.

-
Under Escalate after, choose how long to wait before escalating:
-
Select the owners and users to escalate to. You can pick any combination, but you must select at least one.

- Select Add escalation. The new Escalation stage appears below the stage you configured.
- Save the request configuration.
What escalation looks like on a request
On a pending request, the Reviewers section labels both halves of the pair. The original stage is tagged with the wait time you configured, and the stage below it is tagged ESCALATION.
No reviewer responded in time - escalating.—so the handoff is visible in the Activity feed.
The timer only moves the request forward to the escalation stage. It is not an approval of the request: the escalated reviewers still have to approve before access is granted.
Examples
Production database access — 4 hours
An engineer requests read access to the production database during an incident. First-line reviewers are the database owners; the escalation reviewers are the on-call SRE rotation.- Escalate after: 4 hours
- Escalate to: SRE on-call
Marketing tool seat — 24 hours
A new hire requests a seat in a marketing SaaS tool. The team manager reviews these, and the escalation reviewers are the marketing ops team.- Escalate after: 24 hours
- Escalate to: Marketing Ops
Admin role on a sensitive system — 8 hours, escalating to security
A developer requests an admin role on a system holding customer data. The resource owner reviews first; the escalation reviewers are the security team.- Escalate after: 8 hours
- Escalate to: Security