Made in Germany
GDPR and NIS2 compliant
25 Jahre IAM Experts
Vendor- and cloud-independent
Reality Check:
When approvals become a weak point
Not every permission should be granted automatically. Some decisions deliberately require a responsible person, such as the manager of a sensitive resource. Without a reliable process, controlling access becomes more than difficult.
Sensitive groups without protection
Critical permissions are accidentally granted without prior review.
Approvals get lost in emails
Requests remain stuck in inboxes during absences.
Every request treated the same
A trivial request goes through the same review process as a critical permission.
Responsibility becomes unclear
When positions change, responsible approvers are missing.

Your approval workflows with the IDM-Portal

Reliably protect sensitive groups
Group memberships under control
In the FirstWare IDM-Portal, you define which groups and therefore which resources are considered sensitive. When someone requests that a colleague be added to such a group, they state directly what the request is about, with a short comment and, if needed, a planned date from which the membership should apply.
The responsible approver is automatically notified and makes the decision through a clear web interface.
Once the decision is approved, the membership is implemented directly in the respective target system.
Clear responsibility at every level
Multi-stage approvals for large teams
For critical decisions, multiple approvers can be involved one after another, such as a department head followed by a compliance officer. Each stage is automatically notified as soon as the previous one has been completed.
Instead of a single person, a group can also be defined as the approver. This ensures that a decision can still be made even when responsibilities change or an individual person is currently unavailable.


Individual, tailored review processes
Review depth matched to risk
When an approver is on vacation or ill, a designated substitute automatically takes over. This ensures that no request remains unprocessed.
In addition, not every access request has to go through the same level of review. Non-critical group memberships are implemented directly, while especially sensitive permissions still require a deliberate decision.
These processes are configured individually according to your company's needs.
What is the FirstWare IDM-Portal?
Flexible IAM solution for Identity Governance & Administration
The FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.
Powered by my-IAM – the underlying technology platform that enables seamless integration of any IT systems and cloud services.

Approvals, independent of your system landscape
Whether cloud-native or hybrid: approved changes take effect consistently across all connected systems, regardless of which directory services you use.
Lifecycle automation
Personio, SAP SuccessFactors, SD Worx / Loga3
Identity Providers & Directories
Microsoft Entra ID, Keycloak, hybride Infrastrukturen
Specialized and industry software
Dedalus Orbis, SQL integrations, CSV and API connectors

Your benefits
Reliable protection for sensitive groups
Responsibility with the right decision-makers
Automatic substitution
Approval depth matched to risk
Stable role ownership during personnel changes
Secure audit traceability
Frequently Asked Questions
Frequently asked questions about role-based approval workflows, automated approval processes, clear responsibilities and secure decisions with the FirstWare IDM-Portal.
What is an approval workflow?
An approval workflow defines that certain access rights only become effective after a deliberate approval. A responsible decision-maker, such as a team lead or resource owner, reviews the request and decides whether to approve or reject it.
What is the difference between an approval workflow and Self Management?
Self Management describes how an employee submits a request. The approval workflow describes what happens afterwards: who reviews the request, in which order, and according to which rules it is approved.
Can several people approve a request one after another?
Yes. For especially sensitive permissions, multi-stage approvals can be configured in which several responsible people must approve one after another before the change takes effect.
What happens if an approval is rejected?
The change is not implemented, and the requester automatically receives feedback about the rejection. The process therefore remains transparent for everyone involved.
What happens if an approver is absent?
You define a substitute who takes over the decision during this time, permanently, once only or for a specified period. This prevents requests from being left pending simply because the actual approver is currently unavailable.
Does every request have to go through the same review effort?
No. Non-critical requests are implemented directly, without any approval step, while especially sensitive permissions still require a deliberate manual decision. You define where this boundary lies.
How does the approval workflow support compliance requirements?
Every decision, every approver and every point in time is recorded completely in the IDM-Portal log. This makes providing evidence to auditors much easier, for example for ISO 27001, NIS2, TISAX or KRITIS.
Let's Talk
We are here for you
Do you want to automate your approval processes securely?
Call us at 0 8196 - 998 4330 or use our contact form.
