Deliberate Approvals

Approval Workflows

Decisions where responsibility lies

Sensitive permissions deserve a deliberate decision. With the FirstWare IDM-Portal, you define which changes require approval and who grants it, directly through the responsible team lead or resource owner.

Approval workflows with the FirstWare IDM-Portal
Siegel Made in Germany

Made in Germany

firstware-dsgvo-nis2-konform

GDPR and NIS2 compliant

firstware-25-Jahre

25 Jahre IAM Experts

Vendor- and cloud-independent_Variant B

Vendor- and cloud-independent

Quick Navi

Groups

To memberships

Stages

To multi-stage approvals

Review depth

To individual processes

Reality Check:
When approvals become a weak point

 

Not every permission should be granted automatically. Some decisions deliberately require a responsible person, such as the manager of a sensitive resource. Without a reliable process, controlling access becomes more than difficult.

Sensitive groups without protection

Critical permissions are accidentally granted without prior review.

Approvals get lost in emails

Requests remain stuck in inboxes during absences.

Every request treated the same

A trivial request goes through the same review process as a critical permission.

Responsibility becomes unclear

When positions change, responsible approvers are missing.

When approval workflows become a weak point

Your approval workflows with the IDM-Portal

Approval workflows for sensitive group memberships in the IDM-Portal

Reliably protect sensitive groups

Group memberships under control

In the FirstWare IDM-Portal, you define which groups and therefore which resources are considered sensitive. When someone requests that a colleague be added to such a group, they state directly what the request is about, with a short comment and, if needed, a planned date from which the membership should apply.

The responsible approver is automatically notified and makes the decision through a clear web interface.

Once the decision is approved, the membership is implemented directly in the respective target system.

Clear responsibility at every level

Multi-stage approvals for large teams

For critical decisions, multiple approvers can be involved one after another, such as a department head followed by a compliance officer. Each stage is automatically notified as soon as the previous one has been completed.

Instead of a single person, a group can also be defined as the approver. This ensures that a decision can still be made even when responsibilities change or an individual person is currently unavailable.

Multi-stage approval workflows for large teams
Individual approval workflows with the right review depth

Individual, tailored review processes

Review depth matched to risk

When an approver is on vacation or ill, a designated substitute automatically takes over. This ensures that no request remains unprocessed.

In addition, not every access request has to go through the same level of review. Non-critical group memberships are implemented directly, while especially sensitive permissions still require a deliberate decision.

These processes are configured individually according to your company's needs.

What is the FirstWare IDM-Portal?

Flexible IAM solution for Identity Governance & Administration

 

The FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.

Powered by my-IAM – the underlying technology platform that enables seamless integration of any IT systems and cloud services.

Flexible IAM solution for Identity Governance & Administration

Approvals, independent of your system landscape

Whether cloud-native or hybrid: approved changes take effect consistently across all connected systems, regardless of which directory services you use.

N

Lifecycle automation

Personio, SAP SuccessFactors, SD Worx / Loga3

N

Identity Providers & Directories

Microsoft Entra ID, Keycloak, hybride Infrastrukturen

N

Specialized and industry software

Dedalus Orbis, SQL integrations, CSV and API connectors

FirstWare IDM-Portal: IAM solution for Identity Governance in hybrid IT landscapes

Your benefits

Approval workflows reliably protect sensitive groups

Reliable protection for sensitive groups

Approval workflows place responsibility with the right decision-makers

Responsibility with the right decision-makers

Approval workflows with automatic substitution

Automatic substitution

Approval depth matched to risk im Workflow

Approval depth matched to risk

Approval workflows ensure stable role ownership during personnel changes

Stable role ownership during personnel changes

Approval workflows with complete audit traceability

Secure audit traceability

Frequently Asked Questions

Frequently asked questions about role-based approval workflows, automated approval processes, clear responsibilities and secure decisions with the FirstWare IDM-Portal.

What is an approval workflow?

An approval workflow defines that certain access rights only become effective after a deliberate approval. A responsible decision-maker, such as a team lead or resource owner, reviews the request and decides whether to approve or reject it.

What is the difference between an approval workflow and Self Management?

Self Management describes how an employee submits a request. The approval workflow describes what happens afterwards: who reviews the request, in which order, and according to which rules it is approved.

Can several people approve a request one after another?

Yes. For especially sensitive permissions, multi-stage approvals can be configured in which several responsible people must approve one after another before the change takes effect.

What happens if an approval is rejected?

The change is not implemented, and the requester automatically receives feedback about the rejection. The process therefore remains transparent for everyone involved.

What happens if an approver is absent?

You define a substitute who takes over the decision during this time, permanently, once only or for a specified period. This prevents requests from being left pending simply because the actual approver is currently unavailable.

Does every request have to go through the same review effort?

No. Non-critical requests are implemented directly, without any approval step, while especially sensitive permissions still require a deliberate manual decision. You define where this boundary lies.

How does the approval workflow support compliance requirements?

Every decision, every approver and every point in time is recorded completely in the IDM-Portal log. This makes providing evidence to auditors much easier, for example for ISO 27001, NIS2, TISAX or KRITIS.

Let's Talk

We are here for you

 

Do you want to automate your approval processes securely?

Call us at 0 8196 - 998 4330 or use our contact form.