Review → Approvals
Use Review → Approvals to inspect request history across automation and access policies. Use the top-navigation message icon to review requests awaiting your decision or check your own requests.
Personal inbox
The message icon in the top navigation opens Approvals. To review lists pending requests you can approve or deny; My requests lists your own pending and completed requests. The notification badge counts only pending requests you can review. One eligible member of any selected approver role can decide. UI notifications are always enabled; email is optional. Opening a request never approves it.
Both lists show the request title, source, scope, requester, deadline, and status badge. Source labels distinguish Interactive Session request, File Transfer request, and Automation Playbook. Open a request to review its message, access details, and requester, then choose Approve or Deny. An optional comment becomes part of the evidence. Membership and the source feature’s scope rules are checked again when you decide. Once decided, expired, or cancelled, a request disappears from To review and remains in the requester’s My requests until its evidence is deleted by retention. An administrator does not bypass approver-role membership. Requesters can view their own requests without policy-history permissions, but can approve them only when they are eligible approvers. Policy requests additionally require the rule to allow self-approval; automation requests allow eligible users to approve their own requests.
Historical evidence
Open Review → Approvals to view a timeline grouped by request date. Each entry shows the request time, source, scope, requester, and current outcome. Use the view button to open the recorded details. Filter by source, status, and request dates; both selected UTC days are included. More requests load as you scroll. Scope identifies the entity concerned, when there is one. A request can have no scope. Links appear only when the entity exists and you may open it.
History follows the source feature’s read permission and scope:
- Automation requests require
app.automation.read. - Session and File Transfer policy requests require
app.policy.read.
These permissions allow inspection; they do not grant the right to decide. Eligible approvers can use the top-navigation modal without access to Automate or Govern.
Evidence records the original title, message, source and subject labels, selected roles, requester, deadline, decision, deciding user, and comment. Editing or deleting a source does not rewrite historical evidence. Deleting a source can cancel its pending request or revoke its access grant according to that feature’s rules.
Retention
The scheduled Telemetry Data Cleanup task removes eligible evidence from the database. Its default interval is 60 minutes:
- Automation approval evidence is deleted with completed runs under
automation_runs_retention_days. - Terminal policy approval evidence uses
policy_log_retention_days; pending requests and grants still valid are protected. - Email delivery evidence uses
local_tasks_retention_daysindependently. A decision can remain visible after its email details have been removed.
All three retention settings default to 90 days. Pending automation runs remain retained. Cleanup deletes the records; it does not archive them. Database backups have their own retention outside this feature.
See automation approvals and policy access approvals for source-specific behavior.