Access approval rules
An Approve rule requires a human decision before a user opens a new connection or starts a file transfer. Configure it in Govern → Session Policy or Govern → File Transfer using the rule editor.
Configure a rule
Choose Approve, select the matching resources and requester roles, then select the approver roles. Set the request expiration and access validity, and optionally enable email notification. Request expiration defaults to 24 hours; access validity defaults to one hour. Both accept durations from one minute to 30 days. UI notification is always enabled.
Session Approve rules cannot reference command ACLs. File Transfer Approve rules cannot reference paths or transfer directions: both kinds gate access to the resource. Session type remains an available Session selector.
Approve rules are evaluated before ordinary Accept/Deny rules, regardless of their displayed position. The first matching enabled Approve rule supplies the request. After approval, ordinary rules still apply in their normal order; approval alone never overrides a denial, missing permission, or default-deny result.
The policy feature entitlement governs access approvals; automation execution is not required. Policy approvals do not create playbooks or automation runs.
Request and decision
When approval is needed, the connecting user sees Approval required. Repeating the same request while it is pending reuses it. Credentials are requested only after access approval. Closing the modal leaves the request pending.
One eligible member of a selected approver role may approve or deny. The Allow self-approval toggle defaults to off. Enable it to let a requester who belongs to an eligible approver role approve or deny their own request. The requester and deciding user remain recorded in the evidence, including when they are the same person. Approvers must retain resource read access in the applicable location scope.
After approval, the requester chooses Continue. This makes a fresh access check and begins a new connection attempt. Denied, expired, or cancelled requests do not automatically retry. A later explicit attempt may create a new request.
A grant belongs to the requester, resource, policy kind, and matching rule revision. Its validity starts at approval time and is not extended by use. Within that period, it can cover subsequent matching connections or transfers. Session and File Transfer grants are separate. Every new file transfer checks the grant, even through an already open file session.
Reattaching an existing live shell or file transport does not require a new approval. Graphical connections create a new transport and are checked again. Expiry does not terminate a running session or stop an already accepted transfer; it governs the next new operation.
Rule changes and role deletion
Changing an Approve rule’s matching criteria, approver settings (including self-approval), or enabled state invalidates affected requests and grants. After changing the toggle, start a fresh connection or transfer attempt. Changing the ordered sequence of enabled Approve rules—including appending, disabling, or deleting one—invalidates existing grants across that policy domain. Renaming a rule or changing its comment does not. Changing only ordinary rule order leaves grants intact, but the current ordinary rules still apply to new work.
A role cannot be deleted while an Approve configuration references it, including a disabled rule or playbook, an unfinished automation run, or a pending shared request. Remove the configuration references and resolve the pending work first. Terminal historical role snapshots do not block deletion.
The Approve rule’s hit count increases once for each new request, not for polling or repeated attempts against the same pending request.
Scope and evidence
These gates protect interactive resource sessions and the governed file-transfer endpoints. They do not add approval to independent MCP device commands, background snapshots, or other standalone resource actions.
Inspect decisions in Review → Approvals. The original decision stays Approved when its grant later expires or is revoked; the access state separately reports whether it can still be used.