Approval Workflows

Configurable multi-step approval chains for access requests. Define who approves, in what order, and with what time limits — across web apps, endpoints, groups, resource sessions, and VPN tunnels. Auto-approve trusted roles, auto-deny stale requests, and notify approvers via email, Slack, Discord, or webhooks.

Included Capabilities

Multi-step approval chains — team lead, then manager, then security
Configurable approver types: by role level, team membership, or specific users
Per-step required approval counts and timeout limits
Auto-approve for trusted roles — skip the queue when policy allows
Auto-deny for stale requests — timed-out requests denied automatically
Time-bound access with configurable duration and automatic revocation
Multi-channel notifications: email, Slack, Discord, Teams, Telegram, webhooks
Covers all resource types: web apps, endpoints, groups, resource sessions, VPN
Full audit trail for every decision with approver identity and notes
Priority-based workflow matching — most specific policy wins

Feature Overview

Secure Access — Overview
Zero Trust Access
Identity-verified connections
Session Recording
Complete audit trail
Just-In-Time Access
Time-limited permissions
Browser-Based
No legacy VPN or client software

How It Works

1. Connect Identity Provider

Integrate with Okta, Azure AD, Google Workspace, or any SAML/OIDC provider in minutes.

2. Add Resources

Register your servers, databases, and web apps. Define role-based access policies.

3. Secure Access

Users access resources through the browser with identity verification, session recording, and audit logs.

Ready for Approval Workflows?

Deploy in minutes. No legacy VPN required. No credit card required.