Control access duration, justification requirements, and approval workflows
Access policies define the rules that govern how users request and receive access to applications and resources. Create reusable policies to maintain consistent access controls across your organization.
When creating or editing an access policy, configure the following settings to manage duration, and approvals needed for roles.
Policy Name
Descriptive name that indicates when the policy should be used (e.g., “High Security”, “Standard Access”)
Policy Description
Detailed explanation of what the policy covers and when to apply it
Max Access Length
Maximum duration users can keep access before automatic revocation (options: indefinite, hours, days, weeks, months)
Recommended Access Length
Suggested duration to guide users toward shorter access periods while still allowing maximum if needed
Require Business Justification
Toggle on to require users to explain why they need access; Serval evaluates reasonableness based on guidance settings
Require Confirmation for Requests Made on Behalf of Others
Toggle on to add verification step when someone requests access for another user
Require Approval
Select who must approve: specific users, groups (optionally with a quorum), the requester’s manager, resource, app, or role owners, or a custom approval workflow
Allow Self-Approval
Control whether approvers can approve their own requests, per approver or for the whole procedure
Multiple Approval Steps
Add sequential approval requirements where each step must be completed before the next begins
Approval Timeout
How long each step waits for a decision before timing out (30 days by default). A step that times out ends the approval without granting access.
Impact Preview
View how many applications and roles will be affected by policy changes before saving
Each step is governed by an All must approve or Any one can approve rule. For sequential approval, add multiple steps. Each step begins only after the previous one completes.
Approvers can modify the requested duration when approving. For example, if a user requests 2 hours of access, an approver can approve for 30 minutes instead. This gives approvers flexibility to grant appropriate access based on the specific request context.
Separately from the requester’s business justification, an approval step can prompt the approver to record their own note when they decide a request. For each step, choose how the approver’s note is handled: None, Optional, Required, Required to approve, or Required to deny. The approver enters the note as part of approving or denying, and it’s captured wherever they act (Slack, Microsoft Teams, the Serval inbox, and the web ticket card) and stored with the decision.
Click “Create policy” or select an existing access policy to modify
2
Name the policy
Enter a policy name and description. Use descriptive names like “General Access” or “Temporary Admin Access” that indicate when the policy should be used.
3
Set access duration
Choose indefinite or time-limited access for Max Access Length. Optionally set a Recommended Access Length to guide users toward shorter access periods while still allowing them to request the maximum if needed.
Use time-limited access for elevated permissions like admin roles. Use indefinite access for standard user roles.
4
Configure justification and confirmation
Toggle on “Require business justification” to require users to explain why they need access. Serval will evaluate whether the justification is reasonable based on your guidance settings.Toggle on “Require confirmation for requests made on behalf of others” to add verification when someone requests access for another user.
5
Set up approvals
Build the procedure as a sequence of steps. In each step, add one or more approvers: specific users, groups (optionally with a quorum), the requester’s manager, resource, app, or role owners, or a custom approval workflow.For each step, configure:
The approvers, and whether each is notified or a backup who can approve but isn’t notified
Whether all must approve or any one can approve
For a group, a quorum: how many of its members must approve
For the whole procedure, set whether approvers can self-approve their own requests (Allow all approvers to self approve?) and the Approver justification requirement (whether approvers must leave a note when they decide).Add multiple approval steps for sensitive access by clicking “Add approval step”. Approvals happen sequentially—the second step only begins after the first is complete.Set Approval timeout to control how long each step waits for a decision before timing out, 30 days by default. If a step times out with no decision, the approval ends without granting access.
The approval steps builder in an access policy
Each step is governed by an All must approve or Any one can approve rule. For sequential approval, add multiple steps. Each step begins only after the previous one completes.
6
Preview impact
Check how many roles will be affected by this policy before saving.
7
Save the policy
Click “Save policy” to make it available for role configuration. You’ll see which applications will be affected by the new policy.
Existing workflow and access-policy approval procedures remain supported in configuration pushes. If a workflow or policy already references a versioned library procedure, exports reject that reference rather than omit its approval requirement. Legacy approval editors also reject replacing a versioned reference.
Once created, access policies can be managed centrally and applied to multiple roles across your organization.To access policy management, open the team in the sidebar, then go to Settings → Access Policies.
Set a default policy
Choose a default policy that applies to new roles automatically to ensure consistent baseline access controls.
Edit existing policies
Modify policy settings. Changes apply to all roles using that policy, making it easy to update access controls organization-wide.
View policy usage
See which roles currently use each policy to understand the impact before making changes.
Apply policies to roles
Add or remove roles that the policy should apply to. Reuse policies across similar access patterns for consistency.
Add new policies
Set up new standard policies for your organization to be used across any number of roles.
Users can request extensions or reductions to their active access. These modification requests follow the same approval workflow as initial requests:
Extensions require approval if configured in the access policy
Approvers can modify durations when approving extension requests
Users can amend requests before approval (the final requested duration is what the approver sees)
No approval required? If no approval procedure is configured, requests and extensions auto-approve with the requested duration
If a user amends their request multiple times before approval, only the final amendment is submitted for approval. Earlier amendments are automatically superseded.