Request types
Different requests route through Approvals, and the review experience varies by type. For some types the reviewer can adjust the request before approving; others are review-only (approve or reject as-is).
Work session
A request for a new work session. The reviewer sees the requested duration, features, target servers, and the requester’s justification.
Adjustable before approving. In the Admin adjustments area, the reviewer can:
- Change the requested features — add or remove features (scopes) before granting.
- Change the target servers — add or remove servers.
- Add recommendations — notes the assignee sees before starting the session.
Work sessions also include an AI pre-review and may show an urgency warning when the session window is about to expire. Approving sends along any adjustments you made.
Work session modification
A request to change an existing session’s servers or features. The reviewer sees the before/after changes and approves or rejects them. Review-only.
Service token
A request to issue a service token for an application. The reviewer sees the requested scopes, the risk level with a per-scope breakdown, and the reason. Review-only (approve or reject).
Token modification
A request to change a service token (for example, enabling it or changing scopes). The reviewer sees the changes. Review-only.
Username
A request to set a username that requires approval. The reviewer sees the requested identity. Review-only.
Group name
A request to set a group name that requires approval. The reviewer sees the requested name. Review-only.
Summary
| Type | Reviewer can adjust? | Has AI pre-review |
|---|---|---|
| Work session | Yes — features, servers, recommendations | Yes |
| Work session modification | No | No |
| Service token | No | No (risk from scopes) |
| Token modification | No | No |
| Username | No | No |
| Group name | No | No |