Skip to main content
Version: latest

Approve a pending session

When a Safe has Approval required enabled, a user clicking Launch Session puts a request in your approval queue. Until you approve (or deny), the user waits.

Steps

  1. You receive an email and in-app notification: "{Requester} wants to launch a session on {Safe}".
  2. Open Approvals from the sidebar (badge shows pending count).
  3. Click the pending request. You see:
    • Who is requesting, their last login, their MFA status.
    • Which Safe and Resource they want to reach.
    • The justification text the requester provided.
    • Policy-enforced time window (e.g., "valid for the next 15 minutes").
  4. Click Approve to let the session start. The requester's waiting browser tab auto-launches.
  5. Click Deny if the request is not legitimate. Provide a short reason — it is shown to the requester and logged.

Multi-approver workflows

Some Safes require two approvers ("four eyes"). The queue shows the required count next to the request. Your approval moves the request to the next approver; it only unblocks the session when the count is met.

Emergency break-glass

If the user needs access right now and you cannot get to the dashboard, use the Approve button in the email — it works from any authenticated browser session.