Approval workflows
An approval workflow – “Workflow” in the user interface – defines who decides on an access request for a role. Every entitlement and every business role points to at most one workflow through its “Approval workflow” field. Without a workflow it cannot be requested.
Maintaining workflows
Administrators maintain workflows under “Administration” → “Workflows”. A workflow consists of the fields “ID (slug)”, “Name” and “Description” plus an ordered list of steps (“Approval Steps”); each step has an approver type.
- Only administrators create, change or delete workflows.
- A workflow needs at least one step; without steps Nova accepts no request.
- Nova does not delete a workflow that roles still point to.
- On submission, Nova copies the steps into the request. Later changes to the workflow apply to new requests.
Who decides a step
| Approver type | Who decides |
|---|---|
| “Manager” | the target identity's manager, recorded or derived from the organisation; for a department, its head |
| “Role Owner” | the “Owner” of the requested role |
| “Agent Owner” | the accountable owner of the AI agent |
| “Risk Owner” | the identity stored in the step |
| “Specific User” | the identity stored in the step |
| “Security” | every identity holding the “Security” entitlement |
| “SoD Review” | every identity holding the “SoD Reviewer” or “Security” entitlement |
- For open steps, Nova keeps resolving the responsible person anew. If the manager changes, for example, the new manager may decide; the person resolved at submission remains authorised as well.
- If nobody can be resolved – for example because a role has no owner – only administrators can decide the step.
- An “SoD Review” step only becomes active when there are open risk findings; otherwise Nova skips it. Whoever approves it despite open findings must enter a comment. See Segregation of duties.
- Administrators can decide any open step and close a request as a whole with “Approve (admin)” or “Reject (admin)”. Nova logs this intervention as a separate event and notifies the requester and the approvers of open steps.
Order and outcome
- All steps of a workflow are open from submission and can be decided in any order. The step number determines the order of notifications.
- A requested role is approved when all its steps are approved or skipped. A single rejection rejects it.
- “Approve” and “Reject” in the request decide, in one go, all open steps for which the signed-in identity is the resolved approver. A comment is optional.
- If a workflow consists only of “SoD Review” steps and there are no findings, the role counts as approved on submission.
Deputies during absence
An identity can have a “Deputy” and, under “Absence”, the dates “Absent from” and “Absent until”. If both dates are set and today falls within this period, the deputy may additionally decide the absent person's open steps.
- The absent person remains authorised.
- Nova does not resolve chains: if the deputy is also absent, the authority does not pass on to the deputy's deputy.
- In the “To approve” tab, such requests carry the note “As deputy for …”. Nova logs the decision together with the person represented.
- During the absence, the deputy also receives the notifications addressed to approvers.
Reminders and escalation
The background job “Approval Escalation” makes overdue steps visible. Nova does not create it by itself; administrators set it up under “Monitoring” → “Background Jobs” with “New job”.
- From “Remind After (Days)” – default 3 – Nova reminds the responsible approvers, at most once a day.
- From “Escalate After (Days)” – default 7 – Nova alerts the administrators once. The reminders continue.
- A step's age counts from the latest decision on an earlier step of the same role, otherwise from submission.
- The job approves nothing and skips no step.
Notifications
| Event | Recipients |
|---|---|
| “Access request submitted” | resolved approvers of the first active step |
| “Approval step completed” | resolved approvers of the next step |
| “Access request approved” | requester, target identity |
| “Access request rejected” | requester |
| “Access request cancelled” | approvers of open steps |
| “Admin override on request” | requester, approvers of open steps |
| “Pending approval reminder” | responsible approvers |
| “Overdue approval escalated” | administrators |
Under “Administration” → “Notifications”, administrators define per event whether Nova notifies and through which channels; the texts can be adapted. The “Email” channel only sends once a mail server is configured. The “Send mode” (“Active”, “Paused”, “Off”) applies to all channels.
Microsoft Teams is an add-on module: after “Microsoft Teams Notifications” has been switched on under “Administration” → “Plugins”, Nova can post messages to a Teams channel through a webhook. If “Interactive approvals (approve in Teams)” is also set up, the notified approvers receive a card with “Approve” and “Reject” through a Power Automate flow. One click decides an open step of that person; Nova checks the authorisation just as for a decision made in Nova.