Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from this space and version 8.1.0-8.1.1

...

  • Add: Creating a new Group, Zone, Pool, Record, or Server
  • Delete: Deleting a Group, Zone, Pool, Record, or Server
  • Update: Any change to an item that isn't Add, Delete, or Push - such as a settings change, renaming, or entering a value in a field. 
  • Push / BackgroundPush: DNS or DHCP Server Pushes - manual or scheduled
  • Change Group: Moving a DNS Zone from one Group to another.
  • Bulk Move Zones: Moving all DNS Zones in a Group to another.

It is important to note that Action types in Approvals is related-to-but-different than CRUD permissions as set in User groups - although the "Add" Action type and "Create" CRUD permission seem the same, the action type "Add" only applies to a specific event occurring, rather than a holistic overarching system-level permission. In order to perform a certain Approval Action Type, a user must already have the CRUD permissions to attempt it. The CRUD permissions determine whether the user can even view an area or attempt an action to begin with, Approvals Policies on Action Types determine what is done with the Action Action after the attempted change.

...

Group 1A (Admin)Group 1BGroup 1C
  • Global Admins (Full TLR User Group Perms + Admin)
  • All Admins in this group can approve any change requests
  • It doesn't matter which Admin user approves a request

Approval Group Settings:

  • Set to policy "Must Approve" for all DNS Family / Action types
  • Tip: Click the quick select checkbox next to each DNS Family name to select all actions under that family
  • Users with minimal oversight
  • Can work fully in all DNS family areas
  • Only needs admin approval for DNS Pushes

Approval Group Settings:

  • Set to policy "Action to be Approved" for "Push" and "Background Push" actions only, under each DNS Family in Group Assignment
  • Users with high oversight
  • Not allowed to Add or Delete any DNS item
  • Needs admin approval for all DNS Push and Updates

Approval Group Settings:

  • Set to policy "Deny" for "Add" and "Delete" actions under each DNS Family; save
  • Open again, set the policy to "Action to be Approved", and select "Update" and "Push / Background Push" actions under each DNS family, and set the policy to "Action to be Approved"; save.; save.

Expand the Expand the following link to view example images of setting the assignments for all three groups:

Expand
titleSetting the Group Assignments....

These examples use the "Assign" button for the Group under the ApprovalsPermission Groups sub-tab, Groups page.

Scenario 1

Group A:

Image RemovedImage Added

Group B:

Image RemovedImage Added

Group C, Deny Policy:

Image RemovedImage Added

Group C, Action to be Approved Policy:

Image RemovedImage Added

These settings may also be set by Action Type instead of Group, from the Approvals Permission Groups sub-tab, Actions page.

...

Group 2A (Admin Approvers)Group 2B (Admin Approver Bob)Group 2C
  • Global Admins (Full TLR User Group Perms + Admin)
  • All Admins in this group can approve any change requests
  • It doesn't matter which Admin user approves a request
  • DNS Group changes require multiple levels of oversight- from both this group and Bob

Approval Group Settings:

  • Set to policy "Must Approve" for all DNS Family / Action types
  • Tip: Click the quick select checkbox next to each DNS Family name to select all actions under that family
  • Global Admins (Full TLR User Group Perms + Admin)
  • Only contains one user - Bob, who specifically must approve of any change to DNS Groups

Approval Group Settings:

  • Set to policy "Action to be Approved" for "Push" and "Background Push" actions only, under each DNS Family in Group Assignment
  • Full Access throughout DNS
  • Not allowed to work with DNS Servers, even if they might have admin level access otherwise
  • Changes to DNS Groups and DNS Records require approval

Approval Group Settings:

  • Set to policy "Deny" after before quick-selecting the DNS Servers Family; save
  • Open again, set the policy to "Action to be Approved", then quick-select the "DNS Groups" and "DNS Records" families, then set the policy to "Action to be Approved"; save.

Approval Workflows

...

From the Approvals Tab, navigate to the Permission Groups sub-tab:.

...


Image Modified

Then, under the Groups page tab, find the ProVision User Group you want to assign a policy to and click "Assign".

Image Modified

Clicking the "Assign" button for a group brings up a checklist to select what policy to apply to the group for what Family and Actions (i.e. DNS Zone 'Add' or DNS Group 'Update').

...

Select either "Deny", "Action to be Approved", or "Must Approve Action" under Policy. Once you've selected a policy, you can "quick-select" all actions for a DNS Family (Severs, Groups, Zones, Records) by clicking the checkbox next to the family name, or only select individual action types for each Family.

Image Removed

Once you've selected the applicable Family/Action combinations to apply a policy for, select either "Deny", "Action to be Approved", or "Must Approve Action" under Policy.

Image Added

When done, Click "Assign", and repeat as needed for other Policy types or User Groups.

Step 4 - Enable Notifications (Optional)

If using Approvals notifications, enable notifications for the appropriate Permissions Group(s):

From the the Approvals Tab, navigate to the Permission Groups sub-tab Groups page tab:

...

.

Image Modified

Click on the group name for which you want to set notifications - the Group Permissions Detail page will provide additional information on the group's settings.

Image Modified

For any Family/Action that you want to enable notifications, click the checkbox under "Enable Notifications". All users of that group will get email notifications when a change of the selected type(s) are made.

Step 5 - Add Scheduler Task: "Approvals - Process Subscription"

If using Approvals notifications, set up a Scheduler task for "Approvals - Process Subscription"

The "Approvals - Process Subscription" task processes approval request events and handles the sending of notification emails to subscribed Approvals Groups - this task must be created and running on a regular interval in order for Approval Notification emails to be sent.

...

Step 6 - Add Scheduler Task: "Approvals - Delete events older than 1 month"

Set up a Scheduler Task for "Approvals - Delete events older than 1 month", to occasionally clear out old and obsolete Approval request

...

events

...

It is recommended to set this task to run monthly with no end date, to clear out obsolete approvals items, reduce data storage space needs, and reduce approvals page load time.

...