Who approves
Who may approve a request comes from the rule, not from a role. Every Ask rule names a team and how many people from it must say yes.
Teams and counts
Section titled “Teams and counts”- A rule needs N different people from its team. A person counts once, whether they decide in the web app, Slack or Teams.
- One Deny from the team stops the request.
- Someone outside the team cannot decide; they see “You are not an approver for this rule”.
- When a request matches several Ask rules, each rule needs its own approvals. A person in two of those teams counts for both.
Admins make teams and add people on the People page.
| Role | May |
|---|---|
| Admin | everything: people, roles, teams, gates, integrations, settings, rules |
| Rule editor | create and change rules |
| Member | start agents; approve or deny when in the rule’s team; read the audit log |
| Auditor | read everything and export the evidence; never approves |
An admin approves only when they are in the rule’s team.
Four eyes
Section titled “Four eyes”The person who started the agent cannot approve its requests. The request shows “started the agent, so this approval does not count”.
Four eyes is on by default. An admin can switch it off under Settings › Organization; when there is another admin, that waits for them (see admin changes).
When you pick a team and a count for a rule, the editor warns if the count may never be reached: with four eyes on, a team of two can only give one approval when one of them started the agent.
When someone leaves
Section titled “When someone leaves”- Someone who leaves the rule’s team, or is offboarded, stops counting on requests that still wait. Their approval stays in the audit log but shows “No longer counts”.
- Decided requests keep their count.
- Noset never adds an approver on its own. When offboarding someone would leave a team with fewer people than a rule needs, the admin adds someone to the team first.