Skip to main content

Configuring phased authorization

You can configure Bravura Security Fabric to subject requests to multiple phases of authorization. The WF PHASED AUTH option enables the phased authorization functionality (Manage the system > Workflow > Options > General).

Once WF PHASED AUTH is enabled, the Authorization phase setting appears when assigning static authorizers and when assigning authorizers by user class.

The phased authorization configuration is separate from the non-phased authorization configuration. When phased authorization is enabled, the authorization requirements set up previously are no longer accessible. However, this configuration persists, and will apply again if phased authorization is disabled. Similarly, if phased authorization is disabled after configuration is done, that configuration is kept and will be used immediately if phased authorization is again enabled.

The Minimum number of authorizers and Number of denials before a change request is terminated settings apply to each individual authorization phase.

When enabled, navigate to the Authorization page for a resource or policy, then:

  • Click Add new… if you want to add a phase.

  • To change the order of phases, change the numbers in the Authorization phase column and click Update.

  • Select a phase to define authorizers and settings.

Determining when to add group owners

If supported by the target system, you can specify the phase in which group owners should be added as authorizers. If phased authorization is enabled, navigate to the target system’s information page and update The phase to which group owner should be added when being automatically added as authorizer.