{"id":48,"date":"2026-03-22T12:26:59","date_gmt":"2026-03-22T12:26:59","guid":{"rendered":"https:\/\/overlaps.co.uk\/docs\/?page_id=48"},"modified":"2026-04-01T15:21:22","modified_gmt":"2026-04-01T14:21:22","slug":"authorisation","status":"publish","type":"page","link":"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/user-interface\/authorisation\/","title":{"rendered":"Authorisation"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">If you have configured an email server (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/email-configuration\/\" data-type=\"page\" data-id=\"72\">Email Server Configuration<\/a>) then you will have the ability to restrict user\u2019s permissions so that they require manual authorisation to read and\/or expire a computer\u2019s password in a given Organisational Unit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is configured through the Permissions screen in the Config page (<a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/container-permissions\/\" data-type=\"page\" data-id=\"66\">Container Permissions<\/a>), or by the per-User\/Group Self-Service settings (<a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/users-and-groups\/managing-user-self-service-computers\/\" data-type=\"page\" data-id=\"253\">Self Service Settings<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a user requires authorisation for an action, they will be prompted to provide their justification. This will then create an Authorisation Request which is emailed to any named Authorisers for that particular OU. Any one of these authorisers can then Authorise or Deny the request (optionally providing their reasoning).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"75\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-pending-requests.png\" alt=\"Pending Authorisation Requests\" class=\"wp-image-362\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-pending-requests.png 602w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-pending-requests-300x37.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><figcaption class=\"wp-element-caption\">Pending Authorisation Requests<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"authorisation-page-sections\">Authorisation Page Sections<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Authorisation page is split into three sections (only one of which are available to non-authorisers):<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"my-requests\">My Requests<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Shows a list of Authorisation Requests for the currently logged in user and their status. Once authorisation has been granted, the user can click the hostname to directly access the password from this screen (without having to browse to or search for the computer again). They can also click the justification link to see the current status of the request and what responses (if any) have been given.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"pending-requests\">Pending Requests<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Lists any pending Authorisation Requests which the currently logged in user has permission to authorise or deny.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Clicking the <strong>hostname<\/strong> of a computer will allow you to authorise or deny individual requests, or you can select multiple requests and click the <strong>Authorise\/Deny Selected Requests<\/strong> button to process them in bulk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Clicking the <strong>Read<\/strong> link under Justification will allow you to see that request\u2019s justification (if any was provided).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once a request has been authorised or denied, it cannot be changed. <strong>To cancel a request which was authorised erroneously you must instead delete it<\/strong>, this can be done from the Historical Requests section.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"historical-requests\">Historical Requests<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Shows a list of old requests which were either authorised or denied. Authorisation Requests are deleted periodically according to your settings (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/settings\/security\/\" data-type=\"page\" data-id=\"161\">Settings -> Security<\/a>). If you need information about an old request which has been deleted, you should consult the History page.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"requesting-permission-to-access-a-password\">Requesting Permission to Access a Password<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a user requires authorisation to view the passwords for the computers in the current Organizational Unit, then when they click to view one of those passwords, instead of immediately seeing the password, they will instead be prompted to request access.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"333\" height=\"389\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-new-request.png\" alt=\"Prompt to request Authorisation to view this computer's password\" class=\"wp-image-363\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-new-request.png 333w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-new-request-257x300.png 257w\" sizes=\"auto, (max-width: 333px) 100vw, 333px\" \/><figcaption class=\"wp-element-caption\">Prompt to request Authorisation to view this computer&#8217;s password<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Users are given the option to provide additional justification for accessing this password. This is not required but is recommended for auditing purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the request has been made, any user or users who have Authoriser permission to this Organizational unit will be emailed to notify them that there is a request that requires their attention. They can then login to OVERLAPS and choose to Authorise or Deny the request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Users who require authorisation to view passwords cannot make use of the bulk \u201cDisplay Passwords\u201d feature to view all of the passwords in that container and must instead retrieve the passwords one at a time.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"370\" height=\"381\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-response.png\" alt=\"Authorise or Deny a Request\" class=\"wp-image-364\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-response.png 370w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/overlaps-ui-authorisation-response-291x300.png 291w\" sizes=\"auto, (max-width: 370px) 100vw, 370px\" \/><figcaption class=\"wp-element-caption\">Authorise or Deny a Request<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Once a request has been authorised or denied, the Requester will be notified by email and only then will, if the request was authorised, be able to read the password.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"authorisation-request-expiry\">Authorisation Request Expiry<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By default, as soon as a user who has received authorisation views the target computer\u2019s password, that request is then automatically expired. This means that if they attempt to view the password again, they will need to send another request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the Security section of the site settings (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/settings\/security\/#authorisation-requests\">Security<\/a>), you can change this so that an authorised Authorisation Request will stay active for a given number of minutes after it is first accessed. This allows a certain amount of grace time in case the user forgets the password or needs it again very soon afterwards.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"justification\">Justification<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"504\" height=\"351\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/justification-required-modal.jpg\" alt=\"Requiring Justification\" class=\"wp-image-365\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/justification-required-modal.jpg 504w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/justification-required-modal-300x209.jpg 300w\" sizes=\"auto, (max-width: 504px) 100vw, 504px\" \/><figcaption class=\"wp-element-caption\">Requiring Justification<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If, instead of authorisation, the user is configured to have to provide Justification before viewing a password, they will be presented with this dialog so that they can log why they are accessing it. This information is written to the History Log.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you have configured an email server (see Email Server Configuration) then you will have the ability to restrict user\u2019s permissions so that they require manual authorisation to read and\/or expire a computer\u2019s password in a given Organisational Unit. This is configured through the Permissions screen in the Config page (Container Permissions), or by the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":40,"menu_order":400,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-48","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/48","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/comments?post=48"}],"version-history":[{"count":2,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/48\/revisions"}],"predecessor-version":[{"id":366,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/48\/revisions\/366"}],"up":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/40"}],"wp:attachment":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/media?parent=48"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}