Set up dynamic approval configuration on a policy for which redlining is enabled.
About this task
A user with the sn_compliance_ws.corporate_compliance_manager role can create dynamic approval configuration and a user with the sn_compliance_ws.corporate_compliance_user role has read permission for the policy record.
To use dynamic approval for policy redlining, ensure that the redlining setup is done and the users in the approver rule have required roles for document access. When redlining is enabled, a user should have the
mp_document_user role with either the sn_grc.business_user or sn_grc.business_user_lite role to access the documents.
Procedure
-
Navigate to .
-
In the Compliance Workspace, select the List icon.
-
Navigate to and open a policy record.
-
Select the Policy text related list to view the contents of the policy text.
-
Select the Enable Word editing button.
-
To create a document as a policy owner, select Create new document in the Enable Word editing list.
-
Enter the path to the Folder including the Folder name in the Folder link field in the Create a document pop-up.
-
Enter the name of the document in the Document name field.
-
Select Create.
-
Select the Request review button.
-
Select Request.
-
Select the Complete publishing checklist button.
-
Select Save.
-
Select Request approval.
If an active dynamic approval configuration does not have any users associated with it, it is not considered as a valid configuration. In such cases, selecting Request approval returns an error
message: Could not request approvals because matching approval rule could not be found. Make sure to configure appropriate approval rule for this policy here. To rectify the error, edit
the configuration and request approval again.
The
Document access tab displays the revised list of the users who can access the policy as described in the following example:
- When the policy first moves to the Awaiting approval state, approval configuration is applied on the policy record. If the policy has two levels of approval, the document access is
provided only to level 1 users by default. Group users of level 1 can get access through the Request document access UI action.
- Once level 1 users approve the policy, the document access is added for level 2 users. If any user rejects the policy at level 1, it moves to the Draft state.
- When the policy moves to the Awaiting approval state again, next level of approval configuration (for example, approval configuration 2) is applied on the policy record. In this case,
all users that are common between the two levels and have access to the document, can access the policy and the document access is removed for the rest of the users.
The Request document access UI action is visible to the users with the business user role and business user lite role. If any user groups do not have these user roles, they cannot access the
document. The approvers have the view access or comment access in the approval state.
Note: In the approval rule, the access is given to the individual users only and not to the group users. Giving access to many users in the group can lead to performance issues.
If you are a group user, you must select Request document access. The group users can log in as one of the users in the group and select Request document access. The group
users are then granted the document access and a message is displayed: Doc access request has been raised, please refresh or try to access document in a few minutes.
In the approval configuration workflow, if an approver rejects the policy at any level, it moves to the Draft state. The Document access tab in the form displays a list of
the users who have access to the policy with the roles and status displayed. Only level 1 users can access and review the record. When level 1 users approve the record, then the document access is provided to level 2
users, and so forth.
When all levels are approved, the policy moves to the Published state.
-
In the Policy text tab, select Open in Word.
The Word document opens up in the tab. In the Manage access tab of the document, you can also view the users who have permissions to view the document. The configured policy approval rule is
displayed in the Approval rule field. The Approval levels related list displays information on the approval levels, users, and status of the approval for the policy record.
If the policy gets rejected at any state, it is reset to the Draft state. Once the approvers approve the policy, it moves to the Published state.