Access Request automatically escalated despite autoApprove

Hello,

A person has submitted an access request for an access profile he owns. The approval process is configured for the manager and the owner:

The manager approved the access request, but I don’t know why the second approval has been escalated to me.

We have the following configuration in our PROD and Sandbox environment :

I just read this documentation but nothing explains the behavior we just encountered. The approval should have been auto approved. Managing Requests for Roles and Access Profiles - SailPoint Identity Services

Can you help me?

Thank you.
Regards,

Mathieu Ghosn

On my understanding what you’re seeing is actually expected behavior with the current configuration. The key point is that self-approval prevention and automatic approval are two different mechanisms in ISC, which are easy to conflate when reading the documentation.

There are two things happening here:

1. Default self-approval prevention = reassignment, not auto-approval

By default, ISC does not allow a requester to approve their own access request. If the requester is also the configured reviewer (in this case, the Access Profile owner), ISC does not simply skip that approval step.

Instead, the review is reassigned to another eligible identity.

For a missing/unresolvable reviewer, ISC follows the documented escalation order:

  • The missing reviewer’s manager
  • The next new identity in the escalation chain
  • The fallback approver
  • The requested access object’s owner
  • An eligible Org Admin

ISC also skips identities that have already been assigned as approvers.

In your scenario, the requester is the Access Profile owner, so the Owner approval resolves back to the requester. Since self-approval is not allowed, ISC needs to reassign that review. Because the requester’s manager has already approved the first step, that identity is skipped, and ISC continues through the escalation chain. If you are an eligible Org Admin, this explains why the approval was eventually assigned to you.

2. Automatic approval is a separate, optional feature

If your expectation is that the Owner approval should simply be skipped when the requester is the Owner, that is not the default self-approval behavior.

ISC has a separate Automatic Approval setting for this purpose. It must be explicitly configured through the Approval Config API:

  • autoApprove: "Direct" — automatically approves when the configured reviewer is directly the requester.
  • autoApprove: "Indirect" — applies when the requester is included in a governance group configured as the reviewer.

Therefore, I would check the tenant’s approval configuration using GET /access-request-config and look at:

approvalConfig.autoApprove

If it is not set to Direct, then the behavior you observed is expected: ISC prevents the self-approval by reassigning the Owner review rather than automatically approving it.

So the important distinction is:

Self-approval prevention → reassign the approval

Automatic Approval (Direct) → skip the self-approval and automatically approve it

That also explains why the documentation can appear confusing at first—the “Preventing Self-Approval” and “Automatic Approval” sections describe two different behaviors.

Hi @mathieug ,

Just to clarify: is the person requesting the access for themselves or for another person ?

The API documentation for autoApprove specifically states that DIRECT applies when requester != requestee.

So if the requester is also the requestee, the DIRECT auto-approval rule would not apply and request will may be redirected to the manager / org admins

The API documentation put-approvals-config-v-1 | SailPoint Developer Community details little bite more the autoApprove :

Hello @baoussounda, thank you for your reply. You are right, the person requested access for themselves. In this case, the requester == requestee. I will therefore approve the request, since it concerns the production environment. However, I find it strange that a request is automatically approved when made for another person, yet there is no automatic approval when it concerns the requester themselves. Is there a reason for that?

Hi @mathieug ,

Yes, this is the expected behavior in ISC.

Self-approval is always prevented. Even when the auto-approval rule would normally apply, it cannot take effect when the requester is also the requestee (requester == requestee), because ISC does not allow users to approve their own access.

In this case, the request is therefore reassigned/escalated to the manager or to an Org Admin.

So autoApprove does not override the self-approval prevention mechanism.

Thanks.