Approval rules
Approval rules define who must approve a new access request based on its estimated monthly cost. You configure rules in Settings → Access approval rules.How rules work
Each rule specifies:- A cost range — a minimum and optional maximum monthly cost.
- Required approval stages — one or more of: Manager, IT, Security, or Finance.
- Priority — when multiple rules match, all matching stages are combined into a single approval chain.
- Manager approval
- IT approval
- Security approval
- Finance approval
Create an approval rule
Add a rule
Click Add rule and configure:
- Name — a descriptive label (e.g. “High-value requests”).
- Minimum monthly cost — the lower bound of the cost range.
- Maximum monthly cost — the upper bound, or leave blank for no cap.
- Required stages — toggle on the approval stages this rule requires.
- Priority — a number to control rule ordering in the list.
Example
| Rule | Cost range | Stages required |
|---|---|---|
| Low-value | 50/mo | Manager |
| Mid-value | 500/mo | Manager, IT |
| High-value | $500+/mo | Manager, IT, Security, Finance |
Access grants
When a request is approved, Layer creates an access grant. Grants can be:- Permanent — no expiration.
- Temporary — expires after a set duration (1 to 168 hours). If no duration is specified, temporary grants default to 24 hours.
Review campaigns
Review campaigns let you audit existing access on a regular cadence. You can run campaigns ad-hoc or on a quarterly or annual schedule.Create a campaign
When you create a review campaign, you configure:- Scope — which identities and applications to include.
- Reviewer strategy — how reviewers are assigned:
- Explicit — you manually assign reviewers.
- App owner — the designated owner of each application reviews access.
- Manager — each user’s manager reviews their access.
- Deadline — days until the review is due (1–365 days, default 7).
- Escalation — days after the deadline before escalation triggers (1–90 days, default 3).
Review lifecycle
Each review in a campaign moves through these states:| Status | Meaning |
|---|---|
| Pending | Awaiting reviewer action |
| Completed | Reviewer confirmed or revoked access |
| Expired | Deadline passed without action |
| Overdue | Past deadline but still pending |
| Escalated | Escalation triggered after overdue period |