Set Up Delegation Settings
To set up delegation settings, users need these permissions:
- settings.admin
- delegation.settings.read
- delegation.settings.edit
You can set up delegation settings to determine how long users can delegate tenant access and who they can delegate tenant access to. These settings help you prevent unauthorized approvals and control delegation based on specific organizational needs.
- From the header, select .
- UnderSecurity, selectDelegation Settings.
- Complete theDelegation Expirationsection:
Option Description Allow Users to Delegate Access with No Expiration Date- If you keep this check box selected, users can delegate access to other users without a specific end date. However, they still have the option to select an end date when delegating access.
- If you deselect this check box, enter theMaximum Delegation Lengththat users can delegate access. The default duration is 365 days.
Notify before Access Expires (Days)This setting enables you to specify the number of days in advance when VNDLY should send theDelegation Access Ending Soon notificationto delegates and delegators. The default option is 7 days.You can also configure notification recipients and delivery methods on theNotificationspage ofCompany Settings. - Complete theDelegation Restrictionsection. This section allows you to restrict delegation for client and MSP users:Before configuring settings in this section, we recommend ensuring that management levels or reporting hierarchies have been set in users’ profiles.
Option Description No RestrictionsThis setting, which is selected by default, allows users to grant delegation access to any other users in the tenant.Restrict By Management LevelThis setting allows users to grant delegation access to other users with a specific management level:- Same Level: Users can delegate access to other users with the same management level as themselves.
- Higher Level: Users can delegate access to other users with a higher management level than themselves.
- Lower Level: Users can delegate access to other users with a lower management level than themselves.
Restrict by Reporting HierarchyThis setting allows users to grant delegation access to other users with a specific reporting hierarchy:- Peers: Users can only grant delegation access to other users who directly report to the same manager as themselves.
- Subordinates: Users can only grant delegation access to their direct reports or subordinates.
- Superiors: Users can only grant delegation access to their managers or superiors.
- ClickSave.
The settings you selected above are reflected on users’
Manage Delegation
page when they grant or request access. Any previous or future delegations in your tenant are also impacted by these settings, which are effective immediately. For example, you want to prevent users from delegating access to users with higher management levels. While setting up delegation settings, you select
Restrict by Management Level
, choosing Same Level
and Lower Level
.