Workflow & Access Control
OmniPriv enforces 4-Eyes approval workflows, temporary privilege assignments, and application credential management — rotating hard-coded passwords in config files, Windows Services, and IIS App Pools.
Key Features
Structured, policy-driven privileged access with full approval governance
4-Eyes Approval Principle
Minimum two independent approvers required before access is granted; no user can self-approve their own privileged access request
Mobile & Email Approvals
Privileged access requests, approvals, and credential retrieval supported from mobile devices; approvals via web GUI, mobile client, or email link without logging in
Multi-Level Flexible Workflows
Configurable multi-level approval chains supporting multiple approvers per step; each approval level must complete before progressing
Time-Based Workflow Conditions
Workflows, policies, and approval rules configurable based on time-of-day or calendar-based conditions
Temporary Privileged Account Assignment
Account authorization for a specific timeframe and target asset; ACL-based mapping auto-reverts to standard restricted account on expiry
Application Credential Management
Eliminates hard-coded credentials in configuration files, databases, registries, Windows Services, scheduled tasks, and IIS App Pools with automated rotation
Zero-Latency Application Credential Handling
Critical applications retrieve credentials without introducing latency or reliance on remote repositories
Application Authentication & Protection
All applications requesting credentials are authenticated and protected against unauthorized changes to prevent credential interception
API Rate & Access Controls
RPS (Request Per Second) limiter, Client IP/CIDR allowlist, Time Limit, and Usage Limit controls on all application token requests
See Workflow & Access Control in Action
Get a personalized walkthrough of how OmniPriv's workflow & access control capabilities can be deployed in your environment.