Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 37 Next »

An Approval Group is a group of users within your PreVeil organization who together can authorize the activities of Admin Management, Data Export, and Account Recovery within the organization. The concepts behind Approval Groups are to:

  • Decentralize trust amongst the members of the group, ensuring no one person has the ability to authorize these activities on their own

  • Prevent single points of failure. The groups will have a pool of users that can approve activities, but only a subset of that pool are needed to approve.

Note: Members of an existing Approval Group cannot be changed, so to minimize the need to replace Approval Groups due to a member of a group no longer being available (if they’ve left the company, for example), we recommend populating the groups with users who are likely to be available to approve group activities.

Also, if a user of an Approval Group is no longer available to approve group activities, then we recommend creating a replacement Approval Group to put in place as soon as possible.

Creating an Approval Group

  • There must be three fully joined members of your organization to be able to create an Approval Group; three is the minimum number required to create an Approval Group.

    • Approval Groups can also consist of more than three people.

  • For a three person group, two out of the three members of that group will need to approve any activity that group gets invoked for.

    • For groups larger than three, you have more flexibility in setting the number of approvers. For example, in a four person group you can set the number of approvers to two or three; for a five person group you can set the number of approvers at two, three, or four; etc.

To create a group:

  • Select Approval Group from the left hand menu, then click on the plus sign icon under the Manage tab.

  • Give the group a name, and then type in the email address of the first user you want to add and click on the Add User button. Repeat to add at least two more additional users to the group. (Remember that you will need to add at least three users before you can create the group; the Create Approval Group button will remain grayed out until at least three users have been added to the group.)

  • Once at least three users have been added to the group, click on the Create Approval Group button. (If you create a group with more than three users that you will have some additional options to select from in the How many approvals are required for recovery drop down menu.)

  • You will receive a notification that the group has been created.

Activities an Approval Group Can Be Assigned To

The three activities in a PreVeil organization that an Approval Group can be assigned to are:

  • Admin Management

    • The purpose of this activity is to add a layer of security in the Admin console. Assigning a group to this activity will make it so that any activity an administrator wishes to undertake in the Admin console will require group approval.

    • If no group is assigned to this activity, a single administrator will have full functionality in the Admin console, and can perform any action without the need for approval.

    • The Approval Group assigned to this activity must consist of entirely admin level users, as a standard level user will not have access to the Admin console functionality.

  • Data Export

    • Data Export allows an administrator within your organization to download a decrypted copy of any data for any user within your organization.

    • The Approval Group assigned to this activity can consist of admin level users, standard level users, or a mix of the two.

  • Account Recovery

    • The account recovery Approval Group (also known as the Recovery Group) is a group of users within your organization that can assist a user in recovering access to their PreVeil account.

    • PreVeil doesn’t utilize user names and passwords for account recovery. Instead, what allows a user to access their PreVeil account is an encryption key that gets generated on a user’s device when they create their PreVeil account.

    • Assigning a Recovery Group to a user in your organization will provide each member of the group with a shard of the user’s encryption key. When invoked, the Recovery Group has the ability to rebuild a user’s key on their device, thereby allowing the user to re-access their account.

    • This is the primary method to protect a user’s account access, as PreVeil does not have access to any of our user’s encryption keys, so we cannot restore these keys for you. As such, the responsibility of making sure this recovery method is available to your users will fall upon the administrators of a PreVeil organization creating and assigning a Recovery Group for their users.

    • The Recovery Group can consist of admin level users, standard level users, or a mix of the two.

Assigning an Approval Group

Depending on the activity you are assigning a group to, there are two different methods for doing so.

To assign an Approval Group to either the Admin Management or Data Export activities

  • Select Approval Group from the left hand menu, then click on the Assign tab.

  • Click on the Assign button next to either Admin Management or Data Export.

  • Select the group that you want to assign to that activity from the drop down list.

  • You will see the details about the group you selected. Click Assign to assign the group to the activity.

  • The selected group will now be assigned to the activity.

To assign an Approval Group as the Recovery Group for your organization’s users

  • Select Approval Group from the left hand menu, then click on the Assign tab.

  • Click on Manage Users.

  • Click on the checkbox next to the user (or users) you want to assign the Recovery Group to. (You can assign it to more than one user at a time.)

  • Click on the Set Recovery Group button.

  • Select the group that you want to assign as the Recovery Group from the drop down list.

  • You will see the details about the group you selected. Click Set Recovery Group to assign the group to the activity.

  • The selected group will now be assigned as the Recovery Group for the selected user (or users).

Note: The user’s computer needs to be online for the Recovery Group to be successfully assigned. If the user’s device is not online, the Recovery Group will not be assigned to the user’s account. The recovery group will show up in the admin console, but the assignment will be incomplete. If the user’s device doesn’t come online within two weeks of the group being assigned, the assignment will fail and the group will be removed from the user’s entry in the admin console.

Copying an Approval Group

To make a copy of an existing group:

  • Select the checkbox of the group you want to copy, and then click on the copy icon.

  • You can then make any changes you want to that group, like changing the name, adding additional users, deleting existing users, and changing the number of required approvers. Once all changes have been made, click on the Create Approval Group button.

  • You will receive a notification that the new group has been created.

Replacing an Approval Group

An existing Approval Group cannot be modified to add or remove users, but it can be replaced if needed. To replace an Approval Group assigned to an activity:

  • Create a new Approval Group using the steps in the Creating An Approval Group section above.

  • Assign the new Approval Group to the activity using the steps in the Assigning An Approval Group section above.

  • The outgoing Approval Group will need to approve this replacement action before the new group will be assigned to the activity.

Deleting an Approval Group

To delete an Approval Group:

  • Select the checkbox of the group you want to delete, and then click on the trash can icon.

  • Click Yes to confirm.

  • You will receive a notification that the group has been deleted.

Note: You will not be able to delete an Approval Group if it is currently assigned to an activity. If this is the case, that Approval Group will need to be replaced before it can be deleted. See the Replacing An Approval Group section above for steps on how to do this.

  • No labels