SASE allows you to create approval workflows for SASE services and third-party applications, and configure settings such as approvers and Approval Permissions. This article describes how to create an approval workflow.
Create an approval flow
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Workflow Management page, click Create Workflow.
-
In the Create Approval Workflow panel, configure the following parameters.
Parameter
Description
Workflow Name
Enter a name for the approval flow.
The name must be 1 to 128 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Approval Process Type
Select the approval flow type.
-
Built-in Approval Process: An approval flow for SASE services.
-
DingTalk Approval Process: An approval flow integrated with DingTalk.
-
WeCom Approval Process: An approval flow integrated with WeCom.
The required parameters depend on the selected Approval Process Type. Configure the parameters accordingly.
Built-in approval flow
Parameter
Description
Approval Workflow
Define the approval process by adding at least one and up to five approval levels.
The request is approved as soon as one approver approves it, and rejected as soon as one approver rejects it.
Application Review
Select one or more workflow templates. If you do not select a template for a specific policy type, you cannot associate that policy type with this workflow.
The workflow templates include the following types:
-
Domain Name Whitelist Template
This template is used for whitelist policies in .
-
Domain Name Blacklist Template
This template is used for blacklist policies in .
-
Software Blacklist Template
This template is used for blacklist policies in .
-
File Exfiltration Template
This template is used for file exfiltration detection policies in .
-
App Uninstall Policy Template
This template is used for uninstall policies in .
-
Peripheral Control Template
This template is used for detection policies in .
DingTalk approval flow
Parameter
Description
Client ID
The DingTalk application ID.
Client Secret
The DingTalk application secret.
aes_key
The encryption key for DingTalk event subscriptions.
token
The signature token for DingTalk event subscriptions.
Request URL
The public URL for DingTalk to receive event subscriptions.
ImportantCopy this URL to DingTalk Open Platform > Application Development > Enterprise internal applications > DingTalk Apps > Development Configuration > Event Subscriptions > Request URL.
Approval Process Configuration
Configure the association and field mapping between the SASE approval template and the DingTalk Approval Flow.
-
Workflow Template: The built-in workflow template in SASE.
-
Associate DingTalk Process ID: Enter the form ID of the DingTalk approval flow.
-
System Fields: The read-only, built-in system fields of the workflow template.
-
Template Fields: The fields configured in the associated DingTalk flow.
NoteA SASE approval flow can be bound to multiple approval forms that are created in the same DingTalk application. You can click Add to configure different approval flows.
WeCom approval flow
To configure this flow type, an administrator must first authorize it by scanning a QR code with the WeCom client. You must then contact Alibaba Cloud support to complete the backend configuration. After the backend is configured, you can proceed with the approval flow settings below.
Parameter
Description
Approval Template Mapping
Configure the built-in SASE workflow template and enter the flow ID that corresponds to the WeCom approval template.
Field ID Mapping
Map the system fields of the SASE workflow template to the fields of the WeCom approval template.
-
-
Click OK.
Other operations
-
Copy a workflow: To copy an existing approval flow, click Copy in the Operation column.
NoteThis operation is supported only for built-in approval flows.
-
Edit a workflow: To edit an approval flow, click Edit in the Operation column.
-
Delete a workflow: You can delete an approval flow only if it is not associated with any policies. To delete an eligible flow, click Delete in the Operation column.
Related documents
-
To view statistics for all approval flows in your organization, see View flow instance statistics.
-
You can apply a built-in workflow template to peripheral devices to enhance data security. For more information, see Enhance data security by managing peripheral devices.
-
To learn how to integrate a WeCom approval flow, see Best practices for integrating a WeCom approval flow.
-
To learn how to integrate a DingTalk approval flow, see Best practices for integrating a DingTalk approval flow.