To enable the Multi-Person Authorization feature, you must download, import, and deploy various authorization workflows from the Commvault Store. To download and view more information of each workflow, click the name of the workflow under the Authorization Workflow column.
Each workflow is designed for a specific operation. These workflows use a common internal workflow, called Get And Process Authorization, to request approvals from the appropriate approvers based on the configurations.
The individual workflow provides optional configuration that can be configured to meet various requirements. A configuration set in an individual workflow will override the identical configuration set in the Get And Process Authorization workflow.
The following configurations are available in both the Get and Process Authorization workflow and the individual workflows:
-
Users who can authenticate the request: The selected users can authenticate requests.
-
User groups which can authenticate the request: The users of the selected user groups can authenticate requests.
-
Number of approvers: Number of users to authorize the request.
To configure the imported workflow, on the Command Center, go to Developers tool > Workflow, click the Action button beside the workflow, select Configurations, and modify the settings as needed.
Authorization Workflow | Description | Configurations |
---|---|---|
Client Properties Modification Authorization | You can download and deploy this workflow in your CommCell environment to authenticate the exclusion of clients from the SLA and disable backup activity operations. | Select client groups in which excluding subclient from SLA will need authorization: The workflow will run for the selected client groups. This option applies to all of the supported client properties. |
Delete Agent Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete an agent. |
- Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting an agent. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting an agent. - Number of approvers: Number of users to authorize the request. |
Delete Backup Set Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete a backup set. |
- Select client groups for which backup set deletion will need authorization: The deletion of backup set from selected client groups would require authorization. - Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a backup set. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a backup set. - Number of approvers: Number of users to authorize the request. |
Delete Company Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete a company. |
- Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a company. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a company. - Number of approvers: Number of users to authorize the request. |
Delete Client Authorization | This operation triggers the authentication email request when a user attempts to retire or delete the client from the Commcell or company level. Note: This operation is enabled by default on Command Center. |
- Select client groups for which client deletion will need authorization:The deletion of clients from selected client groups would require authorization. - Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting the client . - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize the requests for deleting the client. - Number of approvers: Number of users to authorize the request. - Delete Client: By default, requires authorization from the configured approvers to delete a client. Move the toggle key to the left to skip authorizations and perform the delete operation. - Retire Client: By default, requires authorization from the configured approvers to retire a client. Move the toggle key to the left to skip authorizations and perform the retire operation. |
Delete Jobs Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete a job from a storage policy copy. |
- Set two factor authorization for Master user: Selecting this option will enforce Master group users to require authorization as well. - Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a job. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a job. - Number of approvers: Number of users to authorize the request. |
Delete Plan Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete a plan. |
- Select client groups for which backupset deletion will need authorization: The deletion of backup set from selected client groups would require authorization. - Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a plan. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a plan. - Number of approvers: Number of users to authorize the request. |
Enable Root Access Authorization | You can download and deploy this workflow in your CommCell environment to enable authentication for password-based root access on the HyperScale nodes. | N/A |
Delete Subclient Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete a subclient. |
- Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a subclient. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a subclient. - Number of approvers: Number of users to authorize the request. |
Delete Storage Policy Authorization | This operation triggers the authentication email request when a user attempts to delete the storage policies that is associated with a plan. Note: This operation is enabled by default on Command Center. |
- Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a storage policy. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a storage policy. - Number of approvers: Number of users to authorize the request. |
Delete Storage Policy Copy Authorization | This operation triggers the authentication email request when a user attempts to delete the storage policy copies that is associated with a plan. Note: This operation is enabled by default on Command Center. |
- Users who can authenticate the request: The selected users can authenticate or authorize requests for deleting a storage policy copy. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for deleting a storage policy copy. - Number of approvers: Number of users to authorize the request. |
Delete SQL Database Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user attempts to delete the SQL Database. | N/A |
Modify Active Job Authorization | You can download and deploy this workflow in your CommCell environment to authenticate for killing or suspending the active jobs on Job Controller. |
- Set two factor authorization for Master user: Selecting this option will enforce Master group users to require authorization as well. - Users who can authenticate the request: The selected users can authenticate or authorize requests for modifying active jobs. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for modifying active jobs. - Number of approvers: Number of users to authorize the request. |
Modify Additional Settings Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when a user modifies an company additional setting associated with the Security IQ dashboard. | N/A |
Restore Request Authorization | You can download and deploy this workflow in your CommCell environment to authenticate when the user requests restore operation. |
- Select client groups for which restore requests will need authorization: The selected restricted client groups need authorization to perform restores. - Select users to perform restore operations without authorization: The selected users are allowed to perform restores. - Select user groups to perform restore operation without authorization: Users in the selected user groups are allowed to perform restores. - Set two factor authorization for Master user: Selecting this option will enforce Master group users to require authorization as well. - Users who can authenticate the request: The selected users can authenticate or authorize requests for restoring a job. - User groups which can authenticate the request: The users of the selected user groups can authenticate or authorize requests for restoring a job. - Number of approvers: Number of users to authorize the request. |
Subclient Properties Modification Authorization | You can download and deploy this workflow in your CommCell environment to authenticate the requests to update the subclient properties. | Select client groups in which excluding subclient from SLA will need authorization: The workflow will run for the subclients in the selected client groups. This option applies to all of the supported subclient properties. |
Uninstall/Delete Client Restriction | You can download and deploy this workflow in your CommCell environment to authenticate the uninstall, retire, and delete client associated with the client group selected in the Restrict Client Groups configuration. | Restrict Client Groups: Select the client groups for which the associated clients require authorization to perform uninstall, retire, and delete client request. |
Delete Library Mount Path Authorization | This operation triggers the authentication email request to delete a library, a mount path, or a backup destination. Note: This operation is enabled by default on Command Center. |
Restrict Client Groups: Select the client groups for which the associated clients require authorization to perform uninstall, retire, and delete client request. |
Disable Compliance Lock | This operation triggers the authentication email request to disable Compliance Lock option on storage. Note: WORM Storage cannot be disabled. It is not possible to disable Compliance lock without appropriate authorization code. |
Restrict Client Groups: Select the client groups for which the associated clients require authorization to perform this action. |