Approvals
/admin/requests (sidebar Approvals, under Administration) is the reviewer inbox for virtual-key requests, budget changes and governed spend requests. The sidebar badge is the pending count.
Who can open it
Anyone with at least one reviewable team: platform admin (all teams), org admin (every team in their org), or team admin. Users named as an approver or escalation contact on a spend governance policy can also open it for those requests. Others are redirected to the dashboard.
Pending vs decided
Pending: alias, type, requester, team, created, budget/limits, actions.
Decided: status, reviewer, review note, reviewed-at.
Stat cards: pending, approved (7d), rejected (7d), average approval time.
Approve or reject
- Approve — mints a
VirtualKeyinPENDING_REVEAL - Approve with overrides — change access group, tier, budget, duration, RPM, TPM or expiry before minting
- Reject — optional note goes back to the requester
Approve from email, Slack or Teams
Approval emails (new key requests, governed requests) carry Approve and Reject buttons next to Review request. Slack and Teams posts for new key requests carry Approve, Reject and Open in portal.
- A button opens a confirmation page that shows the request (requester, what is asked, team, how long it has waited). Nothing is decided until you press Approve request or Reject request there, so link previews and mail scanners can't approve anything.
- Email links are personal: each approver gets their own, they work without
signing in (unless
APPROVAL_LINKS_REQUIRE_SIGNIN=true), and they expire after 3 days. - Slack and Teams links are shared by the channel, so they ask you to sign in and then check that you can review the request.
- When the decision is made, the same rules as the inbox apply: your current
role and team admin rights are checked again, a request can only be decided
once, and the audit log records the decision with
via: email-linkorvia: chat-link. Opening a link for a request someone already decided shows who decided it and when.