Mode 3: Approver Workflow (Grants)
Follow these steps when an Approver needs to review, approve, or reject pending grant requests raised by requesters.
(Rule: Select the scope flag matching where the entitlement/grant is located:
pass --project=PROJECT_ID, --folder=FOLDER_ID, or
--organization=ORGANIZATION_ID).
Table of Contents
- Prerequisites & Permissions
- Step 1: Search Pending Grants
- Step 2: Approve Pending Grant
- Step 3: Deny Pending Grant
Prerequisites & Permissions {#prerequisites}
- Approver Authorization: To become an approver, the user simply must be
added to the
approverslist in the entitlement'sapprovalWorkflowconfiguration. No explicit IAM roles are required. - Discover Grants to Approve: Approvers can directly search for grants
they are authorized to approve across a project, folder, or organization
using
gcloud pam grants search --caller-relationship=can-approvewithout needing theroles/privilegedaccessmanager.viewerrole or knowing specific entitlement IDs beforehand.
Step 1: Search Pending Grants {#step-1}
Approvers can search directly for pending grants awaiting their decision across a project, folder, or organization:
gcloud pam grants search \
--caller-relationship=can-approve \
--location=global \
--project=PROJECT_ID(Or pass --folder=FOLDER_ID, --organization=ORGANIZATION_ID matching the
target resource hierarchy).
You can also list all grants for a specific entitlement if the entitlement ID is already known:
gcloud pam grants list \
--entitlement=ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID(Note: Read-only search/list operations run autonomously without user prompt).
Step 2: Approve Pending Grant {#step-2}
When the user asks to approve a pending PAM grant:
- Verify grant existence and state using
gcloud pam grants describeorsearch. - Prompt the user to provide a justification string for the approval.
- Prompt the user for explicit approval under Plan-Validate-Execute rules:
"You are about to approve PAM Grant
GRANT_IDunder entitlementENTITLEMENT_IDwith reason: 'USER_PROVIDED_REASON'. Do you approve? (Yes/No)" - Execute approval:
gcloud pam grants approve GRANT_ID \
--entitlement=ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID \
--reason="USER_PROVIDED_REASON"Step 3: Deny Pending Grant {#step-3}
When the user asks to deny or reject a pending PAM grant:
- Verify grant existence and state using
gcloud pam grants describeorsearch. - Prompt the user to provide a justification string for the denial.
- Prompt the user for explicit approval under Plan-Validate-Execute rules:
"You are about to deny PAM Grant
GRANT_IDunder entitlementENTITLEMENT_IDwith reason: 'USER_PROVIDED_REASON'. Do you approve? (Yes/No)" - Execute denial:
gcloud pam grants deny GRANT_ID \
--entitlement=ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID \
--reason="USER_PROVIDED_REASON"