> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up Manager Approval

> TruU supports two methods for enabling Manager Approval when users attempt to verify or enroll their devices: Verification by Entitlement Group Verification by User’s Manager (from User Directory) This guide outlines how each option works and how to configure the appropriate workflow.

## Overview of Manager Approval Methods

| Method                                          | Description                                                                                                                          | When to Use                                                                                                                           |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------- |
| Verification by Entitlement Group               | A designated entitlement group is created in TruU. Members of this group are responsible for approving device verification requests. | When you want a specific set of managers or approvers (not tied to user directory) to review and approve new user device enrollments. |
| Verification by User’s Manager (User Directory) | The device approval request is automatically routed to the user’s manager assigned in the user directory.                            | When your organization’s user directory manager reporting structure is populated and can be used operationally.                       |

## Verification by Entitlement Group

**Prerequisites**

* You must create an entitlement group in TruU before enabling manager approval workflow.
* Add all intended approvers (managers or delegated reviewers) to this group.

### Create Entitlement Group

1. In the TruU Admin Console, navigate to Entitlement Groups and Click Add User Entitlement.

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/4653f05af1f5210d2b8de82dde946ba24ba53fb1d84bf4a642827d00ee9bd519-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=60e65afdfdc49f1cabac9727fbd94753" alt="" width="1149" height="542" data-path="images/docs/4653f05af1f5210d2b8de82dde946ba24ba53fb1d84bf4a642827d00ee9bd519-image.png" />

2. Under Add Entitlement Group,

   1. Provide a group name (e.g., “Device Approval Managers”).
   2. Entitlement Group Description
   3. Assign to certain directory groups our add directory users who will be responsible for approving device verification requests.

   <img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/bee66b2a72b58baf08e62790e2645032dd457a9799b2e5cc3eb7164705495023-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=f781c9b9ccfa0ebc6a2ca3e695fb6257" alt="" width="680" height="632" data-path="images/docs/bee66b2a72b58baf08e62790e2645032dd457a9799b2e5cc3eb7164705495023-image.png" />

3. Save the group.

<img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/d69d8b0ed56cf91c4aef4f501ae3adfb1e35435cd6c10b352bbebc97897e69e6-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=68d33a0152bc5f47ae397c6c2feae3a6" alt="" width="680" height="632" data-path="images/docs/d69d8b0ed56cf91c4aef4f501ae3adfb1e35435cd6c10b352bbebc97897e69e6-image.png" />

### Set up Manager's Approval Workflow

1. Go to User Identification and Click *Add Identity Verification Workflow* on top right

<img src="https://mintcdn.com/truu-2/m22YLP0oXSNG0U3O/images/docs/79dbf8e36ddd83531a3d80b990b25979677409288cad552be5ce3c258d74cf0c-image.png?fit=max&auto=format&n=m22YLP0oXSNG0U3O&q=85&s=515f1ee4f042ab6a0e3b43ae97d20906" alt="" width="842" height="395" data-path="images/docs/79dbf8e36ddd83531a3d80b990b25979677409288cad552be5ce3c258d74cf0c-image.png" />

2. Provide a workflow name and select the User Self-Service needed

<img src="https://mintcdn.com/truu-2/L38yxuvvUa8uAW5I/images/docs/106eee5255a31c5457a66b8e72070b8a9f1436786f346090646cca15b94373c3-image.png?fit=max&auto=format&n=L38yxuvvUa8uAW5I&q=85&s=e2f6f1ae68110ed04ecbc41d0c01a95d" alt="" width="530" height="729" data-path="images/docs/106eee5255a31c5457a66b8e72070b8a9f1436786f346090646cca15b94373c3-image.png" />

3. Select **Add Identity Verification Step**

<img src="https://mintcdn.com/truu-2/m22YLP0oXSNG0U3O/images/docs/6da2f874f8a7f1685914a7be31a5e0adadf702de3d33710a01316858db94bb5d-image.png?fit=max&auto=format&n=m22YLP0oXSNG0U3O&q=85&s=86771b01a86791713bd3ba8dd39ad9f1" alt="" width="530" height="729" data-path="images/docs/6da2f874f8a7f1685914a7be31a5e0adadf702de3d33710a01316858db94bb5d-image.png" />

4. Choose the approvers needed.

<img src="https://mintcdn.com/truu-2/L38yxuvvUa8uAW5I/images/docs/214b5653eb743cbeb5563ac1b7cd3b1265ae8d4a99bc9756feaf72a14c9f8213-image.png?fit=max&auto=format&n=L38yxuvvUa8uAW5I&q=85&s=d8d329693bda28e8d9aeb62c61b11d35" alt="" width="699" height="918" data-path="images/docs/214b5653eb743cbeb5563ac1b7cd3b1265ae8d4a99bc9756feaf72a14c9f8213-image.png" />

i. For **Verification by Entitlement Group**, Select the entitlement group created previously.

<img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/92b907b6fa793615157fe3d2dda58364b325bb0442dbf44e84eff7b2031be742-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=ae75abec04fc3d3eb1ffaa9b70c63122" alt="" width="842" height="749" data-path="images/docs/92b907b6fa793615157fe3d2dda58364b325bb0442dbf44e84eff7b2031be742-image.png" />

ii. For **Verification by User's Manager**, Select a default action if there is no manager saved for that User.

<img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/bb7691702440740cff164409a2f3ab6f70f79c958c0f30fbde6fa9e48c438c8b-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=794cbbec2f73cfbf4384e27e6092135b" alt="" width="842" height="749" data-path="images/docs/bb7691702440740cff164409a2f3ab6f70f79c958c0f30fbde6fa9e48c438c8b-image.png" />

5. Choose the Allowed Verification Methods for the managers.

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/2a906b6be216582eb953011f4953a5a886b9d54b2b5d0113f09bdb4ab61bb552-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=bf91062fa850c5608b9f2b47eae712cc" alt="" width="842" height="749" data-path="images/docs/2a906b6be216582eb953011f4953a5a886b9d54b2b5d0113f09bdb4ab61bb552-image.png" />

6. Select **Require verification to use device for authentication**

**Note**: Devices will be enrolled after completing the self-service portion of enrollment with a state of ‘Unverified’ (which is below ‘Basic’). If a user tries to use this device for authentication, they will be prevented from using it.

<img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/921f102c185de045b10870d2e52fcc961862dfac0698879e7780674613ec5f79-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=ce541490434e3a5dbb99adf49462ad27" alt="" width="842" height="749" data-path="images/docs/921f102c185de045b10870d2e52fcc961862dfac0698879e7780674613ec5f79-image.png" />

7. Click Save to complete this workflow set up.

<img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/6825c8c874d065cdc0cafb5fc2a063d3054efda7d6430e01294adf1140f19fd2-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=3f9059940f8cd54f1597ead0fd68d817" alt="" width="842" height="749" data-path="images/docs/6825c8c874d065cdc0cafb5fc2a063d3054efda7d6430e01294adf1140f19fd2-image.png" />

***

[Settings: User Identification](/docs/settings-user-identification)
