Temporary Approvals

4 min. readlast update: 09.04.2026

Overview

The Temporary Approval permission allows organizations to delegate limited approval authority without granting users the ability to create permanent application policies.

This permission is ideal for organizations that want help desk technicians, junior administrators, or other trusted personnel to quickly resolve application and elevation requests while maintaining administrative oversight. Temporary approvers can restore productivity by allowing users to continue working immediately, while senior administrators retain control over permanent policy decisions.

Any approval created by a Temporary Approver is valid for 24 hours and must be reviewed by a user with a standard approval permission before it becomes permanent.


When to Use Temporary Approvals

Consider using Temporary Approvals when you want to:

  • Delegate routine approval tasks to help desk or Tier 1 support staff.
  • Reduce wait times for end users requesting software or elevation.
  • Maintain centralized control over permanent Application Definitions and policies.
  • Ensure all long-term approval decisions are reviewed by experienced administrators.

Granting the Temporary Approval Permission

The Temporary Approval permission is a standalone permission.

It cannot be combined with any other approval permission. If a user is assigned another approval permission, that permission takes precedence and the Temporary Approval permission is ignored.

Users assigned only this permission receive a limited approval experience designed specifically for temporary approvals.


What Temporary Approvers Can Access

Users with the Temporary Approval permission have access to only the areas required to perform temporary approvals.

Home Page

The Home page displays only:

  • Time Spent Managing widget
  • Notifications widget
  • Favorites widget

All other dashboard widgets are hidden.

Organizations

Users can access the Organizations page; however, no organizations are displayed and no organization management functions are available.

Approval Center

Temporary Approvers have access to the Approval Center, where they can review and action supported approval requests.


What Temporary Approvers Can Approve

Temporary Approvers can only approve:

  • Application (Execute) requests
  • Elevation requests

They cannot approve other request types.


Application Approval Experience

When approving an application request, Temporary Approvers have a simplified approval workflow that can be customized using the Advanced Setting - Temporary Approval Settings.

 


What Happens Behind the Scenes

When a Temporary Approver approves an application request, ThreatLocker automatically creates:

  • A temporary hidden Application Definition 
  • A temporary policy with the same name as the Application Definition

These temporary objects allow the requested application to run only until the approval expires or is reviewed.

Temporary approvals automatically expire after 24 hours unless they are reviewed and converted into permanent policies.


Pending Review

After a Temporary Approver approves a request, the approval enters the Pending Review status.

Users with standard approval permissions can review these requests and determine the final policy that should be created.


Reviewing Temporary Approvals

A reviewer with a standard approval permission has the full approval experience available.

For application requests, the reviewer can choose to:

  • Keep the temporary Application Definition created by the Temporary Approver.
  • Discard the temporary Application Definition and execute the application in a testing environment to generate a new definition.
  • Merge the definition into an existing Application Definition.
  • Create a new permanent Application Definition.
  • Permit the application for:
    • The requesting computer
    • A group of computers
    • The entire organization

  • Configure Ringfencing, if required.
  • Configure whether the application should run with elevation.

For elevation requests, the reviewer can determine whether elevation should remain permitted as part of the permanent policy.

Once the review is completed, the temporary Application Definition and temporary policy are automatically removed and replaced with the permanent objects created during the review.


Temporary Approval Lifecycle

  1. An end user submits an Application or Elevation request.
  2. A Temporary Approver reviews the request.
  3. The Temporary Approver creates a temporary approval.
  4. ThreatLocker creates temporary hidden objects and allows the request for the requesting computer.
  5. The request moves to Pending Review.
  6. A standard approver reviews the request.
  7. The reviewer determines the permanent Application Definition and policy.
  8. The temporary objects are removed and replaced with the permanent configuration.
  9. If no review occurs, the temporary approval expires automatically after the configured exipration time.

 

Was this article helpful?