Overview
The Temporary Approval permission allows organizations to delegate limited approval authority without granting users the ability to create permanent application policies.
This permission is ideal for organizations that want help desk technicians, junior administrators, or other trusted personnel to quickly resolve application and elevation requests while maintaining administrative oversight. Temporary approvers can restore productivity by allowing users to continue working immediately, while senior administrators retain control over permanent policy decisions.
Any approval created by a Temporary Approver is valid for 24 hours and must be reviewed by a user with a standard approval permission before it becomes permanent.
When to Use Temporary Approvals
Consider using Temporary Approvals when you want to:
- Delegate routine approval tasks to help desk or Tier 1 support staff.
- Reduce wait times for end users requesting software or elevation.
- Maintain centralized control over permanent Application Definitions and policies.
- Ensure all long-term approval decisions are reviewed by experienced administrators.
Granting the Temporary Approval Permission
The Temporary Approval permission is a standalone permission.
It cannot be combined with any other approval permission. If a user is assigned another approval permission, that permission takes precedence and the Temporary Approval permission is ignored.
Users assigned only this permission receive a limited approval experience designed specifically for temporary approvals.
What Temporary Approvers Can Access
Users with the Temporary Approval permission have access to only the areas required to perform temporary approvals.

Home Page
The Home page displays only:
- Time Spent Managing widget
- Notifications widget
- Favorites widget
All other dashboard widgets are hidden.
Organizations
Users can access the Organizations page; however, no organizations are displayed and no organization management functions are available.
Approval Center
Temporary Approvers have access to the Approval Center, where they can review and action supported approval requests.
What Temporary Approvers Can Approve
Temporary Approvers can only approve:
- Application (Execute) requests
- Elevation requests
They cannot approve other request types.
Application Approval Experience
When approving an application request, Temporary Approvers have a simplified approval workflow.
They can choose to:
- Use Installation Mode
- Use Learning Mode
- Use a ThreatLocker-created Application Definition
- Allow the application to run with elevation or without elevation

The approval is automatically scoped to only the requesting computer. Temporary Approvers cannot expand the approval to groups or the entire organization, customize Ringfencing, or create permanent Application Definitions or policies.
What Happens Behind the Scenes
When a Temporary Approver approves an application request, ThreatLocker automatically creates:
- A temporary hidden Application Definition
- A temporary policy with the same name as the Application Definition

These temporary objects allow the requested application to run only until the approval expires or is reviewed.
Temporary approvals automatically expire after 24 hours unless they are reviewed and converted into permanent policies.
Pending Review
After a Temporary Approver approves a request, the approval enters the Pending Review status.

Users with standard approval permissions can review these requests and determine the final policy that should be created.
Reviewing Temporary Approvals
A reviewer with a standard approval permission has the full approval experience available.
For application requests, the reviewer can choose to:
- Keep the temporary Application Definition created by the Temporary Approver.

- Discard the temporary Application Definition and execute the application in a testing environment to generate a new definition.

- Merge the definition into an existing Application Definition.

- Create a new permanent Application Definition.

- Permit the application for:
- The requesting computer
- A group of computers
- The entire organization

- Configure Ringfencing, if required.
- Configure whether the application should run with elevation.

For elevation requests, the reviewer can determine whether elevation should remain permitted as part of the permanent policy.
Once the review is completed, the temporary Application Definition and temporary policy are automatically removed and replaced with the permanent objects created during the review.
Temporary Approval Lifecycle
- An end user submits an Application or Elevation request.
- A Temporary Approver reviews the request.
- The Temporary Approver creates a temporary approval.
- ThreatLocker creates temporary hidden objects and allows the request for the requesting computer.
- The request moves to Pending Review.
- A standard approver reviews the request.
- The reviewer determines the permanent Application Definition and policy.
- The temporary objects are removed and replaced with the permanent configuration.
- If no review occurs, the temporary approval expires automatically after 24 hours.
Coming Soon: Customizable Temporary Approval Experience
Future releases will provide administrators with greater control over the Temporary Approval experience by allowing them to configure which options are available to Temporary Approvers.
Planned configuration options include:
- Approval Duration – Configure how long temporary approvals remain active before they expire, rather than using the default 24-hour expiration.
- Built-in Application Matching – Allow Temporary Approvers to approve requests using a matching ThreatLocker Built-in Application Definition when one is available.
- Elevation Control – Choose whether Temporary Approvers can create approvals that allow applications to run with elevation.
- Application Learning Method – Define how Application Definitions are generated during temporary approvals. Administrators will be able to choose whether Temporary Approvers can:
- Use Learning Mode
- Use Installation Mode
- Use both Learning Mode and Installation Mode
- Use ThreatLocker Built-in Application Definitions
- Approval Restrictions – Limit the available approval methods to ensure Temporary Approvers only create approvals that align with your organization's security policies.
These enhancements will allow organizations to tailor the Temporary Approval workflow to their operational and security requirements while maintaining oversight through the Pending Review process.
Help Center