Manage user access requests in Slack and Teams

Last updated:

When a user receives a Pendo link, for example through a Slack or Microsoft Teams message, they can open the link and request to join Pendo. This starts the access request approval process.

This article explains what access requests are, who manages them, and how to add approvers in Pendo.

Overview

When someone clicks a Pendo link and doesn't have an account, they're taken to the Pendo login screen. By attempting to sign in, the person triggers an access request. Any subscription admin can approve or deny requests directly in Pendo. Designated subscription admins are notified in Slack or Microsoft Teams, depending on which integration is enabled, where they can approve or deny the request through a DM.

When a request is approved, Pendo creates a user account with Viewer (read-only) access to the apps the admin configured. You can update permissions at any time from the Users tab.

Access requests are managed from in Settings > Users and teams > Access Requests.

How it works

Access requests involve three roles:

  • Subscription admin. Sets up and controls access requests, and can approve or deny any request in Pendo.
  • Notified approver. A subscription admin who has connected their Pendo account to Slack or Microsoft Teams. They receive a DM for each new request and can approve or deny it from the chat.
  • Requestor. The person asking for access.

The process to enable and manage access requests is:

  1. A subscription admin enables access requests.
  2. In the Configuration tab of Access Requests, the admin sets up the following to apply to all incoming requests:
    • App access. The apps an approved user is given Viewer, read-only access to.
    • Permitted domains. The email domains a request can come from. Requests from any other domain are rejected automatically.
  3. (Optional) The subscription admin adds notified approvers, admins who have connected Pendo to Slack or Microsoft Teams, so they receive a DM whenever a request comes in.
  4. A requestor follows a Pendo link without an account and triggers an access request.
  5. A notified approver approves or denies the request from their DM, or any subscription admin manages it from the Requests tab in Pendo.
  6. The requestor is notified of the decision by email. If approved, Pendo creates their account with Viewer access to the configured apps and adds them to the Users list.

Prerequisites

To use access requests:

  • You must be a subscription admin to enable and set up access requests.
  • SSO (single sign-on) must be enabled for your subscription. For more information, see Set up SAML Single Sign-On (SSO).
  • SCIM (System for Cross-domain Identity Management) must not be enabled for your subscription. For more information, see Set up SCIM in Pendo.
  • Either the Slack or Microsoft Teams integration must be active to send DM notifications to approvers. The access request flow works without an integration (requests can still come from email or any Pendo link), but approvers won't receive DMs.

To appear in the notified approvers list, a subscription admin must have connected their Pendo and Slack or Microsoft Teams accounts by doing one of the following:

  • Enter the command /pendo login into chat.
  • Use Ask Pendo.
  • Send feedback from Slack or Microsoft Teams to Pendo Listen.

Step 1. Enable access requests

Access requests aren't on by default. To enable them:

  1. In Pendo, go to Settings > Subscription settings.
  2. In the Security and privacy section, locate the Allow user access requests setting.

    access-requests-setting.png

  3. Select the checkbox to enable access requests for your subscription.
  4. A confirmation modal asks you to confirm enablement. Type I understand and select Enable to proceed.

You can remove access requests at any time by deselecting this setting.

Step 2. Configure access requests

Before access requests will work, you must configure at least one app and at least one domain on the Configuration tab. If you haven't selected at least one app and one domain, access requests won't work even if the feature is enabled. The Configuration tab will show a warning until both are set.

  1. In Pendo, go to Settings > Users and teams > Access Requests.
  2. Select the Configuration tab.
  3. In the section App access, enable the apps that new users can access when approved.
  4. In the section Permitted domains, select at least one domain to allow requests to be received from users with that email domain. The domains available come from your SAML SSO configuration, see Set up SAML Single Sign-On (SSO) for more information.

Note: App configuration at the time of the request determines what access an approved user receives. If you change the configuration after a request is submitted, it only affects future requests, not pending or approved ones.

All approved users receive Viewer (read-only) access by default for the apps selected. This is the lowest-privilege role and can't be changed at the point of approval. You can update a user's permissions from the Users tab after they've joined.

Step 3. Add notified approvers

Notified approvers are subscription admins who can approve or deny access requests outside of the Pendo app in either Slack or Microsoft Teams, whichever integration is set up for your subscription. Notified approvers receive DMs alerting them to new access requests, where they can then select to approve or deny.

To set up a notified approver:

  1. In Pendo, go to Settings > Users and teams > Access Requests.
  2. Select the Notified approvers tab.
  3. Select Add notified approver.
  4. In the modal, select the admins you want to grant approval access to. The logo of the supported integration where they'll receive notifications is next to the name of the user.
  5. Select Add.

A notified approver is successfully added and can start receiving notifications about access requests in the specified integration.

Step 4. Manage an access request

A person can request access any time they follow a Pendo link without an account. When they click on a Pendo link, they're directed to the Pendo login page and prompted to sign in via SSO. If they don't have an account, this triggers the access request flow.

For the notified approver, they receive a DM from Pendo notifying them that a request has been submitted. The message includes the requestor's name, email, role, the date of the request, and the subscription they're requesting access to.

To manage the request in Slack or Microsoft Teams:

  1. In the notification DM, select Approve to allow the user to join Pendo.
  2. In the notification DM, select Deny to deny the person access to Pendo.
  3. If you select Deny, you can provide a reason. The reason is visible to other subscription admins only.
  4. Select Submit to confirm the response.

When an approver actions the request, the requestor receives an email with the status. If the request is approved, Pendo creates a user account with Viewer (read-only) access to the configured apps, and the requestor receives a link to the original Pendo URL they tried to open. From that point, the user is managed the same way as any other Pendo user.

Note: An approver can deny a request even after it's been approved, either in Pendo or from Slack or Microsoft Teams. This overrides the approval, removes the user from the subscription, and sends the requestor a denial email.

Manage access request in Pendo

Any subscription admin can review and action requests from the Requests tab in Settings > Users and teams > Access Requests. This tab shows all pending, approved, and denied requests. Admins can approve or deny directly from this page without a Slack or Microsoft Teams connection.

Was this article helpful?
0 out of 0 found this helpful