The Approver Request List
Approvers on a user input view usually have no account: the e-mail carrying their decision link is the only copy. The approver request list gives that link back. An approver proves they control their mailbox and sees every approval link already e-mailed to that address, without being given an account.
Where to find it
Architect Panel → Configuration:
- Site Settings — the Approver Request List group switches it on and sets its rules
The page approvers use is at /ajax/uivrequests.php on your site. It ships switched off; until you enable it the page says This page is not available.
How it works for an approver
- They open the page, enter Your e-mail address and press E-mail me a link. The page answers the same way whatever address is entered, so it cannot be used to discover who your approvers are.
- If the address is allowed, they receive an access link. It works for a set number of minutes and can be used repeatedly within that time, so the browser Back button does not break it.
- The link opens Your approval requests: one entry per request, those still awaiting their decision first and then the most recently e-mailed, with its process, stage, reference number, when it was first sent and how many reminders followed.
- Each entry has a status such as Awaiting your decision, You approved this, You declined this, You asked for more information, Timed out, Cancelled by the applicant or Declined at another stage, and a link to open it.
The page can only re-show links that were actually sent to that address and are still valid. It never creates a link, never reaches a request that address was not sent, and never signs anybody in.
The settings
- Enable the approver request list: the master switch, off by default.
- Accepted e-mail domains: semicolon-separated. Leave empty to accept any domain. A leading
*matches sub-domains only:*.nhs.ukacceptstrust.nhs.ukbut not a barenhs.ukaddress, and notnhs.net. List each form you mean, for example*.nhs.uk;nhs.uk;nhs.net. - Minutes an access link lasts: default 60, between 5 and 1440.
- Send access links from: the e-mail account ID that sends the access link. At 0 it works only when there is exactly one account; with several and none named, nothing is sent. Set it explicitly.
- E-mail log rows to examine: how far back through sent mail one page load looks, default 5000. When the limit is reached the page says older requests may not be listed.
Telling approvers it exists
Once it is switched on, automatically written approver e-mails include a sentence linking to the page. A stage that uses its own e-mail template gets that sentence only if the template contains ##AMDATA/MYREQUESTSLINE## (the sentence) or ##AMDATA/MYREQUESTSURL## (just the address). While the feature is off both tags are replaced with nothing, so they are safe to add in advance.
Before you switch it on
- It is a disclosure decision. Anyone who controls an approver's mailbox can already read the links in it; this makes them reachable from a web page too, for as long as the access link lasts. Agree it with whoever owns the process.
- Check your approvers' domains. A domain rule that leaves some out fails silently: those approvers see the same check your e-mail message and simply never receive anything.
Worked example
A work-experience hub's placement supervisors keep deleting approval e-mails and then asking for applications to be re-sent. The hub enables the list, sets Accepted e-mail domains to *.nhs.uk;nhs.uk;nhs.net after checking that none of its supervisors use another domain, names the hub's own e-mail account in Send access links from, and leaves the link lifetime at 60 minutes. Supervisors now find the page linked in every automatically written approval e-mail and recover lost links themselves.
Recommendations
- Agree the disclosure before enabling it.
- List every domain form you need; the wildcard does not cover the bare domain.
- Name the sending account.
- Add the tag to custom approver templates so the page is discoverable.