Self-Service SaaS Entitlement Transfers: Details
Environment
Introduction: Empowering Your Entitlement Management
The Customer Support Portal (CSP) now includes enhanced self-service capabilities for transferring SaaS entitlements within the Prisma Access+ product group, introduced as part of this update. This powerful feature moves you from a manual, ticket-driven process to an empowered self-service model, which enhances your operational agility and accelerates time-to-value. You can now manage and move your own Prisma Access+ entitlements between accounts directly, without needing to create support tickets.
This section provides a comprehensive overview of the self-service transfer process particularly those with the Superuser role. We will explore the available transfer options, the specific permissions required for different user roles, the end-to-end approval workflows, and the integrated notification system that keeps you informed at every step.
To use this feature effectively and securely, it is essential to first understand the roles and permissions that govern the transfer process.
Core Principles of SaaS Entitlement Transfers
Before initiating a transfer, it is important to understand the fundamental rules that govern the process. These principles are designed to ensure that every transfer is predictable, transparent, and does not disrupt the underlying service configurations or tenant allocations associated with your SaaS products.
-
Transfer by Entitlement Group Transfers are executed at the entitlement group level. This means a single transfer action moves all associated entitlements tied to that specific SaaS entitlement group ID. This ensures the entitlement group id moves as a single, atomic unit.
-
No Impact on TSG Allocation A key update is the delinking of the Customer Support Portal (CSP) account from the Tenant Service Group (TSG) for SaaS products. Consequently, transferring an entitlement between different CSP accounts will not impact or alter the underlying TSG allocation. This allows for administrative flexibility within the CSP without affecting the technical configuration of your services.
-
In-App Notifications To provide full visibility, the system generates notifications within the application for both the transferring (sending) and the receiving accounts once a transfer is successfully completed. This ensures all relevant stakeholders are immediately aware of the change in entitlement ownership.
Understanding these core principles allows for a smooth and confident management experience, which is further detailed in the step-by-step guides for different user roles.
Understanding Transfer Roles and Superuser Permissions
The entitlement transfer process is governed by a clear system of roles and permissions to ensure proper account governance and security. Understanding who can initiate a transfer and who must approve it is the foundation of managing your SaaS entitlements effectively within the CSP. Two primary user roles are involved: the Superuser and the Standard User.
|
User Role |
Transfer Capabilities & Limitations |
|
Superuser |
Can directly initiate and complete transfers without requiring further approval. They can review, approve, or reject transfer requests initiated by Standard Users on their account. Crucially, Superusers are the only role that can configure the transfer approval settings for the entire account. |
|
Standard User |
Can initiate entitlement transfers. However, their ability to complete a transfer directly depends on the account's approval settings, which are managed by a Superuser. They cannot manage approval settings, as the Account Actions tab is not visible to users with this role. |
Managing Transfer Approval Requirements
Superusers have direct control over the transfer workflow for their accounts. By default, any transfer initiated by a Standard User requires Superuser approval. A Superuser can modify this setting by following these steps:
-
Navigate to Account Management: From the main CSP menu, select Account Management, then Account Details.
-
Access Account Actions: Click on the Account Actions tab.
-
Locate the Approval Setting in TRANSFER PERMISSIONS: Find the checkbox labeled "Require approval by Super User of this account for Entitlement Transfer". This setting is enabled by default.
-
Configure the Setting:
-
To require approvals (default): Keep the box checked. All transfers initiated by Standard Users will enter a pending state awaiting Superuser review.
-
To allow direct transfers: Uncheck the box. Standard Users will be able to complete transfers immediately without requiring Superuser approval.
-
Note: This transfer approval setting applies specifically to Prisma Access+ products.
With a clear understanding of these roles and controls, we can now explore the specific workflows for initiating and completing a transfer.
Core Transfer Workflows
The exact steps required to complete an entitlement transfer vary based on two key factors: the role of the user initiating the transfer (Superuser vs. Standard User) and the account's "Super User Approval" setting. To provide upfront reassurance, it's important to know that transferring entitlements between CSPs does not impact the TSG allocation. Below are the three primary workflows you may encounter.
Workflow A: Superuser Initiates a Transfer
When a Superuser initiates an entitlement transfer, the process is direct and streamlined. Because the action is performed by a user with the highest level of permissions, no additional approvals from the source account are necessary, regardless of the account's approval setting.
-
The Superuser navigates to the Products-> Assets page -> Prisma Access + tab and selects the Entitlement Group ID they wish to transfer.
-
They initiate the transfer, specifying either a destination CSP Account ID or a specific User Email address.
-
The transfer is processed immediately. In the Outgoing Transfers log, its status is set directly to "Approved".
-
The Entitlement Group is successfully moved from the source account. It will appear in the destination account's assets or, if sent to an email address, will await acceptance from the destination user.
Workflow B: Standard User Initiates a Transfer (Superuser Approval REQUIRED)
This is the default and most common workflow for Standard Users. It includes a mandatory approval step by a Superuser on the source account to ensure proper governance.
-
A Standard User selects an Entitlement Group from Products-> Assets page -> Prisma Access + tab and initiates the transfer.
On submitting the Transfer the entitlement group reflects ‘Transfer Pending’
And in the Outgoing Transfer (accessed by clicking on ‘Account Actions’ -> ‘Outgoing Transfers’ , The transfer's status is immediately set to "Pending Super User Approval".
All Superusers on the source account receive an "Action Required" notification, both via email and the in-app notification bell.
-
A Superuser navigates to the Outgoing Transfers log to review the details of the pending request.
-
The Superuser reviews the request and makes a decision:
-
If Approved: The Superuser approves the request in the portal. The transfer is processed, and the entitlement is successfully moved to the destination.
-
If Rejected: The Superuser rejects the request. The transfer fails, and the entitlement remains in the source account.
-
Workflow C: Standard User Initiates a Transfer (Superuser Approval DISABLED)
This workflow is only active if a Superuser has explicitly disabled the approval requirement for the account. In this scenario, Standard Users are empowered to execute transfers directly.
-
A Standard User selects an Entitlement Group and initiates the transfer.
-
Because Superuser approval has been disabled for the account, the system processes the transfer immediately without a pending period.
-
The transfer's status in the Outgoing Transfers log is set to "Approved", and the entitlement is successfully moved from the source account.
While transfers to a specific account ID are complete at this stage, transfers sent to a user's email require a final approval step from the recipient, as detailed in the next section.
Destination-Side Approval: The Recipient's Role
When an entitlement is transferred to a specific user's email address instead of directly to a CSP account ID, the recipient must actively accept the transfer. This step serves as a safeguard, ensuring the entitlement is placed into the correct destination account as intended by the recipient.
The workflow for the destination user is as follows:
-
Once all necessary source-side approvals are complete, the transfer status updates to "Pending Destination User Approval".
-
The designated destination user receives an "Action Required" notification via email and the in-app notification bell, alerting them that an entitlement is awaiting their action.
-
The user logs into the CSP where they want to accept the entitlement transfer and navigates to the Incoming Transfers log to view the pending transfer. They can access the Incoming Transfers page from ‘Account Actions’ in any of the Product Tabs (ex: Prisma Access + or the other tabs like ‘All Assets/Asset List’
-
The user reviews the transfer details and makes a decision:
-
To Accept: The user approves the transfer. The transfer is completed, and the entitlement is moved into that account's assets.
-
To Decline: The user rejects the transfer. The transfer fails, and the entitlement is not moved, remaining in the original source account.
-
This workflow highlights the flexibility of choosing different transfer destinations, which we will compare next.