Secure Access Service Edge (SASE) seamlessly integrates with DingTalk approval workflows. When you create an approval workflow in SASE, you can link a configured DingTalk approval workflow to enable efficient cross-platform collaboration and unified management. This topic uses a SASE app uninstallation approval workflow as an example to describe how to implement integrated process control by linking a DingTalk approval workflow.
Background
Efficient cross-platform collaboration and unified management are critical for operational security and efficiency. DingTalk is widely used as an enterprise collaboration platform, and many organizations rely on its approval workflow feature for daily management. However, more complex security scenarios, such as requiring approval to uninstall the SASE App, demand seamless integration with DingTalk approval workflows to ensure operational compliance and data security.
SASE offers deep integration with DingTalk approval workflows, which lets you reference existing DingTalk workflows within SASE for efficient collaboration and centralized control. This topic uses the creation of a SASE App uninstallation approval workflow as an example, detailing how to use DingTalk approval workflows for integrated process management, helping you build a more intelligent and secure workplace environment.
Prerequisites
You have activated Secure Access Service Edge. If you have not activated Secure Access Service Edge, you must purchase and activate the service. For more information, see Purchase service. You can also apply for a 7-day free trial. For more information, see Apply for a free trial.
You have downloaded and installed the SASE App.
You have configured a DingTalk identity source and enabled the authentication status.
You have created a user group and selected the DingTalk organizational structure.
Procedure
Step 1: Create a DingTalk application and permissions
To seamlessly integrate SASE with DingTalk approval workflows, you must first create a custom application in DingTalk and configure approval permissions. SASE uses these permissions to connect with the approval workflow configuration.
Log on to the DingTalk Open Platform. From the top menu bar, select Application Development.
In the left-side navigation pane, select DingTalk Application, and then click Create Application.
In the Create Application panel, configure Application Name, Application Description, and Application Icon.
Parameter
Description
Example
Application name
(Required)
The name of the DingTalk application.
SASE-DingTalk Approval App
Application description
(Required)
A description of the application.
Used to create DingTalk approval workflows and synchronize with SASE.
Application icon
The application icon. The system provides a default icon. To use a custom icon, make sure it meets the design specifications.
Upload a JPG or PNG file that is at least 240×240 pixels, has a 1:1 aspect ratio, is within 2 MB, and has no rounded corners. For more information, see DingTalk Application Icon Design Specifications.
Use the default icon.
After you complete the configuration, click Save. You are redirected to the application details page.
In the left-side navigation pane of the application details page, choose Development Configuration > Permission Management.
On the Permission Management page, configure permissions for OA Approval.
The required OA approval workflow permissions are: Approval Flow Data Management, Workflow Instance Write, Workflow Template Write, Workflow Template Read, and Workflow Instance Read. You can request these permissions in bulk by performing the following steps.
Select a Permission Scope based on your business requirements.
In the permission category list on the left, select OA Approval, and then select the checkbox at the top of the list.
In the upper-right corner of the list, click Batch Request.
Step 2: Create a DingTalk approval workflow
Log on to the DingTalk admin console.
In the Common Applications section in the lower-right corner of the page, select Approval.
Alternatively, in the left-side navigation pane, choose Workbench > Application Management. In the application list, locate OA Approval and click Enter in the Actions column to open the OA Approval management console.
Click Create Approval Form. In the Create Approval Form dialog box, select Process Form.
In the approval form, use the configuration wizard to complete the Basic settings, Form design, and Process design.
Basic settings: Configure the Form Name, Group, Who Can Initiate, and Form Administrator.
The system provides built-in form groups. You can also click New Group, enter a group name, and then click
.Form design: Configure the display fields for the approval form, which you can map in SASE.
Click Form design in the configuration wizard.
In the controls area on the left, click a form control to configure its Title and Placeholder Text.
Process design: Configure the approval workflow, including the Initiator, Approver, and Carbon Copy Recipient.
Click Process design in the configuration wizard.
Click the Approver box in the workflow.
In the Approver panel, configure the Approval Type, Approver, and Approval Method based on your business requirements. Then, click Save.
After you complete the configuration, click Publish in the upper-right corner of the page.
Step 3: Create a SASE approval workflow
When creating a SASE approval workflow, you must configure DingTalk application details, event subscription information, and approval field mappings to seamlessly integrate SASE with the DingTalk approval workflow.
Log on to the Secure Access Service Edge console.
In the left-side navigation pane, choose , and then click Create Workflow.
In the Create Approval Workflow panel, configure the following parameters.
Parameter
Description
Example
Workflow Name
The name of the approval workflow.
SASE App uninstallation approval workflow
Approval Process Type
The type of approval workflow. Valid values: built-in approval workflow and DingTalk approval workflow.
DingTalk approval workflow
Client ID
The ID of the DingTalk application.
ding**********zrvwc
Client Secret
The secret of the DingTalk application.
wRQD7BHcK************AyL1bAJDA
aes_key
The encryption credential for DingTalk event subscriptions.
CzSr3F8************Tc3Zz2
token
The signature for DingTalk event subscriptions.
3hszVY***********aY4K3p9tB4
Request URL
The public URL that DingTalk uses to receive event subscriptions.
ImportantYou must copy this URL and paste it into the Request URL field, which is found at the following location: DingTalk Open Platform > Application Development > Enterprise internal applications > DingTalk Application > Development Configuration > Event Subscription > Request URL.
https://default-pre-auth-server.cloudsecsase.com//
Approval Process Configuration
Configure the association and field mapping between the SASE approval template and the DingTalk approval workflow.
Workflow Template: A built-in workflow template in SASE.
Associate DingTalk Process ID: The ID of the DingTalk approval form.
System Fields: A built-in, non-editable system field in the workflow template.
Template Fields: A field configured in the associated DingTalk workflow.
NoteA SASE approval workflow can be bound to multiple approval forms created under the same DingTalk application. You can click Add to configure different approval workflows.
Workflow template: app uninstallation policy
Associated DingTalk workflow ID: PROC-EB35CAE7-******-*****19C5833D0C17
System field: Reason for filing
Template field: DingTalk approval reason for filing
Click OK.
Step 4: Configure DingTalk event subscriptions
When a subscribed event occurs, DingTalk pushes a message to your application.
Open the Event Subscription page of your DingTalk application.
NoteThis is the same page from the "Obtaining the aes_key and token" procedure in Step 3.
Enter the Request URL and click Save.
You can log on to the Secure Access Service Edge console. In the left-side navigation pane, choose . In the Actions column of the target approval workflow, click Edit. You can find the request URL in the Edit Approval Workflow panel.
The panel displays the Client Secret, aes_key, and token fields, and the Request URL. The path of the URL includes
/v1/approval/dingtalk/callback/. Copy this request URL and paste it into the Request URL field on the Event Subscription page of your application in the DingTalk Open Platform.After the URL is saved, in the Approval Events section at the bottom of the page, turn on the Approval Instance Started, Ended subscription switch.
Click Subscription Settings under Approval Instance Started, Ended.
In the Subscription Content dialog box, configure the event subscription address. This provides fine-grained control over subscribed events and reduces resource usage.
NoteA monthly quota applies to the processing of subscription events. You can check your Webhook and Stream usage on the homepage of the DingTalk Open Platform.
Click Add. In the Subscription Address field, enter the address of the event to which you want to subscribe.
Format: /v1.0/event/bpms_instance_change/processCode/{processCode}/type/{type}. Example: /v1.0/event/bpms_instance_change/processCode/PROC-XXXXX/type/*.
Click OK.
Step 5: Configure the anti-uninstallation policy
Log on to the Secure Access Service Edge console.
In the left-side navigation pane, choose .
On the Uninstallation Approval tab, click Anti-uninstallation Policy.
In the Client Anti-uninstallation Policy panel, configure the following parameters, and then click OK.
Parameter
Description
Example
Client Configuration Switch
You can enable Client Anti-uninstallation and Client Auto-start and Anti-logoff.
Enable Client Anti-uninstallation.
Effective Scope
The user group to which the anti-uninstallation policy applies.
DingTalk user group
Whitelist
Users in the whitelist can uninstall the SASE client without being restricted by the anti-uninstallation policy.
Manager Liu
Approval Process Configuration
Specify whether to allow employees to file for approval and select the approval workflow.
Filing workflow: Allow employees to file for approval
Select workflow: Select the approval workflow that you created.
WarningYou must select an approval workflow created in Workflow Management that is associated with the DingTalk system.
Prompt Display Configuration
When a user in the effective scope attempts to uninstall the SASE App, the system displays a pop-up prompt. You can configure the title, content, and button text of the pop-up. Both Chinese and English are supported.
Title: Your SASE is about to be uninstalled
Content: After uninstallation, this device cannot be used for corporate work and will lose intranet access!
Primary button: File for Approval
Secondary button: I Got It
Step 6: Verify the integration
Log on to the SASE App by using the DingTalk identity source.
Attempt to uninstall the SASE App.
In the anti-uninstallation pop-up prompt, click File for Approval.
On the Security Software Uninstall Prohibited page, enter a reason and click Initiate Filing.
The approver can view and process the OA Approval request in the DingTalk application.
An administrator can view and process approval requests in the Secure Access Service Edge console under .
NoteWhether a request is approved or rejected, the approval status is synchronized to the DingTalk client.
After the approval is granted, you can uninstall the SASE App again.