All Products
Search
Document Center

Secure Access Service Edge:Integrate approval workflows with DingTalk

Last Updated:Jun 20, 2026

Secure Access Service Edge (SASE) seamlessly integrates with DingTalk approval workflows. When you create an approval workflow in SASE, you can link a configured DingTalk approval workflow to enable efficient cross-platform collaboration and unified management. This topic uses a SASE app uninstallation approval workflow as an example to describe how to implement integrated process control by linking a DingTalk approval workflow.

Background

Efficient cross-platform collaboration and unified management are critical for operational security and efficiency. DingTalk is widely used as an enterprise collaboration platform, and many organizations rely on its approval workflow feature for daily management. However, more complex security scenarios, such as requiring approval to uninstall the SASE App, demand seamless integration with DingTalk approval workflows to ensure operational compliance and data security.

SASE offers deep integration with DingTalk approval workflows, which lets you reference existing DingTalk workflows within SASE for efficient collaboration and centralized control. This topic uses the creation of a SASE App uninstallation approval workflow as an example, detailing how to use DingTalk approval workflows for integrated process management, helping you build a more intelligent and secure workplace environment.

Prerequisites

Procedure

Step 1: Create a DingTalk application and permissions

To seamlessly integrate SASE with DingTalk approval workflows, you must first create a custom application in DingTalk and configure approval permissions. SASE uses these permissions to connect with the approval workflow configuration.

  1. Log on to the DingTalk Open Platform. From the top menu bar, select Application Development.

  2. In the left-side navigation pane, select DingTalk Application, and then click Create Application.

  3. In the Create Application panel, configure Application Name, Application Description, and Application Icon.

    Parameter

    Description

    Example

    Application name

    (Required)

    The name of the DingTalk application.

    SASE-DingTalk Approval App

    Application description

    (Required)

    A description of the application.

    Used to create DingTalk approval workflows and synchronize with SASE.

    Application icon

    The application icon. The system provides a default icon. To use a custom icon, make sure it meets the design specifications.

    Upload a JPG or PNG file that is at least 240×240 pixels, has a 1:1 aspect ratio, is within 2 MB, and has no rounded corners. For more information, see DingTalk Application Icon Design Specifications.

    Use the default icon.

  4. After you complete the configuration, click Save. You are redirected to the application details page.

  5. In the left-side navigation pane of the application details page, choose Development Configuration > Permission Management.

  6. On the Permission Management page, configure permissions for OA Approval.

    The required OA approval workflow permissions are: Approval Flow Data Management, Workflow Instance Write, Workflow Template Write, Workflow Template Read, and Workflow Instance Read. You can request these permissions in bulk by performing the following steps.

    1. Select a Permission Scope based on your business requirements.

    2. In the permission category list on the left, select OA Approval, and then select the checkbox at the top of the list.

    3. In the upper-right corner of the list, click Batch Request.

Step 2: Create a DingTalk approval workflow

  1. Log on to the DingTalk admin console.

  2. In the Common Applications section in the lower-right corner of the page, select Approval.

    Alternatively, in the left-side navigation pane, choose Workbench > Application Management. In the application list, locate OA Approval and click Enter in the Actions column to open the OA Approval management console.

  3. Click Create Approval Form. In the Create Approval Form dialog box, select Process Form.

  4. In the approval form, use the configuration wizard to complete the Basic settings, Form design, and Process design.

    1. Basic settings: Configure the Form Name, Group, Who Can Initiate, and Form Administrator.

      The system provides built-in form groups. You can also click New Group, enter a group name, and then click image.

    2. Form design: Configure the display fields for the approval form, which you can map in SASE.

      1. Click Form design in the configuration wizard.

      2. In the controls area on the left, click a form control to configure its Title and Placeholder Text.

    3. Process design: Configure the approval workflow, including the Initiator, Approver, and Carbon Copy Recipient.

      1. Click Process design in the configuration wizard.

      2. Click the Approver box in the workflow.

      3. In the Approver panel, configure the Approval Type, Approver, and Approval Method based on your business requirements. Then, click Save.

  5. After you complete the configuration, click Publish in the upper-right corner of the page.

Step 3: Create a SASE approval workflow

When creating a SASE approval workflow, you must configure DingTalk application details, event subscription information, and approval field mappings to seamlessly integrate SASE with the DingTalk approval workflow.

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, choose Approval Center > Workflow Management, and then click Create Workflow.

  3. In the Create Approval Workflow panel, configure the following parameters.

    Parameter

    Description

    Example

    Workflow Name

    The name of the approval workflow.

    SASE App uninstallation approval workflow

    Approval Process Type

    The type of approval workflow. Valid values: built-in approval workflow and DingTalk approval workflow.

    DingTalk approval workflow

    Client ID

    The ID of the DingTalk application.

    Obtaining the Client ID and Client Secret

    1. Log on to the DingTalk Open Platform. From the top menu bar, select Application Development.

    2. In the left-side navigation pane, select DingTalk Application, and then click the name of your application to go to the application details page.

    3. In the left-side navigation pane, select Credentials And Basic Information. On the application credentials page, you can view the Client ID and Client Secret.

    ding**********zrvwc

    Client Secret

    The secret of the DingTalk application.

    wRQD7BHcK************AyL1bAJDA

    aes_key

    The encryption credential for DingTalk event subscriptions.

    Obtaining the aes_key and token

    1. Log on to the DingTalk Open Platform. From the top menu bar, select Application Development.

    2. In the left-side navigation pane, select DingTalk Application, and then click the name of your application to go to the application details page.

    3. In the left-side navigation pane, select Event Subscription.

    4. On the Event Subscription page, set Push Method to HTTP Push and click the reset button to obtain the Encryption aes_key and Signature token.

      Warning

      After you obtain the Encryption aes_key and Signature token, do not reset them again. Keep the current page open, as you will need to configure the Request URL in a later step.

    CzSr3F8************Tc3Zz2

    token

    The signature for DingTalk event subscriptions.

    3hszVY***********aY4K3p9tB4

    Request URL

    The public URL that DingTalk uses to receive event subscriptions.

    Important

    You must copy this URL and paste it into the Request URL field, which is found at the following location: DingTalk Open Platform > Application Development > Enterprise internal applications > DingTalk Application > Development Configuration > Event Subscription > Request URL.

    https://default-pre-auth-server.cloudsecsase.com//

    Approval Process Configuration

    Configure the association and field mapping between the SASE approval template and the DingTalk approval workflow.

    • Workflow Template: A built-in workflow template in SASE.

    • Associate DingTalk Process ID: The ID of the DingTalk approval form.

      Finding the DingTalk approval form ID

      1. Log on to the DingTalk admin console.

      2. In the Common Applications section in the lower-right corner of the page, select Approval.

        Alternatively, in the left-side navigation pane, choose Workbench > Application Management. In the application list, locate OA Approval and click Enter in the Actions column to go to the OA Approval management console.

      3. In the left-side navigation pane, select Form Management.

      4. In the Form Management list, find the ID of the approval form that you created.

    • System Fields: A built-in, non-editable system field in the workflow template.

    • Template Fields: A field configured in the associated DingTalk workflow.

    Note

    A SASE approval workflow can be bound to multiple approval forms created under the same DingTalk application. You can click Add to configure different approval workflows.

    • Workflow template: app uninstallation policy

    • Associated DingTalk workflow ID: PROC-EB35CAE7-******-*****19C5833D0C17

    • System field: Reason for filing

    • Template field: DingTalk approval reason for filing

  4. Click OK.

Step 4: Configure DingTalk event subscriptions

When a subscribed event occurs, DingTalk pushes a message to your application.

  1. Open the Event Subscription page of your DingTalk application.

    Note

    This is the same page from the "Obtaining the aes_key and token" procedure in Step 3.

  2. Enter the Request URL and click Save.

    You can log on to the Secure Access Service Edge console. In the left-side navigation pane, choose Approval Center > Workflow Management. In the Actions column of the target approval workflow, click Edit. You can find the request URL in the Edit Approval Workflow panel.

    The panel displays the Client Secret, aes_key, and token fields, and the Request URL. The path of the URL includes /v1/approval/dingtalk/callback/. Copy this request URL and paste it into the Request URL field on the Event Subscription page of your application in the DingTalk Open Platform.

  3. After the URL is saved, in the Approval Events section at the bottom of the page, turn on the Approval Instance Started, Ended subscription switch.

  4. Click Subscription Settings under Approval Instance Started, Ended.

  5. In the Subscription Content dialog box, configure the event subscription address. This provides fine-grained control over subscribed events and reduces resource usage.

    Note

    A monthly quota applies to the processing of subscription events. You can check your Webhook and Stream usage on the homepage of the DingTalk Open Platform.

    1. Click Add. In the Subscription Address field, enter the address of the event to which you want to subscribe.

      Format: /v1.0/event/bpms_instance_change/processCode/{processCode}/type/{type}. Example: /v1.0/event/bpms_instance_change/processCode/PROC-XXXXX/type/*.

    2. Click OK.

Step 5: Configure the anti-uninstallation policy

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, choose Endpoint Management > Terminal Registration.

  3. On the Uninstallation Approval tab, click Anti-uninstallation Policy.

  4. In the Client Anti-uninstallation Policy panel, configure the following parameters, and then click OK.

    Parameter

    Description

    Example

    Client Configuration Switch

    You can enable Client Anti-uninstallation and Client Auto-start and Anti-logoff.

    Enable Client Anti-uninstallation.

    Effective Scope

    The user group to which the anti-uninstallation policy applies.

    DingTalk user group

    Whitelist

    Users in the whitelist can uninstall the SASE client without being restricted by the anti-uninstallation policy.

    Manager Liu

    Approval Process Configuration

    Specify whether to allow employees to file for approval and select the approval workflow.

    • Filing workflow: Allow employees to file for approval

    • Select workflow: Select the approval workflow that you created.

      Warning

      You must select an approval workflow created in Workflow Management that is associated with the DingTalk system.

    Prompt Display Configuration

    When a user in the effective scope attempts to uninstall the SASE App, the system displays a pop-up prompt. You can configure the title, content, and button text of the pop-up. Both Chinese and English are supported.

    Title: Your SASE is about to be uninstalled

    Content: After uninstallation, this device cannot be used for corporate work and will lose intranet access!

    Primary button: File for Approval

    Secondary button: I Got It

Step 6: Verify the integration

  1. Log on to the SASE App by using the DingTalk identity source.

  2. Attempt to uninstall the SASE App.

  3. In the anti-uninstallation pop-up prompt, click File for Approval.

  4. On the Security Software Uninstall Prohibited page, enter a reason and click Initiate Filing.

  5. The approver can view and process the OA Approval request in the DingTalk application.

    An administrator can view and process approval requests in the Secure Access Service Edge console under Approval Center > Workflow Instance.

    Note
    • Whether a request is approved or rejected, the approval status is synchronized to the DingTalk client.

    • After the approval is granted, you can uninstall the SASE App again.