As an administrator, you can create permission sets for different policy user levels. The Permission Sets allow some policy users not only to create and modify policies and policy assignments, but also to approve or reject policies/ policy assignments created by other users.
You must have administrator rights to change Permission Sets.
To manage policy or policy assignment creation, you can create permission sets for users who can create and modify specific product policies. For example, you can create permission sets that allow one user to change policies and policy assignments and another user to approve or reject those changes.
Policy User permission set — The policy user can create and modify specific product policies and policy assignments, but the policy changes must be approved before the policy or policy assignment is saved.
Policy Administrator permission set — The policy administrator can create and modify specific product policies and policy assignments, and approve or reject the changes created by policy users and other administrators.
Select Menu → User Management → Permission Sets, then click New Permission Sets.
To create the policy administrator permission set, type the name, for example,
policyAdminPS, then click Save.Select the new permission set, scroll down to the Approval Management row, then click Edit.
Select Approver Permission for Policy Approval or Policy Assignment Approval setting , then click Save.
This option allows the policy administrator to approve or reject policy and policy assignment changes for other users who don't have administrator approval.
Scroll down to a row, for example, the Endpoint Security Common, and click Edit.
Select View and change policy and task settings and click Save.
This option allows the policy administrator to make changes to Endpoint Security Common policies.
Configure the edit permissions for different parameters as needed.
To create the policy user permission set, click Actions → Duplicate.
Type a name for the policy user permission set, for example,
policyUserPSand click OK.From the Permission Sets list, click the policyUserPS permission set.
Scroll down to the Approval Management row and click Edit.
Select No Permission for Policy Approval or Policy Assignment Approval setting , then click Save.
This setting forces the users assigned with this permission set to request approval from the administrator before they can save a new or changed policy or policy assignment.
You have created two permission sets; one to assign to a policy user and one to assign to a policy administrator.