What the user sees, per elevation mode
- Auto-elevate
- Require approval
- Deny
No pop-up, and no UAC window. The application starts immediately with administrator privileges.
When the endpoint is offline
Without a connection to the Application Server, Syteca can’t check for approval or confirm an Auto-elevate schedule — so it falls back to denying elevation, regardless of the rule’s configured mode:Requesting and approving access
The approver’s side
A Require approval request appears on the Access Requests page in the Management Tool, visible to the users or groups selected as approvers on the rule. An email notification is also sent to them, including the request date/time, the requesting user and endpoint, their comment, the rule name, and the application’s path. Opening a request shows the same details, plus (once processed) who approved or denied it and when. Approving a request opens a follow-up pop-up where the approver sets how long the granted administrator access should last before it’s automatically revoked.The Request Type filter on the Access Requests page includes Privilege Elevation as its own type, alongside your existing PAM access request types.
The user’s side, after a decision
Syteca Access Center
Once at least one Privilege Elevation request has been approved for an endpoint, a Syteca Access Center icon appears in that endpoint’s Windows notification area.1
Open the Access Center
Right-click the Syteca Client tray icon and select the Access Center option.
2
Review your requests
See every Approved, Pending, Denied, and Expired access request available to you. Use Search to find one by application or file name.
3
Launch an approved application
Each approved entry shows how long it remains valid, with a Run button to launch it directly — no need to trigger a new elevation attempt.

The Syteca Access Center, showing available access requests.
When elevation fails outright
Separate from a Deny decision, an elevation attempt can fail for operational reasons — for example, the account in the rule’s Secret no longer belongs to the local admin group, its password was changed outside Syteca, or the rule only has an Active Directory Secret but the endpoint isn’t domain-joined. In these cases, an error pop-up (“Elevation failed”) tells the user to contact their administrator, and — if configured — the failure notification is emailed to the recipients defined on the rule.Related
Overview
What Privilege Elevation does and how it’s licensed.
Creating and managing rules
Configure the elevation mode and approval settings referenced here.
Events and monitoring
Every request and decision, logged for audit.
