Wildcard Domain Auto-Approvals Enhance FedRAMP Compliance in Trust Center Access Requests
Wildcard domain auto-approvals in the Trust Center
For organizations with FedRAMP certification requirements, manually approving Trust Center access requests one by one isn't just tedious, it's non-compliant. FedRAMP requires uninterrupted data sharing with every authorized party, and manual review breaks that by design.
To solve this, Trust Center accounts now support wildcard email domain rules. Set up a rule like *.gov or *.mil, enable auto-approval, and any requester whose email matches is instantly approved and grouped under that account, no admin intervention required. The most specific rule always wins, so you can have a broad *.gov rule and a more specific abc.hhs.gov override coexist without conflict. CRM-based auto-approval (Salesforce/HubSpot) still takes precedence where it's set up; the wildcard kicks in as the fallback.
One thing to keep in mind: wildcard access groups every matching requester under a single account, which is the right trade-off for broad government-wide access but not for every situation. If you need separate NDAs per agency, distinct content scoping per entity, or per-entity Customer Commitments tracking, you'll want to set up individual accounts instead.
For FedRAMP vendors that need to share certification data at scale with government entities, this closes a real compliance gap. ![]()
