API access requested by a client application is represented through a contract between that application and an API instance or API Group instance. When manual approval is required, the administrator must possess both the relevant contract configuration and sufficient API Manager authority.
MuleSoft's API Manager documentation identifies two prerequisites for manually approving or rejecting an access request. First, an SLA tier must be configured for the application. Second, the user performing the approval must be an Organization Administrator, an API Manager Environment Administrator, or possess the Manage Contracts permission.
The Manage Contracts permission specifically grants the ability to manage contracts and their associated tiers within the API Manager environment. Exchange Administrator permissions alone do not satisfy this API Manager contract-management requirement.
The SLA component is also significant. API Manager contracts can govern access based on an SLA tier, allowing the API owner to determine permitted consumption levels and whether approval is automatic or manual.
Option C therefore contains the complete combination required by the platform: the application's SLA tier configuration plus appropriate administrative or contract-management authority.
Reference topics: API Manager Contracts; Client Applications; SLA Tiers; Manage Contracts permission; API access approval.
Official documentation: https://docs.mulesoft.com/api-manager/latest/manage-client-apps-latest-task
Official documentation: https://docs.mulesoft.com/api-manager/latest/environment-permission-task
===============================================================
Submit