Previous Topic: Role DiscoveryNext Topic: Iterated Search


Basic Roles

This option applies to the currently selected CA GovernanceMinder configuration and identifies possible roles that do not seem to fit into previously defined roles. It is generally recommended to generate a limited set of 3 – 5 candidates, review and select a single candidate, and refine the role. The first set that meet the search criteria will be identified and displayed. The run time to discover roles depends mainly on the parameters specified. If necessary, Basic Roles can be run again with the new role (refer to Iterated Search in the following section).

The following table describes the available fields:

Field

Description

Default Description

A textual description used for your own purposes that later appears as the role’s description in the configuration file. This description is different from the actual name of the role candidate, which is assigned by CA GovernanceMinder. The user can rename each candidate and change its description later. Sometimes it is convenient to fill in a name and/or date in this field. However, do not leave it blank.

Role Name Prefix

Set a prefix that is added to the role name for each role that is discovered.

Minimum number of users

Minimum number of users that should be included in a role candidate

Minimum number of resources

Minimum number of resources that should be included in role candidate

Maximum number of role candidates to propose

Maximum number of role candidates to be proposed in this run. We recommend generating no more than 10 new role candidates in each session. Roles proposed in a single session may have significant overlap with one another thereby increasing the work load on the Role Engineer to distinguish among them.

Minimum newly covered connections

Minimum number of Users, Resources, and User-Resource connections that must be covered by a role candidate and that were not covered by existing and previously discovered roles. This feature is useful to discover roles that are as disjointed from previously discovered roles as possible. If not relevant, use 0. Values can be entered as whole numbers or as a percentage of newly covered connections.

Minimum Users not Covered

Sets the minimum number of Users or the minimum percentage of Users that are not previously discovered by a role.

Minimum Resources not Covered

Sets the minimum number of Resources or the minimum percentage of Resources that are not previously discovered by a role.

The results of a typical Basic Role Discovery run are displayed in a new configuration.

The role name is automatically incremented with each run and is viewable in the Person ID column.

The Default role description is viewable in the User Name column.