Now that you have requested a new role, you can start assigning users and resources to the newly constructed role. Roles can be linked to users, resources and to other roles in a hierarchal relationship as either a parent role or a child role. The Definitions for Role Name [New Role Name] screen provides you with a fast and easy way to select which links your new role will have.
When you have completed your selections, you can test those selections for violations. If you are satisfied with the results, click Submit, located below the entity tables, to generate a request for a new role definition. The request can be checked by you, and if you have no corrections to make, click Submit below the request table, and generate the approval process tickets necessary to confirm the role definitions that you have created.
Note: The users marked with a green dot next to their name in the Users table, are users that are accountable to you (RACI).
This screen is divided into three sections:
Role hierarchy evolves from role trees that are present in many corporate systems. For example, an Identity Manager application can have two levels of roles: Provisioning Role and Provisioning Policy. Users are always linked to a Provisioning Role that is linked to a specific Provisioning Policy. This hierarchal structure is maintained during import/export. When generating a new role, it is important to know whether there are system rules that demand specific hierarchal connections between roles.
Each section contains a customizable entity table listing all the relevant entities. To assist you in your selection the following functions are available:
Provides a filter screen.
Provides suggested users for selected resources or suggested resources for selected users. This service is not available for the Role Hierarchy tables.
In each customizable table there is one pre-defined column that is highlighted. Click the name of the entity to access its data card.
Provides the option to select the fields that will appear in the specified table.
Select the number of records per page.
Tests the selections you made for violations.
If you select to apply the Suggest Entities service to both users and resources, you see data on the enrollment of the users and resources.
To assign users, resources and role hierarchy to the new role
The Requests screen opens. The Requests screen provides both the new role's attributes and links.
| Copyright © 2010 CA. All rights reserved. | Email CA Technologies about this topic |