Previous Topic: Constructing a Rule

Next Topic: Updating Role Definitions

Definitions for Role Name [New Role Name]

Now that you have requested a new role, you can start assigning users and resources to the newly constructed role. Roles can be linked to users, resources and to other roles in a hierarchal relationship as either a parent role or a child role. The Definitions for Role Name [New Role Name] screen provides you with a fast and easy way to select which links your new role will have.

When you have completed your selections, you can test those selections for violations. If you are satisfied with the results, click Submit, located below the entity tables, to generate a request for a new role definition. The request can be checked by you, and if you have no corrections to make, click Submit below the request table, and generate the approval process tickets necessary to confirm the role definitions that you have created.

Note: The users marked with a green dot next to their name in the Users table, are users that are accountable to you (RACI).

This screen is divided into three sections:

Role hierarchy evolves from role trees that are present in many corporate systems. For example, an Identity Manager application can have two levels of roles: Provisioning Role and Provisioning Policy. Users are always linked to a Provisioning Role that is linked to a specific Provisioning Policy. This hierarchal structure is maintained during import/export. When generating a new role, it is important to know whether there are system rules that demand specific hierarchal connections between roles.

Each section contains a customizable entity table listing all the relevant entities. To assist you in your selection the following functions are available:

Find Entities

Provides a filter screen.

Suggest Entities

Provides suggested users for selected resources or suggested resources for selected users. This service is not available for the Role Hierarchy tables.

Highlighted Column

In each customizable table there is one pre-defined column that is highlighted. Click the name of the entity to access its data card.

Customize

Provides the option to select the fields that will appear in the specified table.

Records per page

Select the number of records per page.

Test Compliance

Tests the selections you made for violations.

If you select to apply the Suggest Entities service to both users and resources, you see data on the enrollment of the users and resources.

To assign users, resources and role hierarchy to the new role

  1. Select users, resource and/or role hierarchy entities. Utilize the Find Entity filter and the Suggest Entity utility when necessary.
  2. Click Test Compliance to check your selections for violations.
  3. Click Submit to submit the new role definition request.

    The Requests screen opens. The Requests screen provides both the new role's attributes and links.

  4. Click Back to amend the data.
  5. Click Submit to forward the request to generate a new role.

More information:

Request New Role Definition Screen

Filter a Data Table

Suggesting Entities

Test Compliance

Introducing the Requests Table