Chatee ahora con Soporte
Chat con el soporte

Identity Manager 8.2 - Attestation Administration Guide

Attestation and recertification
One Identity Manager users for attestation Attestation base data Attestation policies Custom mail templates for notifications
Approval processes for attestation cases
Approval policies for attestations Approval workflow for attestations Selecting attestors Setting up multi-factor authentication for attestation Prevent attestation by employee awaiting attestation Attestation by peer group analysis Managing attestation cases
Attestation sequence Default attestation and withdrawal of entitlements User attestation and recertification Mitigating controls Configuration parameters for attestation

Notifications in the attestation process

In an attestation process, various email notifications can be sent to attestors and other employees. The notification procedure uses mail templates to create notifications. The mail text in a mail template is defined in several languages. This ensures that the language of the recipient is taken into account when the email is generated. Mail templates are supplied in the default installation with which you can configure the notification procedure.

Messages are not sent to the chief approval team by default. Fallback approvers are only notified if not enough approvers could be found for an approval step.

To use notification in the request process

  1. Ensure that the email notification system is configured in One Identity Manager. For more information, see the One Identity Manager Installation Guide.

  2. In the Designer, set the QER | Attestation | DefaultSenderAddress configuration parameter and enter the sender address used to send the email notifications.

  3. Ensure that all employees have a default email address. Notifications are sent to this address. For more information, see the One Identity Manager Identity Management Base Module Administration Guide.

  4. Ensure that a language can be determined for all employees. Only then can they receive email notifications in their own language. For more information, see the One Identity Manager Identity Management Base Module Administration Guide.

  5. Configure the notification procedure.

Related topics

Demanding attestation

When a new attestation case is made, the attestor is notified by mail. Demands for attestation can be configured separately for each approval step.

Prerequisite

  • The QER | Attestation | MailTemplateIdents | RequestApproverByCollection configuration parameter is not set.

To set up the notification procedure

  • On the Mail templates tab of the approval step, enter the following data:

    Mail template request: Attestation - approval required

    TIP: To allow approval by email, select the Attestation - approval required (by email) mail template.

NOTE: You can schedule demands for attestation to send a general notification if there are attestations pending. This replaces single demands for attestation at each approval step.

Related topics

Reminding attestors

If an attestor has not made a decision by the time the reminder timeout expires, notification can be sent by email as a reminder. The attestors work time applies to the time calculation.

Prerequisite

  • The QER | Attestation | MailTemplateIdents | RequestApproverByCollection configuration parameter is not set.

To set up the notification procedure

  • Enter the following data for the approval step.

    Table 37: Properties of the approval step for notification

    Property

    Meaning

    Reminder interval (hours)

    Number of working hours to elapse after which the attestor is notified by mail that there are still pending attestation cases for attestation.

    The reminder interval is set to 30 minutes, by default. To change this interval, modify the Checks reminder interval and timeout of attestation cases schedule.

    NOTE: Ensure that a state, county, or both is entered into the employee's main data of determining the correct working hours. If this information is missing, a fallback is used to calculate the working hours. For more information about calculating employees' working hours, see the One Identity Manager Identity Management Base Module Administration Guide.

    TIP: Weekends and public holidays are taken into account when working hours are calculated. If you want weekends and public holidays to be dealt with in the same way as working days, set the QBM | WorkingHours | IgnoreHoliday oder QBM | WorkingHours | IgnoreWeekend configuration parameter. For more information about this, see the One Identity Manager Configuration Guide.

    If more than one attestor was found, each attestor will be notified. The same applies if an additional attestor has been assigned.

    If an attestor delegated the approval, the time point for reminding the delegation recipient is recalculated. The delegation recipient and all the other attestors are notified. The original attestor is not notified.

    If an attestor has made an inquiry, the time point for reminding the queried employee is recalculated. As long as the inquiry has not been answered, only this employee is notified.

    Mail template reminder

    Select the Attestation - Remind approver mail template.

    TIP: To allow approval by email, select the Attestation - remind approver (by email) mail template.

NOTE: You can schedule demands for attestation to send a general notification if there are attestations pending. This replaces single demands for attestation at each approval step.

Related topics

Scheduling attestation demands

Attestors can be regularly notified of attestation cases that are pending. These regular notifications replace the individual prompts and attestation reminders that are configured in the approval step.

To send regular notifications about pending attestations

  1. Enable the QER | Attestation | MailTemplateIdents | RequestApproverByCollection configuration parameter in the Designer.

    By default, a notification is sent with the Attestation - pending requests for approver mail template.

    TIP: To use something other than the default mail template for these notifications, change the value of the configuration parameter in the Designer.

  2. In the Designer, configure and enable the Inform approver about pending attestations schedule.

    For detailed information, see One Identity Manager Operational Guide.

Documentos relacionados

The document was helpful.

Seleccionar calificación

I easily found the information I needed.

Seleccionar calificación