To achieve better classification, you can define role types and assign them to role classes and roles. The following restrictions apply:
-
You can assign a role type to several role classes.
-
If you assign role types to a role class you can only select these role types for the roles of this role class. Other role types are not available for selection.
-
If you do not assign a role type to a role class, you can only use role types that are not assigned to any other role class for roles in this role class.
-
The Business role role type is predefined. This role type cannot be assigned to the Department, Cost center, or Location role classes. Assign this role type to role classes that map business roles.
Example:
The Business role role type is predefined. The Region, Country, Sales, and Development role types are also created.
-
The Business roles role type is assigned to the External projects role class.
The Business roles role type can also be given to roles of this role class.
-
The Business roles, Region, and Country role types are assigned to the Employee role class.
The Business roles, Region, and Country role types can also be given to roles of this role class.
-
The Region and Country role types are assigned to the Location role class.
The Region and Country role types can also be given locations.
-
The Cost center and Department role classes are not assigned any role types.
The Sales and Development role types can also be given to cost centers and departments.
For additional classification, you can create and edit role types. You cannot edit default role types.
To create role types
-
In the Manager, select the Organizations > Basic configuration data > Role types category.
-
Click in the result list.
-
Enter the following information:
-
Role type: Role type name. Translate the given text using the button.
-
Description: (Optional) Text field for additional explanation.
-
No multiple assignment of identities: This option does not work for departments, cost centers, and locations.
- Save the changes.
To create role types
-
In the Manager, select the Organizations > Basic configuration data > Role types category.
-
Select the role type in the result list.
-
Select the Change main data task.
-
Edit the main data.
- Save the changes.
For additional classification, you can define role types and assign them to role classes. Note the restrictions given under Role types for departments, cost centers, and locations.
To assign role classes to a role type
-
In the Manager, select the Organizations > Basic configuration data > Role types category.
-
Select the role type in the result list.
-
Select the Assign role classes task.
-
In the Add assignments pane, assign the organizations:
-
On the Departments tab, assign departments.
-
On the Locations tab, assign locations.
-
On the Cost centers tab, assign cost centers.
TIP: In the Remove assignments pane, you can remove assigned organizations.
To remove an assignment
-
Save the changes.
Related topics
To analyze rule checks for different areas of your company in the context of identity audit, you can set up functional areas. Functional areas can be assigned to hierarchical roles and service items. You can enter criteria that provide information about risks from rule violations for functional areas and hierarchical roles. To do this, you specify how many rule violations are permitted in a functional area or a role. You can enter separate assessment criteria for each role, such as a risk index or transparency index.
Moreover, functional areas can be replaced by peer group analysis during request approvals or attestation cases.
Example: Use of functional areas
To assess the risk of rule violations for cost centers. Proceed as follows:
-
Set up functional areas.
-
Assign cost centers to the functional areas.
-
Define assessment criteria for the cost centers.
-
Specify the number of rule violations allowed for the functional area.
-
Assign compliance rules required for the analysis to the functional area.
-
Use the One Identity Manager report function to create a report that prepares the result of rule checking for the functional area by any criteria.
To create or edit a functional area
-
In the Manager, select the Organizations > Basic configuration data > Functional areas category.
-
In the result list, select a function area and run the Change main data task.
- OR -
Click in the result list.
-
Edit the function area main data.
- Save the changes.
Enter the following data for a functional area.
Table 9: Functional area properties
Functional area |
Description of the functional area |
Parent Functional area |
Parent functional area in a hierarchy.
Select a parent functional area from the list for organizing your functional areas hierarchically. |
Max. number of rule violations |
List of rule violation valid for this functional area. This value can be evaluated during the rule check.
NOTE: This property is available if the Compliance Rules Module is installed. |
Description |
Text field for additional explanation. |
For more detailed information about rule checking, see the One Identity Manager Compliance Rules Administration Guide. For more information about peer group analysis, see the One Identity Manager IT Shop Administration Guide and the One Identity Manager Attestation Administration Guide.