Identities
You can use the following identities in the use cases described.
Celestine Eaton
Tony Denison
Tomas Grenier
Dorreen Palacek
Quentin Payton
Related topics
Scenario 1: Request membership in an Active Directory group
A default user wants to request membership in the Purchase Analysis Active Directory group themselves. The request undergoes an approval procedure. The request is granted approval by the default user's manager and by the owner of the group (product owner). Once the request has been granted approval, the default user's Active Directory user account becomes a member of the requested group. The Starling CertAccess administrator can then verify whether the default user's user account has been assigned to the group.
Identities managed in Starling CertAccess can use requests to apply for access permissions in the connected Active Directory environment. All requests undergo an approval procedure in which approvers grant or deny the requests. In the request history, you can always trace who placed or approved which access requests.
TIP: If an action is not available yet, it means that a background process is running such as, finding the next approver. Wait for a while and reload the page.
To request the Purchase Analysis Active Directory group
-
Log in on the Starling CertAccess Web Portal as .
-
Request the Purchase Analysis Active Directory group.
-
In the menu bar, click Requests > New Request.
-
On the New Request page, on the Purchase Analysis tile, click Add to cart.
-
On the Shopping Cart page, click Submit.
This runs a peer group analysis.
Tony Denison, Tomas Grenier's manager, is determined to be an approver.
-
Sign out as TOMASGRE.
-
Log in as .
A pending requests needs to be approved.
-
Approve the request.
-
In the menu bar, click Requests > Pending Requests.
-
On the Pending Requests page, next to the Purchase Analysis request, click Approve.
-
In the Approve Request pane, click Save.
Dorreen Palacek, the group's owner, is determined to be an approver.
-
Sign out as TONYDEN.
-
Log in as .
A pending requests needs to be approved.
-
Approve the request.
-
In the menu bar, click Requests > Pending Requests.
-
On the Pending Requests page, next to the Purchase Analysis request, click Approve.
-
In the Approve Request pane, click Save.
This finalizes the request approval and adds the membership to the group.
-
Sign out as DORREENPAL.
-
Log in as .
-
In the Data Explorer, check whether the user account has been assigned to the group.
-
In the menu bar, click Data > Data Explorer.
-
In the Data Explorer in the navigation, click System entitlements.
-
In the Search field, enter Purchase Analysis.
-
In the list, click Purchase Analysis.
-
In the details pane, click the Memberships tab.
-
On the Memberships tab, check whether or not the Grenier, Tomas (TOMASGRE) identity's user account is listed as a member.
Related topics
Scenario 2: Attesting a group membership with approval granted
An attestation supervisor would like to have a membership in the Purchase Analysis Active Directory group attested. Membership should be granted. The attestation case is assigned to the member's manager and the owner of the group and confirmed. The Starling CertAccess administrator can then verify whether the user account continues to be a member of the group.
Attestation functionality allows the correctness of various data to be certified. Attestations are run either regularly or they can be triggered explicitly by attestation supervisors. Once attestation starts, attestation cases are created that contain all the necessary information about the attestation objects and the attestor. The attestor checks the attestation objects. They verify the correctness of the data and initiate any changes that need to be made if the data conflicts with internal rules. Attestation cases record the entire attestation sequence. Each attestation step in the attestation case can be audit-proof reconstructed.
TIP: If an action is not available yet, it means that a background process is running such as, finding the next attestor. Wait for a while and reload the page.
Prerequisite
To attest a membership in an Active Directory group
-
Log in on the Starling CertAccess Web Portal as .
-
Start the attestation.
-
In the menu bar, click Attestation > Attestation Policies.
-
On the Attestation Policies page, next to the System entitlement membership attestation (peer group analysis) attestation policy, click
(actions) > Start attestation.
-
In the details pane, next to - Purchase Analysis, click Start attestation.
Tony Denison, Tomas Grenier's manager, is determined to be an attestor.
-
Sign out as QUENTINPAY.
-
Log in as .
A pending attestation needs to be approved.
-
Approve the attestation.
-
In the menu bar, click Attestation > Pending Attestations.
-
On the Pending Attestations page, next to the Should the identity "Grenier, Tomas (TOMASGRE)" have access to the "Purchase Analysis" system entitlement using the "TomasGre" user account? attestation case, click Approve.
-
In the Approve pane, click Save.
Dorreen Palacek, the group's owner, is determined to be an attestor.
-
Sign out as TONYDEN.
-
Log in as .
A pending attestation needs to be approved.
-
Approve the attestation.
-
In the menu bar, click Attestation > Pending Attestations.
-
On the Pending Attestations page, next to the Should the identity "Grenier, Tomas (TOMASGRE)" have access to the "Purchase Analysis" system entitlement using the "TomasGre" user account? attestation case, click Approve.
-
In the Approve pane, click Save.
This finalizes the attestation case and confirms the group membership.
-
Sign out as DORREENPAL.
-
Log in as .
-
In the Data Explorer, check that the user account is still assigned to the group.
-
In the menu bar, click Data > Data Explorer.
-
In the Data Explorer in the navigation, click System entitlements.
-
In the Search field, enter Purchase Analysis.
-
In the list, click Purchase Analysis.
-
In the details pane, click the Memberships tab.
-
On the Memberships tab, check whether or not the Grenier, Tomas (TOMASGRE) identity's user account is listed as a member.
Related topics
Scenario 3: Attesting a group membership with approval denied
An attestation supervisor would like to have a membership in the Sales Analyst Active Directory group attested. Membership should be denied. The attestation case is assigned to the member's manager and the owner of the group. An attestor denies the existing group membership and the user account's assignment is automatically removed from the group. The Starling CertAccess administrator can then verify whether the group membership has really been removed.
Attestation functionality allows the correctness of various data to be certified. Attestations are run either regularly or they can be triggered explicitly by attestation supervisors. Once attestation starts, attestation cases are created that contain all the necessary information about the attestation objects and the attestor. The attestor checks the attestation objects. They verify the correctness of the data and initiate any changes that need to be made if the data conflicts with internal rules. Attestation cases record the entire attestation sequence. Each attestation step in the attestation case can be audit-proof reconstructed.
TIP: If an action is not available yet, it means that a background process is running such as, finding the next attestor. Wait for a while and reload the page.
Prerequisite
To attest membership in an Active Directory and to deny that attestation
-
Log in on the Starling CertAccess Web Portal as .
-
Start the attestation.
-
In the menu bar, click Attestation > Attestation Policies.
-
On the Attestation Policies page, next to the System entitlement membership attestation (peer group analysis) attestation policy, click
(actions) > Start attestation.
-
In the details pane, next to - Sales Analyst, click Start attestation.
Tony Denison, Tomas Grenier's manager, is determined to be an attestor.
-
Sign out as QUENTINPAY.
-
Log in as .
A pending attestation needs to be approved.
-
Approve the attestation.
-
In the menu bar, click Attestation > Pending Attestations.
-
On the Pending Attestations page, next to the Should the identity "Grenier, Tomas (TOMASGRE)" have access to the "Sales Analyst" system entitlement using the "TomasGre" user account? attestation case, click Approve.
-
In the Approve pane, click Save.
Dorreen Palacek, the group's owner, is determined to be an attestor.
-
Sign out as TONYDEN.
-
Log in as .
A pending attestation needs to be approved.
-
Deny the attestation.
-
In the menu bar, click Attestation > Pending Attestations.
-
On the Pending Attestations page, next to the Should the identity "Grenier, Tomas (TOMASGRE)" have access to the "Sales Analyst" system entitlement using the "TomasGre" user account? attestation case, click Deny.
-
In the Deny pane, click Save.
This finalizes denial of the attestation case. The group membership is automatically removed.
-
Sign out as DORREENPAL.
-
Log in as .
-
In the Data Explorer, check that the group membership has been removed.
-
In the menu bar, click Data > Data Explorer.
-
In the Data Explorer in the navigation, click System entitlements.
-
In the Search field, enter Sales Analyst.
-
In the list, click Sales analyst.
-
In the details pane, click the Memberships tab.
-
On the Memberships tab, check whether or not the Grenier, Tomas (TOMASGRE) identity's user account is listed as a member.
Related topics