Managing my business roles
Business roles are defined based on resources to perform specific functions.
Business roles are objects for mapping company-specific functions in One Identity Manager. Business roles map company structures with similar functionality that exist in addition to departments, cost centers, and locations. This might be projects groups, for example.
You can carry out various actions on the system entitlements that you manage and obtain information about them.
Detailed information about this topic
Displaying my business roles
You can display all the business roles for which you are responsible.
To display business roles
-
Open the home page.
-
On the Home page, in the My Responsibilities tile, click Business roles.
This opens the Business Roles page and display all the business roles for which you are responsible.
-
(Optional) To display details of a business role, next to the business role, click Edit.
Displaying and editing my business roles' main data
You can edit the main data of the business roles for which you are responsible.
To display and edit a business role's main data
-
Open the home page.
-
On the Home page, in the My Responsibilities tile, click Business roles.
-
On the Business Roles page, next to the business role whose main data you want to show/edit, click Edit.
-
In the Edit Business Role pane, make your changes in the corresponding fields.
Table 22: Business role main data
Business role |
Enter a full, descriptive name for the business role. |
Short name |
Enter a short name for the business role. |
Internal name |
Enter a company internal name for the business role. |
Description |
Enter a description for the business role. |
Role class |
When you create the business role: Select the role class of the business role.
To differentiate between different business roles, define company specific role classes. Role classes are used to specify which company resource assignments are possible through roles in a role class. |
Parent business role |
Click Assign/Change and select a business role to be the parent business role for organizing the business role hierarchically. If you want the business role at the root of a business role hierarchy, leave the field empty. |
Role type |
Select the role type of the business role.
Role types are mainly used to regulate approval policy inheritance. |
Role approver |
Click Assign/Change and select an application role. Members of the selected application role can approve requests for members of the business role. |
Role approver (IT) |
Click Assign/Change and select an application role. Members of the selected application role can approve requests for members of the business role. |
Manager |
Select the manager who is responsible for the business role. |
2nd Manager |
Select an identity to act as a deputy to the business role's manager. |
Additional manager |
Click Assign/Change and select a cost center. Members of the selected application role are responsible for the department. |
Employees do not inherit |
Select this check box if you want to temporarily prevent identities from inheriting this business role. |
Comment |
Enter a comment for the business role. |
-
Click Save.
Copying/splitting my business roles
You can copy or move memberships and entitlements from business roles you are responsible for to new objects (departments, business roles, cost centers, locations).
To copy a business role or move memberships and entitlements
-
Open the home page.
-
On the Home page, in the My Responsibilities tile, click Business roles.
-
On the Business Roles page, next to the business role you want to copy or whose memberships and entitlements you want to move, click Edit.
-
In the Edit Business Role pane, click (Actions) > Split.
-
In the Split pane, In the Type of new role menu, select which type to give the new object.
-
Depending on the object type you have selected, enter the basic main data of the new object in the corresponding fields.
-
Click Continue.
-
In the Select assignments to be copied or moved to the new role step, perform the following actions:
-
To neither copy nor move an entitlement/a membership to a new object, in the menu next to the corresponding entitlement/membership, select Keep this assignment. The entitlement/membership is later only available in the source object.
-
To copy or move an entitlement/a membership to a new object, in the menu next to the corresponding entitlement/membership, select Keep and copy new role. The entitlement/membership is included later in the source object as well as the target object.
-
To move an entitlement/a membership to a new object, in the menu next to the corresponding entitlement/membership, select Move to new role. The entitlement/membership is later removed from the source object and only included in the target object.
-
Click Continue.
-
(Optional) In the Verify step, you verify the actions to run and deselect the check box in front of any actions that should not be run.
-
Click Continue.
Related topics