You can assign compliance rules to employees that are responsible for rule content. This may be an auditor or a auditing department, for example. To do this, assign compliance rules to an application role for rule supervisors. Assign employees to this application role, who are authorized to edit working copies of compliance rules.
A default application role for target system managers is available in One Identity Manager. You may create other application roles as required.
User | Task |
---|---|
Rule supervisor |
Rule supervisors must be assigned to the application role Identity & Access Governance | Identity Audit | Rule supervisors or to a child role. Users with this application role:
|
To edit a rule supervisor
- OR -
Select an application role in the result list. Select Change master data in the task view.
- OR -
Click in the result list toolbar.
Property | Value |
---|---|
Parent application role | Assign the application role Identity & Access Governance | Identity Audit | Rule supervisors or a child application role. |
- OR -
Remove employees from Remove assignments.
Employees who can issue exception approvals for rule violations can be assigned to compliance rules. To do this, assign an application role for exception approvers to the compliance rule. Assign those employees who are entitled to approve rule violation exceptions to this application role.
A default application role for exception approvers is available in One Identity Manager. You may create other application roles as required.
User | Task |
---|---|
Exception approver |
Administrators must be assigned to the application role Identity & Access Governance | Identity Audit | Exception approvers or to a child role. Users with this application role:
|
To edit an exception approver
- OR -
Select an application role in the result list. Select Change master data in the task view.
- OR -
Click in the result list toolbar.
Property | Value |
---|---|
Parent application role | Assign the application role Identity & Access Governance | Identity Audit | Exception approvers or a child application role. |
- OR -
Remove employees from Remove assignments.
In the Web Portal, you can enter reasons, which provide explanations for individual approval decisions of the
To edit standard reasons
- OR -
Click in the result list toolbar.
Enter the following properties for the standard reason.
Property | Description |
---|---|
Standard reason | Reason text as displayed in the Web Portal. |
Description | Spare text box for additional explanation. |
Automatic Approval | Specifies whether the reason text is entered automatically by One Identity Manager into the Do not set this option if the you want to select the standard reason in the Web Portal. |
Additional text required | Specifies whether an additional reason should be entered in freely formatted text for the |
The One Identity Manager supplies predefined standard reasons. These standard reasons are added to the rule violations by One Identity Manager, if approval is automatic.
To display predefined standard reasons
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy