In the Entitlements view of a responsibility you can delete entitlements in the same way.
To delete an entitlement
The original idea behind splitting a role is to take assignments from role A and transfer them to role B. An example of role splitting could be, if memberships assigned to role B have less entitlements as memberships assigned to role A.
By splitting role A assigned memberships and individual entitlements of role A can be retained, moved or copied to role B.
Any combination of role types is allowed.
To split a role
This opens a dialog box. The New role data view is shown.
Fields marked with * are compulsory.
Role type |
Setting |
Description |
---|---|---|
All |
Type of the new role |
Menu for selecting a type for the new role. The following object types are available in the Web Portal. |
All |
Department / Business role / Cost center / Location * |
Text box for the new role's name. A name must be entered for every role type. |
All |
Short name |
Text box for entering a short name for the role. This is compulsory (*) for the role type 'cost center'. |
Department |
Object ID |
Text box for an object ID for the new role. |
Location / business role |
Location |
Text box for entering a location. |
Business role |
Internal name |
Text box for an internal name for the business role. |
Location |
Name |
Text box for entering the location's name. |
Department / Business role / Cost center / Location |
Manager |
Control for selecting a manager. |
Department |
Deputy Manager |
Control for selecting a deputy manager. |
Business role |
Role class * |
Role class menu. |
Business role / Cost center / Location * |
Deputy manager |
Control for selecting a deputy manager. The option Employees do not inherit is also available. |
Department |
Parent department / Attestor / Cost center / Role approver / Role approver (IT) |
Controls for selecting the respective settings. |
Business role |
Parent business role / Role type / Role approver / Role approver (IT) |
Controls for selecting the respective settings. |
Cost center |
Parent cost center / Attestor / Department / Role approver / Role approver (IT) |
Controls for selecting the respective settings. |
Location |
Parent location / Attestor / Department / Cost center /Role approver / Role approver (IT) |
Controls for selecting the respective settings. |
All |
Description |
Text box for more detailed description. |
Business role |
Comment |
Text box for additional comments. |
After clicking Next, the Splitting view is opens. The view is divided in to the sections No change, Copy to new role and Move to new role, which a differentiated by color.
All memberships assigned to role A are listed in Copy to new role. Assigned members are copied to the new role by default. This means, they are contained in role A and in role B after splitting.
However, You can copy or move these members to the new role or retain them. The following edit options are available. Edit option also apply to assigned entitlements.
Section |
Action |
Significance |
---|---|---|
No change / Copy to new role / Move to new role |
Retain assignment |
The entitlement / membership remains in role A. |
Retain and copy to new role. |
The entitlement / membership is copied to role B. It is now in role A and in role B. | |
Move to new role |
The entitlement / membership is moved to role B. It is now in role B but not in role A. |
This opens the Verify view and lists the actions.
Save changes to the script. This opens the Results view.
You can compare and merge any combination of role types. For example, you can compare the properties of a business role and a department, take the properties you want from them and merge them. This function is available in the My Responsibilities menu for your responsibilities.
|
NOTE: You can only compare and merge roles that you own or you are their administrator. |
To compare and merge roles
This opens a dialog box. the view Select a comparison role.
|
NOTE: If a role is already selected, user Change to edit the selection. |
Memberships and entitlements of the selected roles containing the following information are listed:
Column | Description |
---|---|
Object |
Display name of the assigned entitlement or membership, which occurs in one of the selected roles. |
Type |
Type of the entitlement or membership. |
Name of the source role |
Assignment type if the entitlement or membership. The following assignment types are available.
For more detailed information about "Basics for Assigning Company Resources", see the One Identity Manager Identity Management Base Module Administration Guide. |
Name of the second role | See "Name of the source role". |
Comparison |
Name of the role with this assignment. |
|
NOTE: Use the filter function, which is available on nearly every column, to make the list of assignments clearer. For more information, see Filter. |
The Verify view is active. This lists the actions that need to run to merge the roles.
Save changes to the script. This opens the Results view.
If you have transferred all the properties of the second role by merging, this role is removed from the overview.
In the History view you can roll back the current state of a business role to a state it has had in the past. In the process, you decide yourself which attributes to change. After selecting the business role, all attributes are displayed. These attributes can all be rolled back, with a few exceptions, to a historical state.
In the following table, reasons are listed that prevent roll back to a historical state.
Factor | Description |
---|---|
Attribute was not changed. | Change is not possible without a comparative value. |
Membership resulting from delegation. | These memberships are not reset. |
Inherited membership | These memberships cannot be deleted. |
Membership resulting from a dynamic group. | These memberships cannot be deleted. |
To roll back the state of a business role to a historical state
All the attributes for this business role are displayed in a list. These include business role properties, memberships, actions, amongst others. By default, all attributes are selected.
|
NOTE: If you cannot select an attribute, the check box is not set. |
The selected attributes are displayed in the Roll back changes dialog box. You can still change your choice by disabling enabled attributes.
There are other actions available in the context menu View settings, which are listed in the following table.
Menu Item |
Description |
---|---|
Reset view |
Sets the view back to default after you have, for example, applied a filter. |
Save current view |
Save the current view to using with filters, for example. |
Reload data |
Reloads the data. |
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy