Chat now with support
Chat with Support

Identity Manager 8.1.5 - Attestation Administration Guide

Attestation and recertification
One Identity Manager users for attestation Attestation base data Attestation policies Custom mail templates for notifications
Approval processes for attestation cases
Approval policies for attestations Approval workflow for attestations Selecting attestors Setting up multi-factor authentication for attestation Prevent attestation by employee awaiting attestation Attestation by peer group analysis Managing attestation cases
Attestation sequence Default attestation and withdrawal of entitlements User attestation and recertification Mitigating controls Configuration parameters for attestation

Compliance framework overview

You can see the most important information about a compliance framework on the overview form.

To obtain an overview of a compliance framework

  1. In the Manager, select the Attestation | Basic configuration data | Compliance Frameworks category.

  2. Select the compliance framework from the result list.
  3. Select the Compliance framework overview task.

Assigning attestation policies

Use this task to assign attestation policies to the selected compliance framework.

To assign attestation policies to a compliance framework

  1. In the Manager, select the Attestation | Basic configuration data | Compliance Frameworks category.

  2. Select the compliance framework from the result list.
  3. Select the Assign attestation polices task.

    Assign the attestation policies in Add assignments.

    TIP: In the Remove assignments pane, you can remove attestation policy assignments.

    To remove an assignment

    • Select the approval policy and double-click .

  4. Save the changes.

Chief approval team

Sometimes, approval decisions cannot be made for attestation cases because an attestor is not available or does not have access to One Identity Manager tools. To complete these attestations, you can define a chief approval team whose members are authorized to intervene in the approval process at any time.

There is a default application role in One Identity Manager for the chief approval team. Assign this application role to all employees who are authorized to approve, deny, abort attestations in special cases, or to authorize other attestors. For detailed information about application roles, see the One Identity Manager Authorization and Authentication Guide.

Table 7: Default application role for chief approval team

User

Tasks

Chief approval team

The chief approver must be assigned to the Identity & Access Governance | Attestation | Chief approval team application role.

Users with this application role:

  • Approve using attestation cases.
  • Assign attestation cases to other attestors.

To add members to the chief approval team

  1. In the Manager, select the Attestation | Basic configuration data | Chief approval team category.

  2. Select the Assign employees task.

    In Add assignments, assign the employees who are authorized to approve all attestations.

    TIP: In Remove assignments, you can remove the assignment of employees.

    To remove an assignment

    • Select the employee and double-click .

  3. Save the changes.
Detailed information about this topic

Standard reasons for attestation

For attestations, you can specify reasons in the Web Portal that explain the individual approval decisions. You can freely formulate this text. You also have the option to predefine reasons. The attestors can select a suitable text from these standard reasons in the Web Portal and store it with the attestation case.

Standard reasons are displayed in the attestation history.

To edit standard reasons

  1. Select the Attestation | Basic configuration data | Standard reasons category.
  2. Select a standard reason in the result list and run the Change master data task.

    - OR -

    Click in the result list.

  3. Edit the master data for a standard reason.

  4. Save the changes.

Enter the following properties for the standard reason.

Table 8: General master data for a standard reason

Property

Description

Standard reason

Reason text as displayed in the Web Portal and in the attestation history.

Description

Text field for additional explanation.

Automatic Approval

Specifies whether the reason text is only used for automatic approvals by One Identity Manager. This standard reason cannot be selected by manual approvals in the Web Portal.

Do not set the option if the you want to select the standard reason in the Web Portal.

Additional text required

Specifies whether an additional reason should be entered in free text for the attestation.

Usage type

Usage type of standard reason. Assign one or more usage types to allow filtering of the standard reasons in the Web Portal.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating