Owner Correlation

Configure owner correlation on each resource to map aggregated objects to the human identity responsible for managing and reviewing them. Configure each resource separately.

Owner correlation uses attribute mapping rules on the resource schema. It does not use account correlation to link source accounts to human identities.

Note
Configure owner correlation before or after dataset aggregation. Identity Security Cloud applies your mapping rules when aggregated objects are processed. If you do not configure owner correlation, or if the mapping produces no match, an owner is not assigned.

Configuring Owner Correlation

To configure owner correlation for a resource:

  1. Go to Admin > Connections > Sources, and open your source.

  2. Go to Dataset Management > Resources.

  3. Select the resource you want to configure.

  4. Select the Owner Correlation tab.

    The Owner Correlation tab contains Primary Correlation and Additional Owners. Use Primary Correlation to define the accountable owner. Use Additional Owners to add human identities or a governance group for review workflows.

Primary Correlation

Primary correlation identifies the accountable owner for each aggregated object from the resource.

To configure primary correlation:

  1. (Optional) Select Sync to Machine Accounts to apply the primary owner mapping to machine accounts when the connector supports this option for the resource.

  2. Select + Add Criteria if no criteria row is present.

  3. Set Attribute type to Human Identity or Account:

    • Select Human Identity to match a resource schema attribute directly to a human identity attribute.

    • Select Account to match through an account attribute on the source.

  4. In Schema Attribute, search for and select the resource schema attribute to use in the match.

  5. (Optional) In Transform, search for and select a transform to apply to the schema attribute value before matching.

  6. Complete the target attribute for the attribute type you selected:

    • When Attribute type is Human Identity, search for and select a value in Human Identity Attribute.

    • When Attribute type is Account, search for and select a value in Account Attribute.

  7. (Optional) Select + Add Criteria to add more mapping rules. Identity Security Cloud evaluates criteria from top to bottom. Drag a criteria row to change evaluation order or select the delete icon to remove a criteria row you no longer need.

  8. Configure additional owners if needed.

  9. Select Save.

Additional Owners

Additional owners supplement the owner defined in primary correlation for governance and review workflows. You can assign additional owners using human identity criteria or a governance group.

Using Human Identity Criteria

To configure additional owners using human identity criteria:

  1. On the Owner Correlation tab, under Additional Owners, set the owner type to Human Identity.

  2. Select + Add Criteria if no criteria row is present.

  3. Set Attribute type to Human Identity or Account.

  4. In Schema Attribute, search for and select the resource schema attribute to use in the match.

  5. (Optional) In Transform, search for and select a transform to apply to the schema attribute value before matching.

  6. Complete the target attribute for the attribute type you selected:

    • When Attribute type is Human Identity, search for and select a value in Human Identity Attribute.

    • When Attribute type is Account, search for and select a value in Account Attribute.

  7. (Optional) Select + Add Criteria to add another mapping rule. Drag a criteria row to change evaluation order or select the delete icon to remove a criteria row you no longer need.

  8. Select Save.

Using a Governance Group

To assign a governance group as an additional owner:

  1. On the Owner Correlation tab, under Additional Owners, set the owner type to Governance Group.

  2. In Governance Group, search for and select the governance group to assign as an additional owner.

  3. Select Save.

Tip
Define correlation criteria using attributes that reliably identify the accountable owner in your environment, such as email or employee ID mapped to a human identity attribute.