The Normalization Process

The normalization process reconfigures permissions into dedicated groups. Once a resource is normalized, we can automatically fulfill access certification campaigns and requests.

Normalized resources are enabled and relevant only for applications that support fulfillment.

Every resource managed by File Access Manager (except for AD groups) must go through a normalization process.

  • The system creates and sets managed permission groups with the correct permissions on the resource.

  • The system distributes Users with permissions on a resource among the managed permission groups, based on their current access levels. (It is possible to customize the action applicable to an inexact permission match).

  • The resource inheritance of permissions is set to false.

After successful normalization, it is possible to change resource permissions by:

    Access Request

    Whether self-issued, or as the result of an access certification campaign (Access Revoked).

    An approved What-If simulation

    One that a logged-in user has been requested to fulfill.