Role Editor Page

Use the Role Editor to define the roles for your enterprise. A role is a collection of entitlements or profiles that enable an identity to perform certain operations. For example, one role might enable an identity to request a purchase order and another might enable an identity to approve purchase requests. Use roles to monitor identity entitlements, identify policy violations, and compile identity risk scores to enable you to maintain compliance.

See How to Create or Edit a Role From the Role Management Page for information on how to work with roles the Role Editor.

Note: When adding new roles, the list of attributes changes to reflect the currently selected role type. When editing a role, if the role type changes, any attributes from the original role are preserved and the user is prompted with the warning message "This attribute does not apply to the current roletype."

Roles that are awaiting approval are displayed with a red square around the role icon. You can edit roles with approval or analysis pending, but a notice displays at the top of the page alerting you that "An approval or impact analysis work item is pending on this role." If you change and submit a role with changes pending, the original work item is deleted and replaced with a work item containing the latest changes. A role with changes pending approval displays the original, unchanged, role information on the Role Information panel, but the latest, changed, information on the Role Editor page. This enables you to view the role as it currently exists in the Role Information panel, but ensures that you do not duplicate changes on the Role Edit page.

The Role Editor panel contains all of the information associated with the selected role. Some of the sections listed in the table might not be available for all role types. If there is information associated with a role that is not supported by the assigned role type, the information is displayed with a warning message.

Role Editor – Archived Role Panel

Click an archived role to display the Archived Role panel and view the details of the archived role and determine the proper version for this rollback.

Click Roll Back to Archive Role to return to the Role Editor page. Use the action buttons on the bottom of the page to complete the procedure. If approval is required on role changes it is required when a role is rolled back to a previous version.

Role Editor – Edit Entitlement Panel

Use the Edit Entitlement panel to define the profiles that are included in the role. A profile is a set of entitlements on an application. An entitlement is either a specific value for an account attribute, most commonly group membership, or a permission. Profiles are not shared between roles.

Click Submit to save changes or add the profile to the role.

Note: The simple view may not be available for all roles.

There are two options for adding entitlements to a role, the Simple View or the Advanced View. The simple view eliminates the need to create attribute rules to locate entitlements and provides a dropdown list of the entitlement configured for selection for each application. See How to Create or Edit a Profile for information on how to work with profiles.

Role Editor – Provisioning Policy Editor Panel

Provisioning policies define the fields required for a role to be provisioned, often including a default value or script / rule for calculating a value. With a provisioning policy in place, when a role is requested and a field cannot be calculated by the system, the user must input specified criteria into a generated form before the request can be completed.

See How to Create or Edit a Provisioning Policy for information on how to work with provisioning policies.

The Provisioning Policy Editor panel contains the following information: