# SailPoint Non-Employee Risk Management User Help > SailPoint Non-Employee Risk Management Documentation User Help # SailPoint Non-Employee Risk Management User Help # SailPoint Non-Employee Risk Management User Help As a recognized leader in both Identity Lifecycle Management and Identity Access Management Software and Services, Non-Employee Risk Management provides the most comprehensive solutions to addressing employee and non-employee identity lifecycle. With products like Lifecycle and Collaboration built to fill the gaps in Identity Governance & Administration (IGA) products’ identity lifecycle capabilities, Non-Employee Risk Management provides software to gain full visibility of global identities and true management and control of non-employee lifecycle and risk. You can find documentation for administrators of your non-employee system in our [Admin Help](https://documentation.sailpoint.com/ne-admin/help/) section. ## Lifecycle Lifecycle is a powerful solution that allows an organization to easily manage business processes for third party identities, their relationships with your organizations and the risk associated with those relationships. With Lifecycle, users can: - Quickly onboard third-party resources and other identity types - Administer a single repository for all third-party identities and other identity types - Create relationships across identities while making those relationships actionable through forms and workflows - Easily configure the user interface and process workflows through an administrative UI - Manage identity risk Lifecycle is designed to provide your internal administrators, identity managers and owners the ability to manage third party identities. ## Collaboration Collaboration is an isolated web portal that enables the self-registration and self-service functionalities to third parties. Collaboration allows third parties the opportunity to collaborate in the process of managing the third-party identity lifecycle. The portal-based system allows for third parties to interact through third party delegated administration, or self-service based on the specific use cases and permissions granted to them by the internal organization. # Using the Dashboard The Home page of Lifecycle is referred to as the Dashboard and the menu on the left side of the dashboard is referred to as the Left Navigation. Users will only have access to the applications for which valid licenses have been installed like Lifecycle or Collaboration. For the purposes of this document, only the Lifecycle dashboard and dashboard left navigation are covered. ## Dashboard Home Page The dashboard home page is presented upon successful authentication of a user. There are several components to the dashboard home page outlined below. ### Widgets Band The widgets band at the top of the home page allows you to see your pending requests and the tasks that are pending your action. ### Workflow Bar In the workflow bar on the dashboard, 2 of the 4 types of workflows are displayed. The left side of the workflow bar displays the available Create Profiles workflows that the current user has permission to run. The right side of the workflow bar displays Batch workflows that the current user has permission to run. Note Workflows enabled for Bulk Import Usage can only be launched using the CSV Import process from the [Profiles](https://documentation.sailpoint.com/ne-user/help/profiles/index.html) page. ## Active Profiles Table The Active Profiles table contains a more in-depth tabular view of the number of active profiles, pending requests, and pending actions associated with the current user. Your administrator might customize this view, displaying the preferred data in each table. ## Language Selection If multi-language support is enabled for your environment, the supported languages will be displayed at the bottom of the dashboard. Selecting one will reload the page in the selected language and use that language while you are signed in to Lifecycle. ## Dashboard Left Navigation On the left side of the dashboard is a navigation pane referred to as “left nav” or “left navigation”. This allows quick access to available application features. ### Application Accessibility Depending on which licenses are registered, the available applications in the left navigation will vary. ### Home Selecting the **Home** link in the Dashboard Left Navigation returns the current user to the default view of the Dashboard Homepage. # Dashboard Filters You can refine the list of items displayed on your Dashboard by applying filters. ## Filtering Requests and Actions Filters refine the results of the [Requests](https://documentation.sailpoint.com/ne-user/help/dashboard/my-requests.html) and [Needs Action](https://documentation.sailpoint.com/ne-user/help/dashboard/needs-action.html) views. To apply a filter: 1. Select the ellipsis icon next to Filter. 1. Attribute 1. Enter the name of the attribute to filter on in the Search box. 1. Once the selection has been made, the **Operator** and **Value** fields appear. 1. Operator 1. Select the desired operator. 1. These values available will vary based on attribute selected. 1. Value Enter the filter criteria of the data to view. If a date attribute is selected and the operator selected is *more than*, *less than*, or *exactly*, 2 additional fields (Days and Timeframe) will appear. 1. Select the plus icon to add the filter. The applied filter will appear under the Conditions section. 1. Conditions Underneath the Attribute, Operator, and Value fields, the current filter(s) applied will appear under this section. If no filters are currently applied, it will read “None (Add conditions using the inputs above). All fields required.” 1. The filtered results are displayed. 1. Multiple filters can be added by repeating steps 3-6. By default, when multiple filters are added, each filter defaults as an ‘AND’ condition. Users can select the toggle switch to change the AND condition to an OR condition. 1. The number of filters applied will appear next to the Request header. To remove a filter: 1. Select the delete icon next to the filter to remove. Filters are not persistent. When users navigate away from the page, the applied filter(s) will disappear. ## Filtering Profiles You can filter which profiles are displayed in your list of profiles. You can also save those filters and share them with users that have specific roles in your organization. **To filter the list of profiles:** 1. Go to **Lifecycle > Profiles** from your Dashboard. 1. In the **Profile Type** dropdown, begin typing the name of a profile type. Select the profile type that contains the profiles you want to view. 1. Select the ellipsis icon beside the **Filter** header. 1. Choose whether you want to [create](#creating-a-profile-filter) a new filter or [apply](#applying-a-profile-filter) one that has been created already. ### Creating a Profile Filter 1. From the filter screen, in the **FILTER BY** tab, choose the type of filter you want to create by selecting the **Type** dropdown list. Complete the additional fields that are added based on your selection. 1. To add additional filter criteria, select **Add Criteria**. Choose an operator between each set of criteria. The options are AND or OR. 1. Select **Apply**. Your filter is applied to the list of profiles. 1. To save your filter, select **Save as New Filter**. Note You must apply your filter before you can save it. 1. Enter a label for your new filter. 1. If you want to be able to apply your new filter to multiple profile types, type the name of the additional profile types you want to add in the **Profile Type** field and select them from the dropdown list. 1. Select **Save**. Your profile filter is added to the list of profile filters. You can also create a new filter by editing an existing filter and selecting **Save as New Filter**. ### Applying a Profile Filter 1. From the filter screen, select the **SAVED FILTERS** tab. A list of filters that you own or that have been shared with you is displayed. 1. Select the name of the filter you want to use. The list of profiles is updated to reflect your selected filter. You can [edit](#editing-a-saved-profile-filter) this filter and save your changes, or save it as a new filter based on the existing criteria. ### Editing a Saved Profile Filter You can make changes to a saved profile filter. 1. From the filter screen, select the **SAVED FILTERS** tab. A list of filters that you own or that have been shared with you is displayed. 1. Select the filter you want to edit. 1. In the **Criteria** panel, make the necessary changes to your profile filter. You can edit the existing criteria, delete them, or add new criteria. 1. Select **Apply**. 1. To create a new filter with the criteria you applied, select **Save as New Filter**. To overwrite the existing filter you edited, select **Update Saved Filter**. ### Sharing Profile Filters You can share a filter you own with other users by their roles. 1. From the filter screen, select the **SAVED FILTERS** tab. A list of filters that you own or that have been shared with you is displayed. 1. Select the Actions icon and select **Share**. 1. In the **User Role** field, begin typing the name of a user role. Select the name of the role you want to add. Repeat for each user role that needs access to this filter. 1. Select **Share**. Users with any of the roles you selected in the Share Filter screen will be able to use the filter you shared with them. They will not be able to edit the filter or share it with others. # Requests The **Requests** link in the Dashboard left navigation displays all requests that the current user submitted. The current user appears in the **request by** field. This is also accessible from the Widgets Band and the Active Profiles Table via the **Pending Requests** tab. - **Pending tab** This is the default view of the requests page. This view lists the requests submitted by the current user that are currently in a Pending status. Only items which the user has permission to will appear here. You might see the BULK ACTIONS tab allowing actions to be performed in bulk. Select **BULK ACTIONS** and go to the Pending tab, select multiple requests and select **Actions > Cancel Requests**. Note If the reviewer rejects your request, it will be returned to you and you will need to resubmit the request. - **Completed tab** This view lists the requests in a Completed, Closed or Workflow Changed status that were submitted by the current user. - **All tab** This view lists all requests, regardless of status, that the user has submitted. - **Filters** Filters will refine the results of a view. Refer to [Filters](https://documentation.sailpoint.com/ne-user/help/dashboard/filters.html) to learn more on applying filters. # Needs Action The **Needs Action** link in the Dashboard left navigation displays all requests that requires the current user’s action. This is also accessible from the Widgets Band and the Active Profiles Table via the **Needs Action** tab. The total number of Requests on each tab is displayed next to the REQUESTS header. - **Pending tab** The needs action page defaults to the Pending tab. This view lists the requests in a Pending status that require the current user’s action. Only items which the current user has permission to will appear here. You might see the BULK ACTIONS tab. Selecting **BULK ACTIONS** and then selecting the **Pending** tab lists the requests in a Pending status that the current user can approve or reject in bulk. - **Completed tab** This view lists the requests in a Completed, Closed or Workflow Changed status. These do not require any action and only items which the current user has permission to will appear here. You might see the BULK ACTIONS tab. Selecting **BULK ACTIONS** and then selecting the **Completed** tab lists the requests in a Completed, Closed, or Workflow Changed status that were available to be approved or rejected in bulk. - **All tab** This view lists all requests, regardless of status, that the current user has permission to view. You might see the BULK ACTIONS tab. Selecting **BULK ACTIONS** and then selecting the **All** tab lists all requests, regardless of status, that were available to be approved or rejected in bulk. - **Filters** Filters will refine the results of a view. Refer to [Filters](https://documentation.sailpoint.com/ne-user/help/dashboard/filters.html) to learn more on applying filters. # Delegating Work On the dashboard left navigation, directly below the current user’s username is the option to assign a delegate. Assigning a delegate grants specified user(s) temporary access to the current user’s privileges. Delegates, for the duration of their delegation, will have access to all profiles that the current user owns, or have access to through the current user’s role, giving them the ability to act on the current user’s behalf. ## Adding a Delegate In the Dashboard Left Navigation: 1. Select the plus icon next to Delegates. 1. In the Delegate search box, enter the username or email address of the desired user. 1. Complete the following fields: - **Expires?**: Choose **No**, if the delegated user shall retain the privileges granted indefinitely (these can always be revoked manually). Choose Yes to set an expiration date for when the delegated privileges should expire. - **Expiration Date**: This field only appears if **Yes** is chosen in the Expires? field. Select the date the privileges should automatically expire. 1. Select **Delegate**. 1. Repeat Steps 1-4 to add additional delegates. ## Updating a Delegate Once access has been delegated, users may want to extend an expiration date or end the delegation early. To update an existing delegate: In the Dashboard Left Navigation: 1. Select the delegated user’s icon. 1. To revoke the delegation, select the button. 1. To edit the delegation, modify the **Expires?** and/or **Expiration Date** fields and select the button to save the changes. ## Acting as a Delegate Once a user has been granted delegate access, they can then act on behalf of the user that delegated access. If someone has delegated work and access to you, you can act as the user who delegated access. In the Dashboard Left Navigation: 1. Hover over the delegate’s icon next to **Act as**, the image should change from the default picture to a login icon. 1. Select the login icon. 1. The user is now acting on behalf of the user that delegated access. 1. Select the button to switch back to the current user’s account. # Getting Started in Non-Employee Risk Management ## Before Using the System Before you use Lifecycle, make sure your browser is supported and learn more about the terminology used in Non-Employee Risk Management. ### Supported Browsers Use the following table to verify that your browser is supported: | Browser | Version | | ----------------- | -------------- | | Firefox | Latest Version | | Chrome | Latest Version | | Edge Chromium | Latest Version | | Internet Explorer | Not Supported | Earlier versions of the above browsers may experience mixed results for display and functionality as they may interpret HTML, CSS, and JavaScript differently. ## Understanding the System To understand how to use Lifecycle it is important to first understand the terminology and relationship between the system components. ### Profile Types and Profiles In the Identity and Access Management (IAM) space, *identity* refers to the body of information about an individual, organization, or thing (e.g., electronic device) that exists. Within the Non-Employee Risk Management Identity Suite, identities are referred to as profiles. A *profile* within the application is the collection of data that forms an identity. A *profile type*, like a category, is used for grouping like profiles. #### Profiles There is an infinite number of profiles that can be created within the Identify Suite. Below are some of the examples of the most used profiles: - People: The profile data for a person will contain personal information, data that is unique to that individual. Some examples of profile data for a person might be: first name, last name, address, and phone number. - Entities: The profile data for an entity will contain data that is unique to that entity. An example of an entity may be your Vendors, Partners or Clients. Some examples of profile data for an entity might be: Company Name, Company Address, Company Contact E-Mail. - Things: Items can also have profiles, for example, a laptop. In this case, profile data might include make, model, serial number, etc. - Areas within an Organization: Areas within a company can also have profiles, for example a department. In this case, profile data might include department name, department number, manager, location, etc. #### Profile Types Profile types, like a category, are used for grouping similar profiles. Like profiles, there are an infinite amount of profile types that can be created within the Identify Suite. Using the example above, the following are examples of commonly used profile types: - Non-Employee: This profile type is used to classify the group of people who are considered Non-Employees. - Vendor: This profile type is used to classify external entities that provide services to your organization. - Laptop: This profile type is used to classify laptops used throughout your organization. Related profile types could be desktops, cell phones or even software. - Department: This profile type is used to classify departments throughout your organization. The advantage of organizing data into different profile types is that distinct owners and contributors can be assigned to each profile type, allowing each profile type and its lifecycle to be managed independently of each other. ### Workflows A *workflow* is a series of sequential tasks that are executed based on Lifecycle administrator defined rules, tasks, data and/or conditions, to perform various actions, tasks, or trigger notifications within the Identity Suite. Users are presented with a workflow button to initiate the required action; however, the actual components of a workflow are not visible to general users of the system. Workflows are defined by Lifecycle administrators and discussed in depth in the Lifecycle Admin guide. There are 4 types of workflows in Lifecycle: - **Create**: are viewable from the dashboard and are used to create new profiles in the system. - **Update**: are viewable when looking at a profile and are used to update the profile that users are currently viewing. - **Automated**: are date triggered by attribute on existing profiles and run automatically. - **Batches**: are viewable from the dashboard. Batches start with a filter tool that allows a user to search and select multiple profiles to run an update action against. ### Relationships within the Identity Suite #### Between Profiles and other Profiles As described above in the [Profiles](https://documentation.sailpoint.com/ne-user/help/profiles/index.html) section, profiles can include information about people or information about other identities such as vendors, departments, laptops, etc. Profiles can have relationships to one another, such as, a person profile can have a relationship to a vendor profile, department profile and a laptop profile. As the number of relationships grows exponentially, the Identity Suite allows organizations to efficiently identify and manage all these relationships. The most effective method to manage these relationships, is defining a relationship between the various profile types. For example, your organization creates a profile type named **Vendors** and populates it with all the third-party profiles that provide the organization with non-employees. Next the organization creates a profile type named **Non-Employees** and populates it with all the applicable people profiles. Organizations can now identify each Non-Employee and the Vendor from which they originate by linking the third-party profile to the people profile, thus creating a relationship between that individual and their organization. This allows management of all the data related to third-party profiles to be performed independently from a person’s profile. For instance, if a third-party’s address changes, only the third-party’s profile requires an update and not a field in every related person’s profile. This is also effective because system users who manage vendor data may be different than those who manage non-employees. As another example, one of your organization’s third parties has multiple non-employees providing services where each person is issued a mobile device. If the relationship with that vendor is terminated, you need to retrieve all issued company mobile phones that were issued to these non-employees. By tracking and maintaining these relationships within the Identity Suite, it is easy to keep business processes on track. #### Between Users and Profiles User-to-Profile relationships exist to identify the responsible owner who will manage a *profile*. There are two types of User-to-Profile management options: “Owner” and “Contributor”. These User-to-Profile relationships control what profiles a user can see and act against. The exception to this, is when an Administrator is granted permission that overrides this relationship. - **Owner**: Every profile should have an Owner. The owner is the individual ultimately responsible for the profile and associated relationships which they are assigned ownership. An owner is limited to one user. - **Contributor**: Contributors are users and/or groups with the responsibility to assist with the management of a profile. Unlike owners there can be several contributors. User Roles can also be set as contributors so that many users with shifting roles will always maintain appropriate profile access. For example: Human Resources may be a contributor in the management of a group of non-employees, but the owner is the business unit responsible for the relationship with the vendor for which those non-employees work. #### Between Users and Users User-to-User relationships may be imported via the Non-Employee API to mimic the management structure of your organization. These relationships may be leveraged within workflows to direct approval and fulfillment actions. ### Users and User Roles The Identity Suite requires user accounts and roles to establish authentication and determine access to specific resources in the application. #### Users Users are internal employees of the organization who are responsible for administering the Identity Suite or managing various components of the system and its processes. The system is designed to import user data from an SSO provider as users log in to the system. In addition, user records can be pre-loaded into the application via the API. #### User Roles User roles tie application access to entitlements associated to a user account by the SSO provider. ### Identifying and Managing Risk A key component of managing third parties is identifying, evaluating, and acting upon identified risks. #### Risk Scoring A risk scoring model allows organizations to individually identify key criteria and assign different values to characteristics, that are applicable to their own specific situation. The Identity Suite provides robust risk scoring capabilities that allows organizations to identify and address risks that are posed to an organization by assigning a risk scale to profiles and profile types within the application. For example, organizations can evaluate risk associated with all their Non-Employees. Risk scores are categorized into configurable risk levels (i.e. High, Medium, Low etc.) and risk levels can trigger actions or workflows such as additional approvals, policy driven action and escalations. #### Risk Categories Risk categories are a specific way to group risks under a common area which provides a structured and systematic approach in identifying risks to a consistent level of detail. For example, the human resource department may choose to evaluate non-employee risk including demographic information such as citizenship and location, while the information security department may choose to evaluate vendor risk including what data the vendor has access to and the security controls they have in place to protect that data. Risk categories in combination with the Identity Suite’s robust risk scoring offers organizations the ability to improve the effectiveness and quality of the risk identification, analysis, and mitigation processes. #### Mitigating Controls Mitigating controls are put in place to reduce either the probability or consequences of a threat. For risk mitigation to be effective organizations need to take immediate action to reduce human and financial consequences later. The Identity Suite allows mitigating controls to be defined and assigned to identified risks within the system providing the organization a true measurement of posed risks. # Managing Your Account On the dashboard left navigation the current user’s name and avatar is displayed. You can view information about your account and upload an avatar to your account in Non-Employee Risk Management. In the Dashboard Left Navigation: 1. Select the username to view the current user account information 1. On the user account page, the following information is displayed: - **Avatar**: This is the only user account setting that is editable within the application. The recommended size is 200px x 200px and no larger than 75 kb. To edit the avatar: 1. Hover over the current avatar. The image changes from the default picture to the edit icon. 1. Select the edit icon. 1. Select **Choose File** and browse to desired image. 1. Select **Update**. If the image disappears when the page is refreshed, re-size the image to smaller dimensions and re-load. - **Name**: This is Read Only and is provided by the SSO provider on login. - **Email**: This is Read Only and is provided by the the SSO provider on login. - **Title**: This is Read Only and is is provided by the SSO provider on login. - **Roles**: This is Read Only and is based on the groups assigned to you within your SSO provider. Some types of users might be able to edit some of this information. Refer to [Editing My Profile](https://documentation.sailpoint.com/ne-user/help/getting-started/my-profile.html) for more information. # Editing My Profile If this capability is configured, non-employees can access the system to edit their own profiles. The **Edit my profile** section allows these non-employee users to view and update their information, access assigned workflows and perform other actions for which they have permission. On the **User Account** page, the current user can view and update their information. Uploading an image: 1. On the user account page: 1. Hover over the current avatar, the image changes from the default picture to an edit icon 1. Select the edit icon. 1. Select **Choose File** and browse to the desired image. 1. Select **Update**. To edit your information: 1. On the **User Account** page: 1. Select the edit icon in the field to edit. 1. Make the necessary changes. 1. Select **Update**. Users can edit multiple fields at a time by selecting the icon next to each field to edit. # Registering and Logging In as a Non-Employee In many cases, an account has already been created for you before you visit Non-Employee Risk Management for the first time. In other cases, you'll be sent a link to register or log in with Non-Employee. ## Registering for Non-Employee Risk Management Prior to being able to access the portal, most first time users must register their account within the system. If your company is using Microsoft Entra ID, you are required to provide a verifiable credential to verify your identity. Notes - The following is a sample registration workflow for first time users. Fields may vary based on actual configurations. - If at any time during the registration process a user must stop or the process is disrupted, users can return to where they left off by selecting the **Resume registration** link on the login screen. **To register a profile:** 1. If you received an email invitation to register for Non Employee Risk Management, go to the URL in the invitation and select **Resume registration**. If you haven't received an invitation, you can go directly to the URL provided by the site administrator and select the appropriate registration button under the **First Time Users** section. 1. In the **Email** field, enter a valid email address. 1. Select **Send Verification**. 1. Check your email for a registration email that will contain the required verification code. Users can open a new browser session by selecting **Enter verification code here** or enter the verification code in the browser session already open. 1. In the **Verification code** field, enter the verification code received via email. 1. Select **Submit**. Note If the verification code was not received, select **Resend** to send a new verification code. 1. Upon selecting **Submit**, users are presented with a form to complete. 1. Enter the required information. - The **Close Request** button allows users to exit the registration process. Users are prompted to confirm they want to close the request. Once closed, it can not be resumed. - The **Show Comments** button allows users to provide comments during the registration process. Comments are shown after the user selects the Submit button. 1. Select **Submit**. 1. Users are presented with the Collaboration account page to create their login to the portal: - Username: enter a unique username - Password: enter a strong password - Password confirmation: re-enter the strong password Collaboration passwords must meet the following criteria: - The password must be 8 or more characters long. - It must contain at least 3 out of these 4 types of characters: - Lowercase letters - Uppercase letters - Numeric characters - Special characters 1. Select **Submit**. Users are presented with a confirmation page. **To register a profile using Microsoft Entra Identity Verification** 1. Go to the URL in your email invitation. 1. In the **Email** field, enter your email address. 1. Select **Send Verification**. 1. Check your email for a registration email that will contain the required verification code. 1. In the **Verification code** field, enter the verification code received in the email. 1. Select **Submit**. Note If the verification code was not received, select **Resend** to send a new verification code. 1. Upon selecting **Submit**, users are presented with a form to complete. 1. Enter your first name and last name. - The **close request** button allows users to exit the registration process. Users are prompted to confirm they want to close the request. Once closed, it can not be resumed. - The **show comments** button allows users to provide comments during the registration process. Comments are shown after the user selects the submit button. 1. Select **Submit**. 1. To verify your identity you must provide a verifiable credential. - **If you do not have a digital credential** to use for registration, select **Create a Verifiable Credential**. Scan the QR code and follow the instructions on the identity verification provider’s site. - **If you have a digital credential** to use for registration, go to the next step. 1. Select **Use Verifiable Credential**. Scan the QR code and follow the instructions on your device to complete the identity verification. Users are presented with a registration completion page. ## Logging In In most cases, you will sign in using your company's SSO provider and be directed to SailPoint Human Fabric. From there, you can select the App Switcher and go to Non-Employee Risk Management. Depending on your administrator's settings, you might instead be directed to your Non-Employee Risk Management dashboard. When you authenticate using your company's SSO provider, the username and password fields won't be visible. If you need to sign in using a username and password, the steps might vary based on your administrator's configurations. To login, you might: 1. Username: enter the username specified during registration. 1. Password: enter the password specified during registration. 1. Select the **Login** button. ## Recovering Usernames If a user has forgotten the username specified during the registered process: 1. Select the **forgot my username** link on the login screen. 1. Provide a valid email address in the **Username Recovery** dialog box. 1. Select **Submit**. 1. If a valid email address was entered, the user will receive an email with the username specified during registration. ## Resetting Passwords If a user has forgotten the password specified during the registered process: 1. Select the **forgot my password** link on the login screen. 1. Provide either the username or email address specified during registration in the **Password Reset** dialog box. 1. Select **Submit**. 1. If a valid email address or username was entered, the user will receive an email with a validation code. 1. In the **Verification code** field, enter the verification code received via email. 1. Select **Submit**. Note: If the code was never received, users have the option to resend the verification code by selecting the Resend button 1. In the **New password** field, enter a new strong password. 1. In the **Password confirmation** field, re-enter the strong password. 1. Select **Submit**. 1. Users will be redirected to the login page. # Managing Profiles A profile is any individual, organization, or other object you can manage. This includes non-employees, the organizations they come from, or the assignments they work on, and additional data related to non-employees in your organization. ## Creating Profiles You can create profiles within your organization so that they can be managed. ### Creating an Individual Profile To create an individual profile: 1. On your Home page, in the **Create Profiles** section, select the button corresponding to the type of profile you want to create. This begins a workflow designed by your administrator to create a new profile of the selected profile type. 1. If applicable, complete the form as configured by your administrator. 1. Select **Submit**. Depending on the configurations your administrator made to this workflow, the profile might be created immediately or it might need to be approved by a reviewer before it can be created. Go to the [Requests](https://documentation.sailpoint.com/ne-user/help/dashboard/my-requests.html) page to review your submitted requests, or go to [Needs Action](https://documentation.sailpoint.com/ne-user/help/dashboard/needs-action.html) to review the requests other users have submitted that require your attention. ### Uploading Profiles in Bulk You can also upload a CSV file containing details about a list of profiles you would like to add to Non-Employee Risk Management. 1. Select **Lifecycle > Profiles** from the left sidebar. 1. Select **Import**. 1. In the **Action** section, select **Create**. 1. Select the workflow that should be used to create these profiles. The workflow you should select usually depends on the type of profile being created. 1. If your CSV file does not contain headers, move the **Use CSV file first row as column headers** toggle switch to **Off**. 1. Under **File Upload**, select a CSV file containing a list of profiles. Note This file must contain no more than 1,000 profiles. Each column in this file is expected to correspond to one attribute of a profile, and each row is used as one profile. Your file can include up to 500 columns. The values in each column will be used as the values for the attributes you select in the next step. 1. In the **Column Attribute Recommendations & File Preview** section, select the attribute that best corresponds to the data in each column. If you do not select an attribute for a column, the values in that column will not be uploaded or assigned to profiles. If your file included column headers, attributes are recommended based on the column headers. Use the horizontal scroll bar to find all of the columns you uploaded with the CSV file. 1. Select **Import**. The workflow you selected is started for each row in the CSV file. Depending on the workflow's actions, the profiles are created. ## Editing Profiles If you have edit access to a profile, you can edit it after it has been created. ### Editing an Individual Profile To edit an individual profile: 1. Go to **Home > Lifecycle > Profiles**. 1. In the dropdown list, select the profile type of the profile you want to edit. 1. Select the profile you want to edit. 1. Select the **Edit** button. 1. Update the applicable fields on the profile. These fields vary based on your organization's configurations. 1. Select **Save**. In some cases, you can also make certain types of changes by selecting the workflows at the top of the page, depending on the workflows your administrator has configured. ### Updating Profiles in Bulk You can upload a CSV file of profiles to update multiple profiles at once. To upload a list of profiles to edit: 1. Select **Lifecycle > Profiles** from the left sidebar. 1. Select **Import**. 1. In the **Action** section, select **Update**. 1. Select the workflow that should be used to update these profiles. The workflow you select usually depends on the type of profile you're updating. 1. If your CSV file does not contain headers, move the **Use CSV file first row as column headers** toggle switch to **Off**. 1. Under **File Upload**, select a CSV file containing a list of profiles. Note This file must contain no more than 1,000 profiles. Each column in this file is expected to correspond to one attribute of a profile, and each row is used as one profile. Your file can include up to 500 columns. The values in each column will be used as the values for the attributes you select in the next step. 1. In the **Column Attribute Recommendations & File Preview** section, select the attribute that best corresponds to the data in each column. If you do not select an attribute for a column, those columns will not be added to attributes on your profiles. If your file included column headers, attributes are recommended based on the column headers. Use the horizontal scroll bar to find all of the columns you uploaded with the CSV file. 1. In the **Unique Identifier Attribute** field underneath the table, select the attribute used as a unique identifier for profiles in this profile type. This attribute must be selected for one of the columns in the file preview. 1. Select **Import**. The workflow you selected is started for each row in the CSV file. Depending on the workflow's actions, the profiles are updated. ## Viewing Profiles and Profile Types To view profiles and profile types: In the Dashboard Left Navigation: 1. Select the **Profiles** link. On this page users are presented with variety of options for viewing the profiles associated with a profile type. All the available profile types are displayed on the top of the page. Selecting a profile type link displays the associated profiles on the bottom of the page. The total number of profiles the current user has access to is displayed next to the profile type header. Users also can apply filters to limit the number of profiles that appear on the table. Refer to [Filters](https://documentation.sailpoint.com/ne-user/help/dashboard/filters.html) to learn more about applying filters. Within a profile, there may be workflows present that can be initiated by the current user. Workflows vary widely and are completely dependent on the actions defined by the Lifecycle Administrator. To initiate the action, select the workflow button. Depending on the workflow, additional actions may be required. Refer to [workflows](https://documentation.sailpoint.com/ne-user/help/getting-started/index.html#workflows) to learn more about the types of workflows. #### Active tab The Active tab is the default view of the specific profile type selected in the left navigation. This view lists the profiles associated with the selected profile type that are in an active status. Only items that the user has permission to will appear here. #### Inactive tab The Inactive tab lists the profiles associated with the selected profile type that have been marked inactive or terminated. Only items that the user has access to will appear here. #### All tab The All tab lists all profiles associated with the selected profile type, regardless of status, that the user has access to. Users can also apply an additional layer of filtering, further refining the results by My Profiles or Show All. #### My Profiles The My Profiles tab lists the only the profiles the current user is responsible for managing. This occurs when the user is an owner or a contributor to a profile, or if a user role they have grants them those permissions. #### Show All The Show All tab lists the all the profiles the current user has access to whether they manage them or not. Only profiles that the user has access to will appear here. ### Viewing Risk on Profiles Profiles assigned risk display an overall risk score and level that you can use to identify risks and help assess the threat they pose. Selecting the overall risk score on the profile table and profile detail page displays the profiles risk breakdown. Details of all risk elements assigned to the profile are displayed. Risk elements include: - **Overall Risk** - The overall risk score and risk level assigned to the profile. - **Impact** or **Probability** - Attributes assigned to the profile with the *impact* or *probability* risk type. - **Attribute** - The attribute assigned to the profile. - **value** - The chosen option for the attribute. - **risk** - The risk score assigned to the chosen option. - **mitigated by** - The name of the mitigation attribute, its chosen option, and the assigned mitigated risk score. If there is no mitigation assigned this will be blank. - **residual risk** - The attribute's risk score after mitigation is applied. - **avg impact/probability** - The averaged value of all impact or probability attributes residual risk scores. Notes - If the profile inherits risk from another profile, the overall risk score includes an asterisk, and details of the inherited profile are displayed at the top of the breakdown chart. - If the profile includes a subcategory, details of the subcategory are displayed at the bottom of the breakdown chart. Subcategories provide an additional risk score for profiles to help identify additional risk. For example subcategories may have been created for departments that have different risk factors. - Subcategories do not affect the profiles overall risk score. ## Dashboard Search Functionality Search results are limited to the Profiles that the user is permitted to view. ### Search Bar The search bar on the home page on the Dashboard enables a user to search for profiles by their profile name. This name is the title of the profile as it appears at the top of the profile's page and it depends on your administrator's configuration. You can also find this search bar on the list of profiles. In addition to plain text queries, the search bar supports regular expressions. For example: - `John D[a-z]* Smith` returns all profiles containing John, any word beginning with D, and then Smith. - `Contractor.+2025` returns all profiles containing the word "Contractor," one or more of any other character, and then 2025. - `\(Administrator\)` returns all profiles containing the string, "(Administrator)". Note that the parentheses are escaped by backslashes. The profiles that are returned reflect profiles you are allowed to view that match the results of your search query. #### Advanced Search Selecting the **advanced** button directs users to the advanced search page, allowing users to refine the search criteria using filters. When multiple filters are added, each filter value is treated as an ‘AND’ condition. Advanced searches can be saved and once saved will appear on the saved searches tab. #### Creating a New Advanced Search To create a new advanced search, from the Dashboard: 1. Select the advanced button in the search bar. Users land on the new search page and are presented with a default filter by profile type. Users can either modify this default filter or select the delete icon to remove the filter. 1. Adding filters 1. Select the **+ Add Filter** button. 1. Select the appropriate value from the **Type** dropdown to filter: Profile ID, Profile attribute, Profile risk level, Profile status and Profile type. 1. Complete the related filter criteria for the Type selected. Various filtering selections are available based on the Type selected. 1. Select **Search**. 1. The search results will appear in the Results section. 1. Saving Searches 1. Select **Save**. 1. In the dialogue box, enter a unique label for the search. 1. Select **Save**. #### Viewing Saved Advanced Searches To view a previously saved search, from the Dashboard: 1. Select the **Advanced** search button. 1. Select the **Saved Searches** tab. A list of previously saved advanced searches is displayed. # Managing Reports Within the Lifecycle application users can create, manage, and run reports. ## Creating and Exporting a New Report In the Dashboard Left Navigation: 1. Select the **reports** link. 1. Select the button. 1. Complete the following fields: 1. **Name**: Enter a unique name for this report. 1. **Filters**: A default filter is displayed that can be edited. To remove a filter, select the delete icon. Additional filters can be added by selecting the **+ Add Filter** button. 1. Select **Next**. 1. **Define Content**: 3 default fields are displayed. Users can choose to hide these or make them visible in the report by selecting the visibility icon to toggle on or off . - uid - status - risk score 1. **Add Attributes**: Select additional attributes to display in the report (optional). Use the search field to search across the existing attributes to add to the report. Once added to the Define Content section, users can remove the added attributes by selecting the delete icon or drag attributes up or down to change the order the columns in the report. 1. Select **Next**. 1. **Sharing**: (optional) Search and add the User Roles who can access this report. Once a role is selected it appears above and users can remove the added roles by selecting the delete icon. 1. **Generate Reports**: This page provides the user a summary of the report to be created and the ability to generate and export the report, by selecting the **Generate CSV** button. 1. Once the report finishes generating, the report is available under the Exports header. Users are presented with a button and a delete icon. 1. Select the **download** button to download the report to a location of your choice or select the **delete** icon to delete this generated version of the report. Users are prompted to confirm deletion if they selected the delete icon. ## Viewing and Exporting Existing Reports Users can view existing reports that have been previously generated. To edit an existing report: In the Dashboard Left Navigation: 1. Select the **Reports** link. 1. Select the report to edit or download from the My Reports or Shared tab. 1. By default, the Generate Reports page is displayed if the report has been previously generated. Users can either: - Select the **Generate CSV** to regenerate and export a new report. Once selected the report will appear on top of any previously generated reports under the Export header. - Under the Export header, choose from a listing of previously generated reports to download by selecting the **Download** button. - Under the Export header, delete a previous report generation by selecting the **Delete** icon . 1. Users also can modify the parameters of a previously generated report by selecting the **filters** tab on the tool bar. - **filters**: On the Define Filters page, users can choose to edit the Name of the report, edit the existing filter parameters, remove existing filters, and/or add new filters. To keep the same Filters, simply select **Next**. - **content**: On Define Content page, users can choose to add new columns, remove columns, and/or reorder columns. To keep the same columns, simply select **Next**. - **sharing**: On Sharing page, users can choose to remove user roles, add user roles to change who the report is shared with. - **export**: On the Export page, users can generate and download the report. 1. You can delete the entire report and all exports associated with it by selecting **Delete** . ### All tab The All tab is the default view of the reports page. This view lists all reports generated within the application that the logged in user can access. ### My Reports The My Reports tab lists the reports the current user previously defined. ### Shared The Shared tab lists the reports another user has shared with the current user. Only items which the current user has permission to will appear here.