Global Security Forum

Security Global Forum

Our mission is to provide clients with an online user community of industry peers and IBM experts, to exchange tips and tricks, best practices, and product knowledge. We hope the information you find here helps you maximize the value of your IBM Security solutions.

 View Only
  • 1.  IGI - How to create a requested for the ROLE OWNER

    Posted Wed November 18, 2020 12:55 PM
    Hello,

    I have created a form to grant access to roles, and it also triggers an approval workflow.
    Initially I have created an admin group for approvers and then all requests are directed to this admin group´s members to approve.

    Now I want to send the request´s approval only for the roles owners.
    For example, if I request access to role "AD001" and user testeuser is the owner for the role, only testuser should receive the request for approval.

    Please is there any way to implement such configuration ?

    Regards,
    Lincoln

    ------------------------------
    Lincoln Sant Anna
    ------------------------------


  • 2.  RE: IGI - How to create a requested for the ROLE OWNER

    Posted Thu November 19, 2020 10:12 AM
    Hi Lincoln,

    I believe this is possible we have a similar use case for application owners.

    1. Assuming AD001 is an Admin Role, enable the scope of this role to Entitlements
    2. In the Users tab add the "Admins" for the role (when you add a user ISIGI would prompt you to select entitlements)
    3. In Process Designer add AD001 as a role in the approval workflow that is configured.

    I hope that helps.

    ------------------------------
    Jad Dizon
    ------------------------------



  • 3.  RE: IGI - How to create a requested for the ROLE OWNER

    Posted Thu November 19, 2020 01:45 PM

    Thanks Jad,

     

    I got the idea with your update.

     

    I have set one user linked to  "RoleX" and another user linked to "RoleY" in my admin role users membership.

    Set that admin role in the Process Designer->myprocess->assign->Auth Request.

     

    However if I request "RoleX" the request appears for both users.

     

    I have checked the web and it sems there a few problems reported to scope in admin rules.

     

    I will check with support team if there is any fix.

     

    Thanks,

    Lincoln Sant´Anna

     






  • 4.  RE: IGI - How to create a requested for the ROLE OWNER

    Posted Fri November 20, 2020 09:54 AM
    Great! glad that helped! Best of Luck

    ------------------------------
    Jad Dizon
    ------------------------------