Hello,
We have implemented ARM with workflow for approvals but restrictions on the functional area. A request is only permitted to assign / view roles for the functional area defined in the authorisations
The requestor should only be able to assign roles to users from their site (UserGroup) but from what we can see when the request is submitted the user can select any user in the system and submit the request . If approved at the seconf level the roles are auto provisioned without restriction. Is it possible to restrict a requestor to a specific user group or group of users.
Regards
Mark
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Hi Mark,
I am afraid that did i understood your question properly?
Imagine a scenario where a person newly joins the organization and a request is raised.
So it is obvious that he doesn't belongs to any usergroup.
Now how come a requester can raise the request based on usergroup for this new user?
Regards
Raj
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
A better practice would be to not create users without user groups. The automatic job that creates the user ID should assign at least a basic user group, such as ESS_ONLY or UNDETERMINED, and set up the GRC security so that anyone who can submit requests can modify users in that group as well as their own group.
How workable such a scheme would be is likely to depend on how granular the user group design is. If you have 200 user groups, do you really want to maintain 200 different versions of the requester role? Also, if users are constantly needing to be moved from one user group to another, it may not be practical.
.
Regards,
Gretchen
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.