cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Role assignment through HR Triggers

0 Kudos
505

Hi,

Have configured HR Triggers for HIRE , created separate HR request type and maintained action as Create User and assign object. Have configured workflow for the same using BRF+ and It's working fine , user is being created in connected back end system,

Now the requirement is, HR will assign some role to position while creating an account in HR system, so it should create user and then role should be assigned automatically,

Maintained global provisioning settings:

Role Provisioning type: Combined, Indirect Provisioning type: Position

So the HR configurations which I had done for HIRE , will it also work for role assignment too ? as I have select action as assign object ?

Thank you

Accepted Solutions (0)

Answers (1)

Answers (1)

madhusap
Active Contributor
0 Kudos

Hi Hayatullah,

Yes, the role assignment will work as you already have "Assign Object" action in your request type.

One key point to note is that during combined provisioning, GRC will assign roles first to the position (Indirect) of the user and if position is not available only then will assign roles to the user directly.

If the access provisioning is only to HR system then no need to have "Assign Object" action in your NEW HIRE request type as the User Account creation will take place through CREATE USER action and the roles assigned to position will get automatically assigned to the user through indirect assignment based on position.

You just need to run user comparison job regularly using PFUD in your HR system.

Regards,

Madhu