Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
maxLevel1
typeflat

...

Hier finden sich die Benutzergruppen, die für die Freigabe einer Anfrage zuständig sind. Naheliegenderweise handelt es sich hierbei um die hierarchisch betrachtet höherstehenden Instanzen einer Organisation. So eignen sich bspw. die Geschäftsleitung, Systemadministratoren oder Ressourcenverantwortliche als Approval Groups. Die Approval Group für bspw. eine Rolle kann man manuell über die jeweilige Rolle festlegen. Diesbezüglich sind folgende Einstellungen möglich:

  1. All members must approve: D.h. jedes einzelne Mitglied der Approval Group muss den Rollenantrag genehmigen. Falls mind. ein Mitglied ein Veto einreicht, wird die Rolle nicht vergeben. Wird die Option nicht aktiviert, reicht die Zustimmung eines Mitglieds der Approval Group.

  2. Approve automatic assignments: D.h. dass Rollen, die einer Coreidentität aufgrund ihrer Beschäftigung automatisch zugewiesen werden, nochmals manuell durch Mitglieder der Approval Group geprüft werden sollen.

  3. Approve manual assignments: Heisst, dass Rollen, die einer Coreidentität manuell zugewiesen wurden, nochmals manuell durch Mitglieder der Approval Group zu prüfen sind.

Konfigurationsparameter

Folgende Konfigurationsparameter sind vorhanden:

...

Parameter

...

Werte

...

Beschreibung

...

Folgende Zielsystem Releases werden unterstützt:

How-to Artikel

Filter by label (Content by label)
showLabelsfalse
showSpacefalse
cqllabel in ( "systemkonnektor" , "how-to" ) and type = "page" and space = "IKB"

...

Introduction

Approval groups can be used to manually group a bunch of Core Identity into a group that then serve as an approval group for assignements of either a Role or a Resource. Whenever a new assignement between a Core Identity and such a role or resource is set, the members of the approval groups reveive a notification and are asked to either approve or decline this assignment. If multiple approval groups are set, then the approval of each group will be required.

Properties

When adding or configuring an approval group to a Role or a Resource, you are presented with the following properties:

All members must approve

This means that every single member of the approval group must approve the role application. If at least one member vetoes, the role will not be assigned. If the option is not activated, the approval of one member of the approval group is sufficient.

Approve automatic assignments

This means that roles that are automatically assigned to a core identity due to its employment should be checked again manually by members of the Approval Group.

Approve manual assignments

Means that roles that have been manually assigned to a core identity are to be checked again manually by members of the Approval Group.

If neither Approve automatic assignements nor Approve manual assignments is checked, the approval group will not have any effect. You can use both of them at the same time, or either one or the other.

Include manager & include line manager

When configuring Approval groups within Master data management, you may optionally activate either of these two features:

Including the manager will automatically add the Core Identity configured to be the assignee’s manager to the approval group, if a manager is set.

Including the line manager will automatically add the Core Identity identified to be the assignee’s next superior using the organizational structure (see Organizational unit), if it can be resolved.