Introduction
With the the introduction of the catalogs, you have the ability to define which roles can be received by which Core Identities and you can define which Core Identities can assign which roles. But to fully cover your use case, there is one thing missing. You need a way of defining which Core Identities can assign roles to which other Core Identities. To solve this issue, there are four predefined Security Rule Groups that you can assign to your users.
Predefined Security Rule Groups
The following predefined Security Rule Groups are available from version 8.0:
Rule Group | Description |
---|---|
| Allows a Core Identity to assign Roles to himself or order Roles for himself. |
| Allows a Core Identity to assign Roles to his co workers. Co workers are all Core Identities that are employed in the same organization unit or below. |
| All Core Identities can be selected. |
| For any advanced use case, you can assign this rule group and then the Core Identity can assign roles to all Core Identities that he has read rights to. |