Role Assignment

Introduction

A role assignment is association of a role to a Core Identity. With the association of the role, the Core Identity gets access to the appropriate resources within the role. It’s one of the most fundamental tools to assign permissions to Core Identities. A structured role model is the key to a successful identity and access management strategy.

Properties

Each role assignment consists of the following properties

Property

Data Type

Mandatory

Example

Description

Property

Data Type

Mandatory

Example

Description

Role

Role

Adobe Photoshop

The actual role that has been assigned to the core identity.

Assignment Type

Enum

Automatically

Depending on how the assignment was created, the assignment has a different assignment type:

Automatically → The system assigned the assignment based on a rule

Manually → Someone assigned the role manually over the User Interface

Delegated → Someone delegated the role to someone else

Nested → The role was assigned, because the role is nested into another role, that the Core Identity got automatically.

Assignment State

Enum

Assigned

The assignment can take on various states. A full documentation can be found here.

 

Context

Complex Object

Self

The context of the assignment. A full documentation can be found here.

Valid From

Date

01.01.2022

When the assignments starts to be valid.

Valid To

Date

31.12.2090

How long the assignment will be valid.

Ignore

Boolean

False

If an assignment was created automatically, users can ignore it by manually mark it as such in the user interface. This will lead to the removal of the role.

Deny

Boolean

False

If there is an assignment rule that denies the role. This means, the user is not allowed to receive the role.

Assigned by

Core Identity

System

Who assigned the role. If system is presented, the assignment was created based of a rule.

Assignment date

Date

01.01.2022

The date on which the assignment was created.

Reason

Relation

 

ITSENSE AG

The assignment reason can be of two types. Either it’s a text that the user entered while he created the assignment or it’s a reference to the entity that granted the permission to the user. The entity can be an organization unit, a function, an employment type, an assignment rule, a Core identity type or an employment.

© ITSENSE AG. Alle Rechte vorbehalten. ITSENSE und CoreOne sind eingetragene Marken der ITSENSE AG.