Click HERE to see how Saviynt Intelligence is transforming the industry. |
04/12/2022 12:52 PM
I have a SAV Role for some of my admin teams. I also need the members of that SAV Role to be part of a User Group, so that they can see and managed SSM Objects they own (tasks, SOD Risks and Functions, etc).As I don't want my IAM team to manage manually both SAV Roles and User Groups, I would like to find a way to automate this (ideally on SAV_Role assignation).
Is there any way to do it, for example using Technical rules?
Solved! Go to Solution.
04/12/2022 01:44 PM
Hi Fabrice,
You can achieve same by on-boarding Saviynt as an endpoint. This would allow you to leverage SAV_ROLES as entitlements.
Thanks,
Minesh Shah.
04/12/2022 01:44 PM
Hi Minesh,
I already have Saviynt as an endpoint for Access Review... but how having SAV_ROLES as entitlements would help me automatically assign User Groups to users?
04/12/2022 01:44 PM
You would need to run db based entitlement import for Saviynt. In the import read data from savroles table as entitlement.
04/12/2022 01:44 PM
ok but I still don't see how I can use that to automatically assign a User Group...
04/12/2022 01:44 PM
Fabrice, if you have onboarded Saviynt as a managed application which has SAVRoles and UserGroups both as entitlements.
One way to manage the auto assignment of usergroups would be via mapping the "SAVRoles" entitlement to "UserGroups" entitlement. So whenever a user selects the getting membership to a SAVRole, system will auto create task for the membership of usergroup as well.