Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Automated entitlement provision/deprovisioning based on other entitlement

Community_User
Saviynt Employee
Saviynt Employee
Originally posted on March 29 2022 at 06:19 UTC

We have a use case where,


When a request is created for entitlement A of entitlement type X, pending task should be created for entitlement B of Y entitlement type.i.e,


When entitlement A is requested, the assignment of the entitlement B should be done when role A is being assigned. Entitlement B should match to appropriate role A and assign automatically.


Also removal of entitlement B of entitlement type Y, based on the entitlement A of entitlement type X removal being requested.i.e, 


When a entitlement A is requested to be removed, the respective entitlement B should be removed.

 

This message was previously posted on Saviynt's legacy forum by a community user and has been moved over to this forum for continued exposure.
4 REPLIES 4

Community_User
Saviynt Employee
Saviynt Employee
Originally posted on March 29 2022 at 22:38 UTC

Hello Sucheta,


Is your requirement that you have discussed for an entitlement (single access) or a Role (collection of access) ?


It seems that you have interchangeably used it and just wanted a clarification.




Regards,

Avinash Chhetri

This message was previously posted on Saviynt's legacy forum by a community user and has been moved over to this forum for continued exposure.

Community_User
Saviynt Employee
Saviynt Employee
Originally posted on March 30 2022 at 08:21 UTC

Hi Avinash,


This is for SAP system. Basically we need to assign respective  profiles to 'saproles' when any saprole is being requested in Saviynt and same goes for removal, i .e, remove respective profile when removal of saprole requested. 


saproles are getting collected as entitlements in Saviynt however we do have child associations with it. For composite roles, single roles are associated and for single roles, tcodes and auth objects are associated. 


Please let me know if any further information is needed. 


Thanks,

Sucheta

This message was previously posted on Saviynt's legacy forum by a community user and has been moved over to this forum for continued exposure.

Community_User
Saviynt Employee
Saviynt Employee
Originally posted on April 1 2022 at 14:03 UTC

Sucheta,


Please check the associated entitlement section in the link below and see if that helps.


https://saviynt.freshdesk.com/support/solutions/articles/43000527104-viewing-or-updating-entitlement...




Regards,

Avinash Chhetri

This message was previously posted on Saviynt's legacy forum by a community user and has been moved over to this forum for continued exposure.

amit_krishnajit
Saviynt Employee
Saviynt Employee

Entitlement Map feature may be explored for this use-case. With entitlement maps you can provision/deprovision entitlements from different entitlement types and from different endpoints as well. 

Thanks,
Amit