Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Baseline Birthright Role

BrandonLucas_BF
Regular Contributor III
Regular Contributor III

Is it possible to baseline a birthright role for users we have detected match the entitlement list through recon? For example, we have birthright roles for salaried versus hourly employees, and when you move between statuses we successfully remove and add one role or the other using birthright. This doesn't work for users who gained access to the role entitlements before Saviynt was in place. It would be ideal if we could baseline the role somehow so that would work for even "legacy" employees.

I know this is possible for applications and out-of-band access so thought it could be possible for this use case as well.

5 REPLIES 5

rushikeshvartak
All-Star
All-Star

Use baseline feature under endpoint 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

BrandonLucas_BF
Regular Contributor III
Regular Contributor III

I was aware of this, but it will also baseline birthright role or enterprise/application role? How does it do this?

Only Entitlement (actual access) will be baselined. you can use source column of role_user_account to baseline as custom solution


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

It seems like writing an analytic that periodically looks for that or the birthright condition and removes access will be the solution.

I did have one more thought. Wouldn't this also be resolved for us by making the birthright technical rule detective and running the detective rule job periodically? What are the downsides to that? What is the future of this capability given that job type is deprecated?