Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Difference between Entitlement Map,Associated Entitlement and Child Entitlement

Subrahmanyam
New Contributor II
New Contributor II

I am currently going through the Saviynt documentation and found these features. Can anyone point out the key differences between these three. I know that the associated Entitlement doesn't create a task directly assigns the access

2 REPLIES 2

rushikeshvartak
All-Star
All-Star
  • Ent Map - If you want to assign / remove another entitlement then ent map is used
  • associated entitlements are used to show parent child entitlement 
  • child entitlement - are mostly used in cases of privilege based apps 

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

stalluri
Valued Contributor
Valued Contributor

@Subrahmanyam 
Associated Entitlement:
I have added an entitlement Y from Endpoint B as Associated Entitlement to Entitlement X in Endpoint A.

So when a user requests for Entitlement X from endpoint A, entitlement Y from endpoint B should also be assigned to the user.

NotePlease refer to Adding Associated Entitlement section of https://docs.saviyntcloud.com/bundle/EIC-Admin-v23x/page/Content/Chapter02-Identity-Repository/Viewi...

Associated entitlement is also assigned to the user however the tasks will not be visible on the UI. Once the provisioning job runs, the associated entitlements also should be assigned to the user. If you want a task to be created, please use 'Entitlement Map' feature in the Other Entitlement Details. You have configs to enable tasks creations, approvals etc.



Entitlement Map:
Do the entitlements in secondary endpoint need to be granted to user because user has entitlements in primary endpoint?

-> For above scenario, we can add the secondary endpoint's entitlements in the Entitlement Map section of the Primary Endpoint's entitlement show page. (This is used if the mapping is with two separate endpoint entitlements.)

Note: Other entitlement is also assigned to the user however the tasks will be created on the UI. Once the provisioning job runs, the other entitlements also should be assigned based on the SS config of the secondary endpoint entitlement. 

Child Entitlement: 
This is used for the entitlements from the same endpoint. If you have a parent to child mapping in the target to get the same association we will add them in the child entitlement mapping.


Best Regards,
Sam Talluri
If you find this a helpful response, kindly consider selecting Accept As Solution and clicking on the kudos button.