Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

global config and workflow changes can be restricted?

Harsha
Regular Contributor II
Regular Contributor II

Hi Team,

currently the way we can restrict rule addition by workflow. Can we restrict any global config changes or workflow changes? Or can we see history of any changes happened to global config recently. Please let me know if anyone has the idea about this.

 

Thanks,

Harsha

4 REPLIES 4

armaanzahir
Valued Contributor
Valued Contributor

Hi @Harsha ,

Workflow changes will be sent to approval and only any user having admin access would be able to approve the same. You cannot set another workflow to be followed when changes are made to workflows.

Creating Workflows (saviyntcloud.com)

Managing Workflow Approvals (saviyntcloud.com)

 

Global Config changes is exposed to all users having a sav role which has the Global Config Feature access. Modifications to the same can't have a workflow associated to it.

That being said, changes made to global configs can be tracked via application audit logs

armaanzahir_0-1691057473474.png

The below link will have a detailed information, as to changes made to what objects are tracked.

Managing Application Audit Logs (saviyntcloud.com)

You can also track the changes made to workflows by looking at the workflow history tab.

armaanzahir_1-1691057703166.png

 

Thanks,

Armaan

 

Regards,
Md Armaan Zahir

Harsha
Regular Contributor II
Regular Contributor II

Hi Armaan,

Thank you yes I am aware of that it goes for approval list. Currently we have support people who will have admin access, so to have check on it I asked the above question. But yea I believe as we can see the changes made to workflow we can see the history would be fine. But how about global configuration? I think different sav role to them would  work.

Thanks,

Harsha

armaanzahir
Valued Contributor
Valued Contributor

Yes, a Sav role which has access to the Application Audit Logs of Saviynt would be enough. That way they can track any actions made on Global Configurations by any user. 

Feature Access

armaanzahir_2-1691058735579.png

Application Audit Log

armaanzahir_0-1691058551621.png

The below link will have a detailed information, as to changes made to what objects are tracked.

Managing Application Audit Logs (saviyntcloud.com)

 

 

Thanks,

Armaan

Regards,
Md Armaan Zahir

DixshantValecha
Saviynt Employee
Saviynt Employee

Hi,

We are looking into your request and we will keep you posted.