Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Merging Two Entitlements into a Single Role under application Request Page

AtrayeeDutta
Regular Contributor
Regular Contributor

Hi Team,

We aim to merge two entitlements from different endpoints into a single role, with the condition being that we want to display it on the under application request page, not outside.

is there a way to achieve this?

Thanks

7 REPLIES 7

rushikeshvartak
All-Star
All-Star

You can create enterprise role and show under application. Please note this is not best practice to show enterprise role on request form


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

AtrayeeDutta
Regular Contributor
Regular Contributor

Hi,

We have tried creating enterprise role and added the endpoint in endpoint filed but still role is not displaying under application req page, tried changing requestable to true and false both.

AtrayeeDutta_0-1717154671757.png

AtrayeeDutta_1-1717154782285.png

We have also created Transcactional role but for this also facing same issue and for entiltlement role only one AD endpoint is showing for selection while we create the role despite having many AD endpoints.

Could you please let us know, if we are missing anything.

Thanks,

NM
Honored Contributor II
Honored Contributor II

@AtrayeeDutta , I hope in global configuration you have added workflow for role

AtrayeeDutta
Regular Contributor
Regular Contributor

yes,  we have added workflow for role

PremMahadikar
All-Star
All-Star

Hi @AtrayeeDutta ,

As you have workflow in Global configuration (Role Modification Workflow) - Check if any updates are in composing status under versions? This would be one of the reasons you would not see, enterprise role in ARS. If its present, please select and send for approval and approve it.

PremMahadikar_0-1717406428542.png

 

Another solution as the above approach is not good practice:

Best Practice: During role creation, determine the entitlements that will be mapped to the role and ensure that the correct role type is defined. An enterprise role encompasses entitlements that span across multiple endpoints, whereas an application role encompasses entitlements from a single endpoint.

FYI: To handle Enterprise and Emergency role requests, the workflows are defined under Global Configurations. Workflows for Application Roles are defined at security system level.

I would suggest you to two create two roles (application role types) for two different application entitlements. And have parent child mapping. Once the Parent role is requested, the child role entitlements will also be assigned: 

Reference Article: Solved: Role nesting - Saviynt Forums - 15569


If this helps, please consider selecting Accept As Solution and hit Kudos

Hi @PremMahadikar 

Created two app role in two diff endpoint and added one app role as child to another role, after request completion, task is getting created only for child entitlement and not for parent entitlement.
could you please assist, if we are missing something.

Thanks

Check Request Option under entitlement Type.

rushikeshvartak_0-1717467033285.png

 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.