Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Non owner of Mitigation Control can view the Mitigation Control that he does not own it

deepa
New Contributor III
New Contributor III

Hi,

I have 2 Mitigation Controls, One Mitigation Control is for Ruleset1 and other Mitigation Control is for Ruleset2.

MC1 -> Ruleset1 -> Owner1

MC2 -> Ruleset2 -> Owner2

Owner2 is able is view both MC1 and MC2. Is there any configuration that needs to be done to restrict the owner2 from viewing owner1?

The concern is owner2 is seeing details and also has the ability to edit the Mitigation control that he does not know what that mitigation control is and also edit the pre mitigation association which is more concerning.

Thanks,

Deepa.S

5 REPLIES 5

rushikeshvartak
All-Star
All-Star

Where it is visible under SOD tab or request Approval ?


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

User with SAV Role ROLE_SOD_OWNER is able to view all the mitigation controls.

deepa_0-1710773058102.png

When it comes to Ruleset, Risks, the user can view only the objects for which they are the owner, expecting the same behavior with Mitigation Control too.

Thanks,

Deepa.S

 

 

Mitigation controls are not filtered based on owner , Please raise idea ticket for enhancement.

Validated in v24.2


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

@rushikeshvartak 

Any idea how are mitigation controls approached if it is not filtered based on owner in the industry? What are the best practices to implement?

What is recommended workflow for Mitigation Control?

 

Thanks,

Deepa.S

You can provide view access using analytics report


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.