Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

SAV ROLE

NPY
New Contributor III
New Contributor III

Hello,

We have a custom requirement for an end-user SAV role in which the end users accessing ARS need to see the details of other users.  The only way we have found to make this possible is to add the following role (see screenshot) but when the users click on admin to see the user details, they see Job Control Panel (and with the ability to modify the content) which we do not want. I understand that the admin:landing page role is tied to Job control panel so we cannot possibly segregate these two.  So, are there other ways to make the users details under identity repository visible without granting any other permissions (except regular end-user role)?

note: adding only admin:users role is also not helpful as users tab is not visible

NPY_0-1693508347206.png

Thank you

[Updated 9/05/2023]

Does anyone have any suggestions on this?

[This message has been edited by moderator to merge reply comment]

2 REPLIES 2

pruthvi_t
Saviynt Employee
Saviynt Employee

Hi @NPY ,

Did you try to use the out of the box enduser savrole copy and try to remove the feature accesses not needed.

Can you please let me know the business requirement for the custom savrole you’re trying to create. 

Thanks,


Regards,
Pruthvi

NPY
New Contributor III
New Contributor III

Hi Pruthvi,

Basically, we want to create an end user SAV role with the regular end user accesses as well as the accesses that allow users to view the details of other users in the admin>identity repository>users tab. For our use case, when the users are requesting access for others in ARS, the person requesting access to others needs to verify the users through admin>identity repository>users tab. So, we want admin landing page with the ability to see the users tab as well as /users/show/* URL (which is in admin function feature access) to view the details of the users. We want to be able to do this without allowing end users to view the Job control panel.

Note: The OOB end user role does not have the added access that we require.