and more in a single search tool across platforms. Read the announcement here. |
12/08/2023 05:59 AM
Hi All,
We are allowing managers to use Update user request tile in Saviynt to update user attributes.
But noticed a issue here - managers are able to see themself in the request and are able to update their profile. So please advise how to avoid this.
Though in the SAV Role we have selected below option-
12/08/2023 07:24 AM
@Jaya did you check this article : Access Controls (saviyntcloud.com)
12/08/2023 07:34 AM
Hi Manish,
Option mentioned in mentioned link are not available in non-EIC version. Below are the available options-
Can we write some advance query so it will dynamically pick manager's reportees.
12/08/2023 08:43 AM
@Jaya : You can use advanced config what options and opt JSON option with below config to control the list of users to show only user direct reportees.
[{"for":"UpdateUserRequest","query":"select a from Users a where a.manager=${users.id}"}]
For details refer this KBA Article
12/11/2023 03:42 AM
Have tried this query but still that shows my name in update request.
[{"for":"UpdateUserRequest","query":"select a from Users a where a.manager=${users.id}"}]
And rushikesh, these accesses are already not present.
12/11/2023 07:41 AM - edited 12/11/2023 07:42 AM
You can restrict and auto reject in workflow if RequestedFor eq RequestedBy in if-else block
12/11/2023 07:06 AM
@Jaya : Okay I missed this part when you use advanced option then it work as below.
Request for self + for the users retrieved from advanced filter
So whatever query I provided will limit the users to direct reportees of logged in user, But Request for Self (is brining the his own ID).
Only option I can think of is handle it in workflow in such a way that if update user request is submitted for his own id then reject the request.
12/08/2023 07:32 PM
Remove the update user webservice from sav role