Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. On the App menu, navigate to PBAC Assignments > App Rights Assignments.

  2. Click the dropdown arrow on the Assign App Right button and select Assign to Person.

    image-20240627-144029.png

  3. Search for and select the person from the Select Person to Assign Right(s) field.

    image-20240627-144142.png

    This opens the “Assign Rights” modal with the person selected to receive one or more app rights.

    image-20240627-144645.png

  4. Click the app right to be assigned from the All panel on the left of the Assign Rights modal. This allows you to view information about the Access Request Policy governing access to the right and enables the “Add” button.

    image-20240627-144738.png

  5. Optionally, to add a time constraint to the assignment, toggle the Set Duration button, click the End Date Time field, and select the appropriate end time date from the calendar.

    image-20240627-144936.png

  6. Click Add.

    image-20240627-145014.png

    This moves the app right to the Added panel.

    image-20240627-145125.png

  7. Click Add to Cart.

    image-20240627-150657.png

  8. Click the shopping cart icon and fill in the required Add a Comment and Enter Business Request Name fields.

  9. When ready, click Submit.

    image-20240627-152410.png

    You should see a message indicating the status of the cart submission.

    image-20240627-152507.png

  10. Click the status link to view the request status in My Tasks and approve the assignment.

    image-20240627-154318.png

  11. Click Submit to complete the approval process.

    image-20240627-154433.png


    You should see that the request is has been approved and completed.

    image-20240627-155206.png

  12. Return to the App Rights Assignments page in Resource Admin. You should see the assignment.

    image-20240627-155511.png

...

When someone with eligibility for the app right requests access to it from the IAM Shop, the request will be routed to the appropriate PBAC approver(s). To test this, do the following:

  1. Go Sign in to the IAM Shop as a user with eligibility eligible for the application.

  2. Search for the application and click Request Access.

Edit Approval Routing for Field Types

In the above example, PBAC Approval was configure to allow the approvers to approve all requests to view the product catalog. If needed, the assignment can be scoped to limit approval to specific field types defined for the product catalog. To implement scopes, do the following:

...

Click the Edit button for the approval right.

...

If you are assigning the approval right to a single person, do the following:

  1. Click Assign to Person.

  2. Enter the name of the person in the Select Person to Assign Right(s) field and click the tile for that person.

If assigning to another assignee type such as a Manageemnt Role, click Assign Right to any Assignee Type and do the following:

...

Choose Type: Enter the assignee type and then click the tile for that type to select it.

...

Right to Grant: Enter the name of the approval right and click the tile for that right to select it.

...

  1. image-20240627-171110.pngImage Added


    This opens the application drawer.

    image-20240627-175305.pngImage Added

  2. Select one of the rights configured for the application, then select a Field Type and one or more Field Type Values (if configured for the application). In the image below, we have selected “Edit Product Catalog” as the app right and “Lawn Care” and “Tools” Field Type Values from the “Hardware Products” Field Type.

    image-20240627-175624.pngImage Added

  3. Click Add to Cart.

  4. Click the cart icon to open the cart. You should see the app right and any Field Type “Scope” Values (if selected).

    image-20240627-180044.pngImage Added

  5. Fill in the required Comment fields and then click Evaluate Request to check for potential SOD violations.

  6. Once the request has been evaluated, enter a Business Request Name and click Submit.

    image-20240627-180659.pngImage Added


    You should see that the request has been submitted for approval. If Field Type Values were selected and Split By Value Approval was selected for the requested app right, you will see an approval task for each requested Field Type Value.

    image-20240627-181046.pngImage Added

  7. Click the status link.

    image-20240627-181557.pngImage Added


    This directs you to the My Requests page of My Tasks and opens the Request Detail pane for the request.

    image-20240627-181839.pngImage Added

  8. Click the Process Steps tab and then click the Show Approvers link. You should the person designated as the PBAC approver.

    image-20240627-192720.pngImage Added