Unable to render embedded object: File (Emp18Notice.png) not found.

Skip to end of banner
Go to start of banner

Dynamic Group Policies (Hierarchies)

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 7 Current »

If your company or organization always sets up groups or management roles based on Person or user account attributes (e.g., state/city, org chart hierarchy), Dynamic Hierarchy policies provide a way to specify the conditions allowing EmpowerID to automatically provision and/or deprovision specific groups or Management Role Definitions and Management Roles based on one or more Person attributes. Dynamic Hierarchies also dynamically manage the membership of those groups or Management Roles. You can then assign resources to the generated groups and/or Management Roles as needed and EmpowerID will grant those assignments to the people in those groups and roles. The topics in this section show you how.


Every implementation of a Dynamic Hierarchy policy has four steps.
  1. The first step is the Generation process, which finds what objects need to be created or deleted based on the settings applied to the policy. When an object is created, EmpowerID places that object in the Dynamic Hierarchy Provision Inbox queue.
  2. The second step is Membership Recalculation, where changes to group or management role memberships occurring as a result of a Dynamic Hierarchy policy are placed in the Dynamic Hierarchy Membership Inbox queue.
  3. The third step is the Provision process, which pulls the new objects from the Dynamic Hierarchy Membership Provision Inbox and provisions those objects in the appropriate system.
  4. The fourth step is the Set Membership process, which pulls the objects from the Dynamic Hierarchy Membership Inbox and pushes those changes to the external systems.

Getting Started





Organization Chart Groups

Organization Chart Groups

Person Attribute Management Roles

Person Attribute Management Roles

Two-Level Management Roles

Two-Level Management Roles

Two-Level Nested Groups

Two-Level Nested Groups

One-Level Dual Attributes

One-Level Dual Attributes

One-Level Triple Attributes

One-Level Triple Attributes

  • No labels