You are viewing an earlier version of the admin guide. For the latest version, please visit EmpowerID Admin Guide v7.211.0.0.
IT Shop Management Roles
The mechanism by which EmpowerID secures a workflow and the operations within that workflow is known as “Rights-Based Approval Routing” or RBAR. With RBAR, EmpowerID checks in real-time to see if the current person within a workflow process has the delegations needed to perform the operations associated with that process. If the person has the delegations, the process continues; if the person does not have the delegations, the process either exits or routes for approval to someone with the delegations needed to approve the operation. In EmpowerID, these delegations are controlled through the assignment of Access Levels. Before people can access a workflow or perform an operation within that workflow, they must have an Access Level assignment that allows them to do so. These assignments can be made directly to users or more commonly through membership in a Management Role that is configured with the Access Level.
Management Roles are prefixed by their function in EmpowerID and include the following:
UI – Management Roles prefixed with UI grant users access to specific UI elements in the EmpowerID Web interface.
VIS – Management Roles prefixed with VIS grant users the ability to see specific object types in EmpowerID.
ACT – Management Roles prefixed with ACT grant users the ability to manage specific objects in EmpowerID.
To access the Authorization Service Portal, users need to have the Management Roles shown in the below table.
Roles needed to Access the IT Shop
To access the IT Shop, users need to have one of the below Management Role assignments (based on the needed scope):
Management Role | Access Granted by Management Role |
| Inherits the below Access Levels from the parent Management Role Definition: Workflow Access Initiator Access Level for following workflows:
Control (User Interface) Access Viewer Access Level for the following controls:
Application Access Viewer Access Level for the following applications:
Web Service Access Executor Access Level for the following Web services:
Pages and Reports Access Viewer Access Level for the following pages and reports:
VIS-IT-SHOP-MS-API | Grants visibility to the base Web services required by all users of the IT Shop microservice. Web Service Access Executor Access Level for the following Web services: