Explain AssigneeType
RBAC Mapping
Map External Directory Locations to Logical Locations
Business Role and Location mappings allow existing external directory Locations and roles to be mapped to a logical management structure. e.g. Multiple AD or LDAP directory containers for “Offices” can be mapped to a single virtual “USA” Location for unified management and delegation.
ERD: Key RBAC Actors
•Management Role – functional role derived from a single parent
•Management Role Definition – parent for derived Management Roles
•Group – collection of users from external system. Can be used as a role
•SetGroup “Query-Based Collection” – query set of resources or People
Person – primary actor
OrgRole – Business Role
OrgZone – Organizational Location
OrgRoleOrgZone – assignable business role + organizational location/context