EmpowerID restricts access to the IT Shop through the use of Management Roles. To access the IT Shop, users must be assigned to the appropriate roles. Management Roles are prefixed by their function in EmpowerID and include the following:
UI – Management Roles prefixed with UI grant users access to specific UI elements in the EmpowerID Web interface. An example of this type of role for Password Manager is UI-Person-Password-Self-Service. This role grants users access to the user interfaces and workflows for enrolling for self-service password reset and changing their own passwords.
VIS – Management Roles prefixed with VIS grant users the ability to see specific objects in EmpowerID. An example of this type of role for Password Manager is VIS-Person-Self. All users have this Management Role by default.
ACT – Management Roles prefixed with ACT grant users the ability to manage specific objects in EmpowerID. An example of this type of role for Password Manager is ACT-Password-Self-Service. This role grants users access to change passwords, enroll for password self-service reset, and perform other password self-service operations.
Roles needed to shop in the IT Shop
To shop for eligible resources in the IT Shop, users need to have one of the below Management Role assignments (based on the needed scope):
Management Role | Description | Role Type |
---|---|---|
ACT-Person-Password-Self-Service | Grants users access to change password, enroll and other password self-service operations. | Activity |
UI-Person-Password-Self-Service | Grants access to change password, enroll and other password self-service workflows and user interfaces. | Feature Set |
IT Shop, My Tasks, and My Identity Self-Service Full Access | Grants full access for using the IT Shop, My Tasks, My Identity microservices | Role Bundle – Contains the below Management Roles |
Management Role | Access Granted by Management Role |
---|---|
UI-IT-Shop-MS-Full-Access | Inherits the below Access Levels from the parent Management Role Definition: Workflow Access Initiator Access Level for following workflows:
Control (User Interface) Access Viewer Access Level for the following controls:
Application Access Viewer Access Level for the following applications:
Web Service Access Executor Access Level for the following Web services:
Pages and Reports Access Viewer Access Level for the following pages and reports:
|
VIS-IT-SHOP-MS-API | Grants visibility to the base Web services required by all users of the IT Shop microservice. Web Service Access Executor Access Level for the following Web services:
|