Capabilities

Automatic assignment rules

It is possible to configure automatic assignment rules. These rules can be based on all of identity attributes.


A role assignment policy is composed of the following elements:

  • A scope of population for which the assignment policy will automatically grant the role

  • An assignment mode: to determine what operation will be possible or not after the role has been given by the policy. The different modes are the following:

    • Init: The assignment is given automatically but it is possible to modify it, delete it manually afterward

    • Editable: The assignment is given automatically but it is possible to modify it manually after. However, it cannot be removed manually.

    • Strict: The assignment is given automatically and no action on it is possible afterward.


As described in the assignment, the assignment information described how assignment has been granted, so that it is easy to know if assignment was given by an automatic rule.

These rules are evaluated at each modification on an identity, thus making it possible to re-evaluate the rules and to make changes if they are necessary in real time.


RoleAss1.png
Automatic Role Assignment Policy

In this example, the role Now User will be automatically given to all active employee attached to Memority US (and below) or Memority UK (and bellow) or Memority FR (and below). Once given by the policy, it won’t be possible to revoke it manually but if an identity is transferred to Memority Spain, and therefore leaves the scope of the policy, she will be automatically loosing the role.