11.2 Add Permissions to the Team

After you create a team, you can add and remove permissions that apply to team recipients.

11.2.1 Add Resources and Roles

  1. While in the Create Team page or when modifying an existing team, select Add Permission.

  2. Select Add Resources or Add Roles, as needed.

  3. Specify the resources or roles that you want to add:

    All

    Applies only for resources

    Makes all resources available for assignment to team recipients

    Select

    Makes only the selected resources or roles available for assignment to team recipients

    Sub-containers

    Makes only the resources or roles in the specified sub-containers available for assignment to team recipients

    Exclude Roles from Selected Containers

    Applies only when you select the Role sub-containers option and then select a role.

    Makes the selected roles in the specified sub-containers unavailable for assignment to team recipients

    Exclude Resources

    Applies only for resources

    Makes the selected resources unavailable for assignment to team recipients

  4. Select one or more permissions that the team requesters can request on behalf of team members:

    View

    Allows the requester to view the resource or role

    Assign

    Allows the requester to request access to the resource or role for team members

    Revoke

    Allows the requester to request that access for the resource or role be removed

    Assign role to group and container

    Applies only to roles

    Allows the requester to assign the role to the recipient’s group and container in the Identity Vault

    Revoke role from group and container

    Applies only to roles

    Allows the requester to request that a role be revoked from the recipient’s group and container in the Identity Vault

  5. Select Add.

11.2.2 Add Provisioning Request Definitions

You might want to allow team managers to initiate PRDs on behalf of their team members. However, the team manager must have trustee rights to the PRD.

  1. While in the Create Team page or when modifying an existing team, select Add Permission.

  2. Select Add Provisioning Request Definitions.

  3. Specify PRDs that you want to add:

    All

    Makes all PRDs available for assignment to team recipients

    Select

    Makes only the specified PRDs available for assignment to team recipients

    Exclude

    Makes the selected PRDs unavailable for assignment to team recipients

  4. Select one or more permissions that you want to grant to team managers:

    Initiate PRD

    Requesters can start a PRD (workflow) on behalf of a team member

    Retract PRD

    Requesters can stop a PRD on behalf of a team member

    Configure Delegate

    Requesters can make a team member a delegate for other team members’ provisioning requests

    Manage Addressee Task

    Requesters can claim a task for a team member who is a recipient or addressee (based on the task scope)

    Configure Availability

    Requesters can reassign a task for a team member who is a recipient or addressee (based on the task scope)

    NOTE:If Manage Addressee Task and Configure Availability are disabled, the team manager cannot view or act on any active requests. Therefore, you must enable at least one of these options.

  5. Select Add.

11.2.3 Enable Requesters to Make Proxy Assignments

You can enable the team’s requesters to create proxy assignments for the team’s recipients. For example, your organization might want to create teams based on functional departments and allow the department managers to make proxy assignments for their direct reports. For more information about proxy assignments, see Act as or Assign a Proxy.

  1. While in the Create Team page or when modifying an existing team, select Add Permission.

  2. Select Add User Application Driver Permissions.

  3. Select Configure Proxy.

  4. Select Add.