How user-entitlement clusters works when Role Mining in RSA Identity Governance & Lifecycle
Originally Published: 2020-08-12
Article Number
Applies To
RSA Version/Condition: All
Issue
Resolution
For a given set of users and entitlements find a specific percentage of those entitlements that those users have in common and create a Role with those users as members. Once users are added to a new Role through Role Discovery, all their entitlements become part of the new Role (not just the entitlements that they have in common).. This is best illustrated with an example.
EXAMPLE
Consider the following example where Discover Roles is defined as:
Users matching: Iris, Rose, Cherry, Sun, Moon, Tree
Entitlements matching: dog, cat, horse, cow, pig
Clustering Method: allow duplicate entitlements, allow duplicate users
Users with: 50 % entitlements in common
Create with a minimum of 2 users
Create with a minimum of 1 entitlements
Entitlements matching: dog, cat, horse, cow, pig
Clustering Method: allow duplicate entitlements, allow duplicate users
Users with: 50 % entitlements in common
Create with a minimum of 2 users
Create with a minimum of 1 entitlements
NOTE: This example is intentionally simplistic in order to illustrate a complex concept.
| User | Ent1 | Ent2 | Ent3 | Ent4 | Ent5 | Ent6 | Ent7 |
| Iris | dog | cat | goat | ||||
| Rose | dog | cat | pig | cow | |||
| Cherry | horse | cow | sheep | donkey | |||
| Sun | cat | hamster | |||||
| Moon | dog | cow | pig | tiger | zebra | ||
| Tree | dog | cow | pig | panther | sheep | cougar | bear |
Two Roles will be defined as follows:
Role001
Members: Iris, Rose
Entitlements: dog, cat, goat, cow, pig
Entitlements: dog, cat, goat, cow, pig
Role002
Members: Rose, Moon
Entitlements: dog, cow, pig, cat, tiger, zebra
Entitlements: dog, cow, pig, cat, tiger, zebra
Break Down:
- Roles created:
- Iris and Rose have entitlements dog and cat and these entitlements are 50% or greater of their total entitlements which means they have at least 50% of the specified entitlements in common. Goat, pig and cow are added as entitlements to Role001 because either Rose or Iris have them.
- Rose and Moon have dog, cow, and pig as 50% or greater of their total entitlements so all three add up to 50% or more of the specified entitlements in common. Cat, tiger, and zebra are added as entitlements to Role002 because either Rose or Moon have them.
- No Roles created:
- Tree also has entitlements dog, cow, and pig but these are not 50% of Tree's total entitlements. Therefore Tree does not become a member of Role002 because Tree does not have 50% of his entitlements in common with the other users specified in Role002.
- Sun has cat which is 50% of Sun's total entitlements but not 50% of anyone else's entitlements so Sun does not become a member of a new Role.
- Cherry has cow which is only 25% of her total entitlements so this is not enough to become a Role member.
Related Articles
Number of missing Members and Entitlements in Role Definitions is doubled for Local Entitlements on 7.2.0 P01 of RSA Ident… 33Number of Views RSA Identity Governance and Lifecycle Role Sets display the Raw Name instead of the Name in multiple locations in the UI 39Number of Views Add entitlements table shows inconsistent results when the Role Set Policy is set to 'Deny entitlements not matching the e… 44Number of Views 'Request could not be handled' error reverting a Role that has been moved to a different Role Set in RSA Identity Governan… 52Number of Views Role Review Member and/or Entitlement counts are incorrect preventing Role Review completion in RSA Identity Governance & … 536Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?