- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
View accounts just for a specific application
Hi,
I have 3 applications with accounts and entitlements, each application has a manager, the manager must just view all accounts and all entitlements for his application. for the moment i put the manager as an application technical owner, but with the technical owner entitlements the manager can create the collectors and modify the accounts ect..,
I want know how can i give to a manager the entitlements "view account" and "view entitelment" but just for his application?
Regards.
- Tags:
- Community Thread
- Discussion
- entitlement
- Forum Thread
- Identity G&L
- Identity Governance & Lifecycle
- IG&L
- IGL
- RSA Identity
- RSA Identity G&L
- RSA Identity Governance & Lifecycle
- RSA Identity Governance and Lifecycle
- RSA IGL
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I think solution would be to create a new custom user attribute on an application and use that attribute to set to manager.
Then, create a new Application-<View entitlement with a condition to only assign it to that users specified on the application. (see [T_SECURITY_CONTEXT] Customize the Aveksa application entitlements )
Once that new entitlement is added and collected, it should be explicitly granted to the manager users. With that, user would get view privilege on specific application.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I think solution would be to create a new custom user attribute on an application and use that attribute to set to manager.
Then, create a new Application-<View entitlement with a condition to only assign it to that users specified on the application. (see [T_SECURITY_CONTEXT] Customize the Aveksa application entitlements )
Once that new entitlement is added and collected, it should be explicitly granted to the manager users. With that, user would get view privilege on specific application.
