Have a role composition (not membership) such as which permissions are part of a IT role that is reviewed periodically by someone (e.g. role owner, app owner). The idea is to review the contents and not membership.
During the review, the reviewer can select which permission should be kept or removed from the role.

Comments

  • Agree ! There is an old enhancement request for this topic: ER 111095: Role Reviews

  • I would like to provide more details about this request.
    It would be good if we could have the following review type for role composition reviews:

    1. Business role owners review what are the application roles which are part of it
    E.g.: Business role “Security Analyst” has the following app roles “SAP Role 1”, “SAP Role 2”, “CRM Role A”, “CRM Role B”
    2. Each application owner reviews the app roles which are part of a Business Role.
    E.g.: SAP Application Owner reviews if “SAP Role 1”, “SAP Role 2” should be part of the Business role “Security Analyst”