• Votes

    3

    Composite authorization - combining permission and data set views

    In many ERP and CRM systems the authority model is made by a combination of a general permission eg. read, write, delete etc. and the data set or data view for which the ...

  • Votes

    3

    Show unmapped account even under the permission view.

    Today you can see the unmapped account in the application view, on that application you can see the permissions collected. Application -> Application -> Account - ...

  • Votes

    3

    Application Meta Data Collector

    It would be nice to have a Meta data collector for every application. A common thing for over customers is to have a database of all of the applications information ...

  • Votes

    3

    Explicit handling of nested groups

    For at least one of our configurations, we'd like the ability to review groups along side with user in the list of review items. That is, if a group has other groups ...

  • Votes

    3

    central admin page for all configuration

    SSPR like configuration for OSP / Identity Application SSPR, and Identity Governance. Where a bootstrap admin can access the configuration until it is ready to be ...

  • Votes

    3

    Targeted Collection of specific account/permission

    Currently, we can only run collection on the full data set. It would be helpful to allow for us to specify a specific attribute to filter the collection. This would ...

  • Planned

    3

    Review on permissions

    Hello, We need to be able to create a review on a permission (eg Domain admins group imported from AD). Currently if I import AD groups and the Domain admins group ...

  • Planned

    3

    Request Access, allow a form for request

    Currently when you request access there is a simple text box. Would be helpful if there was an ability to a specific message. Add some simple fields for them to fill ...

  • Votes

    3

    Access removal policy

    An Access Removal Policy can be used when a customer would like to have different policies for requesting and removing access. An example is, that for a certain access, ...

  • Votes

    3

    Importing and exporting Access Request Policy definitions

    Almost everything in Identity Governance can be imported and exported in json format. One thing which is still missing in import/export are Access Request Policy ...

  • Votes

    3

    SAP Collector should collect permission assignments for all SAP ...

    The SAP collector from IG 3.5.1 only collects permission (activity groups) assignments for the directly connected system, even if this system is a CUA. So collecting ...

  • Votes

    3

    Business Role Mining

    Large environments (tested with 80.000 users and > 200.000 permissions) require that mining can be started for smaller portions of data. Tech Role Mining already provides ...

  • Votes

    3

    Require application owner review of application permission changes ...

    Business role permission changes should be coordinated with application owners, both to ensure that the business role owner is using the correct application permission ...

  • Votes

    3

    Ability to record delegated (onBehalfOf) permissions and certify them

    Many systems (such as exchange) have delegated permissions. Using MS Exchange as the example the ability to review mailbox and calendar delegate access/permissions is ...

  • Votes

    3

    Filter on reviews based on previous stage answer.

    Working with multistage reviews the need for filtering last stage of a review on the previous stage decision. Showing for example only the items with remove decisions on ...

  • Votes

    3

    Allow fully expanded view of Administration subtabs

    When Configuring Administration tab settings (eg., Authorization Assignments, General Settings, Account Controls, etc.), give admins a way to expand all sections ...

  • Votes

    3

    Protect C-Level Employees with "nrfProxy" style stand-in

    Enable Review Designers to protect C-Level folks (or any specific user by name, role, or title substring) to avoid getting any review items, using a proxy construct like ...

  • Votes

    3

    Ability to trigger Bulk Update utility after Publish

    After publishing a datasource it would be great if there was an option to trigger the bulk update functionality. After for example an import of new identities that need ...

  • Planned

    3

    Review definition can initiate a query onto the IG application ...

    Review definition can initiate a SQL select onto the IG application database to obtain a Review Set For a User or Account Review - the Review Set may be obtained live at ...

  • Votes

    3

    Add Review End Date as a Notification Parameter

    Currently we receive such data as the certifierFullName, reviewLink, taskTimeoutDays, etc. as parameters in our Notification emails. We would like to see the Review End ...