• Votes

    8

    Inactivate as an fulfillment options

    For some systems, especially finanse systems, an requirement is to be able to inactivate the account instead of removing the account. It is therefore requested to be ...

  • Votes

    4

    Create a SoD policy which has as a condition identity attribute data

    Create other types of SoD policies or just access policies that consider the mix of permissions and identity attribute date. For instance, an user who is a contractor ...

  • Planned

    2

    Capability to change the Authorization Assignment permissions

    Use Case: Review Administrators who need to work with their Email Templates (for Reviews, naturally). But only the Global Administrator can work the Notification Emails. ...

  • Planned

    4

    Option to exclude "Keep" by category from the unmapped account review

    When doing an unmapped account review it should be possible to be able to exclude accounts that has been marked as "Keep" and assigned a category from the unmapped ...

  • Votes

    2

    Possibility to chose the source for email-address in Identity ...

    Identity Reporting notification takes the email address from the SSO provider. This does cause problems, if the SSO provider do not have updated email-addresses as an ...

  • Votes

    2

    Use Business Role data for mapping permission in a multi affiliated ...

    Multi affiliation can be implemented in at least two ways: multi accounts one per affiliation, single account combining the affiliation permissions into one account. ...

  • Votes

    2

    On- and offboarding

    The first process in governing identities is onboarding. It would be beneficial if the onboarding process could be initiated from IG, by letting the right people to be ...

  • Votes

    3

    Second-level manager needed in Approval Policy

    Approval Policy needs direct supervisor and second-level supervisor as pickable approver sequence, e.g., First Approver: Requestor's Manager Second Approver: Requestor's ...

  • Planned

    3

    Review definition can initiate a query onto the IG application ...

    Review definition can initiate a SQL select onto the IG application database to obtain a Review Set For a User or Account Review - the Review Set may be obtained live at ...

  • Planned

    3

    Metadata collection for Application Owners, Reviewers, Monitors

    Customer maintains names and userids of (both Business & Technical) Application Owners, Reviewers, and Monitors per Identity Governance application and/or review within ...

  • Votes

    4

    Add capability to generate & display email messages within the IG ...

    Capability to generate & display email messages within the application. In a non-Production environment, it is essential to generate the various IG email messages, but ...

  • Planned

    7

    Provide a Coverage File option in the Unmapped Accounts Review ...

    Provide a Coverage File option in the Unmapped Accounts Review definition Allow account or permission data to assign the (unmapped account) review item to a certain ...

  • Votes

    2

    Add connection failoverPartner configuration to JDBC collector

    Customer provided this JDBC connection string for an Application collector. jdbc:sqlserver://LENVSSDS10;databaseName=GetAccess;failoverPartner=COLVSSDS10 At any given ...

  • Votes

    4

    Add query capability to the CSV collector

    Add query capability to the CSV collector In an Application collector with a CSV source file, adding a query statement capability (SQL SELECT) against the CSV data would ...

  • Planned

    11

    Data Purge Utility needs to become an automatic process

    The Data Purge Utility needs to become an automatic process. Increasingly, Application Administrators are not permitted server access. Provide Purge Utility parameter ...

  • Votes

    7

    Request for time limited access and for access in the future

    When requesting access it is sometime needed to be able to limit the request to a specific time period already at access time. It is similar to the possibility in ...

  • Planned

    4

    IG: Compare the IdM expected status with the actual status in the ...

    IG customers with an IdM solution (independent of vendor) do heavily rely on the status of users and permissions in their IdM system. The status of the IdM system is ...

  • Planned

    5

    Manager employee relationship review

    Before reviewing employees access rights many companies would like to have a review of the manager/employee relationship. Make it possible to have Identity review, ...

  • Votes

    6

    Need for grouping AD permissions into application specific groups

    AD is used as the authorization and authentication source for many applications via federation. A typical setup is that a number of security groups are created in AD to ...

  • Votes

    8

    Handling "Orphan Reviews"

    If a reviewer is no longer valid while a review is in flight, the system should escalate the "orphaned review" to the original reviewer's supervisor and up the chain.