• Votes

    1

    Be able to create a dashboard listing users by risk level and ...

    Be able to create a dashboard to identify and separate users by risk and also per department or job title (or any other identity attribute). This view can help the ...

  • Planned

    4

    Reviewer can visualize more detailed info about the IT and Business ...

    Today, in version 3.0, the reviewer cannot visualize some detailed information of the Role being reviewed. For instance, if a Technical role is being reviewed, it would ...

  • Planned

    2

    Capability to change the Authorization Assignment permissions

    Use Case: Review Administrators who need to work with their Email Templates (for Reviews, naturally). But only the Global Administrator can work the Notification Emails. ...

  • Planned

    2

    Capability Matrix per Authorization Assignment

    Provide a Capability Matrix (of IG left navigation Menu selections & privileges) per Authorization Assignment. (Global Administrator, Access Request Administrator, etc) ...

  • Votes

    2

    Data Dictionary of attributes listing values & purpose

    The application needs a Data Dictionary providing a list of the attributes for User / Account / Group / Permission / Business Roles and their values & purpose within the ...

  • Planned

    4

    Option to exclude "Keep" by category from the unmapped account review

    When doing an unmapped account review it should be possible to be able to exclude accounts that has been marked as "Keep" and assigned a category from the unmapped ...

  • Votes

    9

    IG: Deprovisioning of granted Permissions by Business Role ...

    IG 3.0 seems not to provide a mechanism that causes deprovisioning of a granted permission that is deleted from a Business Role. There must be a way to achieve this. ...

  • Votes

    2

    Possibility to chose the source for email-address in Identity ...

    Identity Reporting notification takes the email address from the SSO provider. This does cause problems, if the SSO provider do not have updated email-addresses as an ...

  • Votes

    2

    Use Business Role data for mapping permission in a multi affiliated ...

    Multi affiliation can be implemented in at least two ways: multi accounts one per affiliation, single account combining the affiliation permissions into one account. ...

  • Votes

    2

    On- and offboarding

    The first process in governing identities is onboarding. It would be beneficial if the onboarding process could be initiated from IG, by letting the right people to be ...

  • Votes

    3

    Second-level manager needed in Approval Policy

    Approval Policy needs direct supervisor and second-level supervisor as pickable approver sequence, e.g., First Approver: Requestor's Manager Second Approver: Requestor's ...

  • Votes

    2

    The REMOVE_PERMISSION_ASSIGNMENT change items in the change set should ...

    In version 2.5.1, each change item in the REMOVE_PERMISSION_ASSIGNMENT change set contains the permission name, but does not contain the permission ID from source. The ...

  • Votes

    1

    Software appliance installation option

    Have a software appliance option to install IG. That would make easier the deployment of it in projects, POCs, demos, and mainly for maintenance of the patches/updates in ...

  • Votes

    2

    Have a SAP collector that gets object authorization and transactions ...

    Collect object authorization and transactions that users are assigned on SAP system. That makes possible to have SoD at that level of access in SAP systems. This is a ...

  • Votes

    8

    Have a native linux and windows local account collector

    Have a native linux and windows collector to get local accounts to identify and review orphans accounts on these systems. This is a very common and important requirement.

  • Votes

    5

    SoD Policies need a periodic review process to satisfy audit ...

    From the customer: A required expiration/approval cycle for SOD policies: On a periodic basis (configurable), SoD policies will move to a “Review & Approval Required” ...

  • Planned

    3

    Review definition can initiate a query onto the IG application ...

    Review definition can initiate a SQL select onto the IG application database to obtain a Review Set For a User or Account Review - the Review Set may be obtained live at ...

  • Planned

    3

    Metadata collection for Application Owners, Reviewers, Monitors

    Customer maintains names and userids of (both Business & Technical) Application Owners, Reviewers, and Monitors per Identity Governance application and/or review within ...

  • Votes

    4

    Add capability to generate & display email messages within the IG ...

    Capability to generate & display email messages within the application. In a non-Production environment, it is essential to generate the various IG email messages, but ...

  • Planned

    7

    Provide a Coverage File option in the Unmapped Accounts Review ...

    Provide a Coverage File option in the Unmapped Accounts Review definition Allow account or permission data to assign the (unmapped account) review item to a certain ...