Build and operate role models
Role-based access
Model group membership as reusable roles, validate the intended access, then activate the model for controlled execution.
A role combines target-system groups with the accounts that should belong to them. Roles simplify entitlement assignment through group memberships; they do not grant entitlements directly in NIM.
Choose the right toolDirect link to Choose the right tool
| Need | Use |
|---|---|
| Maintain membership in existing groups as an access policy | Roles |
| Create, update, or remove groups and resources | Mappings |
| Generate many roles from source data | Role generators |
| Suggest a starting group-to-role fit from existing memberships | Role mining |
Do not manage the membership of one group through both mappings and roles. When NIM manages a group through roles, it reconciles that group’s membership as a whole.
Create a roleDirect link to Create a role
Work in the development modelDirect link to Work in the development model
Go to Output > Roles > Role Models, then edit the current development role model. Select Add Role and enter a descriptive role name.
Choose the account populationDirect link to Choose the account population
Edit the new role and select its Based on Filter. The filter must return the target account's unique identifier, such as Active Directory objectGUID.
If the filter has parameters, enter values in Filter Parameters to limit the population for this role.
Add a role itemDirect link to Add a role item
Add a role item and select the target System, Group Table, group identifier, and filter member identifier. On the Groups tab, select the groups the role manages.
Validate the membership resultDirect link to Validate the membership result
Use the Members tab to review pending member-to-group assignments. Add more role items when the role spans multiple systems, then save it.
Role model lifecycleDirect link to Role model lifecycle
Every role belongs to a role model. NIM uses three model states to separate design from production.
| Model | Purpose | Can you edit it? |
|---|---|---|
| Active | The production model used by groupmembership job operations. | No |
| Development | The working model for manual roles, generators, mining, and review. | Yes |
| History | A previous active or development version retained for inspection or restoration. | No |
Create or manage a role modelDirect link to Create or manage a role model
- Go to Output > Roles > Role Models.
- Select Add to create a new empty development model. The previous development model becomes history.
- Select Edit Role Model to update the current development model.
- Select Remove Role Model and confirm to remove an unused model.
Only the current development role model can be edited.
Scope a role modelDirect link to Scope a role model
Scopes control which accounts NIM can grant to or revoke from groups, separately for each system used by the model.
Define who NIM may manageDirect link to Define who NIM may manage
Create an include filter for the accounts NIM should normally manage and, when needed, an exclude filter for accounts that must remain outside automated membership changes. Both filters must return the appropriate key column for the target system.
Set the system behaviorDirect link to Set the system behavior
Open the development role model's Scope tab. For each listed system, select the include and exclude filters and choose whether NIM can Grant and/or Revoke group memberships.
Confirm inclusions and exclusionsDirect link to Confirm inclusions and exclusions
Use the Group Membership Report to inspect actions such as add, remove, not added (account excluded), and not removed (account not included) before activation.
Inspect, activate, or restore a modelDirect link to Inspect, activate, or restore a model
Inspect active or history modelsDirect link to Inspect active or history models
Select Inspect Role Model for an active or history model, then select Inspect Role to view its configuration. To inspect a development model, edit it directly.
Activate the development modelDirect link to Activate the development model
Select Activate Development Role Model and confirm. NIM copies its configuration to the active model; the previous active model becomes history. The development model remains available and matches the new active model.
Activation makes the model eligible for the next groupmembership job operation. Review pending actions before activating it.
Restore a history modelDirect link to Restore a history model
Select Copy Role Model for a history model. NIM makes that configuration the new development model and moves the previous development model to history.
Inspect pending role changesDirect link to Inspect pending role changes
The read-only Group Membership Reports tool shows what the development model would do.
- Edit the development role model and select Group Membership Reports.
- On Memberships, select a member, role, or group to see its related records. Use Ctrl-click to select multiple rows.
- On Actions, select Evaluate to list the pending group-membership operations that a future job will execute.
Edit, copy, rename, or remove a roleDirect link to Edit, copy, rename, or remove a role
From the development model, select Edit Role to update a role; use Copy Object to create a numbered copy; use Rename Object to change its name; or select Remove Role and confirm.
Use roles in jobsDirect link to Use roles in jobs
Add a groupmembership operation to a job for each target system. The job executes all pending membership changes for the active model in that system. Do not add more than one group-membership operation for the same system to a job.
Role safety guidelinesDirect link to Role safety guidelines
- Configure every role filter to include all accounts that should remain members of the managed group.
- Do not use roles to manage built-in Active Directory groups such as
AdministratorsorDomain Admins. - Review scopes and pending actions before every activation.
- Use troubleshooting guidance when a system, identifier, or scope is missing.