Skip to main content

Build and operate role models

Role-based access

Model group membership as reusable roles, validate the intended access, then activate the model for controlled execution.

A role combines target-system groups with the accounts that should belong to them. Roles simplify entitlement assignment through group memberships; they do not grant entitlements directly in NIM.

Choose the right toolDirect link to Choose the right tool

NeedUse
Maintain membership in existing groups as an access policyRoles
Create, update, or remove groups and resourcesMappings
Generate many roles from source dataRole generators
Suggest a starting group-to-role fit from existing membershipsRole mining
caution

Do not manage the membership of one group through both mappings and roles. When NIM manages a group through roles, it reconciles that group’s membership as a whole.

Create a roleDirect link to Create a role

Work in the development modelDirect link to Work in the development model

Go to Output > Roles > Role Models, then edit the current development role model. Select Add Role and enter a descriptive role name.

Step 1 of 4

Role model lifecycleDirect link to Role model lifecycle

Every role belongs to a role model. NIM uses three model states to separate design from production.

ModelPurposeCan you edit it?
ActiveThe production model used by groupmembership job operations.No
DevelopmentThe working model for manual roles, generators, mining, and review.Yes
HistoryA previous active or development version retained for inspection or restoration.No

Create or manage a role modelDirect link to Create or manage a role model

  1. Go to Output > Roles > Role Models.
  2. Select Add to create a new empty development model. The previous development model becomes history.
  3. Select Edit Role Model to update the current development model.
  4. Select Remove Role Model and confirm to remove an unused model.

Only the current development role model can be edited.

Scope a role modelDirect link to Scope a role model

Scopes control which accounts NIM can grant to or revoke from groups, separately for each system used by the model.

Define who NIM may manageDirect link to Define who NIM may manage

Create an include filter for the accounts NIM should normally manage and, when needed, an exclude filter for accounts that must remain outside automated membership changes. Both filters must return the appropriate key column for the target system.

Step 1 of 3

Inspect, activate, or restore a modelDirect link to Inspect, activate, or restore a model

Inspect active or history modelsDirect link to Inspect active or history models

Select Inspect Role Model for an active or history model, then select Inspect Role to view its configuration. To inspect a development model, edit it directly.

Activate the development modelDirect link to Activate the development model

Select Activate Development Role Model and confirm. NIM copies its configuration to the active model; the previous active model becomes history. The development model remains available and matches the new active model.

warning

Activation makes the model eligible for the next groupmembership job operation. Review pending actions before activating it.

Restore a history modelDirect link to Restore a history model

Select Copy Role Model for a history model. NIM makes that configuration the new development model and moves the previous development model to history.

Inspect pending role changesDirect link to Inspect pending role changes

The read-only Group Membership Reports tool shows what the development model would do.

  1. Edit the development role model and select Group Membership Reports.
  2. On Memberships, select a member, role, or group to see its related records. Use Ctrl-click to select multiple rows.
  3. On Actions, select Evaluate to list the pending group-membership operations that a future job will execute.

Edit, copy, rename, or remove a roleDirect link to Edit, copy, rename, or remove a role

From the development model, select Edit Role to update a role; use Copy Object to create a numbered copy; use Rename Object to change its name; or select Remove Role and confirm.

Use roles in jobsDirect link to Use roles in jobs

Add a groupmembership operation to a job for each target system. The job executes all pending membership changes for the active model in that system. Do not add more than one group-membership operation for the same system to a job.

Role safety guidelinesDirect link to Role safety guidelines

  • Configure every role filter to include all accounts that should remain members of the managed group.
  • Do not use roles to manage built-in Active Directory groups such as Administrators or Domain Admins.
  • Review scopes and pending actions before every activation.
  • Use troubleshooting guidance when a system, identifier, or scope is missing.