Inspect Group Membership Reports
Role model reports
Group Membership Reports evaluate an individual role model. You can open a report for an active, development, or history model. The report is read-only: opening or evaluating it does not process the role model or change group memberships.
Open a reportDirect link to Open a report
- Go to Output → Roles and open the model version you want to inspect.
- Open Group Membership Reports. NIM evaluates that model and displays the Memberships, Actions, and Status tabs.
- Check Status first. If it contains errors, correct the configuration and select Evaluate to refresh the report before relying on the other tabs.
Status: check the evaluationDirect link to Status: check the evaluation
The Status tab shows evaluation messages, including their time, severity, and description. Read the messages even when the summary at the top says Success, result data available: that summary can appear while the message list contains an error.
If the model has evaluation errors, the Memberships and Actions tabs may be incomplete or incorrect. Follow the error message to fix the affected configuration, select Evaluate, and check the messages again.
For example, this report has result data, but its messages identify a filter configuration error:
A successful evaluation has no error messages:
Memberships: audit the role modelDirect link to Memberships: audit the role model
The Memberships tab shows three connected lists: Members, Roles, and Groups. Use it to see which members are assigned to roles and which groups those roles assign. It reflects the evaluated model configuration, so confirm the Status tab has no errors first.
| Select | NIM highlights |
|---|---|
| A Member | The member's associated roles and groups |
| A Role | All associated members and groups |
| A Group | All associated roles and members |
For a step-by-step investigation of a specific account, follow Trace a user's roles and groups.
Actions: preview group membership changesDirect link to Actions: preview group membership changes
The Actions tab shows what would happen if a job processed this role model. Each row identifies an action, member, and group, with additional source and target details to help you inspect the result.
| Action | Meaning |
|---|---|
| add | The job would add the member to the group. |
| remove | The job would remove the member from the group. |
| not added or not removed | The proposed change would be skipped. Read the reason in parentheses. |
Common skip reasons are account not included, meaning the account is outside the role model's include scope, and account excluded, meaning it is within the exclude scope.
After changing the role model, select Evaluate and review Status again before using the refreshed Memberships and Actions results. If the report identifies an issue you cannot resolve, see Troubleshoot roles.