Skip to main content

Inspect Group Membership Reports

Role model reports

Group Membership Reports evaluate an individual role model. You can open a report for an active, development, or history model. The report is read-only: opening or evaluating it does not process the role model or change group memberships.

Open a reportDirect link to Open a report

  1. Go to Output → Roles and open the model version you want to inspect.
  2. Open Group Membership Reports. NIM evaluates that model and displays the Memberships, Actions, and Status tabs.
  3. Check Status first. If it contains errors, correct the configuration and select Evaluate to refresh the report before relying on the other tabs.

Status: check the evaluationDirect link to Status: check the evaluation

The Status tab shows evaluation messages, including their time, severity, and description. Read the messages even when the summary at the top says Success, result data available: that summary can appear while the message list contains an error.

Resolve errors before reviewing results

If the model has evaluation errors, the Memberships and Actions tabs may be incomplete or incorrect. Follow the error message to fix the affected configuration, select Evaluate, and check the messages again.

For example, this report has result data, but its messages identify a filter configuration error:

A successful evaluation has no error messages:

Memberships: audit the role modelDirect link to Memberships: audit the role model

The Memberships tab shows three connected lists: Members, Roles, and Groups. Use it to see which members are assigned to roles and which groups those roles assign. It reflects the evaluated model configuration, so confirm the Status tab has no errors first.

SelectNIM highlights
A MemberThe member's associated roles and groups
A RoleAll associated members and groups
A GroupAll associated roles and members

For a step-by-step investigation of a specific account, follow Trace a user's roles and groups.

Actions: preview group membership changesDirect link to Actions: preview group membership changes

The Actions tab shows what would happen if a job processed this role model. Each row identifies an action, member, and group, with additional source and target details to help you inspect the result.

ActionMeaning
addThe job would add the member to the group.
removeThe job would remove the member from the group.
not added or not removedThe proposed change would be skipped. Read the reason in parentheses.

Common skip reasons are account not included, meaning the account is outside the role model's include scope, and account excluded, meaning it is within the exclude scope.

After changing the role model, select Evaluate and review Status again before using the refreshed Memberships and Actions results. If the report identifies an issue you cannot resolve, see Troubleshoot roles.