Skip to main content

Generate roles from identity data

Role automation

Generate repeatable role structures from source data, preview the impact, and apply the result to the development role model.

Role generators use two filters: one determines which roles exist; the other determines the accounts assigned to each role. They update only the development role model—target memberships change later when the active model is executed in a job.

Build a role generatorDirect link to Build a role generator

Define roles and membersDirect link to Define roles and members

Create a Role Generation Filter with a column whose rows become role names. Optionally add an include lookup of that value against target groups when the generator should attach matching groups.

Create a Role Member Filter that relates source identities to target accounts, includes the target account's unique identifier, and has a parameter for the value that identifies each role.

Step 1 of 3
info

Applying a role generator updates the development role model only. It does not write changes to target systems.

Edit or remove a generatorDirect link to Edit or remove a generator

Select Edit Role Generator to adjust the filters or settings. Select Remove Role Generator and confirm to delete one that is no longer needed. For a complete worked example, see the Role model tutorial.