Generate roles from identity data
Role automation
Generate repeatable role structures from source data, preview the impact, and apply the result to the development role model.
Role generators use two filters: one determines which roles exist; the other determines the accounts assigned to each role. They update only the development role model—target memberships change later when the active model is executed in a job.
Build a role generatorDirect link to Build a role generator
Define roles and membersDirect link to Define roles and members
Create a Role Generation Filter with a column whose rows become role names. Optionally add an include lookup of that value against target groups when the generator should attach matching groups.
Create a Role Member Filter that relates source identities to target accounts, includes the target account's unique identifier, and has a parameter for the value that identifies each role.
Connect the input valuesDirect link to Connect the input values
Go to Output > Roles > Role Generation and add or edit a generator. Select the role-generation filter, its Role Name Column, the role-member filter, the parameter name, and the role-generation column that supplies each parameter value.
Enable the relevant group lookup rows in Role Groups when NIM should associate found groups with the generated roles.
Evaluate before changing the modelDirect link to Evaluate before changing the model
Use Calculate on the Members, Groups, Roles, and Run tabs to preview results. Select the desired execution options, review the impact analysis, then select Apply Generator.
Applying a role generator updates the development role model only. It does not write changes to target systems.
Edit or remove a generatorDirect link to Edit or remove a generator
Select Edit Role Generator to adjust the filters or settings. Select Remove Role Generator and confirm to delete one that is no longer needed. For a complete worked example, see the Role model tutorial.