Skip to main content

Troubleshoot roles and role models

Role troubleshooting

Trace a user's roles to the groups they provide, then resolve assignment, identifier, and scope issues.

Trace a user's roles and groupsDirect link to Trace a user's roles and groups

Use Group Membership Reports to answer which roles a user receives, which groups those roles provide, and which membership changes NIM would make. Have the user's target-system account identifier and the group you are investigating ready so you can distinguish accounts or groups with similar names.

Inspect the model used for the assignmentDirect link to Inspect the model used for the assignment

  1. Go to Output → Roles → Role Models.
  2. Open the active model when investigating the assignments used by production jobs. Open the development model when reviewing a proposed change, or a history model when comparing an earlier configuration.
  3. Select Group Membership Reports.

The report evaluates one model at a time. A role in development does not affect production until that model is activated and a job processes its membership changes.

Step 1 of 6
Keep the full assignment path

Record the model version, member identifier, role name, target system, group identifier, and action or skip reason. This gives you a concrete path to compare after a correction or include in a support request.

TroubleshootingDirect link to Troubleshooting

Choose the card that matches the issue you see. After correcting a filter or role item, review the validation report and confirm the expected role or scope is available.

A system is unavailable for a role itemDirect link to A system is unavailable for a role item

Problem

A system is unavailable for a role item

Likely cause

The selected filter does not return the system's unique account identifier, or the system has no appropriate N-N relation between its users and groups or assignable role items.

Resolution

  1. Verify that the filter returns the unique account identifier, such as Users.objectGUID for Active Directory or Users.ID for Google Workspace.
  2. Verify the N-N relation between users and the groups or items the role assigns.
  3. Reopen the role item and check whether the system is available.

Member ID is blank in the reportDirect link to Member ID is blank in the report

Problem

Member ID is blank in the report

Likely cause

The role filter no longer returns the target user identifier, or the identifier column was renamed and the role-item binding still points to the old name.

Resolution

  1. Confirm the role filter returns the target user identifier.
  2. If the column was renamed, open the role-item bindings and select the renamed column.
  3. Run the report again and confirm Member ID is populated.

Review a renamed member-ID binding

A system is missing from role scopesDirect link to A system is missing from role scopes

Problem

A system is missing from role scopes

Likely cause

The system is not used by a role item, or a role filter for that system is invalid.

Resolution

  1. Confirm the system appears in at least one role item.
  2. Review the validation report and correct any role-filter errors.
  3. Reopen role scopes and check for the system.

A role scope is unavailableDirect link to A role scope is unavailable

Problem

A role scope is unavailable

Likely cause

The scope's role items were removed, or its related filters are missing or invalid.

Resolution

  1. Restore the required role items and valid filters.
  2. Review and resolve any validation errors.
  3. Reopen the scope and confirm it is available.

Unavailable role scope