Skip to main content

Create and schedule role generator tasks

Scheduler task guide

Apply role generator results consistently while protecting role models from unexpected change volume.

Create a role generator taskDirect link to Create a role generator task

Build and validate the generatorDirect link to Build and validate the generator

Create and validate the role generator before scheduling it. Identify the role models that should receive its output.

Step 1 of 3

Choose where the generated roles goDirect link to Choose where the generated roles go

OptionEffect
Role generatorSelects the saved role generator whose filters and group lookups produce the roles.
Apply generator to development role modelApplies the result to the editable development model for review.
Apply generator to active role modelApplies the result to the active model used by role-processing jobs. Review the expected changes before enabling this option on a recurring task.
Store original active role model as historical role modelKeeps the previous active model as a history version when the task updates the active model.

The manual Apply Generator action in the role generator editor updates the development model. A scheduled role-generator task also exposes the active-model option shown above. Changing the active model does not itself update target-system group memberships; those changes occur when the role model is processed by a job.

Set guard limitsDirect link to Set guard limits

Each guard is a maximum for one type of proposed change. If the task would exceed a configured value, NIM does not change the role model. The screenshot shows 10 for each guard as an example, not a required value.

Guard settingLimits
Maximum number of roles createdNew roles the generator may create.
Maximum number of roles deletedExisting roles the generator may delete.
Maximum number of groups addedGroup assignments added to roles.
Maximum number of groups removedGroup assignments removed from roles.

Use Resize to adjust the guard grid while reviewing values. Select Save after changing the configuration, Schedule to set run times, and History to inspect previous runs and guard failures.