Create and schedule role generator tasks
Scheduler task guide
Apply role generator results consistently while protecting role models from unexpected change volume.
Create a role generator taskDirect link to Create a role generator task
Build and validate the generatorDirect link to Build and validate the generator
Create and validate the role generator before scheduling it. Identify the role models that should receive its output.
Configure the taskDirect link to Configure the task
Create a role-generator task and choose the Role generator to run. Select whether its results should be applied to the development role model, the active role model, or both. When updating the active model, you can retain its original version as a historical role model.
Limit unexpected changesDirect link to Limit unexpected changes
Set the four Guard settings to cap roles created or deleted and groups added or removed. Select Save, run the task once, and review its result in History before enabling recurring execution on the Schedule tab.
Choose where the generated roles goDirect link to Choose where the generated roles go
| Option | Effect |
|---|---|
| Role generator | Selects the saved role generator whose filters and group lookups produce the roles. |
| Apply generator to development role model | Applies the result to the editable development model for review. |
| Apply generator to active role model | Applies the result to the active model used by role-processing jobs. Review the expected changes before enabling this option on a recurring task. |
| Store original active role model as historical role model | Keeps the previous active model as a history version when the task updates the active model. |
The manual Apply Generator action in the role generator editor updates the development model. A scheduled role-generator task also exposes the active-model option shown above. Changing the active model does not itself update target-system group memberships; those changes occur when the role model is processed by a job.
Set guard limitsDirect link to Set guard limits
Each guard is a maximum for one type of proposed change. If the task would exceed a configured value, NIM does not change the role model. The screenshot shows 10 for each guard as an example, not a required value.
| Guard setting | Limits |
|---|---|
| Maximum number of roles created | New roles the generator may create. |
| Maximum number of roles deleted | Existing roles the generator may delete. |
| Maximum number of groups added | Group assignments added to roles. |
| Maximum number of groups removed | Group assignments removed from roles. |
Use Resize to adjust the guard grid while reviewing values. Select Save after changing the configuration, Schedule to set run times, and History to inspect previous runs and guard failures.Related training videosDirect link to Related training videos