Evidian Approval WorkflowApproval Workflow enables enterprises to put in place efficient responsibility chains to automate user lifecycle management. For example, end users can request access right updates and administrators can enroll new employees. All these requests are sent to approval authorities who grant or reject them. Thus, Approval Workflow is an added value to the deployment of reliable IAM projects. ArchitectureApproval Workflow can be used in conjunction with Evidian Policy Manager, ID Synchronization , User Provisioning, Evidian Enterprise SSO, Web Access Manager and SOA Access Manager. The Approval Workflow module provides:
User profilesThree workflow user profiles can be defined:
How an approval workflow worksA process is activated upon a user's request. This request automatically reaches an authority in charge of its approval, who is informed by an e-mail including a hypertext link to a reply form. Then, an approval authority can grant, reject, or forward the request. The process ends when the request is granted or rejected. Escalation and delegationOn time-out, the approval procedure may be subjected to escalation to other authorities. An approval authority may also choose to delegate his or her task over a specific period. In this case, the workflow engine sends the request to the delegated authority.
|
White paper: Approval workflow and agentless provisioning
Account provisioning is a major function in the implementation of an Identity and Access Management solution. It helps to make the account process creation more reliable. It builds a central account database that is the exact image of the target systems' situation. And it provides reports to demonstrate the effectiveness of the policy implementation. Unfortunately, not all target systems and applications support the IT agents that are usually used to create accounts reliably. Nevertheless, even without a agent, an application may be integrated into the global provisioning process via adapted workflows. This white paper describes how you can use workflow to implement reliable account creation processes without IT agents. |
||