Manage IGA Solution Users
Manage IGA solution Users
IGA Solution includes ready-made user groups and responsibilities, which are taking into use based on selected IGA package.

Use Case Description
This use case is needed in all IGA packages, but IGA solutions user groups and responsibilities varies according to the selected package.
| Description | |
Overview |
This use case describes IGA solutions users can managed. IGA solution user can be 1. Self-Service Portal users (user, Manager, Approver etc.) 2. IGA solution user (IGA Admin, IGA Owner etc.) |
Operators |
IGA solution |
Prerequisites |
IGA solutions users are managed similar way than other user accounts and accesses are managed in the Customers directory. 1. This means that user needs to have user account in the directory 2. IGA solutions access are created as groups to the directory and read to IGA Entitlement datacards |
Result |
Customers users are able to access Self-Service Portal and in IGA solution (Matrix42 Service Management platform) functionalities. Users have accesses as defined in IGA Solutions user groups section. |
Operating chain for accessing IGA solution |
|
| Operating chain for managing IGA solutions responsibilities |
|
Related datacards |
IGA Entitlement |
Delete
IGA Solutions User Groups & Responsibilities
In this section are described different user groups and their accesses to different services and functionalities.
1. User groups
| Entitlement (directory group) | IGA user group description |
Efecte_ESS_User |
IGA User Can access to Matrix42 Self-Service Portal and may request access rights or roles for him-/herself. User may also request access right removal. When user sign into this role, it will show as an Entitlement. |
|
Efecte_ESS_Manager Efecte_test_ESS_Manager |
IGA Manager Can access to Matrix42 Self-Service Portal and may request adding or removing access rights for him-/herself or subordinates. Endorses / rejects subordinate access right requests. **Manager can re-certificate and request active access right removal for subordinates. **Manager can request for urgent lock for user accounts and access rights. *Manager can add new user or update information for existing users through Self-Service Portal User can have only one Manager. When user is signed in this role, it will show as an active Entitlement. |
|
Efecte_IGA_Starter_Admin Efecte_IGA_Growth_Admin Efecte_IGA_Enterprise_Admin Efecte_test_IGA_Starter_Admin Efecte_test_IGA_Growth_Admin Efecte_test_IGA_Enterprise_Admin |
IGA Admin Can access to all datacards related to IGA solution and can manage datacards which allows manual changes. With this access IGA Admin can perform all daily tasks and maintenance according to IGA packages. IGA Admin does not have any access to the Matrix42 Service Management -platforms configuration, but they can manage info text's, logo, colors etc. in Matrix42 Self Service Portals admin site. Notice! To get this access, IGA Admin training is mandatory for user. When user is signed in this IGA Entitlement, it will show as an active Entitlement and can be managed as any of the IGA Entitlements. |
|
Efecte_IGA_Starter_Module_Admin Efecte_IGA_Growth_Module_Admin Efecte_IGA_Enterprise_Module_Admin Efecte_test_IGA_Starter_Module_Admin Efecte_test_IGA_Growth_Module_Admin Efecte_test_IGA_Enterprise_Module_Admin |
IGA Module Admin** As an IGA Module Admin, user get's same access that IGA Admins and they can manage IGA configuration, provisioning tasks, workflows and has most powerful access rights to Matrix42 Service Management -platform, Self-Service Portal and to IGA solution. Notice! To get this access, Efecte's Advanced training's are mandatory for user. When user is signed in this IGA Entitlement, it will show as an active Entitlement and can be managed as any of the IGA Entitlements. |
|
IGA Owner Efecte_IGA_Owner |
IGA Owner Can see owner view in IGA Admin console, can start re-certification and manage access rights, roles assigned to her/him. |
|
IGA Security Manager Efecte_IGA_Security Efecte_test_IGA_Security |
IGA Security Manager Can access to risk levels, approves security clearances, IGA admin functionalities and has access to report and audit all information founded in IGA solution. |
|
IGA Password Manager Efecte_IGA_Password Efecte_test_IGA_Password |
IGA Password Manager Can access to change password to others service in Self-Service Portal and can change passwords to all other users. |
2. Responsibilities
| Responsibility | Description |
| Approvers |
Access right requests, re-certification requests**, reconciliation requests** and IGA Admin actions are approved according to approval levels and Approvers set in the datacards. Approvers can access only to Matrix42 Self-Service Portal. |
| Support groups |
Users who belongs to support group can manage, report and see requests pointed to the support group. Support group members are managed inside IGA solution, or directory groups can be used for defining support group members. Notice, that support group members are using IGA solution (Matrix42 Service Management -platform), so all users needs to have license. |
| Application admin for manual provisioning |
Access right requests, which IGA Entitlements provisioning type is manual, can be sent via email to application admins, for manual actions to add accesses to the user. Application admin needs to answer to the email, so that IGA Admin Task is closed. Application admins for manual provisioning are managed in IGA Entitlement datacards. |
Configuration Changes
Customer can define these configuration changes, without them affecting the projects schedule or work estimations.
1. Directory group names
Customer can define own names for the needed groups.
2. Availability for services in Self-Service Portal
Customer can define which services are available for pre-defined user groups.
Delete
Expansion Possibilities
In this chapter are listed expansion possibilities, but please notice that these might have affect to the projects schedule and work estimations, so these will always needs Matrix42 Consultants review before agreeing on implementation.
1. New Matrix42 Self-Service Portal Users
Customer can define new user groups to be allowed access to Matrix42 Self-Service and which services are available for the new user group.
2. New IGA Solution Users
Customer can define new user groups to be allowed access to IGA solution, please notice that this may also affect on licenses. These users can be for example application owners.
3. Modify existing role accesses
Customer can define, that for example IGA user can access to more services in Self-Service Portal or other changes to role access levels.
4. Use local users instead of directory users
Customer can define that only local users founded in IGA solution, can access to its services and functionalities.
DeleteRelations & configuration instructions
Relations to other use cases,
Relations to other data cards,
IGA Entitlement
IGA Access Right Record
IGA Account
Configuration instructions,
- Check that needed User groups are created to directory and imported to ESM
- IGA Entitlement data cards
- EPE task Reading Data from [Directory]
- Check tha needed Test users are created to directory and imported to ESM
- IGA Account data cards
- EPE task Reading Data from [Directory]
- Change ESM servlet settings (platform settings) to point right groups
-
servlet.
auth. admin. ad. group - servlet.
auth. user. ad. group
-
servlet.
- Change ESS groups to point right groups
- ESS Admin site and tab Roles check IGA for Managers and IGA for Users