12.07.2015 Views

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Task Optimizations■A user accesses a relationship tabA relationship tab is any tab where a user can view or manage aone-to-many relationship between the task's subject and a set ofentitlements. An example of a relationship tab is the Admin Roles tab, whichdisplays the roles that a user has.■A user adds objects on a relationship tabFor example, <strong>Identity</strong> <strong>Manager</strong> performs additional security checks when auser adds additional roles to another user on the Admin Roles tab.Task performance is affected by the following:■■Task scope, which determines where an administrator can use a taskRelationship tabs, which display an object's relationship to other objectsTask Scope Evaluation and PerformanceWhen an administrator uses an admin task that involves searching for amanaged object, such as a user, group, organization, task, or role, <strong>Identity</strong><strong>Manager</strong> evaluates and applies task scope rules. These rules can significantlyimpact the amount of time <strong>Identity</strong> <strong>Manager</strong> takes to display the list of objects toselect for the task.Note: Unlike member, admin, and owner policy evaluations, information aboutscope rule evaluations is not stored in a cache.Task scope is determined by the following:■■■The type of object that the task manages.Scope rules that apply to the admin role that includes the task. Scope rulesare defined in member, owner, and admin policies.Any user-defined search criteria.For example, consider a Modify User task, which is included in the User <strong>Manager</strong>role. The User <strong>Manager</strong> role has a member policy with a scope rule that allowsUser <strong>Manager</strong>s to manage users in the Employees organization. An administratoropens the Modify User task and enters the search criteria: Last Name starts withA. In this case, the scope for the Modify User task is all users in the Employeesorganization whose last name starts with A.How <strong>Identity</strong> <strong>Manager</strong> Renders Relationship TabsA relationship tab allows users to view and manage the relationship that a task'ssubject has with a set of entitlements. For example, the Provisioning Roles tabshows the provisioning roles that a user has.78 <strong>Implementation</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!