Merge security roles
|
Security administrator
|
You can merge existing security roles into another existing security role or a new security role.
On merge:
- The selected roles remain unchanged.
- The selected roles aren't added to the target role as such.
- The duties and privileges of the selected roles aren't added to the target role as such.
- All lowest entry points of the selected roles are grouped into one privilege or into a privilege for each selected type of entry point. For each selection, by default, a new privilege is created. However, if the target role already exists, you can also select an existing privilege of that role to which the entry points are added.
- Entry points with a higher license type than the defined Max user license type are not added to the privileges.
- If you do not define duties, the new privileges are added to the target role and, if applicable, entry points are added to the defined existing privileges.
- You can add the defined privileges to one duty or to a duty for each selected type of privilege. For each selection, by default, a new duty is created. However, if the target role already exists, you can also select an existing duty of that role to which the privilege is added.
- If you define duties, the new duties are added to the target role and, if applicable, privileges are added to the defined existing duties.
- If the target role doesn't have any duties and privileges, it will only have the new privileges or duties.
- If the target role already has duties and privileges which are not changed during the merge, these duties and privileges stay.
- Permissions for the entry points are given as defined in the wizard. This is only applicable if the target role already exists and has the same entry points. You can choose:
- Merge - The highest permission, whether it comes from the source role or the target role entry point, is set as the permission for the merged entry point.
- Unset, Grant, or Deny - Whatever the permission for the entry point is in the source role or target role, it is set to the chosen one.
- The target role is validated for segregation of duties violations. Note: If enhanced segregation of duties rules are enabled, the role assignment is validated against the enhanced segregation of duties rules.
|