Previous Topic: Business Policy Rules (BPRs)Next Topic: Suggested Provisioning Roles


Edit Global Smart Provisioning Settings

To enable or disable Smart Provisioning functionality or edit global defaults for suggested roles and compliance checking across all tasks, log into the User Console as an administrator and go to System, CA Identity Governance Configuration, Define Configuration, and access the Smart Provisioning tab.

Note: If any task must be configured differently than the global settings, you can adjust the settings at the task level. Task-level settings override global settings.

You can edit the following Smart Provisioning settings:

Smart Provisioning Settings
Enable Smart Provisioning

Enables or disables Smart Provisioning functionality. Smart Provisioning can be disabled even though a connection with CA Identity Governance exists.

Global Tab Settings
Display Suggested Provisioning Roles Button

Determines whether the Suggested Provisioning Roles button appears on the Provisioning Roles tab.

Analytics Suggest Search Screen

Defines the search screen used for the role suggest feature.

Display Advanced Suggestion Configuration for Results

Determines whether the Advanced Suggestion Configuration section appears on the results page of the role suggest feature, after a search is performed.

The Advanced Suggestion Configuration section allows administrators to enter new criteria for a suggested roles search. Administrators can select the type of criteria (Matched Rule and Matched Attributes).

Enable 'Matched Rules' Analytics by Default

Determines whether CA Identity Manager suggests provisioning roles if the current user matches the rule that determines membership in a CA Identity Governance role.

You can override this default setting during the search using the Advanced Suggestion configuration screen.

Enable 'Matched Attributes' Analytics by Default

Determines whether CA Identity Manager suggests provisioning roles that other users who have similar profile attributes also have.

You can override this default setting during the search using the Advanced Suggestion configuration screen.

Display Weighted Score Column for 'Matched Attributes' Analytics

Determines the display of columns in the list of suggested provisioning roles. When this option is selected, CA Identity Manager displays the Weighted Score column, which indicates the highest score the suggested provisioning role received across all the criteria in the search.

Weighted Score Threshold for 'Matched Attributes' Analytics

Defines a threshold for 'Matched Attributes' search results returned by the suggest role feature. For each suggested role, CA Identity Governance returns a score from 1 to 100 percent depending on the level of attribute matching. Roles suggested with a score less than the threshold are not displayed.

Note: Some CA Identity Manager attributes may be more important to you than others, therefore CA Identity Governance allows you to customize the weight of any attribute in order to provide more useful analytics. For more information about setting attribute weights, see the Configuration Guide.

Bulk Loader Task Settings
Automatically Assign Roles that Match Rule

Determines if the Bulk Loader task uses ‘Matched Rules’ to search for roles. Any roles returned are automatically assigned.

Automatically Assign Roles that Match Attributes

Determines if the Bulk Loader task uses ‘Matched Attributes’ to search for roles. Any roles returned that exceed the Weighted Score Threshold are automatically assigned.

Weighted Score Threshold for 'Matched Attributes' Analytics

Defines a threshold for 'Matched Attributes' search results returned by the suggest role feature. For each suggested role, CA Identity Governance returns a score from 1 to 100 percent depending on the level of attribute matching. Roles suggested with a score less than or equal to the threshold are not assigned.

Note: Some CA Identity Manager attributes may be more important to you than others, therefore CA Identity Governance allows you to customize the weight of any attribute in order to provide more useful analytics. For more information about setting attribute weights, see the CA Identity Governance Configuration Guide.

Compliance Settings
Out of Compliance Analytics Level

Determines the level of information from the CA Identity Governance compliance analysis that CA Identity Manager displays.

You can set the following levels:

  • No Analytics
  • Issue Info Messages
  • Issue Warning Messages
  • Issue Error Messages

Note: For more information about the behavior of the different levels, see Types of Violations.

Out of Compliance Severity Threshold

Indicates the minimum severity score of compliance violations to display. For example, if you specify 75, CA Identity Manager only displays compliance violations that have a severity score of 75 or above.

This setting limits the number of compliance violations that appear for the task.

If Issue Error Messages is selected, this setting also affects which tasks can be submitted. For example, if you set the cutoff to skip errors with low scores, users can submit tasks that contain errors.

Enforce Compliance Check on Submit

When selected, compliance checks occur automatically when a task is submitted. Users do not have to manually select the Check Compliance button to see compliance violations.

Note: If enabled, tasks executed by TEWS also enforce compliance checks on submit. This option does not apply to bulk loader tasks.