cancel
Showing results for 
Search instead for 
Did you mean: 

auto provision

Former Member
0 Kudos

Have a strange behavior. When a request (new or change) goes thru the approval workflow and is approved at every step with the exception of the last step, which rejects the request, the rejected request (still has roles) gets auto provisioned in the back end R3. In the Workflow->Auto Provisioning->Auto-Provisioning Type is set to "Auto-Provision at end of request". It was my belief that meant approved requests, not all requests. Is there a workaround for this? GRC 5.3 SP9

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Yes, there is. It depeneds on the stage level settings you have. What is the last stage of your Path? Go to that stage and make sure that the settings for 'Approval Level' and 'Rejection Level' are configured to select 'Request' instead of 'Role'.

Alpesh

Former Member
0 Kudos

That's what I was afaid of....I have the workflow set to approve/reject the request at the first level(s), but at the final level, which is security, I have it at the role level because that's where any final changes to the roles are made. Do I have to make another level for secuity that is at the request level in addition? And any ideas to make this seamless to the security folks would be helpful as well.

Former Member
0 Kudos

You can change it to request level and still security can make changes to the role assignment. There is no need to add additional stage.

Alpesh

koehntopp
Product and Topic Expert
Product and Topic Expert
0 Kudos

That of course means you're ok with the fact that any role approver can reject the whole request...

Usually, the role approver stage looks like this:

- Request rejection = no (role approvers should only worry about their roles and not cancel other poeple's responsibilities)

- rejection level = role (so they can reject all their roles in one go.

I prefer to not have role owners reject anything, but rather take away roles one by one and then approve that, so that role owner will only ever press "approve" with 0 to n roles.

Frank.

Former Member
0 Kudos

Frank,

He mentioned that the last stage is security and not role owner. He still wanted to keep approval/rejection level at role which is not needed at all. Usually, customers keep approval/rejection level at role when in role owner stage.

Alpesh

Answers (0)