Skip to main content

Data quality reports

Users with no managers

Purpose: Shows users who do not have a manager in the OrgChart.

Executable: usersnomanagers

Table 1. Users with no managers report search criteria

Criteria

Description

Report type

Select a report type:

  • Show all users with no manager : displays all users that do not have a manager, regardless of their subordinates.

  • Show users with no manager and no subordinates : displays all users that do not have a manager and do not have any subordinates.

  • Show users with no manager and some subordinates : displays all users that do not have a manager but have at least one subordinate.

  • Show users with no manager and list direct subordinates : list the users who are managers of orphaned subtrees along with their direct subordinates.

  • Show users with no manager and list direct and indirect subordinates : list the users who are managers of orphaned subtrees along with their direct and indirect subordinates



The top manager is not considered a user with no manager.

Inconsistent account attributes

Purpose: Reports on users with corresponding account attributes that have inconsistent values.

Executable: inconsisacctattrib

Table 2. Inconsistent account attributes report search criteria

Criteria

Description

Attribute

Select one or more profile attributes for which to report inconsistencies. Attributes are only displayed here if they can be applied to a user profile (not request-only).

User ID

Type the ID of the user for whom you want to generate the report. Alternatively, search for one or more user profile IDs for which to report inconsistencies.



Invalid user attributes

Purpose: Reports on users with profile attribute values that do not meet validation rules.

Executable: invaliduserattr

Table 3. Invalid user attributes report search criteria

Criteria

Description

Attribute

Select one or more attributes from the list of profile attributes. By default, the report will search for all attributes. Attributes are only displayed here if they can be applied to a user profile (not request-only).

Report type

Select a report type:

  • Show users with empty attribute values : All users who do have not specified a value for the selected attribute are listed.

  • Show users with non-empty attribute values shorter or equal to : Type a positive integer value in the field. This value specifies the number of characters in the selected attribute values. The report lists all users whose attribute value is shorter than the specified length. For example, if you select the Email address attribute, and enter 10 for this option, then the report lists all users whose email address is shorter than 10 characters in length.

  • Show users with invalid attribute values : All users who have an invalid value for the selected attribute are listed. Attribute values are invalid if:

    • Not enough values: value missing for mandatory attribute

    • Too long: value exceeds specified maximum length

    • Not in restricted list: value is not from restricted list, if restricted values are defined

    • Bad format: value format does not match the required attribute format



Disappeared groups

Purpose: Shows managed groups where the corresponding target system has disappeared.

Executable: disappearedgroups

Table 4. Disappeared groups report search criteria

Criteria

Description

Target system ID

Type a comma-and-space-delimited list of target system IDs to list invalid managed groups from those systems. Alternatively, you can search for one or more target systems.

Show resources

Select this checkbox if you want to display resources that use the disappeared group.



Users with inactive roles

Purpose: Shows users with deprecated, disabled, or not assignable roles.

Executable: inactiveroles

Table 5. Users with inactive roles report search criteria

Criteria

Description

Roles

Type a comma-and-space-delimited list of roles to include in the report. Alternatively, you can search for one or more roles.

Role status

Select one or more role statuses to include in the report:

  • Deprecated

  • Disabled

  • Unassignable



Duplicate entries can appear in report output if you select multiple role statuses and a role has multiple statuses of invalidity, or a user has multiple roles which are in different statuses of invalidity.

For example, if a role is both deprecated and unassigned, and a user has both roles, then that user is reported twice.

Entitlements with invalid authorizers

Purpose: Reports on entitlements with invalid or insufficient authorizers.

Executable: invalidauthor

Table 6. Entitlements with invalid authorizers report search criteria

Criteria

Description

Report type

Select a report type:

  • Invalid authorizers : lists all authorizers that are no longer valid; for example, authorizers that were removed from the target system.

  • Insufficient authorizers : lists all resources that have less than the minimum required number of authorizers defined.

Entitlement type

This is the type of resource from which you want to list invalid or insufficient authorizers. Select an entitlement type:

  • Target system

  • Template account

  • Managed group

  • Role

  • Segregation of duties rules

Target system ID

Type a comma-and-space-delimited list of target system IDs to list entitlements from those systems. Alternatively, you can search for one or more target systems.

This option is only displayed if Entitlement type is set to Target system , Template account , or Managed group .

Managed groups

Type a comma-and-space-delimited list of managed groups to list entitlements for those groups. Alternatively, you can search for one or more managed groups.

This option is only displayed if Entitlement type is set to Managed group .

Roles

Select one or more roles. This option is only displayed if Entitlement type is set to Role and there is at least one role defined.

Segregation of duties rules

Select one or more SoD rules. By default, all SoD rules are included in the report output. This option is only displayed if Entitlement type is set to Segregation of duties rules and there is at least one SoD rule defined.

Include discovery templates

Select to include discovery templates for target systems.

This option is only displayed if Entitlement type is set to Target system .



Invalid reviewers

Purpose: Invalid reviewers assigned to active certification campaigns.

Executable: invalidcertifiers

Table 7. Invalid reviewers report search criteria

Criteria

Description

Campaign description

Type the description of one or more certification campaigns to only include those rounds in the report. Alternatively, you can search for one or more certification campaigns.

Certification method

Select a value to only include saved configurations with a matching certification method. The possible values are:

  • All certification methods

  • Single reviewer

  • Segment reviewers

  • Resource authorizers

  • Orgchart manager

Choose start date

Define a date range.



Profile attribute histogram

Purpose: Show the distribution of profile attribute.

Executable: profileattrhistogram

Table 8. Profile attribute histogram report search criteria

Criteria

Description

Profile attribute to analyze

The profile attribute which is used tally.

Profile attribute to search

Select a profile attribute and the value to filter the users that are considered to be included in the results.

Comparator

This field is displayed if a Profile attribute to search field is other than Attribute not required. Select the value type of comparator to apply on the profile attribute to search.

  • is equal to - if you want Bravura Security Fabric to search on values equal to a specified string.

  • is not equal to - if you want Bravura Security Fabric to search on values not equal to a specified string.

  • is empty to - if you want Bravura Security Fabric to search on attributes without a value.

  • is not empty to - if you want Bravura Security Fabric to search on attributes with a value.

Value

This field is displayed and required if a Comparator field is set to is equal to or is not equal to . Type the value of the string to compare with.

This searches against the attribute’s stored string value in the database, regardless of attribute type.

User class ID

Select the single participant user classes to filter the users that are considered in the totals.

Minimum value

The minimum value to include.

Maximum value

The maximum value to include.

Size of bands

The size of bands that are tallied.

Graph type

The graph type to display the data bands.



Profile attribute frequency

Purpose: For a given attribute or a set of two profile attributes, show all values (or combinations of two values) that appear at least a specified number of times. This includes individual values of multi-valued attributes as well as duplicate values where multiple values and duplicates are allowed for an attribute.

Executable: profileattrfreq

Table 9. Profile attribute frequency

Criteria

Description

Attribute

Enter the profile attribute for which to count the value frequency.

Attribute value to search

Type the value of the profile attribute.

Attribute

Optionally, enter the second profile attribute for which to count the value frequency in combination with the first one.

Attribute value to search

This field is displayed if the second attribute is other than "Attribute not required". Type the value of the profile attribute.

Minimum frequency

Enter the minimum appearance count for an attribute value to be displayed.

Graph type

Select the graph type:

  • (None): No graph generated

  • Horizontal bar chart : bar chart will be generated

Number of rows for graph

The maximum rows for graph to display. The selected rows will be displayed with the frequency of attributes in descending order.



Mismatched role assignments

Purpose: Lists roles per user where the user has been assigned the role and has some or all of the entitlements, but the correct information is not reflected in the Bravura Security Fabric database. For example, a user is assigned a role that includes only template accounts. A managed group is later added to the role, and the user is added to the group out of band. In this case the user meets the role requirements, but the database does not contain correct information.

Executable: mismatchedrole

Table 10. Mismatched role assignments report search criteria

Criteria

Description

Reference role

The roles to show surpluses or deficiencies for.

Show mismatch based on expanded role definitions

The mismatched items are expanded on sub-roles to display deficient and surplus entitlements.



Users with missing accounts

Purpose: Lists users that do not have an account on a target.

Executable: missingaccounts

Table 11. Users with missing accounts report search criteria

Criteria

Description

UserID

Type the ID of the user or search to find a user for whom you want to generate the report.

Attribute

Select a profile attribute from the drop-down list. A value is required once an attribute is selected.

Target system ID

Type in the target system ID or search to find the target system to report users that do not have an account.



Profile attribute coverage

Purpose: Show the number of times a given profile attribute is used.

Executable: profileattrcoverage

Table 12. Profile attribute coverage report search criteria

Criteria

Description

Minimum number of distinct values:

Type a positive integer to display only profile attributes that have the "Number of distinct values" greater than or equal to this integer. It is set to 1 by default.

Maximum number of distinct values (-1=infinite):

Type a positive integer to display only profile attributes that have the "Number of distinct values" less than or equal to this integer. It must be greater than or equal to "Minimum number of distinct values" and is set to infinite (-1) by default.

Minimum percentage of users with a value (%):

Type an integer between 0 and 100 to display only profile attributes that have the "Percentage of users with a value" greater than or equal to this integer. It is set to 0 by default. For each profile attribute, the "Percentage of users with a value" is calculated as its "Number of users with a value" divided by "Number of users excluding console users and superusers".

Maximum percentage of users with a value (%):

Type an integer between 0 and 100 to display only profile attributes that have the "Percentage of users with a value" less than or equal to this integer. It must be less than or equal to "Minimum percentage of users with a value" and is set to 100 by default. For each profile attribute, the "Percentage of users with a value" is calculated as its "Number of users with a value" divided by "Number of users excluding console users and superusers".



OrgChart loop

Purpose: Lists loops in the source data (for example, the "manager" account attribute in an Active Directory system) used to build the OrgChart.

The results are returned as a path in the following manner: UserA, UserC, UserB, UserA

What this means is UserA is a manager of UserB, UserB is a manager of UserC, and UserC is a manager of UserA.

Executable: orgchartloop

Search Criteria: None

Group loops

Purpose: Lists cyclic groups found on target systems.

The results are returned as a path in the following manner: GroupA, GroupB, GroupC, GroupD, GroupE

What this means is GroupB is a member of GroupA, GroupC is a member of GroupB, and so on and so forth. The final group, GroupD is the owner of the first group, GroupA

Executable: grouploops

Table 13. Group loops report search criteria

Criteria

Description

GroupID

Type the ID of the group or search to find a group for which you want to generate the report.

Target system ID

Type in target system ID or search to find target system to report all cyclic groups on that target.



Resource attributes

Purpose: Returns resources based on their attributes.

Executable: resourceattributes

Table 14. Resource attributes report search criteria

Criteria

Description

Resource type

Select a resource type:

  • Template account

  • Target system

  • Managed group

  • Role

  • Segregation of duties

  • Managed system

  • Managed account

    This criterion is not available for summarized reports.

Resource attribute

Select a resource attribute on which to filter resources. You can select up to eight attributes. The union of all attributes configured will be returned. For detailed reporting, only the resource attributes for the resource type configured are available. For summarized reporting, all resource attributes are available.

If no attributes are specified, the report lists all resources filtered by resource type.

Comparison

This field is displayed if a Resource attribute field is something other than Attribute not required . Select the comparator to apply on the selected resource attribute. Comparators available depend on the resource attribute type.

  • is empty - if you want Bravura Security Fabric to search on empty values.

  • is not empty - if you want Bravura Security Fabric to search on non empty values.

  • is equal to - if you want Bravura Security Fabric to search on values equal to a specified string.

  • is not equal to - if you want Bravura Security Fabric to search on values not equal to a specified string.

  • is less than - if you want Bravura Security Fabric to search on values that are less than a specific integer.

  • is less than or equal to - if you want Bravura Security Fabric to search on values that are less than or equal to a specific integer.

  • is greater than - if you want Bravura Security Fabric to search on values that are greater than a specific integer.

  • is greater than or equal to - if you want Bravura Security Fabric to search on values that are greater than or equal to a specific integer.

  • is later than today + N days - if you want Bravura Security Fabric to search on dates that are later than N days after today.

  • is earlier than, or equal to, today - N days - if you want Bravura Security Fabric to search on dates that are earlier or equal to N days before today.

Value

This field is displayed and required if a Comparison field is set to something other than is empty or is not empty . Type or select the value to compare.

Resource attribute to display

Choose which resource attributes to display alongside the resources.

Summarize report

Select this option to summarize the report.

In this mode, the report includes a count of each resource type.



If you do not specify any search criteria, the report output includes all resources.

Entitlements with invalid implementers

Purpose: Reports on entitlements with invalid or no implementers.

Executable: invalidimplementers

Table 15. Entitlements with invalid implementers report search criteria

Criteria

Description

Report type

Select a report type:

  • Invalid implementers : lists all implementers that are no longer valid; for example, implementers that were removed from the target system.

  • No implementer : lists all resources that have empty user class as implementers or no implementers in user class.

Entitlement type

This is the type of resource from which you want to list invalid or no implementers. Select an entitlement type:

  • Target system

  • Template account

  • Managed group

Target system ID

Type a comma-and-space-delimited list of target system IDs to list entitlements from those systems. Alternatively, you can search for one or more target systems.

This option is only displayed if Entitlement type is set to Target system or Managed group

Managed groups

Type a comma-and-space-delimited list of managed groups to list entitlements for those groups. Alternatively, you can search for one or more managed groups.

This option is only displayed if Entitlement type is set to Managed group .

Template accounts

Select one or more accounts.

This option is only displayed if Entitlement type is set to Template account and there is at least one template account defined.

Include inherited implementers

Select to include implementers inherited from the target system.

This option is only displayed if Entitlement type is set to Template account or Managed group .

Include discovery templates

Select to include discovery templates for target systems.

This option is only displayed if Entitlement type is set to Target system .