Skip to main content

Built-in pre-defined requests

The following is a list of some example built-in pre-defined requests included in the Bravura Security Fabric :

_AUTORES_

Used by the autores utility during automatic resource assignment.

_CERT_ACCOUNT_GROUP_REMEDIATION_

Default remediation request for revoking account group memberships in certification.

_CERT_ACCOUNT_REMEDIATION_

Default remediation request for revoking accounts in certification.

_CERT_ATTR_REMEDIATION_

Default remediation request for updating profile attributes in certification.

_CERT_CHILD_GROUP_REMEDIATION_

Default remediation request for revoking child group memberships in certification.

_CERT_ROLE_REMEDIATION_

Default remediation request for revoking a role assignment in certification.

_CERT_TRANSFER_REMEDIATION_

Default remediation request for transferring a user profile in certification.

_CERT_USER_REMEDIATION_

Default remediation request for revoking a user profile in certification.

_COMPLETE_ATTRS_

Allows users to supply required profile and request attribute values when enforced enrollment is enabled for this task.

_DISABLE_ACCOUNTS_

Allows help desk users to disable other users’ accounts. The requester must be a member of the _GLOBAL_HELP_DESK_ user class and the GLOBAL_HELP_DESK rules must include the ”Disable account” privilege.

_ENABLE_ACCOUNTS_

Allows help desk users to enable other users’ accounts. The requester must be a member of the _GLOBAL_HELP_DESK_ user class and the GLOBAL_HELP_DESK rules must include the ”Enable account” privilege.

_GROUP_ADD_MEMBERS_

Allows group owners to add accounts and child groups as members to multiple groups on target systems, using the Groups app .

_GROUP_ADD_OWNERS_

Allows group owners to add owners to multiple groups on target systems, using the Groups app .

_GROUP_ADD_PARENTGROUPS_

Allows group owners to add parent groups to multiple groups on target systems, using the Groups app.

_GROUP_CREATE_

Allows users who belong to the _GROUP_CREATE_USERS_ user class to create a group on a target system, using the Groups app .

_GROUP_DELETE_

Allows group owners to delete a group on a target system, using the Groups app .

_GROUP_DELETE_MEMBERS

Allows group owners to delete members from multiple groups, using the Groups app .

_GROUP_DELETE_OWNERS

Allows group owners to delete owners from a multiple groups, using the Groups app .

_GROUP_DELETE_PARENTGROUPS

Allows group owners to delete parent groups from multiple groups, using the Groups app .

_GROUP_UPDATE_ATTRS

Allows group owners to update attributes on one or more groups, using the Groups app .

_GROUP_UPDATE_MEMBERS

Allows group owners to add or remove members from a group, using the Groups app .

_GROUP_UPDATE_OWNERS

Allows group owners to add or remove owners from a group, using the Groups app .

_GROUP_UPDATE_PARENTGROUPS

Allows group owners to add or remove parent groups from a group, using the Groups app .

_IDTRACK_

Used by the idtrack utility when submitting requests.

_RESOLVE_ENFORCEMENT_VIOLATIONS_

This pre-defined request is used for rbacenforce -generated requests. By default, it is enabled but not accessible to requesters.

_RESOLVE_ROLE_DEFICITS_

Allows users to add missing role entitlements.

_RESOLVE_SOD_VIOLATIONS_

Allows users to resolve SoD rules violations.

_UPDATE_ACCOUNTS_

Allows users to request to add or delete accounts from their profile or other users’ profiles, when the requester has the ”Create account” permission and a template account exists.

_UPDATE_ATTRS_

Allows users to update profile information for themselves or others, when the requester has the ”Update profile” permission.

_UPDATE_GROUPS_

Allows users to add or revoke group memberships for themselves or others, when the requester has the ”Manage group memberships” permission and groups are managed.

_UPDATE_ROLES_

Allows users to add or remove roles from their profiles or other users’ profiles, when the requester has the ”Add role” permission and a role exists.

_USER_ADD_GROUPS_

Allows users to join groups using the Groups app.

_USER_DELETE_GROUPS_

Allows users to leave groups using the Groups app.