Policies reports
User class errors
Purpose: Lists user class configuration error; for example, where a PSLang expression could not be evaluated.
Executable: ucerrors
Criteria | Description |
|---|---|
User class ID | Type the User class ID to list its information. |
Policies where the user class can be referenced | Select one or more user class policy points to include in the report. All user class policy points are included by default. |
Display errors only | Select this checkbox to display errors only. |
The report output contains the following columns:
Column | Description |
|---|---|
User class ID | The user class identifier. |
User class description | The description of the user class. |
Actor | The actor type in the user class. |
Configuration item | The configuration item that caused the error. |
Result | The error result or message. |
User class members
Purpose: Lists membership in single participant user classes. Relational user classes are not included.
Executable: ucmember
Criteria | Description |
|---|---|
Single-participant user classes | Select one or more single-participant user classes. All single-participant user classes are included by default. |
Policies where the user class can be referenced | Select one or more user class policy points to include in the report. All user class policy points are included by default. |
Do not display built-in user classes | Enable this checkbox to exclude built-in user classes, which are hard-coded. For example, _USER_IS_MANAGER_ is built-in. |
Summarize report | Select this checkbox to summarize the report details. |
Minimum number of user class members | The minimum number of user class members allowed to display. This option will only display when Summarize report is selected. |
Maximum number of user class members | The maximum number of user class members allowed to display. This option will only display when Summarize report is selected. |
The report output depends on whether the Summarize report option is selected.
When Summarize report is not selected, the report contains the following columns:
Column | Description |
|---|---|
User class ID | The user class identifier. |
User class description | The description of the user class. |
Actor | The actor type. |
Actor description | The description of the actor. |
User ID | The profile ID of the member. |
User name | The full name of the member. |
When Summarize report is selected, the report contains the following columns:
Column | Description |
|---|---|
User class ID | The user class identifier. |
User class description | The description of the user class. |
Actor | The actor type. |
Member count | The number of members. |
User classes
Purpose: Lists configuration, use and cache status of user classes.
Executable: userclasses
Criteria | Description |
|---|---|
User class ID | Type the User class ID to list its information. |
Policies where the user class can be referenced | Select one or more user class policy points to include in the report. All user class policy points are included by default. |
Date user class created | (Optional) Choose a date range for the user class creation. |
The report output contains the following columns:
Column | Description |
|---|---|
User class ID | The user class identifier. |
User class description | The description of the user class. |
Participation point | The participation point of the user class. |
Date created | The date the user class was created. |
Validity | The validity status of the user class. |
Validity date | The date the validity was last checked. |
User access privileges
Purpose: Security privileges granted to users.
Executable: userpriv
Criteria | Description |
|---|---|
Requester ID | Type the ID of the user whose privileges you want listed. Alternatively, you can search for one or more profile IDs. |
Allowed privileges | Select one or more privileges to display. All privileges are included by default. |
Rules | Select which set of user access rules to generate the report for:
|
Recipient | Type the profile ID of the recipient for whom you want to run the report. |
The report output contains the following columns:
Column | Description |
|---|---|
User ID | The profile ID of the user. |
User name | The full name of the user. |
Privilege | The access privilege name. |
Description | The description of the privilege. |
Entitlement review privileges
Purpose: The link between reviewers and users they are allowed to review.
Executable: adhoccertificationprivileges
Criteria | Description |
|---|---|
Options | Select to:
|
Users to be reviewed | This option is displayed if |
Reviewer ID | The option is displayed |
The report output depends on the selected option.
When List reviewers for selected users is selected, the report contains the following columns:
Column | Description |
|---|---|
Reviewable user ID | The profile ID of the user whose entitlements can be reviewed. |
Reviewable user name | The full name of the reviewable user. |
Certifier ID | The profile ID of the certifier. |
Certifier name | The full name of the certifier. |
Rule description | The description of the user access rule that grants the review privilege. |
When List users who can be reviewed by selected reviewers is selected, the report contains the following columns:
Column | Description |
|---|---|
Certifier ID | The profile ID of the certifier. |
Certifier name | The full name of the certifier. |
Reviewable user ID | The profile ID of the user whose entitlements can be reviewed. |
Reviewable user name | The full name of the reviewable user. |
Rule description | The description of the user access rule that grants the review privilege. |
Authentication chains
Purpose: Authentication chains configuration and usage statistics. Lists the results (successes and failures) of authentication chains.
Executable: authchain
Criteria | Description |
|---|---|
Authentication chain | Select one or more authentication chains to include in the report. |
Status | Select the authentication chain status to include in the report:
|
User ID | Type the profile ID of the user for whom you want to generate the report. By default, all users are included. Alternatively, you can search for one or more profile IDs. |
Choose relative date | (Optional) Choose a date range for authentication chain initiation. |
Show detailed report | Select this checkbox to display additional report details. |
Graph type | Select the graph type:
|
The report output depends on the Show detailed report option.
When Show detailed report is selected and a specific authentication chain is clicked, the drill-down report contains the following columns:
Column | Description |
|---|---|
User | The user who authenticated (combined name and profile link). |
Event time | The date and time of the authentication event. |
When Show detailed report is selected, the main report contains the following columns:
Column | Description |
|---|---|
Authentication chain ID | The identifier of the authentication chain. |
User ID | The profile ID of the user. |
Event time | The date and time of the authentication event. |
Result | The result of the authentication attempt. |
IP address | The IP address from which the authentication was attempted. |
When Show detailed report is not selected, the report contains the following columns:
Column | Description |
|---|---|
Authentication chain ID | The identifier of the authentication chain. |
Description | The description of the authentication chain. |
Successful | The number of successful authentications. |
Failed | The number of failed authentications. |
Policy configuration
Purpose: Displays the policy configuration stored in the external database.
Executable: dumppolicyconfiguration
Criteria | Description |
|---|---|
Table | Choose a table in the external database. |
Format | Choose:
|
Omit Blank | Choose "Yes" to omit blank rows/columns. |
The report output depends on the selected Format option.
When Tabular is selected, the columns are dynamic — one column per policy configuration field. The columns displayed depend on the selected policy table.
When Transposed is selected, the report contains the following columns:
Column | Description |
|---|---|
Field | The policy configuration field name. |
Value | The value of the configuration field. |
Question set configuration
Purpose: Provides information on pre-defined question sets, question set usage, and users who have populated question sets.
Executable: questionsetinformation
Criteria | Description |
|---|---|
Report type | Select:
|
Question set | List all enabled pre-defined question sets. |
Question status | List all question statuses (Answered and/or Unanswered). This option is only shown when |
User ID | For reports on users with answers to question sets, type the profile ID of the user for whom you want to generate the report. By default, all users are included. Alternatively, you can search for one or more profile IDs. |
Graph type | Select the graph type:
This option is only shown when |
Number of rows for graph | The maximum rows for graph to display. The selected rows will be displayed with the number of questions in descending order. |
The report output depends on the selected Report type.
When List question sets is selected, the report contains the following columns:
Column | Description |
|---|---|
User | The user (combined name and profile link). |
Last modified date | The date the question set answers were last modified. |
When Question set usage summary is selected, the report contains the following columns:
Column | Description |
|---|---|
Question set | The question set identifier. |
Description | The description of the question set. |
When Question usage details is selected, the report contains the following columns:
Column | Description |
|---|---|
Question set | The question set identifier. |
Description | The description of the question set. |
Question | The question text. |
Users answered | The number of users who answered this question. |
When Users with answers to question sets is selected, the report contains the following columns:
Column | Description |
|---|---|
User ID | The profile ID of the user. |
User name | The full name of the user. |
Question set | The question set identifier. |
Description | The description of the question set. |
Question | The question text. |
Answered | Whether the user answered this question. |
The question set members report contains the following columns:
Column | Description |
|---|---|
Question set | The question set identifier. |
Description | The description of the question set. |
User ID | The profile ID of the user. |
User name | The full name of the user. |
Explicit user class members
Purpose: Track when a user class membership (explicit users) is added/removed.
Executable: usersexplicit
Criteria | Description |
|---|---|
User class ID | Type the User class ID to list its information. |
User ID | Type the profile ID of the user for whom you want to generate the report. By default, all users are included. Alternatively, you can search for one or more profile IDs. |
Operations on explicit users | Choose the operation type for explicit user class members:
|
Added/deleted in last N days | Specify a certain number of past days for the report to search within. |
The report output contains the following columns:
Column | Description |
|---|---|
User class ID | The user class identifier. |
User class description | The description of the user class. |
User ID | The profile ID of the explicitly added member. |
User name | The full name of the member. |
Operation code | The operation code (add or remove). |
Operation description | The description of the operation. |
Operation date | The date the operation was performed. |
User class overlap
Purpose: Identifies user classes with overlapping user populations.
Executable: userclassoverlap
Criteria | Description |
|---|---|
Compare these user classes | Type the user class ID or a comma-and-space-delimited list of user class IDs for which you want to analyze the overlapping membership against all selected user classes to generate the report. You can not leave this box empty. Alternatively, you can search for one or more user class IDs. |
… to these user classes | Type the user class ID or a comma-and-space-delimited list of user class IDs against which you want to compare to generate the report. By default, this box is empty and all user classes but the built-in ones are included. Alternatively, you can search for one or more user class IDs. |
Overlap (%) | Type the overlap threshold that is used to add user classes to the output if their membership overlap meets or exceeds the threshold. Its range is 1-100 and by default it is set to 75%. |
The report output contains the following columns:
Column | Description |
|---|---|
User class ID (1) | The identifier of the first user class. |
User class description (1) | The description of the first user class. |
Overlap | The number of overlapping members between the two user classes. |
User class ID (2) | The identifier of the second user class. |
User class description (2) | The description of the second user class. |
Overlap (2) | The number of overlapping members from the second user class perspective. |