16.2 Configuring Roles and Role Options

Key Takeaways

  • A role's assignment rule can be a Match List, Filter, Script, Rule, or Population, and it runs during Identity Refresh with the assigned/detected roles option.

  • Entitlement profiles use attribute rules (filters combined with AND/OR) and permissions; profiles are not shared between roles.

  • Granted IdentityIQ User Rights on a role (capabilities and scopes) are applied only when Identity Refresh runs with the provision assignments option.

  • Role versioning needs doArchive set to true in the role create/update/delete business process; archived versions can be rolled back.

  • Removing entitlements from a role reaches existing holders only through Allow propagation of role changes plus the Propagate Role Changes task.

Last updated: September 2026

Configuring Roles and Role Options

Objective 7.2 asks you to configure roles and role options. Roles are created and edited on Setup > Roles (Role Viewer and Role Editor). Behavior that applies to all roles is set on gear icon > Global Settings > IdentityIQ Configuration > Roles, and role types and extended role attributes on Global Settings > Role Configuration.

The Role Editor

Field or panelPurpose
Name / Display Name / TypeThe type decides which panels appear (section 16.1). Changing a type keeps the old data but flags attributes that no longer apply.
OwnerAn identity or workgroup. It usually approves role changes and role requests, and reviews role certifications.
Scope, Description (multi-language), ClassificationsVisibility, text, and sensitivity flags
Extended role attributesCustom attributes defined in Role Configuration (section 2.3)
Assignment RuleAutomatic assignment through a Match List (identity or application attributes and permissions, with Is Null), Filter, Script, Rule, or Population
Required / Permitted / Inherited RolesThe relationships from section 16.1
Entitlements (profiles)For each application, attribute rules built from filters (field, search type such as equals, like, is null, or contains all for multi-valued, value, ignore case) combined with AND/OR, plus permissions (rights such as create, read, update, delete, execute on a target). A Simple View lets you pick catalog entitlements, and an Advanced View builds filters. Profiles are not shared between roles.
Provisioning PolicyFields needed to provision the role (section 4.2). It removes the uncertainty of OR profiles.
Granted IdentityIQ User RightsCapabilities and scopes given to holders, applied when Identity Refresh runs with the provision assigned roles option
Scheduled EventsActivation and deactivation of the role on dates
Allow multiple application accounts / Enable multiple assignmentsCovered below
DisableMakes the role unavailable. It appears grayed out.

Roles with pending approval or impact analysis show a red square on the icon. Submitting new changes replaces the pending work item.

Global Role Options (IdentityIQ Configuration > Roles)

  • Enable Sunrise / Sunset Dates on Role Assignment – time-limited assignments, run by the Scheduled Assignment business process.
  • Enable Sunrise / Sunset Dates on Role Activation – date-based activation or deactivation of the role itself, run by Scheduled Role Activation.
  • Days before Sunset expiration to send notification – notify the requester and the recipient before access expires (0 disables it).
  • Role create, update, and delete business process – for example, Role Modeler – Owner Approval or Role Modeler – Impact Analysis.
  • Show UI option to allow multiple application accounts – a role may use its own or a new account even when another role requires it. Without it, required roles use the top-level role's account.
  • Show UI option to allow multiple assignments / Allow multiple assignment for all assignable roles – the same role assigned more than once to one identity. The global setting overrides per-role settings.
  • Allow propagation of role changes – records RoleChangeEvents (below).
  • Retain assigned entitlements when detected roles are removed / when assigned roles are removed.
  • Require comments for all access items in Access Requests.

Making Role Changes Take Effect

ChangeWhat applies it
New or changed assignment rule or profileIdentity Refresh with Refresh assigned, detected roles and promote additional entitlements
Provisioning newly assigned rolesRefresh with Provision assignments, or an LCM request
Entitlements removed from a role definitionAllow propagation of role changes plus the Propagate Role Changes task, scheduled regularly. It can run policy checks and has a time limit.
Granted user rightsRefresh with the provision option

Role propagation covers the changed role and roles that inherit or require it. The console import -noroleevents option suppresses role-change events for bulk imports (section 3.1).

Versioning and Rollback

Role versioning is off by default. To turn it on, set the doArchive variable to true in the role create/update/delete business process. After every fully activated change, the previous state is archived. On the Role Viewer or Role Editor, open Archived Roles, choose a version, and Roll Back to Archived Role, then Submit. The replaced version is archived too, and approval is still required if role changes need approval. Identities keep their current associations until the next refresh with role options, unless the business process refreshes them.

Worked Example: A Temporary Project Role

A two-month audit project needs the Audit Workspace business role for six people.

  1. On IdentityIQ Configuration > Roles, confirm that Enable Sunrise / Sunset Dates on Role Assignment is on and that the Scheduled Assignment process is selected.
  2. Create the role with an owner workgroup, required IT roles for the workspace entitlements, and no assignment rule, because it is request-only.
  3. Managers request it through LCM with a sunset date at the project end. Days before Sunset expiration notifications warn requesters beforehand.
  4. On the sunset date, the scheduled process removes the assignment and deprovisions the required access, unless retention options keep assigned entitlements.

Other Role Tools

  • Role Mining builds candidate roles from identity data, using attributes marked minable in schemas (section 12.2), and generates assignment rules. If you edit mined roles, check that the generated rules still fit.
  • Entitlement Analysis and Impact Analysis show who would gain or lose access before a change.
  • Refresh Role Indexes must run before role searches work, and the console rolerelationship command inspects role relationships.
Test Your Knowledge

A new assignment rule on the "Finance Analyst" business role is saved, but no identities receive the role. What must run?

A

Identity Refresh with "Refresh assigned, detected roles and promote additional entitlements" selected

B

Account Group Aggregation with Promote managed attributes

C

The Propagate Role Changes task with no other settings

D

Perform Maintenance with Prune identity snapshots

Test Your Knowledge

A role grants the Help Desk Personnel capability through Granted IdentityIQ User Rights, but members do not receive it. What is missing?

A

Adding the capability to a QuickLink population

B

Marking the role as requestable

C

Running Identity Refresh with the provision assigned roles option, which applies granted capabilities and scopes

D

Enabling multiple assignments

Test Your Knowledge

An administrator removes an AD group from an IT role's profile and wants that group removed from everyone who holds the role. What configuration supports this?

A

Retain assigned entitlements when assigned roles are removed

B

Import the role with -noroleevents

C

Enable sunrise and sunset dates on role activation

D

Allow propagation of role changes, plus a scheduled Propagate Role Changes task

Test Your Knowledge

How is role versioning with rollback enabled?

A

It is always on; every save creates a version.

B

By enabling Allow multiple assignments.

C

By running the Refresh Role Indexes task.

D

By setting the doArchive variable to true in the role create, update, and delete business process

Sections you finish are checked off in the contents.