16.1 Default Role Models and Role Types
Key Takeaways
The four default role types are Organizational (containers for navigation), Business (job functions, assigned), IT (entitlement bundles, detected), and Entitlement (legacy, not recommended).
In the two-tier model, business roles link to IT roles through Required Roles (always provisioned) and Permitted Roles (allowed on request).
Business roles are assigned by assignment rules or requests; IT roles are detected when an identity's entitlements satisfy the role's profiles.
With inheritance, only the deepest matching role in a hierarchy is assigned or detected, and organizational roles in the chain break inheritance.
Role type definitions switch capabilities on or off, such as profiles, assignment rules, manual assignment, detection, inheritance, and required and permitted lists.
Default Role Models and Role Types
Objective 7.1 asks you to understand default role models and types. A role (object class Bundle) packages access. IdentityIQ's default configuration uses four role types arranged in a two-tier model.
The Four Default Role Types
| Type | Represents | Assigned or detected? | Notes |
|---|---|---|---|
| Organizational | Containers that organize the role hierarchy in the Role Modeler | Neither. They only provide nesting. | Group roles by org structure, application, alphabet, or any scheme that helps administrators navigate |
| Business | Job functions, titles, or responsibilities, such as AP Clerk or Treasury Analyst. The desired state of access. | Assigned, automatically by assignment rules or through requests | Birthright business roles are often not requestable and may be excluded from certifications |
| IT | Sets of system entitlements on one or more applications. The actual state of access. | Detected from entitlements, and can also be provisioned | Group related entitlements for reuse. Too many makes them single-use, and too few causes role explosion. |
| Entitlement | A single entitlement on one application | Legacy | Kept for backward compatibility with 5.x and earlier; not recommended |
Custom role types can model structures that do not fit the defaults, and the default types can be reconfigured (section 16.2). Rapid Setup adds a birthright type, rapidSetupBirthright by default (section 5.4).
The Two-Tier Model
Business roles are what managers and reviewers understand. IT roles are what target systems understand. In the two-tier model, business roles link to IT roles, so a manager can approve "AP Clerk" without reading twenty group names. One IT role can serve many business roles.
Required vs. Permitted
| Relationship | Meaning | Provisioning effect |
|---|---|---|
| Required Roles | Access someone with the business role must have | Assigning the business role provisions the required IT roles' entitlements |
| Permitted Roles | Access the person may have, "pre-screened" but discretionary, such as VPN | Nothing is provisioned until someone requests it |
Required and permitted links also show missing entitlements during certifications, although certifications do not fix them. Refresh or other processes do.
Hard vs. soft permitted: a hard permitted role was requested through IdentityIQ. A soft permitted role was discovered through aggregation and correlation. When the parent business role is removed, hard permitted roles are also deprovisioned (if nothing else depends on them), and soft ones are not.
How Roles Reach Identities
- Assignment (business roles): an assignment rule (Match List, Filter, Script/Rule, or Population) is evaluated when Identity Refresh runs with "Refresh assigned, detected roles and promote additional entitlements." Assignment can also come from LCM requests or batch requests.
- Detection (IT roles): the same refresh option compares each IT role's profiles with the identity's entitlements. Profile filters joined by AND require all entitlements, and OR requires any. A detected role replaces its individual entitlements in the identity's entitlement view. A role can be detected more than once when different assignments target different accounts.
Inheritance
- Business roles: with increasingly specific criteria, such as Help Desk Level 1, then 2, then 3, an identity is assigned only the deepest matching role.
- IT roles: when one set of access is a superset of another, only the deepest role is detected, and only if all entitlements of the chain are present. For example, Developer inherits Engineering.
- Limits: an organizational role placed in the chain breaks inheritance. Inheritance works only between roles of the same type. An IT role cannot be inherited directly by a business or container role.
Designing a Role Model: Practical Guidance
- Start with business roles people recognize. Use job codes, departments, and titles from HR. If reviewers cannot explain a role name, it will be rubber-stamped in certifications.
- Build IT roles around reuse. An IT role should bundle entitlements that several business roles share. SailPoint warns about both extremes: over-grouped IT roles are single-use, and under-grouped ones cause role proliferation.
- Use organizational roles only for navigation. They do nothing at run time, and placing them inside an inheritance chain breaks inheritance.
- Keep birthright separate. Birthright business roles, such as "All Employees," are usually assigned by rule, not requestable, and often excluded from certifications.
- Use required roles for provisioning and permitted roles for pre-approved options. This keeps requests fast and approvals meaningful.
- Let detection reveal gaps. Detected IT roles that are not covered by any assigned business role show access that came from outside the model, which is a good target for certification.
What a Role Type Controls
A role type definition sets what roles of that type can do. The options include disallow inheritance, no automatic detection with profiles (or no detection unless assigned), no entitlement profiles, no automatic assignment with rule, no manual assignment, no permitted or required roles list, disallow appearing on permitted or required lists, and disallow granting IdentityIQ user rights. This is why, for example, the Role Editor shows no Assignment Rule panel for an IT role and no entitlement panel for an organizational role.
In IdentityIQ's default role model, which role type is detected when an identity's entitlements satisfy its profiles?
IT role
Business role
Organizational role
Entitlement role, which is the recommended type for new installations
A business role must always grant ERP access, and it should let users request VPN access without granting it automatically. How are the IT roles related to the business role?
Both as Required Roles
ERP as Permitted and VPN as Required
ERP as a Required Role and VPN as a Permitted Role
Both as inherited roles
Help Desk Level 1, Level 2, and Level 3 business roles form an inheritance chain. An identity matches the criteria for Levels 1 and 2. Which roles are assigned?
Levels 1 and 2
All three levels
None, because inheritance blocks assignment
Only Level 2, the deepest matching role
A business role that contains a hard permitted role and a soft permitted role is removed from an identity. What happens to the permitted roles?
Both are deprovisioned.
Neither is deprovisioned.
The hard permitted role (requested through IdentityIQ) is deprovisioned if nothing else depends on it; the soft permitted role (discovered) is not.
The soft permitted role is deprovisioned, and the hard one is kept.
Sections you finish are checked off in the contents.