Hitachi ID Systems, Inc.

Hitachi

Technology Roles & Rules

Headlines

Hitachi, Ltd. acquires M-Tech Information Technology, Inc. ... More»

ID-Synch Roles and Rules

(1) ID-Synch® provisions new users with templates and roles:

(2) ID-Synch does not require that users be classified into roles. While policy-based provisioning, where users' real access privileges are compared to those predicted by their role membership is technically possible with ID-Synch, Hitachi ID recognizes that most organizations will be unable to reliably and fully classify existing users into roles, so user/role classification and policy reconciliation is not an ID-Synch pre-requisite.

Search tags are attached to templates and roles in ID-Synch, to make them easier to find by end-users. Search tags include type and location. Resources such as templates, roles and managed groups also are associated with authorizers.

In order to ensure that the numbers of templates and roles are manageable, ID-Synch supports request attributes, which override the detailed attributes of templates and roles.

Request attributes may be entered by users and are in general validated and filled out by plug-in programs, written to implement customer-specific business logic. These plug-in programs can be thought of as implementing rules.

The combination of roles and rules can be best explained using an example: