Access
Who may sign in, which directory vouches for them, what they may reach once they are in, who is signed in at this moment, the duties that must not be combined, administrator authority borrowed for a fixed window, and one person’s identity borrowed for another to debug with.
11 steps · 7 questions · 7 screens on this shelf
The screens on this shelf
- Users Who may sign in, which roles they hold, and where they are allowed to work.
- Roles What a role may reach: modules, locations and warehouses.
- Single Sign-On One connection per directory — SAML 2.0, OpenID Connect, OAuth 2.0, WS-Federation, CAS, LDAP, SCIM and the res
- Signed In Now One row per live session rather than per person, so somebody working on a laptop and a tablet appears twice. E
- Segregation of Duties Pairs of duties that should not sit with one person, and who currently holds both. Administrators are exempt —
- Elevated Access Administrator authority borrowed for a fixed window, against a written reason, a ticket and two approvals. It
- Assumed Identity Signing in as another person to reproduce their transaction, for a fixed window, against a written reason, a t
Progress is kept in this browser only — it is not sent anywhere and nobody else can see it.