Administering Cloud EPM: The Platform Beneath the Business Processes · Module 6 · Users, Groups and the Role Model
The decision that does not feel like one
Lesson 63 of 201 · 2 min · Free preview
THE ONLY FLAGSHIP IN THIS COURSE WHERE THE WRONG DECISION DOES NOT FEEL LIKE A DECISION AT ALL. Nobody chooses per-user assignment. They just start. And then they have five hundred users. Five environments. Five hundred users. An average of two roles each. Five thousand grants. Every joiner is ten actions. Every leaver is ten actions — all of which must happen, none of which anyone will verify. What the group model does instead. Roles are assigned to groups. People are added to groups. A joiner is one action. A leaver is one action. And an access review reads a group membership list rather than five thousand grants. Why retrofitting is expensive. You cannot simply switch. You must map existing grants, design the groups, assign roles to them, add members, verify equivalence, then remove the individual grants. On a live estate that is weeks, and it needs a security sign-off.…
This lesson is free
Watch the full lesson, with its written notes, without an account. It is one of the free lessons this course opens with.
Watch the full lessonIn this module: Module 6 · Users, Groups and the Role Model
- 1What we are building
- 2The decision that does not feel like oneFree preview
- 3The access object model
- 4Predefined application roles
- 5Roles by business process
- 6Domain-level administrator roles
- 7Designing the group model
- 8Creating users
- 9Creating groups
- 10Policies for users and groups
- 11Assigning roles to groups
- 12Unassigning and offboarding
- 13Proving the model works
- 14What breaks
- 15Lab briefing: a role model for eight environments
- 16Lab solution walkthrough
