cancel
Showing results for 
Search instead for 
Did you mean: 

GRC10-Cancelling Path when added both system&role for request type"New Account"

Former Member
0 Kudos

Hi Experts,

We are on GRC-AC10-SP06.We have configured MSMP workflow..every thing is working fine when i add only role while creating request type"New /Change Account". we have configured 1st stage as "role owner" 2nd stage as "Security" any violations then request goes to detour path.

Iam facing issue when i add system and role together in the same Access request.. I couldn't able to add only system also, because the system is not allowing me to create request with out adding role (getting Error- Add atleast one role)

Is the system looking for any Agent to approve for "system" ? As per our client,they don't want to add Manager stage for "system"approval in the workflow,because we want to follow the process where approval for "system" by manager will get out of GRC box (through our internal ticketing tool)before creating Access request.

But user creation and role assignment must happen through "Access request Management" Auto provisioning..

Please let me know how should i configure workflow so that GRC system must allow workflow to proceed further with out cancelling path with error "No agent found"  Plz find below screen shot for Audit log..

Please Help me out with your valuable suggestions to overcome this issue..

Regards,

Ravi.

Accepted Solutions (0)

Answers (4)

Answers (4)

Former Member
0 Kudos

Hi Ravi,

I have the same problem... how did u solve that?

Thanks

Eliane

Former Member
0 Kudos

Hi Ravi,

As per the description, can you please check with stage level setting and set 'Request Approval' to

role level.

Request will behave as per the role settings then.

Best Regards,

Akhil Chopra

Former Member
0 Kudos

Hi Akhil,

Thanks for the reply..

I have made changes as suggested,but still not working. Am getting same error in Audit log.

Regards,

Ravi.

Former Member
0 Kudos

Hi Ravi,

Not sure fi your issue is resolved but here is the suggestion:

For the role you are selecting follow the path: Access management-->Role mass maintenance -->Role Update-> Select the role--> Select Criteria ( Owners) + Add --> GO till last .....

Then try to submit the request again.

Rajesh    

Former Member
0 Kudos

Hi Ravi,

In the request you have added two entities , one is a system and
another is a role.Since you have just one path for this request , the
request is throwing a no role owner error ( since a system does not
have an owner) .If you simply wish to create a new user and assign a new
role, just assign a role and remove the system entry. If you wish to
keep the system also in the request , you need to have another path for
that line item and that path should not have a role owner stage.

Kindly refer to note 1599245. This note has detailed info on setting
up a customer agent.If you still have doubts let me know .

Best Regards,

Nandita

Former Member
0 Kudos

Hi Nandita,

Thanks for the reply..

We would like to keep the system also along with Role in the request.

As our intention is to Create New user by assigning the requested roles at the end of request through Auto provisioning..(So User details & system is necessary)

If you wish to keep the system also in the request , you need to have another path for
that line item and that path should not have a role owner stage.

Kindly refer to note 1599245. This note has detailed info on setting
up a customer agent.If you still have doubts let me know .

Best Regards,

Nandita

You mean to say do i need to create customized Detour/rerouting path using BRF+lineitem ?

If so, At what stage do i need to Detour it to another path (System path).

Note:- First stage in my workflow is "Role owner"stage , Second stage is "Security stage"

Can a request split at zero stage?

As per my scenario "system" should go to another path and come to "security stage" (This stage will become 1st and last stage for "System" line item..

Role should go to 1st stage "Role owner" next to "Security stage" from their auto provisiong happens for user creation in specified system and roles get assigned.

Is it possible to run 2 different paths parallely and finally joins at a single stage (Security stage)?

Please let me know how shall we go with this..

Regards,

Ravi.

Former Member
0 Kudos

Hi Gurus,

Please share your valuable suggestions to resolve my issue..

Regards,

Ravi.

Former Member
0 Kudos

Please find the Audit log of the above request..