on 07-13-2012 11:49 PM
GRC Team:
I am trying to import composite roles but always I got the error message "Composite role relation attribute and authorization do not match", take in account:
1. I have already import all single roles
2. I have already run Authorization sync job
Could you help me? please
Thank you!
Leon
HI Leon,
Please ensure that you are not maintaing Authorizations in 'maintain Authorization' stage while importing the Composite Roles.
Furthermore, please do take care of the following things:
- If you are importing composites you need to have the child roles in the same file so that it properly maps. There is a link between them that is needed otherwise it will error.
- Please be sure you are selecting technical role and not business role in the input screen.
- Also, try loading just one Composite and a child role directly from the back-end system and make the selections in the input screen.
Hope it resolves your issue!
Thanks & Regards,
Shreya Gupta
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
The problem was the template!
Thank you.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Role | associtaed roles | ||
CEC_XXXXXXXXXX_XXX | DE_XXXXXXXX_XXXXXXXX | ||
DE2_XXXXXX_XXXXXX | |||
DE3_XXXXXXXXX_XXXXXXX | |||
CEC2_XXXXXXXXX_XXXXX | DE5_XXXXXXX_XXXXXXXX | ||
DE6_XXXXXXX_XXXXXXX | |||
DE9_XXXXXXXXXXX_XXXXX |
check the example in order to know how to add associated roles to the composite, column X in the template.
regards
Leon
The issue I'm having is similar, but not exactly the same. I, too, am receiving this error message. However, I'm only getting it on my Q system.
I have a set of source files - one for my single roles, and one for my composite roles. I've used these to load roles into my Dev system, and both loaded fine with no errors. Tested etc, 100% good to go.
Same files in the Q system results in 100% success on the single role load file. Testing shows that the role names appear within BRM. The corresponding composite role file results in the above discussed error messages for certain roles, NOT ALL ROLES.
When I examine those roles without the error message, I find them to have been loaded successfully. Composite roles have single roles listed in them.
When I examine those roles WITH the error message, I find them to not have any single role name listed.
I've re-run the authorization sync job and have confirmed that all the roles associated with the composite roles in fact are available in the Q system.
At this point, I'm not sure why these roles are not loading, as I feel certain the data load template files are without any problem.
Thanks,
Santosh
Hi Leon,
This issue mainly occurs because the Single roles associated with composite role are not imported/available in GRC system before importing composite roles and Authorizations are not synchronized for the connector against which roles are imported.
To resolve the issue make sure that all the single roles associated to the composite roles are already imported into GRC box before your try to import the composite roles.
Also make sure that Authorization Sync job is already run and successfully finished for the connector against which you are trying to import the single/composite roles.
Regards
Shaily
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.