Role Base Provisioning

Key Components for Role-Based Provisioning and Portal Access

Our district is implementing a role-based automated provisioning and a personalized portal. Our integrated identity-management platform can manage risk, protect sensitive information assets, and improve business performance. Our identity management initiative  can be used to integrate information portals, providing a sophisticated solution for access management, provisioning, and role management.

Our initiative includes four key components:

  • The provisioning platform (Rapid Identity's Identity Automation) using extracts from McAleer

  • The role management process (HR - Angela Day)

  • The access management platform (Rapid Identity's Identity Automation)

  • The portal  (Rapid Identity's Identity Automation)

Provisioning Platform

Rapid Identity pulls identities from McAleer the(HR system) and facilitates provisioning by automatically creating accounts in Active Directory, Office365, Docushare, and the enterprise locally hosted file system (X-Drive). It is responsible for synchronizing user data between the HR system and target systems where there are changes to user data, such as new-hires, job role changes, or employee termination. When a user is removed from a role and no longer requires access, the provisioning platform automatically deletes the user privileges from the target system.

Rapid Identity maintains a comprehensive, time-stamped audit trail of all user-provisioning activities.

Role Management

The importance of role-based management is a relatively new component of Identity and Access Management (IAM) that is quickly gaining acceptance. Based on 2009 field research, for instance, the Burton Group highlighted the importance of role management, stating that role-based initiatives benefit a business by improving compliance and reducing risk and expenses associated with excessive privileges.

Many organizations are adopting role-management technology to speed the provisioning process. Role management organizes user-access rights based on similar responsibilities across the enterprise. For instance, the district might formalize job codes or responsibilities into particular roles that carry their own specific system-access rights and security levels. As a user's role changes, so do the user's access permissions. The Rapid Identity and role manager will work in tandem to ensure that provisioning events are based on roles.

Access Management

The access management platform allows users of applications or IT systems to log in once and gain access to District resources across the enterprise. This allows the District  to create a centralized and automated single sign-on (SSO) solution for managing who has access to what information across the District.

Portal

Portals provide unified access to enterprise information in a personalized fashion. Portals can leverage the access-management platform to authenticate and authorize users. Once the user is authenticated and authorized, the portal presents an interface that can display only the data and applications that user has access to.