applying scope to a user access to certifications

  • 7011020
  • 17-Jun-2011
  • 01-Nov-2012

Environment

Access Governance

Resolution

Before displaying a cert to a user, the 5.0 UI verifies the user's access (read,write).

The following user conditions give read access (covering the user or any assigned workgroups):
- Owner of a parent cert (if viewing a reassignment)
- Certifier
- Creator
- is in the cert's Scope
- Any of the above for a parent cert (hierarchy view)
- System administrator
- FullAccessCertifications (SPRight to view any cert)

The following user conditions give write access (covering the user or any assigned workgroups):
- Certifier
- Certifier of a parent cert (allows reassignments
   to be completed by the person that reassigned them)

When relating a user to their certs, the user could view their certs from "Inbox", "Outbox", dashboard's "My Certifications", "Manage" -> "Certifications".

The following spots allow a user to see other certs:

- Dashboard: Certification Owner Status
- Dashboard: Certification Owner Status by Group
- Dashboard: Application Certification Status
- Dashboard: Group Certification Status
- Dashboard: Certification Completion Status
- Analyze -> Certifications