Attestation Engine About Attestation

Managing Attestation Processes 19-13

19.1.9.4.2 Subject Line The following is the Subject line for e-mail defined by the Notify

Process Owner About Reviewers with No Email Defined template: E-mail address is not defined for some of the reviewers in attestation process Attestation Definition.Process Name, request Attestation Request.Request Id

19.1.9.4.3 Body The following is the body of the message:

The following attestation reviewers do not have e-mail addresses defined. Attestation requests have been generated for these reviewers and can be accessed by logging in to Oracle Identity Manager. However, notification e-mails were not sent. Attestation process: Attestation Definition.Process Name Attestation Request ID: request Attestation Request.Request Id Request date: Attestation Request.Request Creation Date Reviewers Without Email: Attestation Task.Reviewer First Name Attestation Task.Reviewer Last Name [Attestation Task.Reviewer User Id]

19.1.9.4.4 Special Comments Each reviewer detail appears on a new line.

19.2 Attestation Process Configuration

A menu item in Oracle Identity Manager Administrative and User Console provides access to the Attestation Process Configuration pages. Oracle Identity Manager administrators can use these pages to: ■ Define new attestation processes. ■ Manage existing processes. ■ Initiate ad-hoc attestation processes.

19.2.1 Menu Structure

The top-level Attestation menu contains the following links in the Policies section of Oracle Identity Manager Advanced Administration: ■ Create Attestation Process ■ Manage Attestation Process These menu items are governed by the same delegated administration permissions that govern all menu items in the Advanced Administration. These menu items are defined but not assigned to any group in Oracle Identity Manager. They will be assigned to the System Administrators group in Oracle Identity Manager if audit compliance components are installed. Attestation Definition.Process Name Name of the attestation process Attestation Request.Request Creation Date Date when the attestation request was created Attestation Task.Reviewer First Name First name of the reviewer that is invalid Attestation Task.Reviewer Last Name Last name of the reviewer that is invalid Attestation Task.Reviewer User Id User ID of the reviewer that is invalid Variable Description 19-14 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

19.2.2 System Control

Attestation has the following dependencies: ■ The User Profile Audit feature must be enabled. ■ Historical data must be collected at least up to the Process Form level. If the auditing level is set below the required levels, then clicking menu item links related to attestation generates the Attestation Feature Not Available page, and prevents the user from defining any attestation processes. Audit levels are controlled by the system property called XL.UserProfileAuditDataCollection and the attestation feature expects this value to be set to at least Resource Form.

19.3 Creating Attestation Processes

To create an attestation process:

1. In the Welcome page of Oracle Identity Manager Advanced Administration, under

Attestation Configuration list, select Create. The Step1: Define Process page is displayed.

2. Enter values for the fields described in the following table, and then click

Continue :

3. On the Step 2: Define User Scope page:

a. Select an attribute from the Attribute list. The Attribute list displays the user

attributes given in the FormMetaData.xml file and the user-defined attributes from the user form. The attribute that you select is used to specify the criteria that must be met by users on whom the attestation process is applied.

b. From the Condition list, select a condition. The Condition list of values will

change based on the type of attribute selected. For example, if you select User ID in the Attribute field, then the conditions displayed are Contains, Does Not Note: Oracle Identity Manager Permission model applies to the procedure described in this section. This model restricts any list of targets for example, users to only those targets for which the logged-in user has read access. Field Description Name A unique name for the attestation process. The name must be unique across system administrator and deleted attestation processes. Code An identifying code up to 32 characters for the process. The code must be unique across system administrator and deleted attestation processes. Note: A code enhances the identification of the attestation process definition. However, if you do not specify a value in the Code field, then the attestation process is identified by the unique name. Description Detailed description of the attestation process.