Modifying Approval Policies Oracle Fusion Middleware Online Documentation Library

19-2 Oracle Fusion Middleware Users Guide for Oracle Identity Manager ■ Delegation ■ Attestation Lifecycle Process ■ Attestation Engine ■ Attestation Scheduled Task ■ Attestation-Driven Workflow Capability ■ Attestation E-Mail

19.1.1 Definition of an Attestation Process

An attestation process is the mechanism by which an attestation task is set up. Input that an attestation process requires includes information about how to define the components that constitute the attestation task and how to associate the attestation task with a schedule at which the task must be run. This definition is also the basis on which the attestation task can be initiated when required. An attestation process definition includes: ■ User Scope or Resource Scope : This defines the algorithm by which the target user entitlements of the attestation process are determined. ■ Reviewer Setup : This specifies the reviewer, who attests the entitlements of other users. An attestation process can specify a particular user as the reviewer, or can specify more abstractly how to select the reviewer. For example, the reviewer can be specified as the users manager, as an administrator of the resource, as an authorizer of access to the resource, or as a member of the role that grants the entitlement. ■ Definition of Attestation Schedule : This specifies the schedule for running the attestation process. ■ Process Owner : This is a designated group of users that are responsible for monitoring activities related to the process. – They will be notified of any issues that occur when the process runs. – They will have permissions to view the process definition, but will not have administrative permissions by default. – They will be able to execute the process whenever required. A single attestation process could result in multiple attestation tasks, if that process defines a set of reviewers. In such a case, the process would result in one attestation task for each reviewer in the set.

19.1.1.1 Attestation Process Control

The following sections describe how you can control attestation processes.

19.1.1.1.1 Disabling Processes An attestation process can be disabled by the system

administrator to prevent it from running at its preconfigured schedule. This gives an administrator better control over the environment. A system administrator attestation process can be enabled, but it cannot be enabled if its Next Run Time value is in the past. A user who enables an attestation process must set its next run time in the future.

19.1.1.1.2 Deleting Processes An attestation process can be deleted. This is called a

soft-delete. It does not actually delete the records because the records must be maintained for audit purposes. Instead, the attestation process will be marked as deleted.