Table of Contents

Modules - Recertification [rec]

Role recertification module approves assigned user roles again.

When user has a lot of assigned roles for a long time, we want to check these assigned roles periodicaly (in a half year interval for security reasons), if some assigned role has to be already removed. Currently valid manual direct assigned roles are checked - only manual roles can be assigned and stay assigend, after user is changed some way (e.g. user contract is exluded, work position was changed).

CzechIdM version >= 9.7.0 is required.

Terminology

Recertification types

Recertification type defines, who can approve role recertification request and define request content:

When no approver is found for given request, then recertification is blocked after creation - apporovers have to be configured properly by the recertification type and then recertification action can be executed again.

Future improvements

Read More

Admin guide

Admin tutorial

Devel guide