Translate

Monday, 22 December 2025

17 Ares Approval Workflow Types Explained Access Request System

 

Comprehensive Guide to IAM Approval Workflow Types

In Identity and Access Management (IAM), an Approval Workflow is the logical set of rules that dictates how an access request is processed. It functions as a security gatekeeper, ensuring that users only receive access to systems or data after the correct authority figures have validated the request.

17 Ares Approval Workflow Types Explained vlrtraining


Below are the 7 core types of approval workflows used to balance security, compliance, and operational efficiency.


Part 1: The Core Approval Types

1. Manager Approval (Standard)

  • Definition: The request is automatically routed to the requester’s direct supervisor (as defined in the HR system).

  • Logic: The manager understands the employee's specific job function and can verify if the access is necessary for their daily tasks.

2. Resource / Data Owner Approval

  • Definition: The request is routed to the individual responsible for the specific application or data set, regardless of who the requester is.

  • Logic: Even if a manager approves, they may not understand the sensitivity of the specific data. The "Owner" (e.g., the CFO for financial data) has the final say on who enters their domain.

3. Serial Approval (Sequential)

  • Definition: A multi-step chain where Approver A must approve before the request moves to Approver B.

  • Logic: Used for high-security access. If anyone in the chain denies the request, the process stops immediately. It ensures a strict hierarchy of review.

4. Parallel Approval

  • Definition: The request is sent to multiple approvers simultaneously.

  • Logic: This is designed for speed. It can be configured as "Consensus" (everyone must approve) or "First Responder" (the first person to approve grants the access).

5. Self-Approval (Auto-Approval)

  • Definition: If the request meets specific low-risk criteria (e.g., "All Marketing employees get Slack"), the system approves it instantly without human intervention.

  • Logic: Reduces "approval fatigue" for managers by automating routine, low-risk requests.


Part 2: The Maintenance & Exception Types

These two workflows ensure business continuity when people are absent or unresponsive.

6. Delegated Approver (Proxy)

  • Definition: A mechanism where a primary approver temporarily assigns their decision-making authority to another user (a proxy) for a specific period (e.g., during a vacation).

  • Logic: This is proactive. It ensures requests do not pile up while a decision-maker is away. The audit logs record that the proxy approved "on behalf of" the primary user.

7. Escalation Approver (Time-out)

  • Definition: A safeguard mechanism that automatically re-routes a request to a different approver if the primary approver fails to respond within a set timeframe (e.g., 48 hours).

  • Logic: This is reactive. It prevents requests from getting stuck in "limbo" due to negligence or unresponsiveness, ensuring Service Level Agreements (SLAs) are met.


Part 3: Real-World Examples

Here are 5 scenarios illustrating how these workflows function in a real business environment.

Scenario 1: The New Hire (Manager Approval)

  • Context: Alice joins the Sales team and requests a license for Salesforce.

  • The Workflow:

    1. The system identifies Bob as Alice's manager.

    2. Bob receives an email: "Alice requested Salesforce. Approve/Deny?"

    3. Bob clicks Approve, and Alice gets access.

  • Why: Low-risk, operational access verified by a supervisor.

Scenario 2: The Audit (Serial/Multi-Level Approval)

  • Context: John, a developer, needs access to the live Production Database to fix a bug.

  • The Workflow:

    1. Step 1: John's Manager approves (confirming John is working on a valid ticket).

    2. Step 2: The Database Owner approves (confirming the DB is not in maintenance).

    3. Step 3: The CISO (Security Chief) approves (final security check).

    4. Access is granted only after all three say yes.

  • Why: High-risk access requires multiple checks to satisfy compliance.

Scenario 3: The Emergency (Parallel Approval)

  • Context: It is Saturday night, and the website is down. Sarah needs Root Access immediately to fix it.

  • The Workflow:

    1. The system sends an urgent notification to three IT Directors at the same time.

    2. Director A is asleep. Director B is busy. Director C sees the alert and clicks Approve.

    3. Access is granted immediately based on the first response.

  • Why: In an emergency, speed is more important than hierarchy.

Scenario 4: The Vacation (Delegated Approver)

  • Context: Mike, the Finance Director, is going on a two-week honeymoon with no internet. He is the only one who can approve Payroll access.

  • The Workflow:

    1. Before leaving, Mike sets a rule: "Delegate my tasks to Susan (Sr. Manager) for 2 weeks."

    2. While Mike is away, a new payroll specialist requests access.

    3. The request routes to Susan. She approves it on Mike's behalf.

  • Why: Ensures business continuity during planned absences.

Scenario 5: The Bottleneck (Escalation Approver)

  • Context: An auditor needs SharePoint access within 3 days. The request sits in Dave's inbox, but Dave is ignoring his emails.

  • The Workflow:

    1. Day 1 & 2: The system reminds Dave, but he doesn't act.

    2. Day 3 (Time-out): The system triggers an Escalation.

    3. The request is removed from Dave’s queue and auto-forwarded to Dave’s Manager.

    4. The Manager sees the alert and approves it.

  • Why: Prevents work from stalling due to one unresponsive employee.


Summary Table

Workflow TypePrimary Trigger/GoalBest Used For...
ManagerHierarchyStandard daily tools (Email, Slack, Zoom).
OwnerAsset SensitivityFinancial data, sensitive folders, cloud resources.
SerialStep-by-Step SecurityPrivileged access (PAM), production environments.
ParallelSpeed / ConsensusEmergencies or committee decisions.
Self/AutoLow RiskBirthright access (access everyone gets).
DelegatedPlanned AbsenceCovering for vacations or medical leave.
EscalationUnresponsivenessEnforcing SLAs and unblocking stuck requests


------------
17 Ares Approval Workflow Types Explained vlrtraining



IAM ఆమోద వర్క్‌ఫ్లో (Approval Workflow) రకాలపై సమగ్ర గైడ్

ఐడెంటిటీ మరియు యాక్సెస్ మేనేజ్‌మెంట్ (IAM) లో, ఆమోద వర్క్‌ఫ్లో (Approval Workflow) అనేది ఒక యాక్సెస్ రిక్వెస్ట్ (Access Request) ఎలా ప్రాసెస్ చేయబడాలో నిర్ణయించే నియమావళి. ఇది ఒక "గేట్‌కీపర్" (కాపలాదారు) లాగా పనిచేస్తుంది. సరైన అధికారులు ధృవీకరించిన తర్వాతే వినియోగదారులకు సిస్టమ్స్ లేదా డేటాకు యాక్సెస్ లభించేలా ఇది చూస్తుంది.

భద్రత, నిబంధనల పాటించటం (Compliance) మరియు పని వేగాన్ని సమతుల్యం చేయడానికి ఉపయోగించే 7 ప్రధాన రకాల ఆమోద వర్క్‌ఫ్లోలు ఇక్కడ ఉన్నాయి.


భాగం 1: ప్రధాన ఆమోద రకాలు (The Core Approval Types)

1. మేనేజర్ ఆమోదం (Manager Approval - Standard)

  • నిర్వచనం: రిక్వెస్ట్ ఆటోమేటిక్‌గా ఉద్యోగి యొక్క డైరెక్ట్ మేనేజర్‌కు (HR సిస్టమ్‌లో ఉన్నట్లుగా) వెళ్తుంది.

  • లాజిక్ (తర్కం): ఉద్యోగి చేసే పని గురించి మేనేజర్‌కు బాగా తెలుసు కాబట్టి, ఆ యాక్సెస్ వారి రోజువారీ పనులకు అవసరమా కాదా అనేది వారే సరిగ్గా నిర్ధారించగలరు.

2. రిసోర్స్ / డేటా ఓనర్ ఆమోదం (Resource / Data Owner Approval)

  • నిర్వచనం: రిక్వెస్ట్ చేసిన వ్యక్తి ఎవరైనప్పటికీ, ఆ రిక్వెస్ట్ నిర్దిష్ట అప్లికేషన్ లేదా డేటాకు బాధ్యత వహించే వ్యక్తికి (ఓనర్‌కు) వెళ్తుంది.

  • లాజిక్: మేనేజర్ ఆమోదించినప్పటికీ, ఆ డేటా ఎంత సున్నితమైనదో వారికి తెలియకపోవచ్చు. ఉదాహరణకు, ఆర్థిక డేటాకు CFO బాధ్యత వహిస్తారు కాబట్టి, ఆ విభాగంలోకి ఎవరిని అనుమతించాలనేది వారే నిర్ణయించాలి.

3. సీరియల్ ఆమోదం (Serial Approval - వరుస క్రమం)

  • నిర్వచనం: ఇది ఒక బహుళ-దశల (Multi-step) గొలుసుకట్టు ప్రక్రియ. ఇందులో అప్రూవర్ A ఆమోదించిన తర్వాతే రిక్వెస్ట్ అప్రూవర్ B కి వెళ్తుంది.

  • లాజిక్: ఇది అధిక భద్రత అవసరమైనప్పుడు వాడతారు. ఈ గొలుసులో ఎవరైనా రిక్వెస్ట్‌ను తిరస్కరిస్తే, ప్రక్రియ అక్కడితో ఆగిపోతుంది. ఇది కచ్చితమైన సోపానక్రమాన్ని (Hierarchy) నిర్ధారిస్తుంది.

4. ప్యారలల్ ఆమోదం (Parallel Approval - సమాంతర)

  • నిర్వచనం: రిక్వెస్ట్ ఒకేసారి బహుళ అప్రూవర్లకు (Multiple Approvers) పంపబడుతుంది.

  • లాజిక్: ఇది వేగం కోసం రూపొందించబడింది. దీనిని "ఏకాభిప్రాయం" (Consensus) - అంటే అందరూ ఆమోదించాలి, లేదా "ఫస్ట్ రెస్పాండర్" (First Responder) - అంటే మొదట ఎవరు ఆమోదిస్తే వారి నిర్ణయం ఫైనల్, అనేలా సెట్ చేయవచ్చు.

5. సెల్ఫ్-అప్రూవల్ (Self/Auto-Approval - స్వయంచాలక)

  • నిర్వచనం: రిక్వెస్ట్ తక్కువ రిస్క్ ఉన్న ప్రమాణాలకు అనుగుణంగా ఉంటే (ఉదాహరణకు: "మార్కెటింగ్ ఉద్యోగులందరికీ Slack యాక్సెస్ ఇవ్వడం"), సిస్టమ్ ఎవరి ప్రమేయం లేకుండా తక్షణమే ఆమోదిస్తుంది.

  • లాజిక్: ఇది చిన్న చిన్న రిక్వెస్ట్‌ల కోసం మేనేజర్ల సమయాన్ని వృథా చేయకుండా, ఆటోమేషన్ ద్వారా పనిని సులభతరం చేస్తుంది.


భాగం 2: మెయింటెనెన్స్ & మినహాయింపు రకాలు (The Maintenance & Exception Types)

మనుషులు అందుబాటులో లేనప్పుడు లేదా స్పందించనప్పుడు బిజినెస్ ఆగకుండా ఈ రెండు వర్క్‌ఫ్లోలు చూస్తాయి.

6. డెలిగేటెడ్ అప్రూవర్ (Delegated Approver - ప్రతినిధి)

  • నిర్వచనం: ప్రధాన అప్రూవర్ ఒక నిర్ణీత కాలానికి (ఉదాహరణకు: సెలవులో ఉన్నప్పుడు) తన నిర్ణయాధికారాన్ని వేరొక వినియోగదారుకు (Proxy) తాత్కాలికంగా అప్పగించే విధానం.

  • లాజిక్: ఇది ముందుచూపుతో (Proactive) చేసే పని. నిర్ణయం తీసుకునే వ్యక్తి లేనప్పుడు రిక్వెస్ట్‌లు పెండింగ్‌లో పడిపోకుండా ఇది చూస్తుంది. ప్రధాన వ్యక్తి తరపున "ప్రతినిధి" ఆమోదించినట్లుగా ఆడిట్ లాగ్స్‌లో రికార్డ్ అవుతుంది.

7. ఎస్కలేషన్ అప్రూవర్ (Escalation Approver - టైమ్ లిమిట్ దాటినప్పుడు)

  • నిర్వచనం: ప్రధాన అప్రూవర్ నిర్ణీత సమయంలో (ఉదాహరణకు: 48 గంటలు) స్పందించకపోతే, రిక్వెస్ట్‌ను ఆటోమేటిక్‌గా వేరే అప్రూవర్‌కు మళ్లించే రక్షణ విధానం.

  • లాజిక్: ఇది రియాక్టివ్ (Reactive) విధానం. నిర్లక్ష్యం వల్ల లేదా స్పందించకపోవడం వల్ల రిక్వెస్ట్‌లు మధ్యలో ఆగిపోకుండా (Limbo), SLA (సర్వీస్ లెవెల్ అగ్రిమెంట్) ప్రకారం పని జరిగేలా ఇది చూస్తుంది.


భాగం 3: వాస్తవ ప్రపంచ ఉదాహరణలు (Real-World Examples)

వ్యాపార వాతావరణంలో ఈ వర్క్‌ఫ్లోలు ఎలా పనిచేస్తాయో చెప్పడానికి ఇక్కడ 5 ఉదాహరణలు ఉన్నాయి.

సందర్భం 1: కొత్త ఉద్యోగి (మేనేజర్ ఆమోదం)

  • కథ: ఆలిస్ (Alice) సేల్స్ టీమ్‌లో చేరింది. ఆమె Salesforce లైసెన్స్ కోసం రిక్వెస్ట్ చేసింది.

  • వర్క్‌ఫ్లో:

    1. సిస్టమ్ బాబ్‌ (Bob)ను ఆలిస్ మేనేజర్‌గా గుర్తిస్తుంది.

    2. బాబ్‌కు ఈమెయిల్ వెళ్తుంది: "ఆలిస్ Salesforce అడుగుతోంది. ఆమోదించాలా/తిరస్కరించాలా?"

    3. బాబ్ Approve క్లిక్ చేస్తాడు, ఆలిస్‌కు యాక్సెస్ లభిస్తుంది.

  • ఎందుకు: ఇది తక్కువ రిస్క్ ఉన్న ఆపరేషనల్ యాక్సెస్, మేనేజర్ సరిచూస్తే సరిపోతుంది.

సందర్భం 2: ఆడిట్ (సీరియల్/మల్టీ-లెవల్ ఆమోదం)

  • కథ: జాన్ అనే డెవలపర్ ఒక బగ్‌ను సరిచేయడానికి లైవ్ ప్రొడక్షన్ డేటాబేస్ (Production Database) యాక్సెస్ కావాలి.

  • వర్క్‌ఫ్లో:

    1. దశ 1: జాన్ యొక్క మేనేజర్ ఆమోదిస్తాడు (జాన్ నిజంగా పని మీదే ఉన్నాడని నిర్ధారిస్తాడు).

    2. దశ 2: డేటాబేస్ ఓనర్ ఆమోదిస్తాడు (ప్రస్తుతం డేటాబేస్ మెయింటెనెన్స్‌లో లేదని నిర్ధారిస్తాడు).

    3. దశ 3: CISO (సెక్యూరిటీ చీఫ్) ఆమోదిస్తారు (చివరి భద్రతా తనిఖీ).

    4. ముగ్గురూ ఒప్పుకున్న తర్వాతే యాక్సెస్ లభిస్తుంది.

  • ఎందుకు: హై-రిస్క్ యాక్సెస్ కాబట్టి నిబంధనల ప్రకారం (Compliance) బహుళ తనిఖీలు అవసరం.

సందర్భం 3: అత్యవసర పరిస్థితి (ప్యారలల్ ఆమోదం)

  • కథ: శనివారం రాత్రి, వెబ్‌సైట్ డౌన్ అయ్యింది. దాన్ని సరిచేయడానికి సారా (Sarah)కు వెంటనే Root Access కావాలి.

  • వర్క్‌ఫ్లో:

    1. సిస్టమ్ ఒకేసారి ముగ్గురు IT డైరెక్టర్లకు అత్యవసర నోటిఫికేషన్ పంపుతుంది.

    2. డైరెక్టర్ A నిద్రపోతున్నారు. డైరెక్టర్ B బిజీగా ఉన్నారు. డైరెక్టర్ C అలర్ట్ చూసి వెంటనే Approve క్లిక్ చేశారు.

    3. మొదటి స్పందన ఆధారంగా వెంటనే యాక్సెస్ ఇవ్వబడుతుంది.

  • ఎందుకు: ఎమర్జెన్సీలో సోపానక్రమం (Hierarchy) కంటే వేగం ముఖ్యం.

సందర్భం 4: సెలవు (డెలిగేటెడ్ అప్రూవర్)

  • కథ: ఫైనాన్స్ డైరెక్టర్ మైక్, ఇంటర్నెట్ లేని చోటికి రెండు వారాలు హనీమూన్‌కు వెళ్తున్నాడు. పేరోల్ (Payroll) యాక్సెస్ ఆమోదించేది అతను ఒక్కడే.

  • వర్క్‌ఫ్లో:

    1. వెళ్ళే ముందు, మైక్ ఒక రూల్ సెట్ చేస్తాడు: "2 వారాల పాటు నా పనులను సూజన్ (సీనియర్ మేనేజర్)కు అప్పగిస్తున్నాను (Delegate)."

    2. మైక్ లేనప్పుడు, ఒక కొత్త పేరోల్ స్పెషలిస్ట్ యాక్సెస్ కోసం రిక్వెస్ట్ చేస్తాడు.

    3. ఆ రిక్వెస్ట్ సూజన్‌ దగ్గరకు వెళ్తుంది. ఆమె మైక్ తరపున ఆమోదిస్తుంది.

  • ఎందుకు: ముందుగా ప్లాన్ చేసుకున్న సెలవుల సమయంలో బిజినెస్ ఆగిపోకుండా ఉంటుంది.

సందర్భం 5: అడ్డంకులు (ఎస్కలేషన్ అప్రూవర్)

  • కథ: ఒక ఆడిటర్‌కు 3 రోజుల్లో SharePoint యాక్సెస్ కావాలి. రిక్వెస్ట్ డేవ్ (Dave) ఇన్‌బాక్స్‌లో ఉంది, కానీ డేవ్ తన ఈమెయిల్స్ చూడటం లేదు.

  • వర్క్‌ఫ్లో:

    1. డే 1 & 2: సిస్టమ్ డేవ్ కు రిమైండర్ పంపుతుంది, కానీ అతను స్పందించడు.

    2. డే 3 (టైమ్-అవుట్): సిస్టమ్ ఎస్కలేషన్ (Escalation) ను ట్రిగ్గర్ చేస్తుంది.

    3. రిక్వెస్ట్ డేవ్ నుంచి తీసివేయబడి, ఆటోమేటిక్‌గా డేవ్ మేనేజర్‌కి ఫార్వార్డ్ చేయబడుతుంది.

    4. మేనేజర్ అలర్ట్ చూసి ఆమోదిస్తారు.

  • ఎందుకు: ఒక ఉద్యోగి స్పందించనంత మాత్రాన పని నిలిచిపోకుండా ఇది చూస్తుంది.


సారాంశం (Summary Table)

వర్క్‌ఫ్లో రకంప్రధాన ట్రిగ్గర్/లక్ష్యంఎప్పుడు ఉపయోగిస్తారు?
మేనేజర్సోపానక్రమం (Hierarchy)సాధారణ రోజువారీ టూల్స్ (Email, Slack, Zoom).
ఓనర్ఆస్తి సున్నితత్వంఫైనాన్షియల్ డేటా, సున్నితమైన ఫోల్డర్లు, క్లౌడ్ రిసోర్సెస్.
సీరియల్దశలవారీ భద్రతప్రివిలేజ్డ్ యాక్సెస్ (PAM), ప్రొడక్షన్ ఎన్విరాన్‌మెంట్స్.
ప్యారలల్వేగం / ఏకాభిప్రాయంఎమర్జెన్సీలు లేదా కమిటీ నిర్ణయాలు.
సెల్ఫ్/ఆటోతక్కువ రిస్క్బర్త్‌రైట్ యాక్సెస్ (అందరికీ వచ్చే సాధారణ యాక్సెస్).
డెలిగేటెడ్ముందుగా ప్లాన్ చేసిన గైర్హాజరుసెలవులు లేదా మెడికల్ లీవ్ ఉన్నప్పుడు కవర్ చేయడానికి.
ఎస్కలేషన్స్పందించకపోవడంSLAలను అమలు చేయడానికి మరియు ఆగిపోయిన రిక్వెస్ట్‌లను కదిలించడానికి.

16 what is ARES, Access Request System Workflow Options

 An Access Request System (ARES) is a critical component of Identity and Access Management (IAM). It serves as the "storefront" or self-service portal where employees can request access to applications, data, or system permissions that they do not have by default.

It replaces the old method of emailing IT support ("Hey, can you give me access to this folder?") with a structured, secure, and often automated workflow.

Here is a detailed breakdown of how it works and three concrete examples.

16 what is ARES, Access Request System Workflow Options vlr training



1. How ARES Works (The Workflow)

ARES is designed to balance security (ensuring only the right people get access) with speed (getting users working quickly).

A. The Catalog (The "Menu")

Just like an e-commerce site, ARES presents a catalog of available resources.

  • Searchable: Users can search for "Adobe Creative Cloud," "Salesforce," or "Finance Shared Drive."

  • Roles & Entitlements: Users can request coarse access (e.g., "Access to Salesforce") or fine-grained entitlements (e.g., "Administrator rights in Salesforce").

B. The Approval Chain (The "Gatekeepers")

Once a request is submitted, ARES determines who needs to say "yes" based on pre-set policies.

  • Manager Approval: Usually the first step. The manager confirms, "Yes, my employee needs this for their job."

  • Resource Owner: The person responsible for the tool (e.g., the Director of Sales for Salesforce access) approves to ensure data security.

  • SoD (Segregation of Duties) Check: The system automatically checks for conflicts. (e.g., "If this user already has permission to create a vendor, they cannot request permission to pay a vendor.")

C. Provisioning (The "Delivery")

  • Automated: If the system is integrated (e.g., with Active Directory or Okta), access is granted instantly after approval.

  • Manual: If the target system is old (legacy), ARES creates a "ticket" for an IT administrator to manually add the user.


2. Three Real-World Examples

Here are three common scenarios illustrating how ARES handles different types of requests.

Example 1: The "Cost-Control" Request (Software Licenses)

  • Scenario: John, a marketing intern, needs Microsoft Visio to create flowcharts. Visio licenses are expensive, so the company doesn't give them to everyone.

  • The ARES Process:

    1. John searches ARES for "Visio" and submits a request.

    2. Approval 1: John's Manager approves (confirming John is working on a project that requires it).

    3. Approval 2: The IT Asset Manager approves (confirming they have a spare license available in the budget).

    4. Action: The system automatically assigns a license to John's Office 365 account.

  • Benefit: Prevents the company from paying for expensive software that employees don't actually need.

Example 2: The "High-Security" Request (Privileged Access)

  • Scenario: Sarah, a backend developer, needs access to the Production Database to fix a critical bug. This is highly sensitive data.

  • The ARES Process:

    1. Sarah requests "Prod DB Read/Write Access" in ARES.

    2. Policy Check: ARES forces Sarah to input a valid "Incident Ticket Number" to prove there is a real bug.

    3. Approval: The Director of Engineering approves.

    4. Time-Bound Action: Access is granted only for 4 hours. After 4 hours, ARES automatically revokes the access.

  • Benefit: Enforces "Least Privilege" and prevents permanent access to dangerous systems.

Example 3: The "Data Compliance" Request (GDPR/HIPAA)

  • Scenario: Mike, a data scientist, requests access to a folder containing Customer Personal Data (PII) for analysis.

  • The ARES Process:

    1. Mike requests access to the "Raw Customer Data" folder.

    2. Approval: The Data Privacy Officer (DPO) receives the request.

    3. Review: The DPO sees Mike's justification but realizes Mike only needs anonymized data, not raw names and addresses.

    4. Rejection/Adjustment: The DPO rejects the request and guides Mike to request the "Anonymized Data Set" instead.

  • Benefit: Protects the company from lawsuits and fines by ensuring sensitive data is not exposed unnecessarily.

Summary

ComponentFunction
RequestUser asks for access via a portal.
JustificationUser explains why (Business Case).
ApprovalManagers/Owners vet the request.
ProvisioningSystem grants access (Auto/Manual).
AuditSystem records the entire chain for compliance.







IAMలో యాక్సెస్ రిక్వెస్ట్ సిస్టమ్ (ARES) అంటే ఏమిటి?

యాక్సెస్ రిక్వెస్ట్ సిస్టమ్ (ARES) అనేది ఐడెంటిటీ అండ్ యాక్సెస్ మేనేజ్‌మెంట్ (IAM)లో ఒక కీలకమైన భాగం. ఇది ఒక "స్టోర్ ఫ్రంట్" (దుకాణం) లేదా సెల్ఫ్-సర్వీస్ పోర్టల్ లాంటిది. ఉద్యోగులకు డిఫాల్ట్‌గా (సాధారణంగా) రాని అప్లికేషన్‌లు, డేటా లేదా సిస్టమ్ అనుమతులు కావాల్సి వచ్చినప్పుడు, వారు ఇక్కడ అభ్యర్థించవచ్చు.

16 what is ARES, Access Request System Workflow Options in telugu vlrtraining


ఇది ఐటీ సపోర్ట్‌కు మెయిల్స్ పంపే పాత పద్ధతిని ("హలో, నాకు ఈ ఫోల్డర్ యాక్సెస్ ఇవ్వగలరా?") తొలగించి, ఒక నిర్మాణాత్మకమైన, సురక్షితమైన మరియు ఆటోమేటిక్ పద్ధతిని అమలు చేస్తుంది.

ఇది ఎలా పనిచేస్తుందో మరియు మూడు ముఖ్యమైన ఉదాహరణలను కింద వివరంగా చూడండి.


1. ARES ఎలా పనిచేస్తుంది? (వర్క్‌ఫ్లో)

ARES ప్రధాన ఉద్దేశ్యం భద్రత (సరైన వ్యక్తులకు మాత్రమే యాక్సెస్ ఇవ్వడం) మరియు వేగం (ఉద్యోగులు త్వరగా పని మొదలుపెట్టేలా చూడటం) మధ్య సమతుల్యతను పాటించడం.

A. కేటలాగ్ ("మెనూ" లాంటిది)

ఒక ఈ-కామర్స్ సైట్ లాగానే, ARES అందుబాటులో ఉన్న వనరుల జాబితాను (Catalog) చూపిస్తుంది.

  • వెతకవచ్చు (Searchable): వినియోగదారులు "Adobe Creative Cloud," "Salesforce," లేదా "Finance Shared Drive" అని సెర్చ్ చేయవచ్చు.

  • పాత్రలు & అర్హతలు (Roles & Entitlements): వినియోగదారులు సాధారణ యాక్సెస్ (ఉదా: "Salesforce యాక్సెస్") లేదా లోతైన అధికారాలు (ఉదా: "Salesforceలో అడ్మినిస్ట్రేటర్ హక్కులు") అడగవచ్చు.

B. ఆమోదించే విధానం ("గేట్‌కీపర్లు")

ఒక అభ్యర్థన (request) వచ్చిన తర్వాత, ముందుగా నిర్ణయించిన పాలసీల ఆధారంగా ఎవరెవరు "సరే" (Yes) చెప్పాలో ARES నిర్ణయిస్తుంది.

  • మేనేజర్ ఆమోదం: సాధారణంగా ఇది మొదటి దశ. "అవును, నా ఉద్యోగికి తన పని కోసం ఇది అవసరం," అని మేనేజర్ నిర్ధారిస్తారు.

  • రిసోర్స్ ఓనర్ (వనరుల యజమాని): ఆ టూల్ లేదా సాఫ్ట్‌వేర్‌కు బాధ్యత వహించే వ్యక్తి (ఉదా: సేల్స్‌ఫోర్స్ కోసం సేల్స్ డైరెక్టర్) డేటా భద్రత కోసం ఆమోదం తెలుపుతారు.

  • SoD (Segregation of Duties) చెక్: సిస్టమ్ ఆటోమేటిక్‌గా విధుల్లో వైరుధ్యం ఉందేమో తనిఖీ చేస్తుంది. (ఉదాహరణకు: "ఒక వినియోగదారుడికి వెండార్‌ను (vendor) సృష్టించే అనుమతి ఉంటే, అతనికి వెండార్‌కి డబ్బు చెల్లించే అనుమతి ఇవ్వకూడదు").

C. ప్రొవిజనింగ్ ("డెలివరీ" లేదా యాక్సెస్ ఇవ్వడం)

  • ఆటోమేటెడ్: సిస్టమ్ గనక Active Directory లేదా Oktaతో అనుసంధానించబడి ఉంటే, ఆమోదం రాగానే తక్షణమే యాక్సెస్ లభిస్తుంది.

  • మాన్యువల్: టార్గెట్ సిస్టమ్ పాతది (legacy) అయితే, ARES ఒక ఐటీ అడ్మినిస్ట్రేటర్‌కు "టికెట్" సృష్టిస్తుంది, వారు మనుషుల ద్వారా (manually) వినియోగదారుని యాడ్ చేస్తారు.


2. మూడు వాస్తవ ప్రపంచ ఉదాహరణలు

విభిన్న రకాల అభ్యర్థనలను ARES ఎలా నిర్వహిస్తుందో అర్థం చేసుకోవడానికి ఇక్కడ మూడు ఉదాహరణలు ఉన్నాయి.

ఉదాహరణ 1: "ఖర్చు-నియంత్రణ" అభ్యర్థన (సాఫ్ట్‌వేర్ లైసెన్స్‌లు)

  • సందర్భం: జాన్ అనే మార్కెటింగ్ ఇంటర్న్‌కు ఫ్లోచార్ట్‌లు గీయడానికి Microsoft Visio అవసరమైంది. Visio లైసెన్స్‌లు ఖరీదైనవి, కాబట్టి కంపెనీ అందరికీ ఇవ్వదు.

  • ARES ప్రక్రియ:

    1. జాన్ ARESలో "Visio" కోసం వెతికి, అభ్యర్థన పెడతాడు.

    2. ఆమోదం 1: జాన్ మేనేజర్ ఆమోదిస్తారు (జాన్ ప్రాజెక్ట్‌కు అది అవసరమని నిర్ధారిస్తూ).

    3. ఆమోదం 2: ఐటీ అసెట్ మేనేజర్ ఆమోదిస్తారు (బడ్జెట్‌లో స్పేర్ లైసెన్స్ ఉందని నిర్ధారిస్తూ).

    4. చర్య: సిస్టమ్ ఆటోమేటిక్‌గా జాన్ Office 365 ఖాతాకు లైసెన్స్‌ను కేటాయిస్తుంది.

  • ప్రయోజనం: ఉద్యోగులకు నిజంగా అవసరం లేని ఖరీదైన సాఫ్ట్‌వేర్‌ల కోసం కంపెనీ డబ్బు ఖర్చు చేయకుండా ఆపుతుంది.

ఉదాహరణ 2: "అధిక-భద్రత" అభ్యర్థన (ప్రివిలేజ్డ్ యాక్సెస్)

  • సందర్భం: సారా అనే బ్యాకెండ్ డెవలపర్‌కు ఒక క్లిష్టమైన బగ్‌ను (bug) సరిచేయడానికి ప్రొడక్షన్ డేటాబేస్ (Production Database) యాక్సెస్ అవసరమైంది. ఇది చాలా సున్నితమైన డేటా.

  • ARES ప్రక్రియ:

    1. సారా ARESలో "Prod DB Read/Write Access" కోరుతుంది.

    2. పాలసీ చెక్: నిజంగా బగ్ ఉందని నిరూపించడానికి "ఇన్సిడెంట్ టికెట్ నంబర్" నమోదు చేయమని ARES సారాను అడుగుతుంది.

    3. ఆమోదం: డైరెక్టర్ ఆఫ్ ఇంజనీరింగ్ ఆమోదిస్తారు.

    4. సమయ పరిమితితో కూడిన చర్య: యాక్సెస్ కేవలం 4 గంటలు మాత్రమే ఇవ్వబడుతుంది. 4 గంటల తర్వాత, ARES ఆటోమేటిక్‌గా యాక్సెస్‌ను రద్దు చేస్తుంది.

  • ప్రయోజనం: ఇది "లీస్ట్ ప్రివిలేజ్" (అత్యల్ప అధికార) సూత్రాన్ని అమలు చేస్తుంది మరియు ప్రమాదకరమైన సిస్టమ్‌లకు శాశ్వత యాక్సెస్‌ను నివారిస్తుంది.

ఉదాహరణ 3: "డేటా నిబంధనల" అభ్యర్థన (GDPR/HIPAA)

  • సందర్భం: మైక్ అనే డేటా సైంటిస్ట్ విశ్లేషణ కోసం కస్టమర్ వ్యక్తిగత డేటా (PII) ఉన్న ఫోల్డర్‌కు యాక్సెస్ కోరతాడు.

  • ARES ప్రక్రియ:

    1. మైక్ "Raw Customer Data" (ముడి డేటా) ఫోల్డర్ కోసం అభ్యర్థిస్తాడు.

    2. ఆమోదం: డేటా ప్రైవసీ ఆఫీసర్ (DPO)కి అభ్యర్థన వెళ్తుంది.

    3. సమీక్ష: DPO మైక్ వివరణ చూసి, మైక్‌కు కేవలం అనానిమైజ్డ్ (పేర్లు లేని) డేటా సరిపోతుందని, ముడి డేటా అవసరం లేదని గుర్తిస్తారు.

    4. తిరస్కరణ/సవరణ: DPO ఆ అభ్యర్థనను తిరస్కరించి, బదులుగా "Anonymized Data Set" కోసం అభ్యర్థించమని మైక్‌కు సూచిస్తారు.

  • ప్రయోజనం: సున్నితమైన డేటా అనవసరంగా బహిర్గతం కాకుండా చూడటం ద్వారా కంపెనీని చట్టపరమైన చిక్కులు మరియు జరిమానాల నుండి కాపాడుతుంది.

సారాంశం

అంశం (Component)పనితీరు (Function)
అభ్యర్థన (Request)వినియోగదారు పోర్టల్ ద్వారా యాక్సెస్ అడుగుతారు.
జస్టిఫికేషన్ (Justification)వినియోగదారు ఎందుకు కావాలో వివరిస్తారు (Business Case).
ఆమోదం (Approval)మేనేజర్లు/ఓనర్లు అభ్యర్థనను పరిశీలిస్తారు.
ప్రొవిజనింగ్ (Provisioning)సిస్టమ్ యాక్సెస్ ఇస్తుంది (ఆటోమేటిక్/మాన్యువల్).
ఆడిట్ (Audit)నిబంధనల కోసం సిస్టమ్ ప్రతి దశను రికార్డ్ చేస్తుంది.

15 Defining Roles and Entitlements

 Here is a detailed explanation of Roles and Entitlements in Identity and Access Management (IAM), broken down by concept, how they relate, and practical examples.

15 Defining Roles and Entitlements vlr training



The Big Picture

In IAM, the goal is to answer the question: "Who has access to what?"

  • Roles answer "Who is this person in the organization?" (e.g., A Manager).

  • Entitlements answer "What exactly can they touch?" (e.g., Can open the safe).


1. What is a Role?

A Role is a collection of permissions associated with a specific job function, title, or responsibility within an organization. Instead of giving permission to every single user individually, you give permissions to a "Role" and then assign users to that role.

This concept is the foundation of RBAC (Role-Based Access Control).

  • The Container Concept: Think of a Role as a "Bucket" or a "Backpack." You fill the backpack with keys (permissions). Anyone who puts on that backpack gets to use those keys.

  • Types of Roles:

    • Business Role: Matches a job title (e.g., "HR Manager", "Junior Developer").

    • IT/System Role: Matches a specific system level (e.g., "Unix Admin", "Database Superuser").

Example:

Imagine a bank.

  • Role: Bank Teller

  • Role: Branch Manager

You don't assign "Cash Drawer Access" to John, Mary, and Steve individually. You assign it to the Bank Teller role. If John moves to the Marketing department, you simply remove the Bank Teller role, and he loses all those keys instantly.


2. What is an Entitlement?

An Entitlement is the specific right or privilege granted to a user (often through a role) to access a specific resource. It is the fine-grained permission that dictates exactly what a user can do inside an application or system.

Entitlements answer the specific questions of capability: Read, Write, Execute, Approve, Delete.

  • Granularity: Entitlements can be high-level (Account on System X) or very deep (Read-only access to Column B in Database Y).

  • The "Ticket": If the Role is the "VIP Pass," the Entitlements are the specific things you can do with it (e.g., "Access the buffet," "Sit in the front row," "Meet the band").

Examples of Entitlements:

  • Active Directory: Membership in the "VPN Users" group.

  • Salesforce: Ability to "Edit" customer records.

  • AWS: Ability to "Reboot" a specific server instance.

  • Physical Security: Badge access to the "Server Room."


3. How They Work Together (The Hierarchy)

The relationship usually flows like this:

User  assigned to $\rightarrow$ Role $\rightarrow$ contains $\rightarrow$ Entitlements

  1. The User (Alice) is hired.

  2. The Role (Sales Manager) is assigned to Alice.

  3. The Entitlements (Access to CRM, Email, and Shared Drive) are automatically granted to Alice because they are inside the Role.


4. Detailed Real-World Example: A Hospital

Let's look at how Roles and Entitlements function in a hospital setting to protect patient data.

Scene A: The Nurse

  • User: Sarah

  • Role: Registered Nurse

  • Entitlements (What the role gives her):

    • System: Patient Records $\rightarrow$ View Patient History.

    • System: Medication Dispenser $\rightarrow$ Dispense Prescribed Drugs.

    • System: Shift Scheduler $\rightarrow$ View Own Schedule.

    • Restriction: She does not have the entitlement to "Prescribe Medication" (only doctors do).

Scene B: The Doctor

  • User: Dr. Rao

  • Role: Cardiologist

  • Entitlements:

    • System: Patient Records $\rightarrow$ View & Edit Patient History.

    • System: Pharmacy System $\rightarrow$ Create New Prescription.

    • System: Lab Results $\rightarrow$ Order Blood Tests.

Scene C: The IT Admin (Changes)

If Sarah (The Nurse) transfers to the IT department to work on the hospital website:

  1. The IAM system removes the Registered Nurse role.

  2. Result: She immediately loses entitlements to the Patient Records and Medication Dispenser.

  3. The IAM system assigns the Web Developer role.

  4. Result: She gains new entitlements to the Web Server and Code Repository.


5. Why separate them? (The Benefits)

FeatureWithout Roles (Direct Entitlements)With Roles (RBAC)
New Hire SetupSlow. You must manually tick 50 boxes for every new employee.Fast. You just select "Role: Marketing" and they get all 50 permissions instantly.
TransfersDangerous. IT often forgets to remove old permissions, leading to "Privilege Creep."Safe. Swapping the role automatically swaps the entitlements.
AuditingHard. "Why does John have access to the Finance Server?" (No one remembers).Easy. "John has access because he holds the 'Accountant' role."

Summary

  • Roles are the Job Descriptions (The Who).

  • Entitlements are the Keys/Permissions (The What).

You define the specific keys (Entitlements) needed for a job, put them on a key ring (Role), and hand that key ring to the employee (User).



ఐడెంటిటీ అండ్ యాక్సెస్ మేనేజ్‌మెంట్ (IAM)లో రోల్స్ (Roles) మరియు ఎన్‌టైటిల్మెంట్‌లు (Entitlements) గురించి వివరణాత్మక సమాచారం కింద ఇవ్వబడింది. ప్రతి కాన్సెప్ట్ అర్థం కావడానికి ఉదాహరణలతో సహా వివరించాను.

15 Defining Roles and Entitlements vlr training telugu



ముఖ్య ఉద్దేశ్యం (The Big Picture)

IAMలో మన ప్రధాన లక్ష్యం ఒక ప్రశ్నకు సమాధానం ఇవ్వడం: "ఎవరికి దేనిపై యాక్సెస్ (Access) ఉంది?"

  • రోల్స్ (Roles): ఇది "సంస్థలో ఈ వ్యక్తి ఎవరు?" అని చెబుతుంది (ఉదాహరణకు: మేనేజర్).

  • ఎన్‌టైటిల్మెంట్‌లు (Entitlements): ఇది "వారు ఖచ్చితంగా దేనిని వాడగలరు లేదా ముట్టుకోగలరు?" అని చెబుతుంది (ఉదాహరణకు: లాకర్‌ను తెరిచే హక్కు).


1. రోల్ (Role) అంటే ఏమిటి?

రోల్ అనేది ఒక సంస్థలోని ఒక ఉద్యోగానికి లేదా బాధ్యతకు సంబంధించిన అనుమతుల (Permissions) సమూహం. ప్రతి యూజర్‌కు విడివిడిగా అనుమతులు ఇచ్చే బదులు, మనం ఒక "రోల్"‌ను సృష్టించి, ఆ రోల్‌ను యూజర్‌కు ఇస్తాం.

ఇది RBAC (Role-Based Access Control) అనే విధానానికి పునాది.

  • కంటైనర్ కాన్సెప్ట్ (Container Concept): రోల్‌ని ఒక "బ్యాగు" (Backpack) లాగా ఊహించుకోండి. ఆ బ్యాగులో ఆఫీసు తాళాలు (Permissions) ఉంటాయి. ఎవరైతే ఆ బ్యాగును వేసుకుంటారో, వారికే ఆ తాళాలు వాడుకునే అర్హత వస్తుంది.

  • రోల్స్ రకాలు:

    • బిజినెస్ రోల్: ఉద్యోగ పేరును బట్టి ఉంటుంది (ఉదా: "HR మేనేజర్", "జూనియర్ డెవలపర్").

    • సిస్టమ్ రోల్: టెక్నికల్ స్థాయిని బట్టి ఉంటుంది (ఉదా: "Unix అడ్మిన్", "డేటాబేస్ సూపర్ యూజర్").

ఉదాహరణ:

ఒక బ్యాంకును ఊహించుకోండి.

  • రోల్: బ్యాంక్ టెల్లర్ (Cashier)

  • రోల్: బ్రాంచ్ మేనేజర్

మీరు జాన్, మేరీ, స్టీవ్ అనే ముగ్గురికీ విడివిడిగా "డబ్బు డ్రాయర్ తెరిచే పర్మిషన్" ఇవ్వరు. బదులుగా, ఆ పర్మిషన్‌ను బ్యాంక్ టెల్లర్ అనే రోల్‌కి ఇస్తారు. ఒకవేళ జాన్ మార్కెటింగ్ విభాగానికి మారితే, అతని నుండి బ్యాంక్ టెల్లర్ రోల్ తీసేస్తే చాలు, ఆ పర్మిషన్లన్నీ ఒకేసారి పోతాయి.


2. ఎన్‌టైటిల్మెంట్‌ (Entitlement) అంటే ఏమిటి?

ఎన్‌టైటిల్మెంట్‌ అనేది ఒక యూజర్‌కు (సాధారణంగా రోల్ ద్వారా) ఒక నిర్దిష్ట వనరును (Resource) వాడుకోవడానికి లభించే ప్రత్యేక హక్కు. ఒక అప్లికేషన్ లోపల యూజర్ ఖచ్చితంగా ఏం చేయగలరో ఇది నిర్ణయిస్తుంది.

ఇది సూక్ష్మమైన వివరాలను చెబుతుంది: చదవగలరా (Read), రాయగలరా (Write), డిలీట్ చేయగలరా (Delete), ఆమోదించగలరా (Approve)?

  • టికెట్ ఉదాహరణ: రోల్ అనేది "VIP పాస్" అయితే, ఎన్‌టైటిల్మెంట్‌లు అనేవి ఆ పాస్‌తో మీరు లోపల ఏం చేయగలరు అనేవి (ఉదాహరణకు: "బఫే తినడం", "ముందు వరుసలో కూర్చోవడం", "ఫోటోలు దిగడం").

ఎన్‌టైటిల్మెంట్‌లకు ఉదాహరణలు:

  • Active Directory: "VPN Users" అనే గ్రూపులో మెంబర్‌షిప్ ఉండటం.

  • Salesforce: కస్టమర్ రికార్డులను "ఎడిట్ (Edit)" చేసే హక్కు.

  • AWS: ఒక సర్వర్‌ను "రీబూట్ (Reboot)" చేసే శక్తి.

  • Physical Security: సర్వర్ గదిలోకి వెళ్ళడానికి "బ్యాడ్జ్ యాక్సెస్".


3. ఇవి రెండూ కలిసి ఎలా పనిచేస్తాయి? (The Hierarchy)

సాధారణంగా ప్రక్రియ ఇలా ఉంటుంది:

యూజర్ (User) $\rightarrow$ అసైన్ చేయబడతారు $\rightarrow$ రోల్ (Role) $\rightarrow$ కలిగి ఉంటుంది $\rightarrow$ ఎన్‌టైటిల్మెంట్‌లు (Entitlements)

  1. యూజర్ (ఆలిస్) ఉద్యోగంలో చేరారు.

  2. ఆమెకు రోల్ (సేల్స్ మేనేజర్) ఇవ్వబడింది.

  3. ఆ రోల్ లోపల ఉన్న ఎన్‌టైటిల్మెంట్‌లు (CRM యాక్సెస్, ఈమెయిల్, షేర్డ్ డ్రైవ్) ఆమెకు ఆటోమేటిక్‌గా వస్తాయి.


4. వాస్తవ ప్రపంచ ఉదాహరణ: ఆసుపత్రి (Hospital)

పేషెంట్ డేటాను రక్షించడానికి ఆసుపత్రిలో ఇవి ఎలా పనిచేస్తాయో చూద్దాం.

దృశ్యం A: నర్సు (Nurse)

  • యూజర్: సారా (Sarah)

  • రోల్: రిజిస్టర్డ్ నర్సు

  • ఎన్‌టైటిల్మెంట్‌లు (ఆమె ఏం చేయగలదు):

    • సిస్టమ్: పేషెంట్ రికార్డులు $\rightarrow$ హిస్టరీని చూడగలదు (View).

    • సిస్టమ్: మందుల గది $\rightarrow$ మందులు ఇవ్వగలదు (Dispense).

    • సిస్టమ్: షిఫ్ట్ ప్లానింగ్ $\rightarrow$ తన షెడ్యూల్ చూడగలదు.

    • పరిమితి: ఆమెకు మందులు "ప్రెస్క్రైబ్ (Prescribe - మందులు రాయడం)" చేసే ఎన్‌టైటిల్మెంట్‌ లేదు (అది డాక్టర్లకు మాత్రమే ఉంటుంది).

దృశ్యం B: డాక్టర్ (Doctor)

  • యూజర్: డాక్టర్ రావు

  • రోల్: కార్డియాలజిస్ట్ (గుండె డాక్టర్)

  • ఎన్‌టైటిల్మెంట్‌లు:

    • సిస్టమ్: పేషెంట్ రికార్డులు $\rightarrow$ హిస్టరీని చూడగలరు & ఎడిట్ చేయగలరు.

    • సిస్టమ్: ఫార్మసీ $\rightarrow$ కొత్త మందులు రాయగలరు (Create Prescription).

    • సిస్టమ్: ల్యాబ్ $\rightarrow$ రక్త పరీక్షలు ఆర్డర్ చేయగలరు.

దృశ్యం C: IT అడ్మిన్ (మార్పు జరిగినప్పుడు)

ఒకవేళ సారా (నర్సు) ఆసుపత్రి వెబ్‌సైట్ చూసుకోవడానికి IT విభాగానికి మారితే:

  1. IAM సిస్టమ్ ఆమె నుండి రిజిస్టర్డ్ నర్సు రోల్‌ని తీసేస్తుంది.

  2. ఫలితం: పేషెంట్ రికార్డులు, మందుల గదికి ఆమె యాక్సెస్ (Entitlements) వెంటనే పోతాయి.

  3. IAM సిస్టమ్ ఆమెకు వెబ్ డెవలపర్ రోల్‌ని ఇస్తుంది.

  4. ఫలితం: ఆమెకు సర్వర్ మరియు కోడింగ్ ఫైల్స్‌కి కొత్త ఎన్‌టైటిల్మెంట్‌లు వస్తాయి.


5. వీటిని ఎందుకు వేరుగా చూడాలి? (లాభాలు)

అంశంరోల్స్ లేకుండా (Direct Entitlements)రోల్స్‌తో (RBAC)
కొత్త ఉద్యోగి నియామకంనెమ్మదిగా జరుగుతుంది. ప్రతి కొత్త ఉద్యోగికి 50 పర్మిషన్లను మాన్యువల్‌గా టిక్ చేయాలి.వేగంగా జరుగుతుంది. కేవలం "రోల్: మార్కెటింగ్" అని సెలెక్ట్ చేస్తే చాలు, 50 పర్మిషన్లు ఒకేసారి వస్తాయి.
బదిలీలు (Transfers)ప్రమాదకరం. పాత పర్మిషన్లు తొలగించడం IT వారు మర్చిపోవచ్చు. దీనివల్ల "ప్రివిలేజ్ క్రీప్" (అవసరానికి మించి యాక్సెస్) వస్తుంది.సురక్షితం. రోల్ మార్చగానే పాత ఎన్‌టైటిల్మెంట్‌లు పోయి, కొత్తవి వస్తాయి.
ఆడిటింగ్ (Auditing)కష్టం. "జాన్‌కు ఫైనాన్స్ సర్వర్ యాక్సెస్ ఎందుకు ఉంది?" అని అడిగితే ఎవరికీ గుర్తుండదు.సులభం. "జాన్ 'అకౌంటెంట్' రోల్‌లో ఉన్నాడు కాబట్టి అతనికి ఆ యాక్సెస్ ఉంది" అని చెప్పవచ్చు.

సారాంశం (Summary)

  • రోల్స్ (Roles): ఇవి జాబ్ డిస్క్రిప్షన్స్ లాంటివి (వ్యక్తి ఎవరు?).

  • ఎన్‌టైటిల్మెంట్‌లు (Entitlements): ఇవి తాళం చెవులు/హక్కులు లాంటివి (వ్యక్తి ఏం చేయగలరు?).

మీరు ఒక ఉద్యోగానికి అవసరమైన తాళాలను (Entitlements) నిర్ణయించి, వాటిని ఒక కీ చైన్‌లో (Role) వేసి, ఆ కీ చైన్‌ను ఉద్యోగికి (User) ఇస్తారు.