Enable the configuration of an application owner profile filtering on a tag

What is a one sentence summary of your feature request?

Enable the configuration of an application owner profile filtering on a tag

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Hello,
It would be great to have a application owner profile by tag in Usercube for several reason :

  • no need to increase the number of categories just for this specific reason
  • no need to create an application filtering on the role or multiply subcategories in complex environments with a lot of ownership, which can decrease the chance to reach the limit database of number of profiles for one user.
  • very flexible and fast, and for a new right can be performed by someone who does not have a high level of proficiency with the product.

It would be a very good combination with the 6.3 incoming, and its connector usercube to itself for profiles attributions.

How do you currently solve the challenges you have by not having this feature?

Multiply the number of subcategories, and hide it by applying a policy that no one have access. It hides the folder but not the rights inside if they have a policy that is visible by the current user. I don’t know if it is a normal behaviour or not, and could be patched in the future. The managements of these subcategories is a mess.

Hello,

Did you have a chance to read me ?

Thank you

Hi @LucasDavid

Thanks for your request. I’m meeting with the team later to discuss. I’ll get back to you with an update asap.

Hi @LucasDavid I had a chance to talk to the team to better understand your request.
I understand how having the category as the only filter is limiting for the need to create roles. Your proposition to use another criteria is pertinent. However, I’m not sure that using tags will be the best option since there is no guardrails or dictionary for them, and using them for a critical function such as assigning profiles could be risky. However, you bring up a good point that they way profiles are assigned could be improved. I’ve added you request to the backlog along with another feature to improve the use of tags.

Hello Kate,

Thank you for your answer. Yes I agree that using tags is not that pertinent. But it is the only way I see to answer to my problematic with what is already existing in Usercube.

My problematic is the following :

For each folder, mail box or access in application, there are owners of data. These owners should be validating every request of access of their assets. In usercube there are 2 solutions :

  • Create sub category and set them application owner of the category
  • Set them application owner of the right.

These owners can be owner of several rights which are cross categories, and it is very difficult to maintain with what is currently possible in usercube.

My idea was then to use the tag to group them cross categories, and then use the new feature in 6.3 and give them the profile of application owner by tag through a right. If the application owner is leaving the company, I just have to give the right of application by tag for the concerning tag to give the profile to the person replacing him. Much easier to maintain.

All the entities I manage request to have specific application owner by assets. 2 entities does not want to be onboarded while I can’t provide them a way to set this up.

I remain avalaible to discuss more about it, or if you have an other solution that I did not think about.

Best regards,

PS : It is possible to recertify per tag, why not validate a right by tag ?