Access Modeling
Access Modeling, also known as role mining, analyzes existing access patterns to help optimize user-to-entitlement assignments. Identity Governance uses machine learning and analytics to propose candidate roles for review and publication by role owners.
|
PingOne Identity Governance add-on capability
Access Modeling is an additional add-on capability for PingOne Identity Governance. Contact your Ping Identity representative if you want to add the Access Modeling (Role Mining) add-on SKU to your PingOne Advanced Identity Cloud Identity Governance subscription. Learn more in Add-on capabilities. |
How Access Modeling works
The Access Modeling workflow involves the following participants:
-
An administrator configures Access Modeling, activates governance lifecycle management (the machine learning model that powers role mining), sets confidence thresholds, and creates the
access-modeling-administratorgroup. -
The administrator assigns one or more end users to the
access-modeling-administratorgroup. -
An authorized end user (a member of the
access-modeling-administratorgroup) runs a role mining job. Identity Governance analyzes the latest access data and generates candidate roles. -
A role owner and an approver review and publish roles. The role owner refines a candidate into a draft, and an approver publishes the draft as an active role in Identity Governance.