PingOne Advanced Identity Cloud

Manage roles

Role lifecycle management (LCM) lets administrators delegate key responsibilities to delegated end users. This lets the delegated end users perform administrative tasks on behalf of other end users without granting them full administrative privileges.

This section is for end users who have been granted role LCM privileges through scopes and internal roles. If you’re a tenant administrator looking to configure role LCM, see Configure role lifecycle management.

The delegated end user can now manage the entire lifecycle of specific roles directly from their hosted page dashboard. This includes the ability to:

  • Create new roles.

  • Modify existing roles.

  • Delete roles that are no longer needed.

To ensure proper governance and security, the system submits every action the delegated end user takes, such as creating, modifying, or deleting a role, as a request that requires workflow approval. This approach streamlines role management by empowering those closest to the business needs to handle these tasks.

The following tasks assume you are a delegated end user who has been granted role LCM permissions.

A `delegated administrator is a user who received scoped administrative privileges to manage specific users or objects without becoming a full tenant administrator.

A delegated end user is a trusted end user who remains in the end-user experience but is allowed to perform a limited set of governed tasks on behalf of others, such as user, entitlement, and role lifecycle actions. Identity Governance routes those actions through request review and approval workflows.

Create a new role and assign it to an end user

  1. In the hosted pages, sign on to your account. You should have received a notification that you have new permissions to manage roles.

  2. Go to Administer > Roles.

  3. On the Roles page, click add New Role.

    Roles page showing a list of existing roles with a New Role button in the top right for creating a new role.
  4. In the New role modal, fill out the form for the new role:

    • Name: Enter a name for the role. This is a required field.

    • Description: Enter a general description of the role.

    • Requestable: Click to enable the role as requestable. This means that the role can be requested in access requests and access reviews.

    • Role Owner: Select a user as a role owner. A role owner is responsible for approving or rejecting requests for a specific role.

      New role modal showing form fields for Name (required), Description, Requestable toggle switch, and Role Owner selector.
  5. Go to Entitlements > add Add Entitlements.

    Role configuration page with Entitlements tab selected, showing an empty entitlements list and an Add Entitlements button.
  6. In the Add entitlements modal, select the entitlement and object type and click Next.

    Add entitlements modal showing application and object type selectors with a list of available entitlements to choose from and a Next button.

    The Add entitlements modal excludes entitlements sourced from unmanaged apps because Advanced Identity Cloud can’t access them through a live connector. These disconnected entitlements remain visible in role LCM views and in an end user’s access details. Learn more in Unmanaged applications.

  7. Go to Members > add Add Role Members.

    Role configuration page with Members tab selected, showing an empty members list and an Add Role Members button.
  8. In the Add role members modal, select the end users who will be members of this role, and click Save.

    Add role members modal displaying a searchable list of users with checkboxes for selection and a Save button.

    This action creates a change request that requires approval from the user specified in the workflow.

  9. Click View request to see the details of the change request you just submitted.

    Success notification banner stating the role creation request was submitted, with a View request button to see the change request details.
    Change request details page showing request status, requester information, requested changes, and approval workflow status.

Modify a role

  1. In the hosted pages, go to Administer > Roles.

  2. Select a role.

  3. On the role details page, modify any field in the Details, Entitlements, and Members tabs, and click Save.

    Role details page with Details, Entitlements, and Members tabs visible, showing editable fields for role properties and a Save button.

    This action creates a change request that requires approval from the user specified in the workflow.

Delete a role

  1. In the hosted pages, go to Administer > Roles.

  2. Click more_horiz > Delete to remove a role.

  3. In the Confirm Removal modal, click Remove if you’re certain you want to delete the role.

    This action creates a change request that requires approval from the user specified in the workflow.