PingOne Advanced Identity Cloud

Manage roles

Role lifecycle management (LCM) lets administrators delegate key responsibilities to delegated end users. This lets the delegated end users perform administrative tasks on behalf of other end users without granting them full administrative privileges.

This section is for end users who have been granted role LCM privileges through scopes and internal roles. If you’re a tenant administrator looking to configure role LCM, see Configure role lifecycle management.

The delegated end user can now manage the entire lifecycle of specific roles directly from their hosted page dashboard. This includes the ability to:

  • Create new roles.

  • Modify existing roles.

  • Delete roles that are no longer needed.

To ensure proper governance and security, the system submits every action the delegated end user takes, such as creating, modifying, or deleting a role, as a request that requires workflow approval. This approach streamlines role management by empowering those closest to the business needs to handle these tasks.

The following tasks assume you are a delegated end user who has been granted role LCM permissions.

A `delegated administrator is a user who received scoped administrative privileges to manage specific users or objects without becoming a full tenant administrator.

A delegated end user is a trusted end user who remains in the end-user experience but is allowed to perform a limited set of governed tasks on behalf of others, such as user, entitlement, and role lifecycle actions. Identity Governance routes those actions through request review and approval workflows.

Create a new role and assign it to an end user

  1. In the hosted pages, sign on to your account. You should have received a notification that you have new permissions to manage roles.

  2. Go to Administer > Roles.

  3. On the Roles page, click add New Role.

    Screen capture of the Roles page showing a list of existing roles with a New Role button in the top right for creating a new role.
  4. In the New role modal, fill out the form for the new role:

    • Name: Enter a name for the role. This is a required field.

    • Description: Enter a general description of the role.

    • Requestable: Click to enable the role as requestable. This means that the role can be requested in access requests and access reviews.

    • Role Owner: Select a user as a role owner. A role owner is responsible for approving or rejecting requests for a specific role.

      Screen capture of the New role modal showing form fields for Name (required), Description, Requestable toggle switch, and Role Owner selector.
  5. Go to Entitlements > add Add Entitlements.

    Screen capture of the role configuration page with Entitlements tab selected, showing an empty entitlements list and an Add Entitlements button.
  6. In the Add entitlements modal, select the entitlement and object type and click Next.

    Screen capture of the Add entitlements modal showing application and object type selectors with a list of available entitlements to choose from and a Next button.
  7. Go to Members > add Add Role Members.

    Screen capture of the role configuration page with Members tab selected, showing an empty members list and an Add Role Members button.
  8. In the Add role members modal, select the end users who will be members of this role, and click Save.

    Screen capture of the Add role members modal displaying a searchable list of users with checkboxes for selection and a Save button.

    This action creates a change request that requires approval from the user specified in the workflow.

  9. Click View request to see the details of the change request you just submitted.

    Screen capture of a success notification banner stating the role creation request was submitted, with a View request button to see the change request details.
    Screen capture of the change request details page showing request status, requester information, requested changes, and approval workflow status.

Modify a role

  1. In the hosted pages, go to Administer > Roles.

  2. Select a role.

  3. On the role details page, modify any field in the Details, Entitlements, and Members tabs, and click Save.

    Screen capture of the role details page with Details, Entitlements, and Members tabs visible, showing editable fields for role properties and a Save button.

    This action creates a change request that requires approval from the user specified in the workflow.

Delete a role

  1. In the hosted pages, go to Administer > Roles.

  2. Click more_horiz > Delete to remove a role.

  3. In the Confirm Removal modal, click Remove if you’re certain you want to delete the role.

    This action creates a change request that requires approval from the user specified in the workflow.