Policies & access
Model
A policy belongs to a category and has one or more connectors assigned with a rank. Granting the policy to a user materializes their accounts on those connectors; when two policies touch the same connector, the highest rank wins.
Revocation (last-access rule)
When a user loses the last policy touching a connector, BIAM disables the account on that system (it does not delete it). If they later receive access again, the account is re-enabled first. Deletion is never automatic: it is a human decision with four eyes.
Naming conventions
Each connector can have its username convention: a template of segments — tokens (first-name initial, surname…) and fixed literals (e.g. the institutional prefix fie_). On collision, a fallback convention is chained and, as a last resort, a numeric suffix. The console previews the username before creating.
Attributes
- Identity attributes: fields of the person's profile (syncable to AD).
- Provisioning attributes: fields each target system requires, scoped per user or per connector, with canonical values and per-connector value mappings.
- Identity → provisioning bridge: a connector attribute can be fed directly from an identity attribute; editing the profile propagates the update to bridged connectors. A manual value on the user's sheet always wins.