Skip to content

Policies & access

Model

A policy belongs to a category and has one or more connectors assigned with a rank. Granting the policy to a user materializes their accounts on those connectors; when two policies touch the same connector, the highest rank wins.

Revocation (last-access rule)

When a user loses the last policy touching a connector, BIAM disables the account on that system (it does not delete it). If they later receive access again, the account is re-enabled first. Deletion is never automatic: it is a human decision with four eyes.

Naming conventions

Each connector can have its username convention: a template of segments — tokens (first-name initial, surname…) and fixed literals (e.g. the institutional prefix fie_). On collision, a fallback convention is chained and, as a last resort, a numeric suffix. The console previews the username before creating.

Attributes

  • Identity attributes: fields of the person's profile (syncable to AD).
  • Provisioning attributes: fields each target system requires, scoped per user or per connector, with canonical values and per-connector value mappings.
  • Identity → provisioning bridge: a connector attribute can be fed directly from an identity attribute; editing the profile propagates the update to bridged connectors. A manual value on the user's sheet always wins.