{"id":1393,"date":"2024-01-16T11:05:12","date_gmt":"2024-01-16T10:05:12","guid":{"rendered":"https:\/\/memority.p2.pp-izhak.fr\/2024\/01\/16\/le-modele-de-role\/"},"modified":"2024-07-07T23:42:22","modified_gmt":"2024-07-07T21:42:22","slug":"the-memority-role-model","status":"publish","type":"post","link":"https:\/\/memority.p2.pp-izhak.fr\/en\/the-memority-role-model\/","title":{"rendered":"The Memority role model"},"content":{"rendered":"<p class=\"has-text-align-left\">Memority offers a powerful role model definition to manage delegated administration into Memority portal but also applications accesses, equipment and any other link between an identity and a resource.<\/p>\n<p class=\"has-text-align-left\"><strong>This blog series<\/strong>\u00a0will allow you to understand\u00a0<strong>how we handled this fundamental part of right management.<\/strong><\/p>\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n<div class=\"wp-block-spacer\" aria-hidden=\"true\"><\/div>\n<p><strong>As named, Identity and Access Management (IAM) allows to manage inside an organization identities that need to access resources.<\/strong>\u00a0In the past, authorizations were given with more or less control, with more or less known processes and with more or less painful rights omissions (to add or to remove).\u00a0<strong>To control and simplify authorizations management, it is necessary to define a role model which will allow to set publication rules, access conditions and most important, role removal at the right point!<\/strong><\/p>\n<p><strong>The role assigns to a user one or more rights about a resource.<\/strong>\u00a0It allows to define a first level of abstraction and automatism against a technical right and to control that two users with the same roles will have the same rights. But when we need to manage thousands of resources with different types, it becomes necessary to organize and design rights into a role model to manage them as one and allow anyone to request roles easily: the user in self-service, its manager, an application manager and more.<\/p>\n<div id=\"attachment_1394\" style=\"width: 1034px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1394\" class=\"wp-image-1394 size-full\" src=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/RoleModel1-Premiere-image-EN-1024x551-1.png\" alt=\"\" width=\"1024\" height=\"551\" srcset=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/RoleModel1-Premiere-image-EN-1024x551-1.png 1024w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/RoleModel1-Premiere-image-EN-1024x551-1-300x161.png 300w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/RoleModel1-Premiere-image-EN-1024x551-1-768x413.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-1394\" class=\"wp-caption-text\">Thanks to role model, it now possible to offers normalized and simple interfaces to users<\/p><\/div>\n<h3 class=\"wp-block-heading\"><strong>A very dynamic role model<\/strong><\/h3>\n<p><strong>Memority\u2019s role model is highly dynamic\u00a0<\/strong>and allows to manage administration rights in Memority, applications accesses, equipment, business roles, contracts and more. In a word, we can represents anything as a resource assigned to a user. To do that, we use several concepts:<\/p>\n<ul>\n<li><strong>Resource:<\/strong>\u00a0the representation of a resource to which we want to get rights (e.g. Memority, ServiceNow, a mobile phone\u2026)<\/li>\n<li><strong>Right:<\/strong>\u00a0the representation of a technical right which links a resource to a role and is used to trigger provisioning or access to an application for example<\/li>\n<li><strong>Role:<\/strong>\u00a0the role that will be assigned to users. It is bind to one or more rights or one or more other roles for a business role<\/li>\n<li><strong>Dimensions:<\/strong>\u00a0additional information or constraints over the right that are set on role\u2019s assignation to a user (e.g. license dimension for Salesforce role). A full article about dimensions is coming \ud83d\ude09<\/li>\n<\/ul>\n<div class=\"wp-block-uagb-image aligncenter uagb-block-3267fa86 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-center\">\n<div id=\"attachment_1397\" style=\"width: 1034px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1397\" class=\"wp-image-1397 size-full\" src=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/2-EN-1024x553-1.png\" alt=\"\" width=\"1024\" height=\"553\" srcset=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/2-EN-1024x553-1.png 1024w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/2-EN-1024x553-1-300x162.png 300w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/2-EN-1024x553-1-768x415.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-1397\" class=\"wp-caption-text\">An administration role, the data model allows to define assignation rules, links between resources and rights<\/p><\/div>\n<\/div>\n<h3 class=\"wp-block-heading\"><strong>Different types of resources and roles<\/strong><\/h3>\n<p><strong>Thanks to these 4 concepts, we can easily design several types of resources and roles to set a dedicated data model, with their own attributes.<\/strong><\/p>\n<p>For example, we can set resource types \u201cApplication\u201d and \u201cEquipment\u201d, and role types \u201cApplication role\u201d, \u201cAdministration role\u201d, \u201cBusiness role\u201d and \u201cSupplies\u201d with their own publication and assignment rules (another article about publication and assignment is coming too \ud83d\ude09). These roles can be displayed separately according to their types, and managed by dedicated administrators.<\/p>\n<div class=\"wp-block-uagb-image aligncenter uagb-block-46edb17e wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-center\"><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1399 size-full\" src=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/3-EN.png\" alt=\"\" width=\"736\" height=\"348\" srcset=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/3-EN.png 736w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/3-EN-300x142.png 300w\" sizes=\"auto, (max-width: 736px) 100vw, 736px\" \/><\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_1401\" style=\"width: 1034px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1401\" class=\"wp-image-1401 size-full\" src=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/EN-1024x555-1.png\" alt=\"\" width=\"1024\" height=\"555\" srcset=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/EN-1024x555-1.png 1024w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/EN-1024x555-1-300x163.png 300w, https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/01\/EN-1024x555-1-768x416.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-1401\" class=\"wp-caption-text\">Links between resource types and role types according to our example. These role types are displayed in separated tabs in portals<\/p><\/div>\n<p>We set our Memority role model,<strong>\u00a0now we can dig deeper:<\/strong><\/p>\n<ul>\n<li>How to set publication and assignation rules?<\/li>\n<li>How to use dimensions?<\/li>\n<li>How to recertify user\u2019s roles?<\/li>\n<\/ul>\n<p>But you have to wait for\u00a0<strong>our next articles of our role model series!<\/strong><\/p>\n<p class=\"has-link-color wp-elements-075215aaa8a82f341d892155255aee0d\">-&gt; To find out more about the benefits of the Memority platform:\u00a0<a href=\"https:\/\/www.memority.com\/\">click here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Memority offers a powerful role model definition to manage delegated administration into Memority portal but also applications accesses, equipment and any other link between an identity and a resource. This blog series\u00a0will allow you to understand\u00a0how we handled this fundamental part of right management. As named, Identity and Access Management (IAM) allows to manage inside [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":999,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[30,31,32,33],"class_list":["post-1393","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-non-classifiee","tag-cybersecurity-en","tag-iam-en","tag-idaas-en","tag-identityfactory-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Memority role model - Memority<\/title>\n<meta name=\"description\" content=\"Memority propose un mod\u00e8le de r\u00f4le extr\u00eamement puissant qui permet de g\u00e9rer des capacit\u00e9s d\u2019administration d\u00e9l\u00e9gu\u00e9es, des acc\u00e8s \u00e0 des applications et des attributions mat\u00e9rielles.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Memority role model - Memority\" \/>\n<meta property=\"og:description\" content=\"Memority propose un mod\u00e8le de r\u00f4le extr\u00eamement puissant qui permet de g\u00e9rer des capacit\u00e9s d\u2019administration d\u00e9l\u00e9gu\u00e9es, des acc\u00e8s \u00e0 des applications et des attributions mat\u00e9rielles.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/\" \/>\n<meta property=\"og:site_name\" content=\"Memority\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-16T10:05:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-07-07T21:42:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Izhak-contenu\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Izhak-contenu\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/\",\"url\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/\",\"name\":\"The Memority role model - Memority\",\"isPartOf\":{\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg\",\"datePublished\":\"2024-01-16T10:05:12+00:00\",\"dateModified\":\"2024-07-07T21:42:22+00:00\",\"author\":{\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/#\/schema\/person\/c6ac154af9e29cdadf1380102b48a162\"},\"description\":\"Memority propose un mod\u00e8le de r\u00f4le extr\u00eamement puissant qui permet de g\u00e9rer des capacit\u00e9s d\u2019administration d\u00e9l\u00e9gu\u00e9es, des acc\u00e8s \u00e0 des applications et des attributions mat\u00e9rielles.\",\"breadcrumb\":{\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#primaryimage\",\"url\":\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg\",\"contentUrl\":\"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/memority.p2.pp-izhak.fr\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Memority role model\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/#website\",\"url\":\"https:\/\/memority.p2.pp-izhak.fr\/\",\"name\":\"Memority\",\"description\":\"L&#039;IDaaS europ\u00e9enau service des enjeux business\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/memority.p2.pp-izhak.fr\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/#\/schema\/person\/c6ac154af9e29cdadf1380102b48a162\",\"name\":\"Izhak-contenu\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/memority.p2.pp-izhak.fr\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/60656c8b16f6a95bfb54034344a959d53d08b47923ca24bc24069dc93f6c7bf1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/60656c8b16f6a95bfb54034344a959d53d08b47923ca24bc24069dc93f6c7bf1?s=96&d=mm&r=g\",\"caption\":\"Izhak-contenu\"},\"url\":\"https:\/\/memority.p2.pp-izhak.fr\/en\/author\/izhak-contenu\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Memority role model - Memority","description":"Memority propose un mod\u00e8le de r\u00f4le extr\u00eamement puissant qui permet de g\u00e9rer des capacit\u00e9s d\u2019administration d\u00e9l\u00e9gu\u00e9es, des acc\u00e8s \u00e0 des applications et des attributions mat\u00e9rielles.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"The Memority role model - Memority","og_description":"Memority propose un mod\u00e8le de r\u00f4le extr\u00eamement puissant qui permet de g\u00e9rer des capacit\u00e9s d\u2019administration d\u00e9l\u00e9gu\u00e9es, des acc\u00e8s \u00e0 des applications et des attributions mat\u00e9rielles.","og_url":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/","og_site_name":"Memority","article_published_time":"2024-01-16T10:05:12+00:00","article_modified_time":"2024-07-07T21:42:22+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg","type":"image\/jpeg"}],"author":"Izhak-contenu","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Izhak-contenu","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/","url":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/","name":"The Memority role model - Memority","isPartOf":{"@id":"https:\/\/memority.p2.pp-izhak.fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#primaryimage"},"image":{"@id":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#primaryimage"},"thumbnailUrl":"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg","datePublished":"2024-01-16T10:05:12+00:00","dateModified":"2024-07-07T21:42:22+00:00","author":{"@id":"https:\/\/memority.p2.pp-izhak.fr\/#\/schema\/person\/c6ac154af9e29cdadf1380102b48a162"},"description":"Memority propose un mod\u00e8le de r\u00f4le extr\u00eamement puissant qui permet de g\u00e9rer des capacit\u00e9s d\u2019administration d\u00e9l\u00e9gu\u00e9es, des acc\u00e8s \u00e0 des applications et des attributions mat\u00e9rielles.","breadcrumb":{"@id":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#primaryimage","url":"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg","contentUrl":"https:\/\/memority.p2.pp-izhak.fr\/wp-content\/uploads\/2024\/06\/modele-role.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/memority.p2.pp-izhak.fr\/le-modele-de-role\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/memority.p2.pp-izhak.fr\/en\/"},{"@type":"ListItem","position":2,"name":"The Memority role model"}]},{"@type":"WebSite","@id":"https:\/\/memority.p2.pp-izhak.fr\/#website","url":"https:\/\/memority.p2.pp-izhak.fr\/","name":"Memority","description":"L&#039;IDaaS europ\u00e9enau service des enjeux business","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/memority.p2.pp-izhak.fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/memority.p2.pp-izhak.fr\/#\/schema\/person\/c6ac154af9e29cdadf1380102b48a162","name":"Izhak-contenu","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/memority.p2.pp-izhak.fr\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/60656c8b16f6a95bfb54034344a959d53d08b47923ca24bc24069dc93f6c7bf1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/60656c8b16f6a95bfb54034344a959d53d08b47923ca24bc24069dc93f6c7bf1?s=96&d=mm&r=g","caption":"Izhak-contenu"},"url":"https:\/\/memority.p2.pp-izhak.fr\/en\/author\/izhak-contenu\/"}]}},"_links":{"self":[{"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/posts\/1393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/comments?post=1393"}],"version-history":[{"count":2,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/posts\/1393\/revisions"}],"predecessor-version":[{"id":1403,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/posts\/1393\/revisions\/1403"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/media\/999"}],"wp:attachment":[{"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/media?parent=1393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/categories?post=1393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/memority.p2.pp-izhak.fr\/en\/wp-json\/wp\/v2\/tags?post=1393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}