Access Management in an Enterprise environment
Access Request Sites are local-only objects, meaning they can reside on a single SAS or the MAS. The rules for selecting personnel and partitions are based on if the Access Request Site is on a MAS or a SAS, and the security access object:
- If the Access Request Site is on a MAS:
- In the Requesters tab, you can assign personnel and partitions from the MAS and any SAS.
- In the Clearances tab, you can assign global clearances and global partitions.
- In the Personnel tab, you can assign global personnel and global partitions
- If the Access Request Site is on a SAS:
- In the Requesters tab, you can assign global partitions and global personnel, and partitions and personnel local to the SAS.
- In the Clearances tab, you can assign partitions and clearances local to the SAS.
- In the Personnel tab, you can assign global partitions and partitions local to the SAS.
In the Access Management web portal, users can complete actions associated with requests created on a SAS for the same requests on a MAS. If a user is logged on to the Access Management web portal on a MAS, they can complete the same actions on SAS-owned requests.
If you edit an approval rule in the Approvals tab using the Clearance editor on the MAS, and the approval rule is owned by a SAS, both MAS and SAS versions of the clearance reflect the change.
All actions associated with a document in the Access Management web portal on a SAS can sync to a MAS, but cannot sync from a MAS to a SAS. The document is available for viewing from the MAS if the SAS is offline.
