Business Role owner cannot remove members

we have around 300 business roles published as assignment resource on IT shop. Currently role owners can only see role information on IT shop.

However, they annot remove members unlike manager of AD group, where group manager can remove members from IT shop. Is this the default behavior? I couldn't figure out permissions to allow member removal option to the role owners, anyone has any insight on this?

Best regards,

Danial

Parents Reply Children
  • I think there is a difference in the way you have published business role or my environment is having some issue.

    I created one business role--> assigned custom group entitlements-->created assignment resource (this step created service item as well)-->added this assignment resource to one IT shop shelve--> Assigned Product owner to the service item (product owner application role has one employee who is authorized to approve membership for this business role)

    Now this product owner is not able to control the membership of this role from IT shop.

    Can you show how you published your business role on IT shop?

  • So here is the point. The product owner is not the owner of the business role.

    The owners of the business roles are defined at the business role itself (Org.UID_PersonHead, Org.UID_PersonHeadSecond). The product owners are merely some additional owners in that use-case.

    For AD Groups, you only have the product owners as "Real" owners, because there are no properties that would define an identity (Person) as owner.

    HtH

  • Thanks Markus! :) this will do the job. Now I just need to sort of permissions to disallow role manager not to mess with entitlements attached with the business role from IT shop.