How to manage users, roles, and privileges
Users and general privileges managed in ARIS Administration
Users are managed centrally in ARIS Administration for all ARIS products. They are assigned license privileges (example: Risk and Compliance (Operate) or ARIS Connect Viewer), function privileges (example: Risk and Compliance administrator or ARIS administrator), data base privileges (example: ARIS Governance Models), and user groups (example: IT department). For detailed information, refer to Manage users, in the online help of ARIS.
Licenses
Users must have one or a combination of the following license privileges: ARIS Connect Viewer, ARIS Connect Designer, Risk and Compliance (Operate), or Risk and Compliance (Contribute) in ARIS Administration. Users who have assigned (directly or via a user group) the ARIS Connect Viewer or ARIS Connect Designer license privilege in ARIS Administration, automatically have the privileges associated with the Risk and Compliance (Contribute) license privilege.
Privileges
Users who have assigned the Risk and Compliance administrator function privilege in ARIS Administration, have system administrator privileges in ARIS Risk and Compliance. System administrator privileges for ARIS Risk and Compliance are granted only in ARIS Administration.
Users who have assigned (directly or via a user group) the User administrator function privilege in ARIS Administration, have user administrator privileges in ARIS Risk and Compliance (and in other applications).
Users who have assigned the Risk and Compliance data transfer manager function privilege (and the Risk and Compliance (Operate) license privilege) in ARIS Administration, can transfer GRC-relevant master data objects (for example, risks or survey schedulers) from ARIS to ARIS Risk and Compliance. The Risk and Compliance data transfer manager function privilege is granted only in ARIS Administration and is only relevant in ARIS.
GRC-specific roles, privileges, and objects
ARIS Risk and Compliance users are assigned to roles that represent their GRC tasks and provide the required privileges. Risk and Compliance roles are defined using a role type and a role level. The role type (example: Risk manager) and the role level (example: Environment-specific) of a role (example: Risk manager role Germany) specify which privileges the assigned users have (example: Read privilege for risks and risk assessments). A user can be assigned to several roles at the same time. A role always has only one role type, which in turn has only one role level.
Only the roles available in the role administration can be assigned to users. Only users with the Risk and Compliance administrator function privilege can manage and transfer roles. Users with the Risk and Compliance data transfer manager function privilege can transfer Risk and Compliance data. To separate administration and management tasks, do not assign both privileges to the same user.
Recommended procedure
Create roles in Risk and Compliance role administration and send roles from there.
To give the users the appropriate ARIS Risk and Compliance-specific privileges, the users must be assigned to the appropriate roles in ARIS Administration (
Configuration > Risk and Compliance > DATA MANAGEMENT > Roles). For detailed information, refer to Manage roles in the online help of ARIS.To be able to assign roles with object-specific role level to the relevant objects, such as risks or controls, in an ARIS modeling environment, transfer the ARIS Risk and Compliance-specific roles to ARIS using Send to ARIS Repository in ARIS Administration (Configuration > Risk and Compliance > DATA MANAGEMENT > Roles. For detailed information, refer to Manage roles in the online help of ARIS.
Connect the transferred roles with Risk and Compliance data in an ARIS modeling environment. For detailed information on modeling guidelines, refer to the Modeling Conventions.
Transfer Risk and compliance data, to transfer objects such as risks and controls, including the modeled role assignments.
The relevant roles and master data objects are available in ARIS Risk and Compliance.
Alternative procedure
Create role objects in an ARIS modeling environment and transfer them to Risk and Compliance role administration.
Model the Risk and Compliance roles in an Organizational chart model and specify the attributes ARIS Risk and Compliance role type and ARIS Risk and Compliance role level. For detailed information, refer to Organizational chart diagram in Modeling Conventions.
Import the roles to ARIS using Get from ARIS Repository in ARIS Administration (Configuration > Risk and Compliance > DATA MANAGEMENT > Roles. For detailed information, refer to Manage roles in the online help of ARIS.
Transfer Risk and compliance data, to transfer objects such as risks and controls, including the modeled role assignments.
The relevant users, roles, and master data objects are available in ARIS Risk and Compliance.