Access model
Nova organises access on three levels: entitlements in the target systems, business roles as bundles of entitlements, and assignments that link both to identities. Entitlements and business roles are listed under “Roles”, each in their own tab.
Entitlements
An entitlement is a single permission in exactly one target system – an SAP role (single or composite role) or a group in Active Directory and LDAP, Microsoft Entra ID, Keycloak or a SCIM-enabled application. Nova takes these entitlements over by importing them from the target system; they are listed in the “System Roles” tab.
Nova also knows entitlements without a target system. Nova does not transfer them to any target system:
- “Nova Entitlements” govern what someone may do in Nova itself. Pre-configured are “Admin” for administering Nova, “Security” and “SoD Reviewer” for decisions in certain approval steps, and “Manager”. Nova assigns this entitlement to people set as manager of an organisational unit.
- “Nova AI” are capabilities for AI agents. Only identities of the AI agent type receive them – see AI agents as identities.
Business roles
A business role bundles entitlements – often from several target systems – for a job function. In the “Assignments” tab of a business role, administrators define per target system which entitlements it contains. In addition, every business role carries:
- “Risk” – its risk score,
- “Owner” – the person responsible,
- “Area” – the business area, which also determines the colour,
- “Approval workflow” – the procedure for access requests for this business role.
Only business roles and entitlements with an approval workflow of at least one step can be requested – see Approval workflows.
When administrators change the content of a business role, Nova adjusts the assignments of all identities holding it as soon as the change is saved.
Assignments
An assignment links an identity to a business role or an entitlement. Nova distinguishes three types:
| Type | Meaning |
|---|---|
| Business role | The identity holds a business role. |
| Indirect | An entitlement from an assigned business role. Nova creates it with the business role and removes it with the business role. |
| Direct | A single entitlement without a business role – for example from an approved access request for that entitlement, from taking over an account from the target system, or a Nova entitlement. |
An identity holds each business role at most once. AI agents do not receive business roles.
Validity
Assignments have a validity period in Nova, “Valid From” and “Valid To”. It describes the intended state:
- A business role without a start date applies from the day it is assigned. The end date is optional and must not be before the start date; without an end date, the assignment has no time limit.
- Indirect assignments take over the period of their business role.
- The end date is inclusive: an assignment applies up to and including the day under “Valid To”.
- For SAP, Nova also records the period it last read from SAP – the actual state.
What happens at the start and end of a period is described in How access is granted and removed.
Organisational units and positions
Business roles can be attached to organisational units; the members of the unit receive them as assignments of their own. If “Inheritance” is switched on for a unit, its members also receive the business roles of all parent units. With the “Planstellen (OSP)” add-on, positions carry business roles too; their holders receive them together with those of the unit the position belongs to. Details are described in Organisation and positions.
Risk score
Every entitlement and every business role carries a risk score: “No Risk”, “Low”, “Medium”, “Critical” or “Not Scored”. The default is “Not Scored”. How Nova assesses risk beyond this is described in Risk assessment.