Glossary
This handbook uses the following terms throughout. The German term is given in brackets.
Access request (Antrag)
A request for an entitlement or business role, decided by an approval workflow.
Account (Konto)
An identity's access to a target system, for example an SAP user or an Active Directory account. An account always belongs to exactly one identity.
Approver (Genehmiger)
A person who approves or rejects an access request. The approval workflow defines who approves.
Audit log (Protokoll)
A chronological record of security-relevant actions: who did what, and when.
Business role (Business-Rolle)
A bundle of entitlements – often spanning several target systems – that describes a job function. Whoever receives a business role receives all entitlements it contains.
Entitlement (Berechtigung)
A single permission in a target system, for example an SAP role or an Active Directory group.
Grace period (Karenzzeit) planned
The period after termination during which an identity's entitlements stay assigned before Nova removes them. See Grace period after termination.
Identity (Identität)
A person or technical actor whose access Nova manages. An identity can hold accounts in several target systems. See Identities and their status.
Joiner, mover, leaver (Eintritt, Wechsel, Austritt)
The three events in the lifecycle of an identity. For each, Nova runs a defined procedure, such as creating accounts, adjusting entitlements or locking accounts.
Provisioning (Provisionierung)
Transferring accounts and entitlements from Nova into the target systems.
Recertification (Rezertifizierung)
A regular review of whether existing entitlements are still needed. Nova removes entitlements whose need is denied.
Reconciliation (Abgleich)
A comparison between what Nova intends for an identity and what actually exists in the target system. Nova shows differences and lets you resolve them in either direction.
Rehire (Wiedereintritt)
The return of a terminated identity. Nova runs its own defined procedure for it.
Retention period (Aufbewahrungsfrist)
The period for which Nova keeps an identity in the trash before its data is permanently deleted.
Source system (Quellsystem)
A system from which Nova takes over data about identities – typically the HR system, for example SAP HCM.
Target system (Zielsystem)
A system in which Nova manages accounts and entitlements – for example SAP, Active Directory and LDAP, Microsoft Entra ID, Keycloak or SCIM-enabled applications.
Trash (Papierkorb)
Storage for deleted identities. From there, identities can be restored or permanently deleted.