How access is granted and removed
In Nova, access is an assignment (see Access model). Nova brings assignments into the target systems through provisioning. This page describes how assignments come about and end, and when Nova transfers them.
How access is granted
| Route | What happens |
|---|---|
| Access request | Once an access request has been fully decided, Nova assigns the approved business roles and entitlements – see Requesting access. |
| Administration | Administrators assign business roles to an identity, optionally with a validity period. |
| Organisation | Members of an organisational unit and holders of a position receive its business roles – see Organisation and positions. |
| Routines | Steps in routines can assign business roles, for example via the position – see Joiners, movers, leavers. |
| Takeover | When Nova reads accounts from a target system, it can take over their existing entitlements as direct assignments – depending on the import settings. |
| Directly on the account | Administrators change the roles or groups of an account in the identity's “Systems” tab; Nova writes this change straight to the target system. |
When Nova transfers to the target systems
Nova transfers assignments in provisioning runs. A run concerns one identity: for each affected target system, it checks the account, creates it if needed and transfers the entitlements. If a step fails in one target system, the steps for the other target systems continue. Runs are listed under “Monitoring” → “Provisioning Log”.
After installation, the setting “Auto-provision backend systems” is switched off (“Administration” → “Provisioning” → “Mapping”, tab “Provisioning settings”). When it is switched on, Nova starts a run when
- administrators change the business roles of an identity – assign, revoke or change the period,
- an access request has been fully decided; the approved items are transferred,
- administrators choose “Apply changes to users” after changing the content of a business role; a run then starts for each identity holding the business role. Until then, the business role shows “Pending changes”,
- a routine has changed assignments – including the mover routine that Nova runs after a person has been added to, removed from or moved to another organisational unit,
- the revocations are executed when a recertification is completed,
- a “Cleanup Expired Assignments” job removes expired assignments.
Routine steps that lock, unlock or delete accounts start runs of their own for the identity's linked accounts – even when automatic provisioning is switched off.
Nova only transfers entitlements that belong to a target system. If an identity holds the same entitlement through several assignments, Nova removes it from the target system only once none of these assignments applies any more.
Differences between Nova and a target system are shown in the identity's “Reconciliation & Provisioning” tab. There, administrators resolve them per target system in either direction.
Start and end of validity
Start. Nova transfers an SAP role together with its start and end date, so a future-dated assignment also reaches SAP with the run straight away. Nova transfers no validity periods to Active Directory and LDAP, Microsoft Entra ID, SCIM and Keycloak; for these, Nova holds a future-dated assignment back. The “Activate Pending Assignments” job transfers it for active identities once its start date has been reached; it is pre-configured to run daily at 02:30.
End. Expired assignments are removed by the “Cleanup Expired Assignments” job: it deletes assignments whose end date has passed and, when automatic provisioning is switched on, starts runs that remove the entitlements from the target systems. Nova does not set up this job by itself; administrators create it with “New job” under “Monitoring” → “Background Jobs” and give it a schedule – see Monitoring and jobs.
How access is removed
| Route | What happens |
|---|---|
| Revocation | Administrators revoke a business role from an identity; Nova removes it together with its indirect assignments. |
| Expiry | The “Cleanup Expired Assignments” job removes assignments whose end date has passed. |
| Recertification | When completing a campaign, administrators can have the revocations executed; Nova then removes the revoked assignments. |
| Organisation | When a person leaves an organisational unit, they lose its business roles unless another unit or position grants them. |
| Leaver | By default, the leaver routine starts runs that lock the identity's linked accounts; it removes assignments only with an additional step – see Joiners, movers, leavers. |
Whether and when one of these changes reaches the target systems is described in the section “When Nova transfers to the target systems” above.