Role mining
Role mining searches the direct assignments of an area for recurring patterns and proposes business roles based on them. Nova creates nothing on its own: administrators review every proposal, and only accepted ones are applied. The feature is available to administrators only, under “Roles” → “Role Mining”.
What data Nova analyses
- Scope: an org unit, optionally with its sub-units (“Include sub-units”, on by default). A run covers at most 10,000 identities.
- Identities: active ones only; technical identities and AI agents are left out by default.
- Assignments: direct ones only. What an identity receives through business roles is already bundled; a run leaves existing business roles and their assignments untouched. Nova does not analyse AI capabilities (
nova-ai:*). - Structure: Nova uses org units and positions to bind proposals to them.
At the start, Nova freezes the scope; review and preview work on this snapshot. Only one run can be active at a time.
How proposals are formed
Nova computes four layers one after the other. Whatever one layer covers no longer counts in the following ones. This way, every direct assignment ends up in exactly one proposal or stays direct.
| Layer | Formed from (defaults) | Binding |
|---|---|---|
| “Global base role” | roles held by at least 90 % of the identities in scope | the scope's org unit |
| “Org-unit base roles” | per org unit, the roles held by at least 70 % of its members | that org unit |
| “Functional roles” | roles shared by all holders of a position, and frequent combinations of at least 2 roles held by at least 3 identities | position or identities |
| “Special functions” | per identity, at least 2 roles held by fewer than 3 identities in scope | that identity |
The thresholds can be adjusted in the “New mining run” dialog, as can the “Maximum number of BRs” (default 12; special functions do not count). Candidates beyond this budget – ranked by the number of assignments they would convert – appear as “Over BR budget”. With the “Outlier mode” set to “Report only”, special functions only appear as “Outlier”. All figures, such as coverage and effects, are calculated by Nova itself.
AI review (optional)
If an AI mode is active, an AI assesses the candidates before they appear as proposals:
- It suggests a name and description, confirms a candidate or places a veto, and classifies special functions as a special function or an anomaly.
- A veto turns the candidate into the finding “No layer candidate” with the AI's reasoning; an anomaly appears as “Anomaly” with a recommendation.
- The AI cannot add roles or identities. Nova discards answers containing unknown identifiers and does not adopt any figures from the AI.
- The AI receives key figures, names, descriptions and ratings of the roles as well as names of org units, positions and existing business roles. For candidates bound to individuals, names of identities are added, for special functions also their department and position.
- Without AI, or if the AI fails, the run delivers the same statistical candidates with generic names.
Review and apply
- Proposals start as “Pending”. Administrators “Accept” or “Reject” them, can rename them and remove individual roles (“Remove role”). A proposal without roles counts as rejected.
- “Apply…” first shows a preview against the current data: how many direct assignments would be converted and which identities would newly receive roles (“New grants”).
- Nova applies accepted proposals only. For each proposal, Nova creates a business role – with the highest risk rating of its roles –, assigns it to the reviewed identities and replaces their covered direct assignments with assignments through the business role. Nova carries over validity dates in the process.
- “Bind business roles to org units and positions” (on by default) additionally attaches the business role to the org unit or position, so that people joining later inherit it. When switched off, only the reviewed identities receive the role.
- If the current data deviates from the reviewed state, Nova skips the proposal (“Skipped (drift)”). A new run then provides an up-to-date picture.
- “Findings” and “Remaining direct assignments” are a report only; Nova revokes nothing based on them. Revocations go through recertification or manual maintenance.
Nova logs the start, review decisions and application of a run, as well as every business role created, together with its origin in the run.