Provisioning runs
A provisioning run brings an identity's intended state from Nova into the target systems. A run concerns exactly one identity. It consists of steps per target system, such as checking the account, creating it and transferring entitlements.
When a run is created
When automatic provisioning is switched on – see How access is granted and removed – every change to the intended state creates a run for each affected identity, including:
- an approved access request,
- assigning or revoking a business role,
- attaching business roles to, or removing them from, organisational units and – with the “Planstellen (OSP)” add-on – positions; see Organisation and positions,
- a change to the definition of an entitlement or business role,
- deleting an entitlement or business role,
- the start and end of a validity period.
Nova stores every run before it executes. If a restart interrupts a run, Nova resumes it afterwards.
For any one identity, only one operation writes to the target systems at a time. This applies to runs as well as to every other way in which Nova writes to target systems.
Transferred and confirmed
Nova distinguishes two states:
| State | Meaning |
|---|---|
| transferred | The target system accepted the write. |
| confirmed | Nova read the state back from the target system; it matches the intended state. |
For each assignment, Nova shows whether it is transferred or confirmed and when Nova last confirmed it.
Removals: an entitlement counts as removed only once the removal is confirmed. If Nova cannot look up a group or role in the target system, the step fails and is retried. In that case, Nova never reports it as done.
Existing roles in SAP
Roles on an SAP account that Nova does not manage are preserved. Before its first write to an account, Nova reads the roles the account already has. In the reconciliation, they appear as present only in the target system until an administrator explicitly decides on them.
Retries
- Nova retries failed runs automatically, at increasing intervals.
- Nova re-evaluates every retry against the current state. Whether Nova locks or unlocks an account, for example, follows the status the identity has at the time of the retry.
- If a newer run has superseded an older one, Nova does not replay the older run.
Validity
Nova evaluates the start and end of validity periods in the configured business time zone.
Bulk changes and pausing
- Preview: when a change affects many identities – for example when a changed business role is applied to all its holders – Nova shows a preview with the number of affected identities and entitlements before it writes anything.
- Pause: each target system has a pause switch, and there is also a global one. While paused, Nova holds back all writes to the affected target systems; they stay queued.
What a run shows
Each run shows
- who or what triggered it: a person, an access request, a business role change, an organisational change or a job – with a link to the request if one triggered it,
- when it was triggered,
- its steps and their results.
Runs are listed under “Monitoring” → “Provisioning Log”. How runs relate to access requests and to changes in the target systems is described under Logs.