Entitlements
Entitlements in Oblique assign roles on resources to subjects (groups, users, and accounts), granting them access.
A user or group has access to a resource when they have one or more entitlements that grant access to that resource. Entitlements can be direct or indirect, such as when a user belongs to a group that has an entitlement.
Entitlements can have an expiration date or be indefinite.
Existing entitlements are imported when an integration is connected to Oblique. Imported entitlements explain the relationship between an account in that integration to a role in that integration; these accounts are then mapped to users in Oblique to reflect the access that a user has.
View access
Section titled “View access”You can view entitlements for roles on resources:
- You can see the entitlements you have, including for indirect access, from your profile page; and the entitlements another user has on their profile page, in the Access section.
- You can see the entitlements an attribute-based group, reporting group, or team group has from their detail page, in the Access section.
- You can see the entitlements for a given role on a resource, including for indirect access, from the resource’s detail page, in the Entitlements section.
To open the access graph to visualize entitlements, select View graph on a user profile or group, team, or resource’s detail page.
Grant access
Section titled “Grant access”In Oblique, access to a resource is granted by a request, which creates an entitlement assigning a role on a resource to a subject. Any user can request access for themselves, or any group, team, or other user. A user is granted access through their account in the resource’s integration, so only users with an account there can be granted access.
Admins can unilaterally make accesss changes, since they can self-approve requests.
Grant access to multiple subjects
Section titled “Grant access to multiple subjects”You can select multiple subjects as part of the same request, to grant them all access to the same roles on a resource.
Grant access to multiple resources
Section titled “Grant access to multiple resources”It’s not currently possible to create a request which grants access to multiple resources at once.
If there is a set of users who need access to the same set of resources, create a group or team to manage access more efficiently. A request adding a user to a group or team will automatically grant them access to the group’s or team’s resources.
Alternatively, create multiple requests.
Edit access
Section titled “Edit access”As with granting access, editing an entitlement requires a request, which admins can can self-approve.
You can create a request to edit an entitlement’s expiration date, to either extend or shorten it. You can also create a request to change an entitlement to change it from being indefinite to expiring, or vice versa. You can only edit an entitlement if it’s direct.
Revoke access
Section titled “Revoke access”As with granting access, revoking an entitlement requires a request, which admins can self-approve.
If a user has multiple entitlements which grant access to the same resource, all entitlements need to be revoked to revoke access.
Expire access
Section titled “Expire access”Entitlements with an expiration date will automatically be revoked by Oblique when the expiration date is reached.