Results Table
Results are displayed in a table with the following information:
| Column | Description |
|---|---|
| User/Role | Affected user or role name |
| Risk ID | Risk identifier (e.g., F001) |
| Risk Description | Human-readable risk name |
| Risk Level | Severity as defined by the ruleset, commonly Critical, High, Medium, Low |
| Risk Type | Type as defined by the ruleset, commonly Segregation of Duties, Critical Action, Critical Permission |
| Function | Business function(s) involved |
| Action | Transaction codes providing the access |
| Role | Role(s) granting the access |
| Composite Role | Parent composite role (if applicable) |
| Business Process | Business process category |
| Department | HR department of the user, when HR data is loaded |
| HR Function | HR function of the user, when HR data is loaded |
| Location | HR location of the user, when HR data is loaded |
Every column has a filter, so a result can be narrowed further after the analysis has run. Scoping before the run is still preferable for large systems, because it keeps the analysis and the report small. See Scoping Your Analysis.
Risk level and risk type are not fixed lists. Both carry through verbatim from the loaded ruleset, and the filter options offered here are built from the distinct values found in it. Two reports produced against different rulesets are only comparable on severity if those rulesets agree on the vocabulary.
Result Tabs
| Tab | Content |
|---|---|
| Info | The criteria the analysis was run with |
| Summary report | One row per user and risk |
| Detailed report | The roles, actions and authorizations behind each conflict |
| Remediation | Recommendations for resolving the risks, see Generating Recommendations |
| Did-do | Execution data for the access involved, when Did do was enabled. See Did-Do Analysis |
The table on screen is a view onto the exported files. For the exact column layout of what gets written to disk, which differs between users and roles mode, see Report Types.