When IAM analysis is enabled in the analysis criteria, simulation extends to IAM business roles, so an access model can be tested at the layer the business actually assigns from.
Availability
Enable IAM analysis in the analysis criteria and select the IAM systems to analyze. The business role tabs then appear in the Simulation panel.
| Tab | Users mode | Roles mode |
|---|---|---|
| Business Role assignments | Yes | No |
| Business Role composition | Yes | Yes |
| Craft Business Roles | Yes | Yes |
Business Role Assignments
Add or remove business roles for users.
| Field | Meaning |
|---|---|
| Business roles | The business roles to add or remove |
| Users | The users the change applies to |
The simulation is the cross product of the two lists, so every listed business role is applied to every listed user. Both lists must be filled in for the entry to simulate anything.
Business Role Composition
Attach or detach the underlying system roles that make up a business role.
| Field | Meaning |
|---|---|
| Business roles | The business roles to modify |
| Target system | The system the roles belong to |
| Target roles | The system roles to attach or detach |
This is the tab that answers whether a business role is safe by construction. A business role that combines two system roles from different processes can carry a conflict that neither system role has on its own, and it will then reproduce that conflict on every user it is assigned to.
Craft Business Roles
Build a business role that does not exist yet, then analyze it.
| Field | Meaning |
|---|---|
| Name | The name the business role would have |
| Description | What it is for |
| Target system | The system its roles come from |
| Target roles | The system roles it would contain |
Use it to validate a proposed business role catalogue before any of it is provisioned. Crafted business roles can be assigned to simulated users, so a whole intended model is testable end to end.
Scope Note
MTC Skopos analyzes IAM business roles and simulates changes to them. It does not write anything back to your IAM system and does not trigger provisioning. The output is analysis and evidence you act on in your own tooling.