View and change identity details¶
Viewing the details of an identity can help you see additional details such as Active Directory information, the applications an identity has access to, and the responsibilities they've been given within Permission Assist.
To view the details of an identity, select an account in the Identities list. The Identities / Details page is displayed.
Directory info¶
When opening the Identities / Details page the Directory Info is displayed by default, which provides more detailed directory source information about the account.

Change an identity type¶
Within Permission Assist, identities can be classified as specific types such as employee, service account, vendor account, and so on. Identity types can be helpful for sorting/searching, and are also used by Permission Assist to create recommendations. The identity type is displayed within the Identity Details / Directory Info area on the right side of the page.
To change the type of an identity, complete the following steps:
- On the Identity Details page, select Directory Info.
- Select the Type link within the Directory Info area (displayed on the right side of the page). The Change Type window appears.
- Select the Type field and then select a new type from the list.
- Select the Change button.
Add or change information to custom fields¶
If your Permission Assist Administrators have defined additional fields, the Custom Fields section is displayed within the Directory Info tab, below the directory information table.
To add or change custom information to an additional field, complete the following steps:
- On the Identity Details page, select Directory Info.
- In the Custom Fields section, select the value to the right of the field name. The Edit Custom Information window is displayed.
- Enter the information in the fields.
- Select the Save button. The page is reloaded with the updated information.
Organization chart¶
Selecting Organization Chart allows you to view the identity's supervisors and direct reports, if applicable. To view the details of a supervisor or direct report, select their name.

Also known as¶
Selecting Also Known As allows you to view a list of employees that have been consolidated with this Identity. Sometimes, employees will have multiple Active Directory accounts to accommodate various situations; for example - their standard account, an admin account for one or more applications, an account for when they visit Branch A, and so on. In the past, Permission Assist considered each of these accounts as separate Identities. Now, you can have all of these accounts associated with a single primary account - all considered a single Identity.
In the example shown below, Abel Solomon is a Human Resources Specialist. Abel has a standard Active Directory account, but he also has an additional admin account that is used to access sensitive permissions within specific applications. Using the "Also Known As" feature within the Identity Details page, you can associate the admin account with Abel.

Consolidate identities¶
To consolidate identities, complete the following steps:
- On the Identity Details page, select the Also Known As option (if it's not already selected), and then select the + Add an Identity link in the upper right corner of the Also Known As area on the right. The Create "Also Known As" window appears.

- Select the Choose an identity to associate field and then select the Identity you want to add under this Identity.
- Select the Associate button. The new Identity appears in the Also Known As list. Permission Assist now considers these a single Identity, which allows Permission Assist to match application users to Identities more consistently and also allows for more appropriate recommendations, reports, and workflows.
Detach identities (from the primary identity)¶
- While viewing the Also Known As area for the primary identity, place your cursor over the identity you want to detach.
- Select the Detach button.
The Are You Sure? message appears - Select the Detach button. The identity is removed from the Also Known As list and is now considered an independent primary Identity.
Detach identities (from the associated identity)¶
- While viewing the Also Known As area for the associated Identity, select the Detach this identity from... link in the upper right corner.
The Are You Sure? message appears - Select the Detach button. The primary Identity is removed. from the Also Known As list.
Responsibilities¶
View responsibilities associated with an identity¶
Selecting Responsibilities on the Identity Details page allows you to see which responsibilities the identity has within Permission Assist. A red circle with a line through means the identity does not have that responsibility. A green check mark means the identity does have that responsibility.

For additional information about the responsibilities for each role, refer to the table below.
| Role | Description |
|---|---|
| Administrator | An identity is an administrator if the identity belongs to the Administrator group within the System Configuration > System Authentication area |
| Security Team | An identity is a Security Team member if the identity belongs to the Security Team group within the System Configuration > System Authentication area |
| Application Manager | An identity is an application manager if the identity is added to the Application Managers field within an application (Manage > Applications > select the application > Responsibilities tab) |
| Area Reviewer | An identity is an area reviewer if the identity is the assigned reviewer for a Reviewable Area within an application (Manage > Applications > select the application > Reviewable Areas tab) |
| Provisioning | An identity is a provision engineer in either of the following cases: (1) When the identity belongs to the Provision Team group within the System Configuration > System Authentication area, or (2) When the identity is assigned to the Provision Engineers field within an application (Manage > Applications > select the application > Responsibilities tab) |
| Reporting | Reporting means that an identity has access to all reports under the Reports menu in Permission Assist. An identity is given access to reports when the identity belongs to the Reporting Only group within the System Configuration > System Authentication area |
| Supervisor | An identity is considered a supervisor if: the identity is defined as a supervisor in the Manage By field in Active Directory and if they are assigned direct reports within Active Directory; the identity is the review supervisor for an application user and the application is included in an open review; or the identity is an "on behalf of" supervisor for someone else |
| Access Model Owner | An identity is an access model owner if they are the assigned owner within the settings of an access model |
Set on behalf of reviewers for supervisors¶
If you have supervisors who either don't typically review the permissions of their direct reports or who may be out of the office during a review, the "On Behalf Of" feature allows you to either temporarily or permanently shift review responsibilities to another person.
To assign a reviewer to act "On Behalf Of" a supervisor, complete the following steps:
- Within the Responsibilities area, select the "On behalf of" supervisor is disabled option.
After selecting this option, the option turns green

-
Select the Always Reviews field and then select one of the following options:
Option Description Never Reviews Selecting this option will permanently reassign all review items to a new identity. After selecting this option, select the Select identity field and then select the person who will be reviewing items on behalf of the supervisor. If you have any open reviews and you want this supervisor's items to be reassigned to the new supervisor/reviewer, select the Reassign all open review items to the new user option Temporarily is not reviewing Selecting this option will allow you to temporarily reassign items to a new identity. After selecting this option, select the Select identity field and then select the person who will be reviewing items on behalf of the supervisor. Select the date field to select the day the supervisor returns -
Select the Save button.
Access models¶
View access models associated with an identity¶
Selecting Access Models on the Identity Details page displays a list of access models in which the identity is enrolled. To view more detailed information about one of the access models, select the access model within the list.

Applications¶
View applications associated with an identity¶
A list of applications associated with the identity is displayed in the Applications list on the right side of the page. In order for the application to show up in this list, an application user must be matched to the identity within the application's Users tab.