Manage roles
After you created an environment, create the required ARIS Risk and Compliance-specific roles and assign users to provide them with the required privileges for ARIS Risk and Compliance. Alternatively, you can first transfer the roles from an ARIS database.
ARIS Risk and Compliance users are assigned to roles that represent their GRC tasks and provide the required privileges. Risk and Compliance roles are defined using a role type and a role level. The role type (example: Risk manager) and the role level (example: Environment-specific) of a role (example: Risk manager role Germany) specify which privileges the assigned users have (example: Read privilege for risks and risk assessments). A user can be assigned to several roles at the same time. A role always has only one role type, which in turn has only one role level.
There are no Risk and Compliance roles for system administrator, issue creator, issue owner, issue reviewer, offline operator, and offline editor. The system administrator obtains the required privileges via the corresponding function privilege in ARIS Administration. In Issue Management, a user is assigned directly to a particular issue in the respective role type instead of being assigned via a role. For detailed information on Risk and Compliance roles, refer to Manage users, user groups, and roles in the online help of ARIS Risk and Compliance.
Prerequisite
You have the Risk and Compliance administrator function privilege.
Click
Application launcher >
Administration.
Configuration is displayed.Click Risk and Compliance.
Under DATA MANAGEMENT, click Roles.
Click
Create Roles.
Under Overview, fill in at least the mandatory fields, then click
Save. Enter a role name, and select the role type and role level from the list boxes.
Click User assignment.
Click
Assign users. The available users are displayed. Alternatively, you can assign the users later.
If required, use the search to filter the list of users.
Select the relevant users, then click Add. The users are assigned to the role.
To remove users, click
Remove in the row of the user to be removed. Alternatively, you can remove all users using
Remove all above the users list.
Click
Save and close the panel.
The role is created, and the assigned users have the privileges associated with the role. If the required license privilege is not assigned to users in ARIS Administration the assignment to the role is ignored (
Ignore assignment).
The role object attributes ARIS Risk and Compliance role type and ARIS Risk and Compliance role level can only be changed under certain conditions:
The role has currently no users assigned.
The role was never assigned to a Risk and Compliance object.
This is required for the object-specific role level to avoid data inconsistencies. Example: If you would change the role type attributes of an assigned role from Control tester to Risk manager, this would result in an invalid control test definition. This condition prevents the unintentional modification of privileges for users who are assigned to a role that is not modeled in an ARIS model.
You can Deactivate a role to remove it from the list of active roles, and you can
Reactivate it to redisplay it in the list. To view deactivated objects, enable Show deactivated objects in the
Extended filter.