Overview
You can use a wizard to automatically generate email notifications when a user gains or loses a specific access right.
This feature is useful in several scenarios, including notifying:
-
The employee, who can then confirm that they have the necessary access.
-
The employee's manager, who can monitor their team's permissions.
-
A system administrator, who may need to perform additional manual tasks to prepare the system for the user.
This final option is particularly useful for systems that are not fully integrated with Active Directory or Azure. The automated notification ensures that the system administrator receives all the necessary user information to grant access in systems that require manual provisioning.
Procedure
Follow these steps to create a new email notification rule.
-
Go to Access Control in the main menu.
-
In the top-right corner of the Access Control view, locate the
+(Plus) and-(Minus) icons.-
Click the
+icon to launch the wizard for creating a notification when a user gains an access right. -
Click the
-icon to launch the wizard for creating a notification when a user loses an access right.
-
-
In the wizard, select who will receive the notification:
-
Employee: The notification is sent to the employee affected by the change.
-
Manager: The notification is sent to the employee's manager.
-
System Administrator: You must enter the administrator's specific email address.
Note: For the Employee and Manager options, the system automatically retrieves the recipient's email address from their user profile.
-
-
Click Create. The system will now generate the required rule set and message flow.
-
Click the Message Flow button or go to the message flow section to view and edit the new template.
Editing and Activating the Notification
As with all message flows, you can customize the notification email by editing the text and adding or removing merge fields to meet your needs.
Warning: All new message flows are created as inactive by default. You must manually open the message flow and activate it when you are ready to use it.
Creating a message flow without the wizard
Use a separate rule set for each notification. This is to prevent a change in the rule set that triggers the notification from having unintended consequences for other notifications. Furthermore, this also makes it possible to limit the sending to a one-time event using the CountMessage feature.
Warning: Message flows created without using the wizard are set to "Active" by default. We recommend that you set them to "Inactive" while you are working on the message flow. When you are ready to use it, you must manually open the message flow and then reactivate it.