How to handle expired / deleted employees in case of DEM

How to handle expired / deleted employees in case of DEM

We are importing the DEM first and then generating the Authorization records based on the imported data. The DEM import creates (if not already there) all the attributes such as employees, diagrams, roles sessions etc. and also creates the relationships, such as Employee to Role relationship. If then an Employee is removed/deleted from DEM and we do a new import, it overwrites / resets the existing data and relationships. If however the employee is deleted from the DEM, its record is no longer there, nothing gets reset and thus the Employee Role relationship remains in the Dynaflow Compliance Repository and results in authorizations if the Access Scan is done.

 

So to avoid the above situation, it would be best if an employee is no longer active, to leave the employee in the DEM, remove all DEM  roles that are linked to this employee and use the end of employment date. When the next DEM import is done, and the end of employment date is today or earlier, the employee is expired. Since there are no longer any roles associated to the employee, the reset of the relationships will remove the roles and all is ok.

 

If however the employee is deleted from the DEM , there is the option to “Purge EZ-Process/DEM Role relationship” in the administration section of the client. This option will remove all Employee Role relationships in the Dynaflow Compliance tables. If then an access scan is done no authorizations are generated for the user which was deleted and if the detect terminated employees is checked, these employees are also expired. (note that when using the detect expired employees, you should avoid using any filters on for example employees or roles etc.)

 

So there are 2 ways to coop with this situation:

 

Option1

  •          Put end of Employment date on Employee in DEM
  •          Remove all DEM roles for this Employee
  •          Export DEM
  •          Import DEM in Dynaflow Compliance
  •          Execute Access Scan

Option 2

  •          Remove Employee in DEM
  •          Export DEM
  •          Purge EZ-Process / DEM Role Relationships
  •          Import DEM in Dynaflow Compliance
  •          Execute Access Scan with detect terminated Employees (and no filters)

    • Related Articles

    • DEM Import Automation

      https://dynaflow-solutions.com/Documents/DEM_Import_automation_R6.pdf
    • DEM Access Scan - Resulting Access Mode for DEM Authorizations

      Upon completion of the DEM Import (all versions) the Compliance Access Scan, generates the authorizations based on the loaded DEM data. The following cascade logic is applied to set the Access Mode (privilege) of the resulting authorization record. ...
    • Release Notes EZ-Compliance 2020a (build 1.20.10.3133)

      See attached document for full details. New and/or Adjusted Functionality DEM Import In the situation that a Process Activity points to another Process, the Activity-to-Role Access Mode is assigned to the (sub) Process-to-Role, instead of the ...
    • Release Notes EZ-Compliance 2022a (build 1.22.10.4144)

      New and/or Adjusted Functionality Merge of the EZ-Compliance and EZ-Dashboard client (TICKET 1836)  EZ-Compliance and EZ-Dashboard are merged into one Client Application. The EZ-Dashboard functionality can now be found under the Master Data menu: ...
    • Release Notes EZ-Compliance 2022a-SP1 (build 1.22.11.4332)

      New and/or Adjusted Functionality Access Scan – EAMS (TICKET 1885) In the Access Scan a new option is added in the section Child Option/Filters. In the sub section “Include Child Access Points in Scan” the option “Both (satellite Sessions ...