← Back to plugin index

Simple Risk-based Role Derivation

Description
An access policy rule deriving new roles from existing roles and Risk Tags.
Type name
SimpleRiskBasedRoleDerivation
Class
com.airlock.iam.authentication.application.configuration.risk.accesspolicy.SimpleRiskBasedRoleDerivationConfig
Properties
Required Roles (requiredRoles)
Description
If defined, this rule only matches if the user has at least one of the specified roles.
Attributes
String-List
Optional
Mandatory Risk Tags (mandatoryRiskTags)
Description
If defined, this rule only matches if the user has all of the specified Risk Tags.
Attributes
Plugin-List
Optional
Assignable plugins
Excluding Risk Tags (excludingRiskTags)
Description
A list of Risk Tags that must not be present.
Attributes
Plugin-List
Optional
Assignable plugins
Target Role (targetRole)
Description
The resulting role if all required roles and risk tags can be satisfied.
Attributes
String
Mandatory
Example
strong
YAML Template (with default values)

type: SimpleRiskBasedRoleDerivation
id: SimpleRiskBasedRoleDerivation-xxxxxx
displayName: 
comment: 
properties:
  excludingRiskTags:
  mandatoryRiskTags:
  requiredRoles:
  targetRole: