Skip to main content

Creating Role Definitions

Role Definitions bundle multiple app rights into reusable groups, enabling efficient access management across PBAC-enabled applications. By grouping rights that represent common job functions or responsibilities, administrators can streamline access assignments and reduce administrative overhead.

Role Definitions in PBAC

Role Definitions provide a structured way to grant multiple related app rights as a single package. This simplifies access management when users need consistent sets of permissions.

This article demonstrates how to create Role Definitions in EmpowerID.

Prerequisites

Before creating Role Definitions, ensure you have:

  • Access to Resource Admin with the Application RBAC Owner Management Role (or higher)
  • An existing PBAC application with app rights available for inclusion in the role definition

Procedure

  1. In Resource Admin, search for the PBAC application for which you want to create Role Definitions.

  2. Click the Details button for the application to open the Application Overview page. Application search results

    The Application Overview page opens. Application Overview page

  3. Expand PBAC Definitions in the left navigation and select Role Definitions.

  4. Click Create Role Definition. Create Role Definition button

    The Onboard Az Local Role wizard opens.

  5. Complete the wizard sections with the appropriate information for the role definition.

    Role Definition Information

    FieldAction
    NameEnter a unique internal name without spaces.
    Display NameEnter a user-friendly label.
    DescriptionEnter a description of the role definition.
    Instructions(Optional) Enter guidance or usage information.
    LocationSelect the EmpowerID location where the role definition applies.
    App Rights OptionsChoose whether to assign app rights now or later.

    Owner Information

    FieldDescriptionAction
    Responsible PartyPrimary accountable personEnter the responsible party's name (required).
    OwnersGovernance ownersEnter owner names (optional).
    DeputiesBackup approvers or contributorsEnter deputy names (optional).

    IAM Shop Settings

    FieldDescriptionAction
    Requestable in IAM ShopMakes the role definition visible for self-service requestsEnable or disable as needed.
    Access Request PolicyDefines the approval policy for requestsSelect the appropriate access policy.
    Eligible to RequestDefines eligible requestorsSelect assignee types (e.g., Person, Group).
    Pre-approved for AccessAutomatically grants access to specified usersDefine pre-approved users or groups.
    Suggested AssigneesShows the role definition as recommended for certain usersConfigure assignee suggestions.
  6. (Optional) If you chose to assign app rights in the wizard, select the applicable app rights and click Next. Selecting app rights for role definition

  7. Review the summary for accuracy. Use the Back button to make corrections if needed. Role definition summary review

  8. Click Submit to finalize the role definition.

  9. Repeat steps 1-8 to create additional role definitions for the application as needed.

Verify the Results

After submission:

  1. The new role definition appears in the Role Definitions list for the application. Role definition added to list
  2. Click the Details button to view or manage app rights assigned to the role definition. Role definition detail view

Next Steps

After creating role definitions, assign them to users or groups who need the bundled set of app rights.