Sun Identity Manager Deployment Reference

ProcedureTo Restrict Administrative View Capabilities

  1. Define new authorization types that extend the WorkItem type. For example, define the RoleApproval type.

  2. Define new capabilities that have rights on the new authorization types rather than WorkItem itself. For example, define a Role Approver capability that has rights on the RoleApproval type.

  3. Assign the Role Approver capability to an administrator rather than the general Approver capability

  4. Set appropriate authorization types in each manual action in your workflows.