Understanding Distributed User Profiles
As your user population increases in size, it can become impractical for one person to centrally administer all of your system's user profiles. You can distribute some or all user profile administration tasks by enabling selected users to use the Distributed User Profiles component (USERMAINT_DIST) to control the granting of selected roles to other users.
The pages in the Distributed User Profiles component are identical to the corresponding pages in the User Profiles component, except that its User Roles page does not include links for editing the assigned roles. You can restrict who can use the component, which users they can administer, and what roles they can grant, based on the roles to which they themselves belong. For example, you might specify that users in the Line Manager role can grant the Shipping Clerk role to other users. The effect of this is to designate line managers as remote security administrators who can administer the user profiles of shipping clerks. In addition to granting and managing roles, a remote security administrator can administer all parts of a user profile, including passwords, email addresses, and workflow.
Important:
Distributing user profile administration might affect regulatory compliance (for example, Sarbanes Oxley). You are responsible for determining and accounting for any effect of using this feature.
To implement distributed user profiles:
-
Use permission lists and roles to configure security to give selected remote security administrators access to the Distributed User Profiles component.
Note:
The PIA navigation path to this component is .
-
Use the Set Distributed User Profile Search Record page to define which user profiles can be administered with the Distributed User Profiles component.
See Defining User Profile Access for Remote Security Administrators.
-
Use the Role Grant page in the Roles component (ROLEMAINT) to specify which roles your remote security administrators can grant with the Distributed User Profiles component.
See Defining Remote Security Administrator Role Grant Capability.