Create Policy Review Campaigns

As an Administrator or Campaign Administrator of Oracle Access Governance, you can create one-time or periodic access review campaigns from the Oracle Access Governance Console. In this article we will look at how you can create on-demand policy reviews, where you define the selection criteria based on the policies associated with users. You can also define the approval workflow to select the number of review levels, review duration, and reviewer details.

Login

  1. Sign in to the Oracle Access Governance Console with a user assigned either the Administrator or Campaign Administrator application role.
  2. You can select one of the following options to navigate to the Campaigns screen:
    • On the console home page, click the Select button on the Let's create some work and define a new campaign tile.
    • Click the Navigation menu icon, and select Access Reviews, and then Campaigns, then click the Create a campaign button.

    You will be navigated to the Create a new access review campaign workflow screen, from which you can define and configure your policy review campaign.

Selection Criteria

By default, all identity data ingested from the connected system is available to the access review campaign. This may be a large amount of data, so selection criteria allows you to narrow the criteria available for the campaign:

Criteria for policy reviews can be filtered based on:
  • Which Policy

Note:

If you select the policy criteria, user criteria selection is no longer applicable and is disabled.
Additionally, you can also add the following filter in combination with those listed above:
  • Which cloud providers

These criteria can be chosen and edited in any order before moving on to the next step. If you do not need to update each dimension, you can select any number from those above, and leave the remaining unchanged. If you do not need to narrow the criteria for your enterprise, then you can choose to move to the next step without adding any selection criteria.

Note:

All criteria can be searched by name
  1. Select the Which cloud providers? tile to specify criteria based on a specific cloud provider. Actual values for this parameter will depend on the target system you select.
    1. If you want to restrict the values further, click on theMenu menu icon, and select Refine further. In the Cloud provider pop-up, you can further refine your criteria by specifying one or more compartments, and/or one or more domains from the cloud provider you have select in the main step.
  2. Select the Which Policy? tile to set criteria for policies.
  3. On selecting this tile, you can select criteria for the following parameters:
    • Policy name
    • Policies created since a given date
  4. Make your selections and when finished, click on Apply my selections or Cancel as appropriate. You are returned to the Create a new access review campaign step.

    Note:

    As you make selections of the various criteria, you can see the effect that your selections make and an estimate of the number of review items that your access review campaign will generate. This information is displayed in the section on the right-hand of the page.

    Note:

    If you need to make changes to your selections before moving on to workflows, select the Modify button on the relevant tile and amend as described in the steps above.
  5. When you are happy with your selection criteria, click I'm good, go to workflows button to proceed to the Assign workflow dimension to select the guided workflow.

Assign Workflow

The Assign Workflow step is where the approval workflow for your access reviews are defined. Oracle Access Governance will provide a suggested optimal workflow based on your selection criteria.

If you wish to define your workflow, click the I'll choose my own workflow button.
  1. Policy reviews have only one level of approval workflow. The following value is selected for you:
    • One-level approval workflow
  2. Select how you want the review to be handled. Choose from the following values:
    Parameter Value
    Who is the first reviewer? Defaults to the following value:
    • Cloud provider custom reviewer
    Whom do you want to be the reviewer? If the current reviewer has the correct permissions then this value defaults to Me. If not then the value will default to the first reviewer with either Administrator or CloudAccessReviewer permissions.
    How many days do they have to review? Number of days for each review
    Who gets the notification?
    • Only reviewer
    • Reviewer and manager
    Who do you want to send reminders to?
    • Only reviewer
    • Reviewer and manager
    How many days between reminders Number of days for the gap between reminders
  3. Select where review decisions require a justification. Choose from the following values:
    • Required for all review decisions
    • Required only for revoke decisions
    • Optional for all review decisions
  4. Select the completion rule for the review. This auto performs a default action for all un-reviewed tasks at the end of each approval workflow level. Choose from the following values:
    • Approve all un-reviewed tasks
    • Revoke all un-reviewed tasks
  5. Select Save to save your workflow definition or Cancel to discard your changes.
  6. When you are happy with your workflow definitions, select Save draft to save your campaign for work later on or select Next to proceed to the Add details page.

Add Details

With the Add Details step, you can define the frequency (one-time or periodic) at which to run an access review campaign, give a meaningful name to your campaign, add a supporting description, and assign values to additional attributes, such as who owns it and when the campaign should start or end.

To add details :
  1. Add values for the following parameters for your campaign:
    • How often do you want this to run?: Select One time to run a single occurrence of this campaign, or select a recurring pattern like Quarterly, Monthly, Half-Yearly, or Yearly to run this access review campaign periodically.
    • What do you want to call this campaign?: Add a name for your campaign.
    • How do you want to describe this campaign?: Add a description for your campaign.
    • Who owns this campaign?: Add the name of the campaign owner.
    • How would you like to schedule your campaign?: You can view this field only if you have selected to run your campaign one time. Select either Run now or Schedule Later. By default, the campaign is set to begin at the top of the next hour, the following day of campaign creation.
    • When do you want to Begin?: If you have set a recurring pattern, then select the start date of when you want to begin the campaign series. By default, the campaign is set to begin at the top of the next hour, the following day of campaign creation. If you want to change this, select the Select Date Time icon and add a new date/time.
    • When do you want to End?: If you have set a recurring pattern, then select the end date of when you want to end the campaign series.
  2. Once you have set your preferences, select Next to go to the Review and submit step.
  3. Optional: You may select one of the additional actions:
    • Save Draft: To save your changes and later come back and edit the workflow or details.
    • Cancel: To cancel the current process.
    • Back: To go back to the previous step.

Review and Submit

The Review and submit step displays the information you have added in the previous steps.

To review and submit your campaign :
  1. Select Save draft to save your campaign for work later on or select Create to create the campaign.