Assignment policy
In Omada Identity, RoPE uses assignment policies for assigning resources to identities.
An assignment policy defines that a set of identities should be assigned to a set of resources. You can define the identities in scope by specifying one or more business contexts and/or using an identity view.
An assignment policy does not need to be scoped on both using a view and business context(s): You can scope both or only one of the two.
We recommend to keep the number of used scoping views low, as it adds an extra load on RoPE when many scoping views are used.
Assignment Policies and Account Types
When creating an assignment policy using an Application role (personal account only) with a child resource (called resource below), take into consideration the following cases:
| If the Assignment policy is assigned to... | And the Resource is for... | Then... |
|---|---|---|
| Personal | Admin | Nothing is assigned. |
| Personal | Admin and Personal | If the identity has a personal account or if auto-account is enabled, then an assignment is made for personal account. |
| Personal and Administrative | Admin and Personal | The resource is assigned to both admin and personal accounts if the identity has such account or it auto-account is enabled. |
| (none specified) | Admin and Personal | Because the Application role allows only Personal, RoPE resolves the assignment to Personal only. If the assigned role allowed both account types, RoPE would resolve one assignment per allowed account type, with each assignment scoping its child resources to that single type. |
Account type handling for child resource of account resources
For direct assignments and assignment policies, a configured account type applies to the referenced resource. The resource is therefore assigned only to an account of that type.
This is different from the account type or account types for which the role resource itself is defined. For more information, see Determining the account type(s) of a resource. The account types defined for the role resource do not filter its child resources.
The account type scope carried by the specific direct assignment or assignment policy that caused the role to be assigned to an identity does cascade to the role's child resources. For more information, see the table above and Account types.
For example, Role X is defined as valid for both Personal and Administrative account types. An identity is given Role X through a direct assignment scoped only to Personal.
Role X's definition allowing both account types does not widen the assignment. Because the assignment that caused Role X to be assigned is scoped to Personal, Role X's child resources are also scoped to Personal for that identity, regardless of which account types Role X itself is defined for.