Reports
Hitachi ID Access Certifier includes a variety of built-in reports relating to the access certification process:
- Security change requests that result from a certification round.
- Certification rounds performed.
- Applications whose users and group memberships were audited.
- Security groups whose memberships were audited.
- Statistical analysis of completion of active certification rounds.
- Details of what users, accounts and group memberships have been reviewed, by whom and when.
There are also built-in reports to enumerate users and entitlements, independent of the certification process, including:
- List users.
- List accounts (i.e., users per system/application).
- List groups.
- List user membership in groups.
- List roles.
- List role assignment to users.
Each report supports a range of data filter options, such as certifier identification, resource identification, certification round ID, date ranges, etc.
Access Certifier's back-end database is SQL-based and a data dictionary is provided. This means that standard, off-the-shelf reporting programs such as Crystal Reports and Cognos can be used to develop custom reports with ease.
Access Certifier customers can also run standard Hitachi ID Identity Manager reports, in particular relating to what users have what entitlements:
All data in Access Certifier is available via SQL or ODBC and accessible using standard analytical tools (Crystal Reports, Cognos, MS-Excel, SQL queries, etc).
The schema is well documented and is available to all product licensees and evaluators under NDA. The current release schema documentation is about 127 pages long, and includes detailed descriptions of every field, table, relation, value constraint, etc.
Data available through Access Certifier includes:
- A list of IDs per user.
- A list of IDs per system.
- A list of IDs per group.
- Allocation of login IDs to user profiles.
- Full detail of transaction history.
- Additional identity attributes (e.g., roles, employee ID) for users who were created using Identity Manager.
- Select identity attributes drawn from target systems -- such as last login time/date, account enabled/disabled, etc.
Access Certifier includes a number of standard reports, available through a web user interface, from the command-line, or by e-mail:
- Orphan and dormant accounts.
- Users who have accounts on specific systems.
- Templates and roles that a particular user has been assigned.
- User groups available on target systems.
- Membership of users in user groups on target systems.
- Transaction history per time period.
- Authorizer actions.
- Delegations (current and pending).
- Implementer definitions.
- Physical inventory availability.
- Requests, by status, state and result.
- Request statistics.
- Identity attributes, by user and by system.
- Past Reports.