TORC: The OneRoleConcept
TORC: The OneRoleConcept benefits with IdM Flexibility Simplicity Transparency
Flexibility:  Works with existing security concepts and is designed with focus on IdM. Simplicity: Simple solution with a minimum of roles. Transparency: Roles can be recognised across systems. TORC will reduce the amount of roles = More transparency of security. TORC: gives you one business role described by one global SAP role = Simplicity. TORC: Aligns the roles across HR used systems, which gives overview of security.       The OneRoleConcept is giving you: Easy access to control user account’s for specific business roles. Easy trace of users with access to specific transactions and why the have this. Easy audit of users and their assigned authorizations. Deliveries in TORC solution: Authorization Concept which is scalable and flexible. You choose if TORC should be used for all HCM business roles or only for segments of your business roles. The remaining business roles can continue to be in operation side by side with TORC. Tools for automatic assignment and removal of roles = no hands on = reduced IT workload in operation and reduced amount of issues. TORC gives you the option to hand the business control of maintaining standard changes  = reduced IT workload = reduced operational costs. •     TORC gives full Overview of access rights in HR related systems so you. •     TORC has no impact on the SAP licensing pr user, but helps you identifying the professional users since we operate with a limited number of roles. IdM Assignment and building of roles. The OneRoleConcept is flexible and scalable and can be implemented for single business roles or for the entire HCM portfolio of roles. You will together with the business select the security method, which is best fit for each business role and then decide to use TORC or existing concept. The OneRoleConcept works together with principles such as Master/Derived, Organisational/ Functional roles and Single roles. The reduced number of roles, which is characteristic for TORC is optimal for IdM processes. The assignment of roles can be optimised with TORC since it segregate the content/ (Who and where you have access) from the functional part / (What you can) Since TORC is an intelligent based access right concept it will based on the users attributes grant access. It follows the ABAC principles. Attribute based access rights. A user will as thump of rule have one role assigned according to his/ here position, but it does not restrict the business from assigned a user several business roles such as a both manager and HR partner role. With Functional roles transaction codes will only exist in one role It is easy for the business to find the right role It is easy for auditors to trace transactions and to identify why users is assign this access. Automatic assignment and delimitation of roles to users can be based on attributes from the employees organizational assignment.  These assignments will determine the role assignment 100% automatic without any request or IT involment. When we use attribute based assignment the role will be automatically assigned when the employee enters the organization and the role will be removed when the employee is leaving the department so a clean up of role assignment is not necessary. there is also the option for enhancing the role assignment with an ABAC rule set where we assign the roles to a user in case the user fullfills teh criterias for being assigned the role. see also page on this site which describes IdM
