How to Control Who Can Assign System Permissions
You can control who is allowed to view an access management system and assign its associated permissions to other users. This is managed using the Available for setting within a permission grouping.
By applying a rule set to this setting, you can define specific criteria for who can act as an administrator for that system.
For example, you could create a system called "Education Services" and configure it so only managers within the Education department can see the system and assign its roles, licenses, and permissions to their employees.
Explanation of the rules
This rule set grants access if any of the following conditions are met:
Rule 1 AND Rule 2: The user is a manager and is employed in one of the specified departments (in this case, "HR and organization" or its sub-departments).
Rule 3: The user is included in the linked rule set "Access: All with servicedesk access and higher," which grants access to anyone with the
servicedeskbruker
permission or higher.Rule 4 AND Rule 5: The user belongs to the correct department AND has the specific "Manager" permission role assigned to them.
Note: You can easily customize these rules for your organization using the rule set wizard.
Video
https://youtu.be/5mtGSN8sJ4w