Skip to Content.
Sympa Menu

grouper-dev - [grouper-dev] deprovisioning screen in Grouper

Subject: Grouper Developers Forum

List archive

[grouper-dev] deprovisioning screen in Grouper

Chronological Thread 
  • From: "Hyzer, Chris" <>
  • To: "" <>
  • Subject: [grouper-dev] deprovisioning screen in Grouper
  • Date: Fri, 20 Jan 2017 19:39:04 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:b1y0xhwS5XxAGZjXCy+O+j09IxM/srCxBDY+r6Qd2ukWIJqq85mqBkHD//Il1AaPBtSHra4fwLOM7ejJYi8p2d65qncMcZhBBVcuqP49uEgeOvODElDxN/XwbiY3T4xoXV5h+GynYwAOQJ6tL1LdrWev4jEMBx7xKRR6JvjvGo7Vks+7y/2+94fdbghMizexe7x/IRu5oQnMqMUbgJZpJ7osxBfOvnZGYfldy3lyJVKUkRb858Ow84Bm/i9Npf8v9NNOXLvjcaggQrNWEDopM2Yu5M32rhbDVheA5mEdUmoNjBVFBRXO4QzgUZfwtiv6sfd92DWfMMbrQ704RSiu4qF2QxLulSwJNSM28HvPh8JwkqxVvQ6hqRJ8zY7VfI6aO+FzcbnBcd8GX2dNQtpdWzJHD4ihb4UPFe0BPeNAooXzpVUPrRq/Che2BO/31zRFmH/23bc70+Q6Hw3NwQstH9cSv3TUrNT0NbkdUfquwanJ1jXMc+la2Srl6IfWdBAhp+uAUqxtfsrM0EQiER7OgFuXqYzgJTyV1+INvnCa7+pmSeKglXQnqwdvrTiz2MsgkJfGiZ8Iyl3C6C53w541KMWmREFhfdKoDZ5duzyHO4drR84iTW5ltDomxrADu5O0YicHxIoiyhPadfCLb4aF7gr+WOufPTt0nnZodK+lixqs7EStzvfwWtS23VtLqCdOj8PCuWoX1xPJ78iKUvt98Vml2TaIzw3d8v1JL0comabGMpIs37w/moQKvUTEBSD5hl/6jKiLdkU44eeo7PnnYrP7qZOGL490kAb+MrgwlcOjHeQ4Mw8OX26B9eS7yb3j4Un5QLJNjv01iKXWrJfaJcEDqq64BQ9azJoj5g6hAzi8zNgUgHwKIE9YdB6aioXpNV7DLOzkAfq6gVmjjjhmy+7DM7DkHJnBMnbOnK/kfbln6k5czAQzzcpY55JRErwBJe78Wk/xtd3ZEBA5KRe5w+f8CNphzI8eRHqPDbGfMKPUq1OH+P8gI/SUaI8PpDn9M+Ql5+LpjXIhll8dZ66p3YYPaH+mBPRqOliWbmTygtoaFWcKvxE+TPDxiFGcSzJTZnCyX74i6TEhDoKpE5vDSp63jLOfwSi7A84eWmcTQF+WFmrwep/BV/oSQCOUPsJ7lDEYD/6sR5JrnUWhrgjn07d9a+bZ5AUZs47uzt54+7eVmB0vo29aFcOYhiutXnN5hCdAbD8s3bs16Rh4wVeSw6Viq/1DHppO//5PVEE3OYOKnL8yMMz7Rg+UJoTBc12hWNjzWTw=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

I would like to have a deprovisioning screen in the Grouper UI.  Here are my thoughts.  What do you think?  Maybe instead of big email discussion you could add a comment to the document or email me directly and I can do that.


This is a design document for deprovisioning support in Grouper.  Comments welcome.

Deprovisioning in Grouper allows a deprovisioning administrator to see someone access and instantly remove it.  It would also help notify application administrators where grouper is not the system of record.

  1. The Grouper UI could have a one-pager for deprovisioning.
  2. Users of this screen would need to be in a certain group.  Grouper admins would also be allowed to use this page
    1. Note: users of this screen would effectively have a lot of access in grouper.  They can pull up any subjects and see what they have.  They can remove most things.  But they do not have to be Grouper admins.  This screen could be used by an HR person.
  3. This screen could be disabled if an institution does not want it.
  4. The screen would start with a subject lookup for someone to be deprovisioned
  5. When submitting that combobox, all the assignments in grouper would display, as well as deprovisioned status
  6. A button "Add to deprovision group" could add the user to a preset group for people who will be deprovisioned.  
    1. This group should have a membership expiry for a certain amount of time (1 month is the default)
    2. This group can be used in "exclude" groups or rules in grouper
    3. Note, some institutions might already have this "lockout" group
  7. Assignments on screen will include memberships, privileges, permissions, and attributes(?)
  8. The screen will have checkbox about assignments to deprovision
  9. There could be a way to see effective as well as immediate assignments, though it will default to immediate (ones you can deprovision)
  10. There will be a "check all" and "uncheck all" button
  11. An "unassign" button will remove all those assignments
    1. All assignments could be stored temporarily in attributes so that the state could be restored (future feature if people interested)
    2. At the very least, the stuff unassigned could be logged and emailed to the user using the app so they could piece it back together.  Maybe grouper import script or GSH?
  12. Groups and folders could have attributes related to deprovisioning
    1. Mark a group or folder as ineligible for deprovisioning (e.g. the lockout group)
    2. Mark a group or folder with attributes so that emails are sent out to application owners to deprovision that user.  This would not remove the assignment in grouper because in this case grouper is not the source of the assignment but instead reflects it in another system.   The receiver of the email would need to unassign the user and that data would flow back to grouper ater the next load
      1. e.g. an attribute to say "deprovision_notify_app_owner", an attribute "deprovision_notify_app_owner_email", attribute "deprovision_notify_app_owner_email_subject", "deprovision_notify_app_owner_email_body"
  13. There could be a feature in loader jobs to not load deprovisioned users (without having to adjust the query).  Of course loader jobs could be exempt from this if they need deprovisioned users inside.  The default would be to not include them
  14. There could be a report of deprovisioned users and assignments they still have access to so that followups can be made after a week or two to make sure everything is removed for that user that should be
  15. There could be a report of inactive users and things they are still assigned to to clean out users who left the institution long ago


  • [grouper-dev] deprovisioning screen in Grouper, Hyzer, Chris, 01/20/2017

Archive powered by MHonArc 2.6.19.

Top of Page