WardeDocs User Guides Admin Guides warde.app

Admin Guides / Access bundles

Build a bundle

Create an access bundle in the Admin Workspace, take it through pre-approval and make it live.

Administrators build bundles directly in the Admin Workspace, with no approval of their own. Anyone else proposes one with a request: see Propose a bundle.

1. Create the bundle

Open Catalog > Access bundles in the Admin Workspace and create a bundle. It starts as a Draft.

FieldWhat to enter
NameThe name requesters see, usually the job, such as Accounts payable officer. Lifecycle integrations find bundles by name, so choose one that will last.
DescriptionWhat the bundle gives and who it is for
OwnerThe person responsible for what it contains
Bundle typeRequestable, or Birthright for bundles your joiner process grants
Available forUser criteria for who it can be requested for. Empty means everyone.
Approval policyHow requests for it are approved. Empty uses the instance default.
Automated in the identity systemTick when your identity system gives this whole bundle by its own rules

2. Add the access

Add entitlements on the bundle's related list. To start from what someone already has, set Copy access from to a person and select Copy access from user. Their current access is added to the draft; anything that cannot be in a bundle is skipped and listed.

Entitlements that cannot be in a bundle: deprecated or retired ones, ones that must have an end date, and PIM-managed groups.

3. Submit for pre-approval

Select Submit for pre-approval. The bundle moves to Pending pre-approval, and each entitlement's owner and approvers are asked, by email, whether their entitlement may be included: Access bundle items waiting for your approval. They decide with Approve inclusion or Reject inclusion, which entitlement owners can do with the requester role.

If nobody is found to decide an entitlement, an administrator decides it from Catalog > Bundle entitlements: pending pre-approval.

While a bundle is pending:

4. Activate

When nothing is waiting for a decision, the owner gets Your access bundle is ready to activate, and so do the administrators who review bundles if the owner is not one. Select Activate. You cannot activate a bundle while any entitlement is pending or rejected.

An active requestable bundle appears on the Access Bundles form for everyone its audience allows. An active birthright bundle can be granted by your joiner process.

Only a draft can be deleted. Once a bundle has been submitted, it is retired rather than deleted.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.