Administrator guide
Collections and entitlements
Take an imported application through Collection Onboarding so people can ask for its access.
A collection is one application or source of access: an ISC source, an IdentityIQ application, an Entra group set or application, or an application you fulfil by hand. Its entitlements are the pieces of access people ask for.
A sync creates collections and entitlements with the status Onboarding. Requesters cannot see a collection until you take it through Collection Onboarding and make it live.
Open Collection Onboarding
Open Warde > Collection Onboarding, or the Setup item on the Admin Workspace rail. Without a collection named, the wizard opens on Choose a collection, a table of every collection with its status, entitlement count and engines. Select Set it up on one.
From a collection record in the Admin Workspace, the Guided onboarding button opens the wizard on that collection. The workspace list Catalog > Collections: onboarding shows everything still waiting.
Collection Onboarding needs the Warde administrator role.
The eight steps
1. Describe the application
Requesters see the name and description in the catalog, so write the description in their words. A configuration item is optional; with one, the next two steps can read the owner and support group from the CMDB.
If the engine names the collection (ISC sources and Entra applications and catalogs do), the name follows the engine and you rename it there. Warde renames the collection, its entitlements' labels and everything that shows them on the next sync.
2. Assign the owner
The person accountable for this application. Search for them, or choose from the people the CMDB links to the configuration item. The owner can be a reviewer for access reviews and appears on the collection's records. Approvers are set in the approval policy, not here.
3. Choose the support group
The group that gets a task when access has to be granted or removed by hand, and what that task tells them to do:
| Setting | What it does |
|---|---|
| Support group source | A fixed group, or a field on the configuration item that holds one (up to three fields, such as support_group) |
| Fulfilment group | The group, when the source is a fixed group. It does not approve anything. |
| Fulfilment instructions | How to carry out a manual grant or removal, copied into every task. An entitlement's own instructions replace these. |
| Grant and removal task templates | Catalog task templates applied to this collection's tasks |
If the group is inactive or has no active members, the task goes to the fallback group from Guided Setup step 8. The step summary says where tasks will go.
4. Decide how requests are approved
| Setting | What it does |
|---|---|
| Approval policy | How requests for this collection's access are approved, when the entitlement or bundle has no policy of its own. Empty uses the instance default. |
| Removal approval policy | How removals are approved, when the entitlement has no policy of its own |
| Pre-approval mode | Whether entitlements here can be pre-approved into access bundles. Empty means allowed. |
| Important information | A notice shown to requesters on the form and to approvers |
| Important approval information | A notice for approvers only. Requesters never see it. |
| Terms | Terms the requester must accept before submitting. Leave empty for none. |
The summary warns if the chosen policy has no rules, or if there is no policy here and no instance default: requests for the collection would stop.
5. Set the expiry policy
| Expiry mode | Meaning |
|---|---|
| Optional (the default) | The requester may set an end date |
| Required | Every request must set an end date |
| Disallowed | Access in this collection never has an end date |
Expiry max days sets the longest a grant may last. Empty means no limit. When access expires, Warde removes it the way Guided Setup step 8 says, after emailing the person 14 days before and the person and their manager 3 days before.
6. Choose the audience
User criteria for who this collection's access can be requested for. Empty means everyone. The person the access is for must match, whoever fills in the form.
7. Review the entitlements
Each entitlement needs an owner and a description. The grid lets you edit several at once with the bulk bar.
| Field | What it does |
|---|---|
| Owner | Approves the entitlement's inclusion in bundles, and can be the reviewer in access reviews |
| Description | What the access lets someone do, in plain words. Requesters and reviewers see it. |
| Risk rating | Reviewers see it. High-risk access is not pre-approved into bundles unless pre-approval is allowed. |
| Requestable | Turn it off for anything people should not ask for. It can still be part of a bundle. |
| Licensing bound | Whether each grant uses a paid licence. Shown to requesters and reviewers. |
| Requires | Other entitlements that must be granted with this one. Warde adds them to the request. |
| Replaces | An entitlement this one supersedes. When someone is granted this one, Warde removes the old one from them once the new access is in place. |
| Lifecycle state | Active, Deprecated (cannot be added to bundles) or Retired (cannot be granted) |
A setting on an entitlement replaces the collection's, except the audience, important information and terms of use, which combine with the collection's.
Clean up entitlement names. Engines often name entitlements in ways nobody outside IT reads, such as CN=APP-FIN-GL-RO,OU=Groups. A name rule on the engine, which a collection can override, rewrites the label people see with a pattern and a replacement. The engine's own name is kept read-only beside it.
Automated in the identity system. Tick this on a collection, an entitlement or a bundle when your identity system grants and removes that access by its own rules, such as an ISC role with membership criteria or an Entra dynamic group. Warde then leaves that access to the identity system: it is not offered for request or removal, is left out of reviews and leaver removals, gets no expiry, and shows on My Access as given automatically. Access an engine reports as given by its own rule is treated the same way without the tick.
8. Go live
Going live sets the status:
| Status | Meaning |
|---|---|
| Managed | An engine is bound. Warde grants and removes through it, and uses tasks only for what the engine cannot do. |
| Unmanaged | No engine is bound, so every change is a ServiceNow task for the support group |
| Onboarding | Being set up, hidden from requesters |
| Retired | No longer used |
If any step still has a warning, the button reads Go live anyway. You can move a collection back to Onboarding at any time with Move to Onboarding. Going live and moving back are both written to the audit history.
Request posture
Each collection also has a Request posture, set on its record:
- Search and guided (the default): its access shows in a plain search, and in guided questions.
- Search only.
- Guided only: hidden until the requester picks the collection and answers its questions. Use it for large collections where a search would return too much.
Collections with no engine
For an application with no identity engine behind it, create the collection by hand in the Admin Workspace, add its entitlements, then onboard it. Every change becomes a task for its support group. See ServiceNow tasks and accounts.
Keeping an eye on the catalog
The Admin Workspace's Access health dashboard has tabs for collection and entitlement health, and the Data quality lists show requestable entitlements with nothing to fulfil them, entitlements with no owner, and live collections with no fulfilment group.