Admin Guides / Collections and entitlements
Catalog health
Keep collections and entitlements complete and current after go-live, using the Access health dashboard and the data quality lists.
A catalog drifts after go-live: engines add and remove access, owners leave, support groups empty out. The Admin Workspace's Access health dashboard counts the gaps, and every count opens the list behind it.
Collection health
The Collection health tab, "Collections, who supports them and what they offer", counts:
| Area | Tiles |
|---|---|
| Onboarding | Collections in total, live collections, still onboarding, onboarding for over 30 days |
| Ownership | No owner, owner is inactive |
| Audience | Live, and offered to everyone |
| Manual work | No fulfilment group for manual tasks, fulfilment group is inactive, fulfilment group has no active members, task template is inactive |
| Engines | Managed with no active binding, bindings on an unmanaged collection, bindings on an engine that is not healthy, bindings on a disabled engine, containers the engine has stopped reporting, active bindings |
| What it offers | No entitlements at all, live and nothing can be requested |
Its charts show collections by status, by request posture and by fulfilment group, active bindings by engine and type, and active and requestable entitlements by collection.
Entitlement health
The Entitlement health tab, "Entitlements, their fulfilment and their sync status", counts:
| Area | Tiles |
|---|---|
| Catalog | Active entitlements, requestable entitlements, requestable but not active, requestable with the collection not live |
| Completeness | Requestable with no owner, owner is inactive, requestable with no risk rating, requestable with no description, expiry required with no maximum set |
| Fulfilment | Bound to an active binding, unmanaged (every change is a manual task), unmanaged with no fulfilment group, not fulfillable with no fulfilment group, the engine cannot grant it |
| Sync | Bound to an inactive binding, on an engine that is not healthy, the engine has stopped reporting it, on an active binding but never seen by sync, duplicate entitlements |
| Lifecycle | Deprecated with nothing replacing it, replaced access held beside its replacement, bundles carrying replaced access, people who still have retired access, active inside a retired collection |
What to check, and when
| When | Check |
|---|---|
| After each catalog sync | Requestable with no owner, requestable with no description, duplicate entitlements |
| Weekly | Onboarding for over 30 days, no fulfilment group for manual tasks, the engine has stopped reporting it |
| Before an access review | Owner is inactive (reviews by owner go to the fallback reviewer), people who still have retired access |
| After an engine change | Bindings on an engine that is not healthy, managed with no active binding |
The data quality lists
The Admin Workspace list menu's Data quality category holds the same questions as lists you can work through:
- Requestable but not fulfillable
- Entitlements with no owner
- Managed collections with no fulfilment group
- Active access never reviewed
- Accounts never synced
- Engines not synced in 24 hours
Renames and removals
- A collection or entitlement named by the engine is renamed there. The next catalog sync renames it in Warde and relabels approvers, bundle members and what people hold.
- An entitlement the engine stops reporting is retired once it has been missing past the grace period (168 hours). If one run would retire more than 500 records, or 10 percent of them, nothing is retired and a sync discrepancy is recorded under Audit > Sync discrepancies.
- To take a collection out of the catalog without deleting anything, move it back to Onboarding in Collection Onboarding, or set it to Retired.