WardeDocs User Guides Admin Guides warde.app

Admin Guides / Collections and entitlements

Catalog health

Keep collections and entitlements complete and current after go-live, using the Access health dashboard and the data quality lists.

A catalog drifts after go-live: engines add and remove access, owners leave, support groups empty out. The Admin Workspace's Access health dashboard counts the gaps, and every count opens the list behind it.

Collection health

The Collection health tab, "Collections, who supports them and what they offer", counts:

AreaTiles
OnboardingCollections in total, live collections, still onboarding, onboarding for over 30 days
OwnershipNo owner, owner is inactive
AudienceLive, and offered to everyone
Manual workNo fulfilment group for manual tasks, fulfilment group is inactive, fulfilment group has no active members, task template is inactive
EnginesManaged with no active binding, bindings on an unmanaged collection, bindings on an engine that is not healthy, bindings on a disabled engine, containers the engine has stopped reporting, active bindings
What it offersNo entitlements at all, live and nothing can be requested

Its charts show collections by status, by request posture and by fulfilment group, active bindings by engine and type, and active and requestable entitlements by collection.

Entitlement health

The Entitlement health tab, "Entitlements, their fulfilment and their sync status", counts:

AreaTiles
CatalogActive entitlements, requestable entitlements, requestable but not active, requestable with the collection not live
CompletenessRequestable with no owner, owner is inactive, requestable with no risk rating, requestable with no description, expiry required with no maximum set
FulfilmentBound to an active binding, unmanaged (every change is a manual task), unmanaged with no fulfilment group, not fulfillable with no fulfilment group, the engine cannot grant it
SyncBound to an inactive binding, on an engine that is not healthy, the engine has stopped reporting it, on an active binding but never seen by sync, duplicate entitlements
LifecycleDeprecated with nothing replacing it, replaced access held beside its replacement, bundles carrying replaced access, people who still have retired access, active inside a retired collection

What to check, and when

WhenCheck
After each catalog syncRequestable with no owner, requestable with no description, duplicate entitlements
WeeklyOnboarding for over 30 days, no fulfilment group for manual tasks, the engine has stopped reporting it
Before an access reviewOwner is inactive (reviews by owner go to the fallback reviewer), people who still have retired access
After an engine changeBindings on an engine that is not healthy, managed with no active binding

The data quality lists

The Admin Workspace list menu's Data quality category holds the same questions as lists you can work through:

Renames and removals

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.