WardeDocs User Guides Admin Guides warde.app

Admin Guides / Collections and entitlements

Onboard a collection

Take an imported collection through the eight steps of Collection Onboarding and make it requestable.

Collection Onboarding prepares one collection for requests: who owns it, who does its manual work, how its requests are approved, how long access lasts, who can ask for it, and what each entitlement is called and allowed to do. The last step makes it live.

Open the wizard

Open Warde > Collection Onboarding, or the Setup item on the Admin Workspace rail. Without a collection named, the wizard opens on Choose a collection, a table of every collection with its status, entitlement count and engines. Select Set it up on one.

From a collection record in the Admin Workspace, the Guided onboarding button opens the wizard on that collection. The workspace list Catalog > Collections: onboarding shows everything still waiting.

Collection Onboarding needs the Warde administrator role.

The eight steps

Each step checks the collection when you open it and shows a summary in the left rail, so you can stop and come back later. A step with a warning does not stop you going live.

1. Describe the application

Requesters see the name and description in the catalog, so write the description in their words. A configuration item is optional; with one, the next two steps can read the owner and support group from the CMDB.

If the engine names the collection (ISC sources and Entra applications and catalogs do), the name follows the engine and you rename it there. Warde renames the collection, its entitlements' labels and everything that shows them on the next sync.

Step 1, Describe the application, for Salesforce: the name, a description, the configuration item Salesforce CRM, and the Automated in the identity system tick box
Step 1. The left rail shows each step's summary.

2. Assign the owner

The person accountable for this application. Search for them, or choose from the people the CMDB links to the configuration item. The owner can be a reviewer for access reviews and appears on the collection's records. Approvers are set in the approval policy, not here.

Step 2, Assign the owner, with Priya Natarajan chosen and a button to choose from the 8 people the CMDB links to the configuration item
Step 2.

3. Choose the support group

The group that gets a task when access has to be granted or removed by hand, and what that task tells them to do:

SettingWhat it does
Support group sourceA fixed group, or a field on the configuration item that holds one (up to three fields, such as support_group)
Fulfilment groupThe group, when the source is a fixed group. It does not approve anything.
Fulfilment instructionsHow to carry out a manual grant or removal, copied into every task. An entitlement's own instructions replace these.
Grant and removal task templatesCatalog task templates applied to this collection's tasks

If the group is inactive or has no active members, the task goes to the fallback group from Guided Setup step 8. The step summary says where tasks will go.

Step 3, Choose the support group, with CRM Support chosen, the built-in task layouts and an empty box for fulfilment instructions
Step 3.

4. Decide how requests are approved

SettingWhat it does
Approval policyHow requests for this collection's access are approved, when the entitlement or bundle has no policy of its own. Empty uses the instance default.
Removal approval policyHow removals are approved, when the entitlement has no policy of its own
Pre-approval modeWhether entitlements here can be pre-approved into access bundles. Empty means allowed.
Important informationA notice shown to requesters on the form and to approvers
Important approval informationA notice for approvers only. Requesters never see it.
TermsTerms the requester must accept before submitting. Leave empty for none.

The summary warns if the chosen policy has no rules, or if there is no policy here and no instance default: requests for the collection would stop.

Step 4, Decide how requests are approved, with the Manager then owner policy, the built-in removal rule, pre-approval allowed and an important information notice
Step 4.

5. Set the expiry policy

Expiry modeMeaning
Optional (the default)The requester may set an end date
RequiredEvery request must set an end date
DisallowedAccess in this collection never has an end date

Expiry max days sets the longest a grant may last. Empty means no limit. When access expires, Warde removes it the way Guided Setup step 8 says, after emailing the person 14 days before and the person and their manager 3 days before.

Step 5, Set the expiry policy, with the expiry mode Required and a longest grant of 180 days
Step 5.

6. Choose the audience

User criteria for who this collection's access can be requested for. Empty means everyone. The person the access is for must match, whoever fills in the form.

Step 6, Choose the audience, with the user criteria Sales and service staff chosen and a note that one entitlement narrows the list further
Step 6.

7. Review the entitlements

Each entitlement needs an owner and a description, and anything people should not ask for needs Requestable turned off. The grid edits several entitlements at once with the bulk bar, and the drawer on each row edits one in full, including what it requires and what it replaces. Clean up entitlement names at the top of the step applies a name rule to every entitlement in the collection.

A setting on an entitlement replaces the collection's, except the audience, important information and terms of use, which combine with the collection's. Every field is described in Entitlements.

Step 7, Review the entitlements: the name rule, filters such as No owner and High risk, the Change several at once bar set to change the risk rating of two selected rows, and the grid of eight entitlements
Step 7, with two rows selected for a bulk change.

8. Go live

Going live sets the status:

StatusMeaning
ManagedAn engine is bound. Warde grants and removes through it, and uses tasks only for what the engine cannot do.
UnmanagedNo engine is bound, so every change is a ServiceNow task for the support group
OnboardingBeing set up, hidden from requesters
RetiredNo longer used

If any step still has a warning, the button reads Go live anyway. You can move a collection back to Onboarding at any time with Move to Onboarding. Going live and moving back are both written to the audit history.

Step 8, Go live, listing the status of every other step, how access will be granted through SailPoint ISC (production), and the Go live as Managed button
Step 8.

After go-live

A live collection keeps changing: the engine adds entitlements, renames things and removes them. A new entitlement in a live collection still needs its owner, description and risk from you, so check the Entitlements with no owner list after each catalog sync. See Catalog health.

To help requesters through a large collection, give it guided questions.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.