Administrator guide
Settings and scheduled jobs
Where Warde's settings live, the ones you are most likely to change, and the scheduled jobs that keep it running.
Most settings are set in Guided Setup, which explains each one in context. Every setting is also a system property, listed under Warde > Properties in categories, or in the Admin Workspace under Settings > Warde properties. Change a setting in Guided Setup where it offers one: some saves do more than write the property, such as audit retention, which also updates the table cleaner.
All Warde properties are named x_66256_warde.* and need the Warde administrator role to read or change.
Settings you are most likely to change
Approvals
| Property | Default | What it does |
|---|---|---|
default_approval_policy | none | The policy used when no entitlement, bundle or collection names one. With none, such requests stop for an administrator. |
approval.exception_group | none | Approves when a rule finds nobody and has no standby |
approval.submitter_approval | require | require asks a submitter who is also an approver; submission counts their submission as approval |
approval.removal_approver | holder | Who approves a removal: holder, manager, rules or none |
approval.removal_default_policy | none | The removal policy when none is named elsewhere |
admin.group | none | The group that approves access bundle proposals |
Fulfilment
| Property | Default | What it does |
|---|---|---|
fulfilment.fallback_group | none | Gets manual tasks for collections with no usable support group |
fulfilment.exception_group | none | Gets failed and parked work |
fulfilment.default_window_days | 2 | Business days promised for manual work |
fulfilment.show_promise | true | Tells requesters when to expect access |
fulfilment.grant_task_template, fulfilment.removal_task_template | none | Default catalog task templates |
queue.manual_poll_mins | 60 | How often Warde checks manual tasks for closure |
queue.retry_base_secs | 60 | The first retry delay after a failed engine call |
queue.retry_window_mins | 240 | How long Warde keeps retrying a failed engine call |
queue.abandon_after_days | 7 | When an operation nobody acts on is abandoned, at most 30 |
Requests and My Access
| Property | Default | What it does |
|---|---|---|
request.act_for_scope | team | Who a requester can ask for: self, team (direct reports), org (everyone below them) or any. Administrators are not limited by it. |
catalog.request_access, catalog.access_bundles, catalog.remove_access, catalog.remove_access_bundles | true | Switches each catalog item on or off. Off hides the item without deactivating it. |
catalog.single_access | false | The conversational item. Needs Now Assist and AI Search. |
my_access.expiring_soon_days | 30 | How soon before its end date My Access marks access as expiring |
my_access.max_rows | 500 | The most rows My Access shows in a panel |
my_access.ticket_reference | sc_req_item | Whether requests are quoted by RITM or REQ number |
Reviews and expiry
| Property | Default | What it does |
|---|---|---|
uar.portal_suffix | esc | The portal reviews and email links open in |
uar.removal_request_mode | direct | How removals from reviews and My Access are made: direct, manual_only or always |
uar.reminder_days_before | 3 | Days before the due date to remind reviewers. 0 means never. |
uar.escalate_after_days | 3 | Days after the due date to escalate to the reviewer's manager. 0 means never. |
uar.default_due_days | 14 | How long reviewers have when a definition sets no due period |
removal.sweep_request_mode | manual_only | How expired access is removed |
expiry.notify_holder_days | 14 | Days before expiry to email the person. 0 turns it off. |
expiry.notify_manager_days | 3 | Days before expiry to email the person and their manager |
Separation of duties
See Separation of duties for sod.enforcement, sod.validation and the related settings.
Other
| Property | Default | What it does |
|---|---|---|
lifecycle.fulfilment | all | What Warde does with a lifecycle call by default |
audit.retention_days | 2557 | How long audit history is kept. Change it in Guided Setup step 11. |
logging.verbosity | warn | The log level: error, warn, info or debug |
correlation.default_attribute, correlation.default_field | The default pair that binds engine accounts to users | |
alerting.sink | none | The default engine alert: none, incident, em_event or both. See Health, alerts and logs. |
Scheduled jobs
Warde runs twelve scheduled jobs. Guided Setup step 13 lists them and shows whether each is active. Leave them all active.
| Job | Runs | What it does |
|---|---|---|
| Warde engine health check | Hourly | Checks each engine with a real authenticated call and records its status |
| Warde engine alerting | Every 5 minutes | Raises and clears engine alerts |
| Warde queue sweeper | Every 15 minutes | Rescues stalled fulfilment work, times out separation of duties checks, and releases removals waiting on a replacement |
| Warde ServiceNow accounts | Every 15 minutes | Keeps the ServiceNow engine's accounts in step with the users who hold the requester role |
| Warde sync: catalog | Daily at 02:00 | Imports collections, then entitlements, from each engine |
| Warde sync: accounts | Every 4 hours | Imports accounts |
| Warde sync: assignments | Every 6 hours | Imports who holds what. A full read runs at most weekly, on the days set in sync.assignment_sweep_days (Saturday and Sunday). |
| Warde sync: approval audit | Daily at 04:00 | Finds SailPoint ISC items with an approval step of their own, and reads when the ISC token expires |
| Warde expiry removal sweeper | Daily at 02:00 | Sends expiry emails, then removes expired access |
| Warde UAR sweeper | Daily at 06:00 | Sends review reminders and escalations, and closes finished campaigns |
| Warde campaign scheduler | Daily at 06:30 | Launches scheduled campaigns |
| Warde weekly licence report | Daily at 03:17, sending once a week | On production instances only, sends Warde the number of people who hold a Warde role. See What leaves your instance. |
Times are the instance's time zone.
What leaves your instance
Warde calls only the engines you connect, with the credentials you give it, plus one weekly report.
The licence report. Once a week, a production instance sends https://licensing.warde.app one signed message: the product name and the number of distinct active people who hold any Warde role. Service accounts, integration users, locked-out users and machine identities are not counted. No names, no access and no other data are sent. Instances that are not production (where glide.installation.production is not true) send nothing. The last report and its outcome are kept in x_66256_warde.licence.last_report, which Warde administrators can read. The connection it uses, Warde licensing, is installed with Warde. If a send fails, Warde logs one warning and tries again the next day.
Table cleaners
| Table | Kept for |
|---|---|
| Audit events | 2,557 days (seven years) by default. Set in Guided Setup step 11. |
| Fulfilment operations | 90 days after they complete or are cancelled |
| Separation of duties probes | 1 day |
Records Warde ships that you can change
- The Line manager approval policy.
- The Warde fulfilment hours schedule, Monday to Friday 9 to 5. Set its time zone and add your public holidays.
- The ten email notifications. You can switch any of them off.
- The seven transform maps. Change one only if you must: Guided Setup marks a changed map, and an upgrade skips records you have changed.