Identity self service

Identity self service

Introduction to Identity self service

What is identity self service?

Soffid Console provides the identity self service, where the end-users can consult or change their credentials, request new permissions or access to applications, manage their profile, or launch applications. All from a single point of entry. 

Another purpose of the identity self service is to reduce the workload of the IT department, as well as improve the overall security of the IT system. 

Soffid allows administrator users to configure access to the different options depending on the end-users roles defined to use Soffid. In this way, end-users will be able to access the identity self service Portal to manage their own requirements always depending on the defined business processes.

Screen overview

image.png

Brief description of each option

My tasks

My tasks display all the tasks in which the user is involved, like a supervisor, manager, o person how has to approve or deny that task. 

For more information, vist My Task page.

My issues

My issues display all the issues that the user will be able to check, and this option allows the user to manage this issues.

For more information, visit My Issues page.

My requests

My requests display all the processes or workflows that the user will be able to run.

And also the included page Query request status displays all the processes that the user has initiated and allows the user to consult all the information about the workflow.

For more information, vist My Request page.

That functionality allows to users search for processes initiated or requested by themselves. Here the users will be able to consult all the information related to the processes and their status and if there are any pending tasks to be completed. If there are pending tasks, the user will be able to browse the task and manage it.

Administrator users will be able to consult all the information about all the processes which have been executed by any user.

For more information, visit the Process search page.

My applications

My applications display all the corporate applications and third-party applications as well to which the user has permission to connect. Those applications have to be configured into Soffid Console

The password vault folder will be displayed as well. In this folder, the users will be able to find the shared accounts on the Soffid vault folder and will be able to save their personal accounts.

For more information, vist My Applications page.

My authentication

My OTP devices

My OTP devices display all the OTP devices configured by the user and allow to the user config new ones.

For more information, vist My OTP devices page.

My certificates and FIDO tokens

My certificates and FIDO token display all the configured certificates and allow to the user config new ones.

For more information, visit My certificates and FIDO tokens page.

My accounts

My Accounts display all the personal user accounts registered into Soffid Console and with which the user will log into the target system.

In this section, if a user has permissions, they can view or change their password.

For more information, visit My Accounts page.

Soffid chat-box (new functionality)

The new Chat-box Soffid functionality is our AI and relies on Soffid's expertise to provide documentation or apply changes directly in the system, feel free to ask your questions.

For more information, visit Soffid chat-box page.

My tasks

Description

Displays the tasks in which the user is involved like a supervisor, manager, or person responsible for approving or rejecting those tasks.

My tasks provides information about the process, the task, the start and due date and the asigned user. By clicking a record, it will be shown de task details and to perform actions will be allowed.

Manual tasks are assigned to named users, groups or roles.  Whatever strategy is followed, each one of the assigned users will see the task at their tasks page. 

You can differentiate tasks by their highlighted style:

The purpose of My tasks as a part of Identity seft service is to reduce the workload of IT department, as well as improve overall security of IT system. Soffid console is concerned about task delegation and workflow management. 

Screen overview

image.png

image.png

Related objects

Standard attributes

Table

Detail

Below you can see the workflow information, which has several tabs.

Task tab

Displays information about the work performed in this task. This information varies for each workflow but is almost always structured as a form.

Image

image.png

Action logs tab

The action logs tab shows basic information about the process and a list with the summary of all the successive phases through which the task has passed.

Image

image.png

Attachments tab

This option only appears if it has been enabled in the workflow settings. This screen lists the documents attached to the task.

Allows you to download those documents and to verify any digital signature attached to them. Some tasks even allow the user to upload documents.

Comments tab

Displays the comments list added during the business process execution. Displays the comments list added during the task execution providing information about the user who wrote the comment, the date and time of that writing, and the comment that was writed.

Actions

Table

Refresh

This action refresh the task table with the last current data.

Download CSV file

This action allows you to download a csv file with the list of all tasks.

View

Allows you to add or remove columns to the table.

It is also possible to change the order of the columns.

"Open task"

By clicking on a record, the task detail will be shown.

Detail

Close

Allows you to closes the task window,  you can add new comments and those will be saved.

Take ownership

Enables the user to self-assign the task to authorize or deny it.

Schedule

Allows you to schedule the task execution.

Delegate

Allows you to to reassign the task to another user, who will must approve or deny it.

Approve

Allows you to authorize the task. When you authorize a task all defined operations for this task will be performed.

Reject

Allows you to deny the task. When you deny a task none defined operations for this task will be performed.

My issues

Description

Soffid provides a tool to manage all issues and allows you to perform the operations available for each type of task. The actions to be performed will depend on each kind of task.

The incidents that appear on this screen are those that the user has initiated or those for which the user has yet to take action in order to continue with their progress.

Screen overview

image.png


Standard attributes

Standard attributes

Actions

Issues query action

Download CSV file Allows you to download a CSV file with the issue data.

Add or remove columns

Allows you to show and hide columns in the table. You can also set the order in which the columns will be displayed. The selected columns and order will be saved for the next time Soffid displays the page. 

Issue detail

Close Allows you to quit without applying any changes.
Acknowledge

Allows you to check as Acknowledged

Solve issue

Allows you to mark as solved the issue.

Send custom email Allows you to send a custom email to one recipient.
Add Comments Allows you to add comments to the Action logs.
account-created
💻 Image

image-1691073560305.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

disconnected-system
💻 Image

image-1691505347878.png

discovered-host
💻 Image

image-1695972298817.png

discovered-system
💻 Image


duplicated-user
💻 Image

image-1691406809609.png

Mege users

If you click this option, Soffid will allow you to merge the identities by selecting the data of each of them.

💻 Image


image-1691406880979.png


failed-job
💻 Image

image-1691073883011.png

enabled-account-on-disabled-user
💻 Image

image-1695972326375.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

global-failed-login
💻 Image

image-1691074786904.png

integration-errors
💻 Image

image-1691074818620.png

locked-account
💻 Image

image-1691412483843.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

login-different-country
💻 Image

image-1696239831327.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

login-from-new-device
💻 Image

image-1691074846496.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

login-not-recognized
💻 Image

image-1691074918985.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

otp-failures
💻 Image

image-1691074948199.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

pam-violation
💻 Image

image-1691404894434.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

password-changed
💻 Image


permissions-granted
💻 Image

image-1691075044973.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

risk-increase
💻 Image

image-1691678367280.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

robot-login
💻 Image

image-1696240262391.png

Unlock account If you click this option, Soffil will unlock the account.

Look affected accounts

 If you click this option, Soffil will lock affected accounts. 

Disable user

If you click this option, Soffid will disable the user.

Lock affected host

If you click this option, Soffid will lock the affected host.

Unlock host

If you click this option, Soffid will unlock the host.

security-exception
💻 Image

image-1691140940313.png

Disable user

If you click this option, Soffid will disable the user.

My requests

Description

Soffid provides a complete workflow engine that allows you to incorporate business processes or define new business processes as needed. End-users with the appropriate permissions will be able to request these processes. You can visit Self service portal examples page for more information.

My request screen allows to users:

More information about process and workflows on BPM Editor Book

Screen overview

image.png

My requests > Query request status

Description

Displays a table with all the processes initiated by the end-user. The end-user can consult processes detail and perform actions depending on the user permissions. You can visit Self service portal examples page for more information.

Screen overview

image.png

image.png

Standard attributes

Actions

The operations to be performed depend on the user permission and the business processes defined with the workflow engine.

You can find documentation about the business processes on BPM Editor Book.

Table

Refresh

Allows you to refresh the processes list with updated data.

Download CSV file

Allows you to download a CSV file with all the information from the list of processes contained in the table.

View

Allows you to add or remove columns to the table.

It is also possible to change the order of the columns.

Process

The actions to perform to each process, depend on the business process definition and the user permissions.

You can find more information about the most commons process actions if you go to Process detail actions

Process search

Description

A process is a series of actions, connected by transitions. An action could be either an automatic action or a manual task. A process is what we commonly refer to as a workflow in Soffid.

Soffid console is concerned about task delegation and workflow management. Any user is able to create new processes or any user can be assigned as an actor for a task belonging to a process.

Process Search page allows users to search process by different criteria, to view the process details and to perform the proper actions depending on the user roles.

In order to view a task, a security constraint must be accomplished. The user must have granted the observer or administrator role on the specific project version or has been assigned as a potential actor of it at some time.

Screen overview

image.png

image.png

Related objects

Standard attributes

Table

The search and the view table can be performed by setting certain parameters, which are as follows:

Process

Each process has commons attributes and specific attributes depending on the business process definition.

You can find documentation about the business processes on BPM Editor Book

Commons process attributes

Other process information

Actions

Table

Actions to be performed on the process list:

Search (quick, basic, advanced)

Allows you to query the processes with the indicated parameters.

Download CSV file

Allows you to download a CSV file with the list of processes. You can open the hamburger icon and Download CSV File.

View

Allows you to add or remove columns to the table.

It is also possible to change the order of the columns.

"Open task"

By clicking on a record, the task detail will be shown.

Detail

Each process has a specific action defined on the business process definition.

You can find documentation about the business processes on BPM Editor Book

The most commons actions are below:

Close

Allows you to close the process detail page and return to the previous page.

Reload

Allows you to reload all process data with the updated data.

Take ownership

Allows you to take the ownership to approve o deny the process.

Approve

Allows you to approve the process and perform the actions defined for that process.

Deny

Allows you to reject the process.

Work in progress actions

Edit task

Allows you to edit a task by clicking on the record. When you click the task, you will browse to the task detail and it will be allowed to perform actions defined to users with the proper permissions.

Attachments

Download

Allows you to download the available attached files.



My applications

Description

My application is a part of the Identity self-service that allows end-users to start corporate applications and third party applications. Also, the end-user can view and use the shared accounts available for the user defined on the Password vault.

Applications

That option shows to each user, all the corporate and third party applications to which the user can connect and the applications with public access. These applications have to be configured on the Application Access Tree option by an administrator user.

Password vault

My Applications option shows the PasswordVault folder. On the vault folder you can find two kind of folders, one a personal folder and other a shared folder

Inside the personal folder, you can create your own accounts, those accounts will not be shared with any other user. The shared folders could be used or managed by the owner/manager/SSO users.

image.png

image.png

 

Actions

"Folder selection"

When you select a folder, its contents will be displayed on a new page.

"Application selecction"

When you select an application, a new page will open with access to the application depending on its type.

 

If only access is visible but it is not configured, nothing will happen.

 

If there is a configuration but you do not have access, you will be notified on screen.

 

My authentication

Description

This screen groups together the different options available to users when authenticating, especially as a second factor in an MFA login.

Screen overview

image.png

 

My authentication > My OTP devices (addon otp)

Description

My OTP devices are part of a Soffid Self-service portal that allows end-users to access their OTP devices configured.

That option display to each user, all their OTP devices and also allows you to manage those and add new OTP devices.

Soffid Administrator user can configure the available OTP types. For more information, you can visit the OTP settings page.

This option will only be available if the OTP addon is installed in the Soffid console. Visit the Two factor authentication book for more information

Screen overview

image.png


Standard attributes

Actions

Add new

Allows you to add a new OTP device. To add new OTP devices you need to click the "Add new" button, then Soffid will display a new wizard to config the OTP devices. First of all, you need to select the OTP device Type, once the type is selected, you need to fill in the required fields, which depend on the Type selected. If you select an Event-based or Time-based HMAC Token, you will need to scan the QR code and write the PIN. Finally, you must Apply changes.

 

 

Images

image.png 

image.png

Delete OTP device

Allows you to delete one or more OTP devices.

To delete OTP devices first select the devices, then click on the Delete, then Soffid will ask you to confirm or cancel the operation.

View

Allows you to add or remove columns to the table.

It is also possible to change the order of the columns.



My authentication > My certificates and FIDO tokens (addon federation)

Description

My certificates and FIDO tokens are part of the Identity self service that allows end-users to access their OTP devices configured.

This option shows each user all their configured OTP devices, which can be certificates, FIDO tokens, and Soffid authenticators. It also allows you to add new devices or delete existing ones.

Certificates

You can use these *.p12 certificates to add them to your favourite browser and use them as a second factor of authentication.

FIDO tokens

If you or your organisation has FIDO devices, I can register them with Soffid and use them as a second factor of authentication.

Soffid authenticator

Soffid has made the Soffid authenticator app available on the Play Store and the App Store, which will allow you to easily and simply perform two-factor authentication from your mobile device.

Screen overview

image.png


Standard attributes

Actions

Table

Add new

Allows you to add new object: Certificate, FIDO token or Soffid authenticator.

Soffid will display a new wizard to configure each type of object.

First of all, you need to select the Type, once the type is selected, you need to follow the required steps which depend on the Type selected. 

Delete token

Allows you to delete one or more objects.

To delete them first you must select one or more objects, then click on the "Delete" button, then Soffid will ask you to confirm or cancel the operation.

Download CSV file

Allows you to download a CSV file with all the information about the objects. 

Add new

Adding a new certificate

Select the "Certificate"  type.

image.png

Save the *.p12 file in a secure location.

Finish with the "Close" button.

image.png


Adding a new FIDO token

Select the "FIDO token"  type.

image.png

Adding a Soffid authenticator

Select the "Soffid authenticator"  type.

image.png

Others

IDP for FIDO and authenticator

To add a FIDO token or a Soffid authenticator, you must have a Soffid IDP configured.

image.png

My accounts

Description

My Account is a part of the Identity self service that allows end-users to access and manage their personal accounts.

That option displays all personal accounts for each user and allows you to set and/or view the password for each account if they have been enabled by configuration.

The accounts that are displayed are those belonging to Soffid's own systems. For external systems, only accounts belonging to active systems are displayed. If an external system (agent in Soffid) is disabled, the account will not be displayed on this page.

Disabled accounts are displayed, but it is not allowed to set or view the password.

image.png

Related objects

Standard attributes

Actions

Download CSV file

Allows you to download a CSV file with all the information about your accounts. 

Set password

Allows you to set a new password for this account. This change will be applied to different target systems.

The new password must comply with the defined password policies.

Query password

Allows you to query and copy the password and the user name.

Soffid chat-bot

Description

This new feature included in Soffid 4 allows you to interact with our AI to request information, or better yet, ask it to apply changes directly in the Console.

This feature is not enabled by default, you must activate a token in order to use it.

The power offered by this new tool is limitless. Our imagination, combined with training in Soffid's documentation and internal structure, enables us to accomplish many tasks.

Screen overview

image.png

image.png

All pages with scripts can use the IA to help you with the scripting

Standard attributes

Actions

Process Send the request to our AI for processing.

Others

Access without a token

When attempting to use this feature without having previously enabled it, the console displays the error: No token configured. Please configure it on the network intelligence page.

For more information go to Network intelligence page.

image.png