Feedback Ideas

Your Voice Matters: Share Your Thoughts and Help Us Enhance Your Experience!

Trending
  1. Ability to Schedule Configuration Backups

    To protect NIM configuration natively, we should provide the ability to schedule automatically backups. This is beneficial when there are multiple NIM Administrators making configuration changes and often forget to back up their configuration.

    Mike Sheldon

    1

  2. Workflows

    A proposed enhancement to the product is the introduction of workflows, allowing requests to be reviewed and approved by designated reviewers before proceeding. This would be particularly beneficial in scenarios such as application access requests or provisioning processes, ensuring oversight and compliance. How Workflows Would Improve the Product Approval Mechanism – When a user submits a request (e.g., access to an application or a provisioning action), it enters a workflow where assigned reviewers must approve or reject it before execution. Role-Based Reviewers – Approval requests could be routed to specific individuals based on their roles (e.g., managers, security officers, or compliance teams). Multi-Step Approvals – Workflows could support multi-tiered approvals where different stakeholders must review a request at various stages. Audit and Compliance – Each approval or rejection would be logged, providing a clear audit trail for governance and regulatory requirements. Example Use Case A user requests access to an HR application. Instead of immediate access, the request follows this workflow: Step 1: The user's manager reviews and approves the request.Step 2: If approved, the HR department reviews and grants final approval.Step 3: Upon approval, the provisioning process assigns the necessary permissions automatically. By incorporating workflows, the product enhances security, ensures compliance, and streamlines access management while preventing unauthorized changes.

    Mike Sheldon

    0

  3. Junior/Light Admin Access

    NIM currently supports only two access levels: FULL or APPS-only. It would be helpful to have an "admin light" security level for junior admins to manage existing source syncs and run existing schedules/jobs when needed, but not be able to make changes to role model, mappings, filters, or what-have-you.

    fe

    1

  4. Allow "in" operator on numeric fields in a filter

    At the moment, numeric fields only support "equals", "exists", "greater than", "not equals", "not exists", and "smaller than" operators. It would be helpful to have other operators, such as "in" so that you can pass in a list of numbers for comparison. Right now, I'm needing to create a calculated field that converts the numeric field into a string for just this purpose.

    Steve M

    0

  5. Provide quick navigation to a selected filter, name generator, etc.

    Often, I will need to modify a filter or something after examining its results in a role or a mapping. It would be nice to quickly navigate to a filter, name generator, password generator, etc. that is being used by something like a mapping or a role. For example, in the screenshot below (Taken from a mapping), having a button to quickly jump to the selected filter, name generator, or password generator would be very handy.

    Steve M

    0

  6. Option for External links with in Apps

    Within apps, we should have the ability to link an external resource. Separate action to navigate to linkThe action is available as all other actionsIn static text we will introduce the option to insert links with a specification similar to the markdown standard: text shown. In NIM, the url specification is the name of the event (https://domain.com). For the links in static text, actions can be configured. When the syntax http(s)://domain.com is used, nim will automatically create the action to navigate to that url.

    Mike Sheldon

    0

  7. Persistent View Customization

    Customization of views should persist. Adding, removing, pinning, and re-ordering columns sometimes persists, but usually does not. Systems > Overview: Pinning the Actions column does not persist. Removing columns does not persist. Re-ordering columns does not persist. Processing > Filters: Pinning the Actions column seemed to work temporarily... but then reverted to unpinned. Adding columns does not persist. Re-ordering columns does not persist. This continues for nearly every list view. Being able to persist view changes is basic functionality that I am baffled to discover missing.

    Myrddin E

    0

  8. Allow for SMS/Email codes to be sent for Onboarding

    Currently you can't leverage SMS or Email Codes for onboarding. It only allows the user to do Question/Answer for the verification. It should provide the same functionality as Password Reset where you can target SMS or Email to send a random pin code to the person.

    Mike Sheldon

    0

  9. Allow filter lookups against other filters

    Use Case: Define a filter that returns all Active Employees. Now, for the corresponding 'Inactive Employee AD Accounts' filter, instead of defining the inverse of all the Active conditions, just target all the relevant accounts (ie: AD, EmployeeType == Employee, etc). Add a Lookup Exclude against the 'Active Employee' filter using the EmployeeID named, with the Lookup named 'Inactive Employee Accounts'. This functionality would allow us to more quickly implement filters that have both a set of Grant and Revoke criteria that are just inverse of each other.

    Mike Sheldon

    1

  10. App Dashboard Customization

    The ability to categorize apps in the interface would be helpful. Also, the ability for users to favorite an app so it always shows at the top would be helpful as well. E.g. local IT always does app X and rather than searching for it each time as we make new apps available it would always show up at the beginning of the available apps.

    Adam P

    0

  11. Support Time-based Access for Privileged Identity Management

    In Privileged Identity Management, elevated rights are typically granted on a temporary basis (e.g., 8 hours). NIM should have native functionality to support this directly. While some target systems offer time-bound permissions, a centralized approach within NIM would provide greater control and consistency. This perhaps is related to https://feedback.nimsuite.com/b/5v84550g/feature-ideas/workflows

    Mike Sheldon

    0

  12. Segregation of Duties/Toxic Roles

    A key concept within the Role Model is implementing Segregation of Duties (SoD) or preventing Toxic Role Combinations to enhance security and compliance. This feature would ensure that conflicting roles are not assigned to the same individual, reducing the risk of fraud or misuse of privileges. Possible Implementation Approaches: Defining Conflicting Roles – Explicitly specify roles that cannot be held by the same user. Example: If your Role Model includes three rolesβ€”Employee, HR, and Payrollβ€”you could define a rule stating that members of the HR role cannot also be assigned the Payroll role. This prevents HR employees from processing payroll, reducing the risk of internal fraud.Defining Conflicting Target Resource – Explicitly specify target resources that cannot be held by the same user. Example: In financial workflows, a system could enforce a rule that the person approving payments cannot also be responsible for issuing checks, ensuring a proper checks-and-balances system. By enforcing these restrictions, the Role Model ensures accountability and minimizes security risks associated with excessive or conflicting permissions.

    Mike Sheldon

    0

  13. Certification Functionality (User Access Reviews/Attestation)

    Proposed Feature Ability to (re)certify access to security/resources via manager, owner(s), users. The following would be some basic requires of the functionality Ability to categorize resourcesAbility to set/retrieve owners and reviewers for a resourceOwner/Manager based review, with confirmation tracking (view and submission)Remediation steps (Report or Automatic Remediation)Ability to create scheduled campaignsOption for failback reviewer Usage Review via NIM AppNotification via Email

    Mike Sheldon

    0

  14. Only send evaluation report if there are changes to be made

    It's no fun getting evaluation reports every hour that show zero changes to be made. An option to only send evaluation reports when there are changes to be made in the target systems would be nice.

    Steve M

    1

  15. Cloud Hosted

    Some organizations want to be fully hosted in the cloud for various reasons. Providing a hosted solution for NIM could be benefical to these organizations.

    Mike Sheldon

    0