WardeDocs Administrators Connectors People using Warde warde.app

Administrator guide

Collections and entitlements

Take an imported application through Collection Onboarding so people can ask for its access.

A collection is one application or source of access: an ISC source, an IdentityIQ application, an Entra group set or application, or an application you fulfil by hand. Its entitlements are the pieces of access people ask for.

A sync creates collections and entitlements with the status Onboarding. Requesters cannot see a collection until you take it through Collection Onboarding and make it live.

Open Collection Onboarding

Open Warde > Collection Onboarding, or the Setup item on the Admin Workspace rail. Without a collection named, the wizard opens on Choose a collection, a table of every collection with its status, entitlement count and engines. Select Set it up on one.

From a collection record in the Admin Workspace, the Guided onboarding button opens the wizard on that collection. The workspace list Catalog > Collections: onboarding shows everything still waiting.

Collection Onboarding needs the Warde administrator role.

The eight steps

1. Describe the application

Requesters see the name and description in the catalog, so write the description in their words. A configuration item is optional; with one, the next two steps can read the owner and support group from the CMDB.

If the engine names the collection (ISC sources and Entra applications and catalogs do), the name follows the engine and you rename it there. Warde renames the collection, its entitlements' labels and everything that shows them on the next sync.

2. Assign the owner

The person accountable for this application. Search for them, or choose from the people the CMDB links to the configuration item. The owner can be a reviewer for access reviews and appears on the collection's records. Approvers are set in the approval policy, not here.

3. Choose the support group

The group that gets a task when access has to be granted or removed by hand, and what that task tells them to do:

SettingWhat it does
Support group sourceA fixed group, or a field on the configuration item that holds one (up to three fields, such as support_group)
Fulfilment groupThe group, when the source is a fixed group. It does not approve anything.
Fulfilment instructionsHow to carry out a manual grant or removal, copied into every task. An entitlement's own instructions replace these.
Grant and removal task templatesCatalog task templates applied to this collection's tasks

If the group is inactive or has no active members, the task goes to the fallback group from Guided Setup step 8. The step summary says where tasks will go.

4. Decide how requests are approved

SettingWhat it does
Approval policyHow requests for this collection's access are approved, when the entitlement or bundle has no policy of its own. Empty uses the instance default.
Removal approval policyHow removals are approved, when the entitlement has no policy of its own
Pre-approval modeWhether entitlements here can be pre-approved into access bundles. Empty means allowed.
Important informationA notice shown to requesters on the form and to approvers
Important approval informationA notice for approvers only. Requesters never see it.
TermsTerms the requester must accept before submitting. Leave empty for none.

The summary warns if the chosen policy has no rules, or if there is no policy here and no instance default: requests for the collection would stop.

5. Set the expiry policy

Expiry modeMeaning
Optional (the default)The requester may set an end date
RequiredEvery request must set an end date
DisallowedAccess in this collection never has an end date

Expiry max days sets the longest a grant may last. Empty means no limit. When access expires, Warde removes it the way Guided Setup step 8 says, after emailing the person 14 days before and the person and their manager 3 days before.

6. Choose the audience

User criteria for who this collection's access can be requested for. Empty means everyone. The person the access is for must match, whoever fills in the form.

7. Review the entitlements

Each entitlement needs an owner and a description. The grid lets you edit several at once with the bulk bar.

FieldWhat it does
OwnerApproves the entitlement's inclusion in bundles, and can be the reviewer in access reviews
DescriptionWhat the access lets someone do, in plain words. Requesters and reviewers see it.
Risk ratingReviewers see it. High-risk access is not pre-approved into bundles unless pre-approval is allowed.
RequestableTurn it off for anything people should not ask for. It can still be part of a bundle.
Licensing boundWhether each grant uses a paid licence. Shown to requesters and reviewers.
RequiresOther entitlements that must be granted with this one. Warde adds them to the request.
ReplacesAn entitlement this one supersedes. When someone is granted this one, Warde removes the old one from them once the new access is in place.
Lifecycle stateActive, Deprecated (cannot be added to bundles) or Retired (cannot be granted)

A setting on an entitlement replaces the collection's, except the audience, important information and terms of use, which combine with the collection's.

Clean up entitlement names. Engines often name entitlements in ways nobody outside IT reads, such as CN=APP-FIN-GL-RO,OU=Groups. A name rule on the engine, which a collection can override, rewrites the label people see with a pattern and a replacement. The engine's own name is kept read-only beside it.

Automated in the identity system. Tick this on a collection, an entitlement or a bundle when your identity system grants and removes that access by its own rules, such as an ISC role with membership criteria or an Entra dynamic group. Warde then leaves that access to the identity system: it is not offered for request or removal, is left out of reviews and leaver removals, gets no expiry, and shows on My Access as given automatically. Access an engine reports as given by its own rule is treated the same way without the tick.

8. Go live

Going live sets the status:

StatusMeaning
ManagedAn engine is bound. Warde grants and removes through it, and uses tasks only for what the engine cannot do.
UnmanagedNo engine is bound, so every change is a ServiceNow task for the support group
OnboardingBeing set up, hidden from requesters
RetiredNo longer used

If any step still has a warning, the button reads Go live anyway. You can move a collection back to Onboarding at any time with Move to Onboarding. Going live and moving back are both written to the audit history.

Request posture

Each collection also has a Request posture, set on its record:

Collections with no engine

For an application with no identity engine behind it, create the collection by hand in the Admin Workspace, add its entitlements, then onboard it. Every change becomes a task for its support group. See ServiceNow tasks and accounts.

Keeping an eye on the catalog

The Admin Workspace's Access health dashboard has tabs for collection and entitlement health, and the Data quality lists show requestable entitlements with nothing to fulfil them, entitlements with no owner, and live collections with no fulfilment group.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.