Administer > Organizations

Organizations

HPE ITOC has two types of organizations – public and consumer. This chapter discusses HPE ITOC organizations, Lightweight Directory Access Protocol (LDAP) integration, and the Organizations Administration UI.

An organization determines a user's entry point into the HPE ITOC system and associates its users with services and resources. The HPE ITOC administrator creates and edits user groups and assigns roles to these user groups, based on LDAP groups. Membership in an organization is determined by the organization's LDAP directory.

HPE ITOC has two types of organizations:

  • Public provider organizations - The provider organization hosts HPE ITOC, manages consumer organizations, and manages resources and services. Production revisions of public objects and resources in the public provider organization are shared with the consumer organizations. For example, a user can import control and policy content from HPELN into the public provider organization. Then, each consumer organization can use these policies; for example, measure the compliance of their business services against shared or common policies.
  • Consumer organizations - The consumer organization subscribes to or consumes the resources and services provided by the provider organization. There may be multiple consumer organizations configured by the provider organization. However, each consumer or subscriber sees only the information of the consumer organization of which he is a member (membership to a consumer organization is determined by the LDAP configuration of the consumer organization).

The administrator configures HPE ITOC to access an LDAP server, at which point LDAP users can log into the HPE ITOC UI. LDAP authenticates user login credentials by verifying that the user name and password match an existing user in the LDAP directory.

Public provider organizations

At installation, one public provider organization is set up by default; no other provider-type organizations can be created. The Administrator (or itocadmin) user has the CSA_ADMINISTRATION role and can log into the Organizations Administration UI. This user can:

  • Configure LDAP - For each organization, the administrator can specify the LDAP end-point to access as the source for users.
  • Create one or more groups - Each group is a representation of an LDAP group.
  • Assign roles to groups - Assigns roles to each group (see Roles).

Consumer organizations

Consumer organizations have the same functionality as public provider organizations. What a user can do within a consumer organization is based on the roles assigned to that user.

You can create separate consumer organizations based on your company's organizational structure.

  • For example, you might create separate consumer organizations for R&D and Finance. R&D can only see R&D objects within its consumer organization plus public content; Finance can only see Finance objects within its consumer organization plus public content.
  • Each organization can set different business configurations - for example, the R&D compliance threshold is set to 95, while the Finance compliance threshold is set to 100.
  • Each organization can have different business processes - for example, R&D may choose to use the Auto-Approval workflow for all object types, while Finance may choose to use the Approval Required workflow.

Related Topics IconRelated Information