Modules - Recertification [rec]
Last modified by Martin Kolombo on 2026/02/12 15:50
Role recertification module approves assigned user roles again.
When user has a lot of assigned roles for a long time, we want to check these assigned roles periodicaly (in a half year interval for security reasons), if some assigned role has to be already removed. Currently valid manual direct assigned roles are checked - only manual roles can be assigned and stay assigend, after user is changed some way (e.g. user contract is exluded, work position was changed).

Version
| Version | Compatible with product | Notes |
|---|---|---|
| 2.2.0 | 11.X.X | Recertification by guarantee (authorizer), UX improvements |
| 4.0.1 | 14.X.X | Bugfixes |
| 4.0.2 | 14.X.X | Bugfixes |
| 14.0.0 | 14.X.X | Added LRT for regular recertifications |
| 15.0.0 | 15.5.0 | See Recertification (IdM 15) |
Terminology
- Recertification action - recertification action (bulk action) creates recertification requests. Action can be executed from user or role table.
- Recertification request - recertification request is created for single user contract or role (by recertification type, see below) an contains items.
- Recertification item - single assigned role, which schould be apporoved in recertification request. Item = assigned user role can be approved (~recertificated) or removed.
Recertification types
Recertification type defines, who can approve role recertification request and define request content:
- Approve by user contract manager (CONTRACT) - recertification request is created for each user contract included in recerrrtification action. Managers defined by user contract can approve this request.
- Approve by role guarantee (ROLE) - recertification request is created for each role included in recerrrtification action. Role guarantees defined by user or by role can approve this request.