RCAR and Request Type Assignees versus Task Assignee
Note: We’ve recently introduced some new features across Okta Identity Governance that streamline the catalog experience for end users called Resource Centric Access Request (RCAR). Still leveraging some of the same approval flows within Access Requests, but providing a much cleaner end user experience when requesting access. Learn more about Resource Centric Access Request.
What is the difference between a Request Assignee versus Task Assignee with an Open Request (submitted via Request Types or RCAR)?
Inquiring minds want to know! What is the major difference between the two?
Let’s first show where they exist within Access Requests / RCAR. Both products use Assignee’s within the Access Request Web UI for approvals. When a new request is created and submitted it shows up in the inbox for any users associated with the request. The Request Assignee role happens to be one of them. The Request Assignee has administrative oversight of any inbound requests. This means the Request Assignee has administrative privileges with Access Requests regardless if the request was generated from chat or via a Request Type or Resource Centric Access Requests.
Additionally, a Request Assignee can be assigned to only 1 user, whereas a Task Assignee can be assigned to more than 1 user, depending upon the output of task configuration.
Capability of Request Assignee:
- Management of any requests generated by Request Type
- Can change approvers
- Can end timers
- Can add users to teams
- Can Create/Manage Request Types
- Can Create/Manager Configuration Lists
Request Assignees are managed with Teams with Request Types only. In Resource Centric Access Requests, Request Assignees are derived from Super Administrators and Access Request Administrators and no longer leverage Teams from the Access Requests Web UI.
Task Assignee(s) are the audience assigned to sub tasks within a Request Type / Resource Centric Access Request. A Task Assignee is assigned questions or actions like approvals with Request Types / Resource Centric Access Requests. In the image above, the Manager Approval task is assigned to SC. Task Assignees are not required to have any administrative privileges to complete tasks.
Capability of Task Assignee:
- Answer questions
- Provide approvals to steps
- Does not provide any administrative oversight within Request Types / Resource Centric Access Requests
Happy Governing!
Related References
Training:
We’ve put together other resources below that can help you as you become familiar with Okta Identity Governance:
- We share two videos about Access Certification campaigns and Access Request in this article: Okta Identity Governance
- Corporate blog: Okta Identity Governance: A Unified IAM and Governance Solution
- How to Grant entitlements via API
- Guide on how to use the Okta Identity Governance API’s
Learn about the new capabilities available, Access Requests, Access Certifications, and more in this FAQ: Identity Governance FAQs
