possibility to add different AD-groups/roles to 1 request form
M
Martine Leisink
Within many applications, there are multiple roles, each role with their own AD-group. At this moment we have to use a separate request forms for each role. As certain applications have sometimes more than 10 different roles, it is not a very nice way of working and it would mean we get many request forms for 1 application.
We would like to have 1 request form for 1 application in which you can select the wanted role. Based on that, the correct AD group is automatically assigned.
M
Michiel van der Veeken
Martine Leisink
Thank you for your feature request. While HelloID does support this use case, we recommend against implementing it in this way based on the current information.
This approach may lead to several limitations. For example, a single request can only be approved or denied as a whole; it is not possible to approve specific roles within a single request. Similarly, when returning an assigned product, only the entire product (all roles) can be returned, rather than individual roles. Additionally, other features like time limits, approval workflows, and the Recertification functionality offer greater value when each role is structured as an individual product.
We suggest reaching out to one of our business consultants, who can further review your use case and offer tailored advice.
M
Martine Leisink
Hello Michiel van der Veeken,
Thanks for your quick reply. What do you mean by "a single request can only be approved or denied as a whole?" If you only want 1 specific role, all AD groups will be assigned?
M
Michiel van der Veeken
Martine Leisink: Each product request can only be approved, denied, or returned in its entirety. For example, if multiple roles or AD groups are configured within a product’s action, all memberships will be granted or revoked upon approval or return. It’s not possible to approve or return a subset of these memberships individually. Therefore, our best practice is to create a separate product for each individual role or AD group.
If your use case differs or if you’d like to discuss further details, we recommend reaching out to our support team to consult with one of our business consultants for a comprehensive review.
M
Martine Leisink
Michiel van der Veeken Thanks I will discuss it further with a consultant