What Is Entitlement?

Entitlement is one of the concepts we use most in Identity and Access Management (IAM) products. Entitlement, meaning granting authority or rights, is essentially the complete set of access rights held by an identity.

When managing entitlements, we generally prefer to build management structures around roles. For example, let’s think of the Manager and Employee job definitions within the Employee Relations department of an organization’s HR function.

Entitlement-Human_Resources

Team employees can see all employees’ permissions but can only view their own payroll, meaning we can define and associate this as the Employee Relations Employee Business Role. The Employee Relations Manager Business Role, on the other hand, can view and edit all employees’ permissions and view all employees’ payroll records.

When defining business roles here, the complete set within which we configure resource access permissions, access policies, and permissions inside a business role is what we’d call a user’s entitlements.

If I were to model this using IBM’s Security Verify Governance product, the structure below would better illustrate the IT role and business role concepts I mentioned above.

Entitlement-Human_Resources

Looking at this model, we can see that a single business role can be associated with multiple IT and/or business roles, and can include permissions belonging to different applications. An IT role, on the other hand, represents a type of role made up of permissions belonging to a specific application.

In Identity and Access Management, when asked what a user’s entitlements are, we can think of it as the complete set of authorities, permissions, and access a user has across all applications. As a quick footnote: authorization tables generally keep track of which permissions belong to which user.