Org settings

Overview

Entitle’s Org settings screen is where you will find all your organizational settings, broken into different categories. On this page, you will find a detailed explanation of each category and its use.

First, log into Entitle and navigate to the Org settings page.

Categories

Connect to

This section allows you to integrate with different applications and services to enhance your Entitle experience. You will find here a few types of applications:

  • Messaging (Slack, Teams, etc.…) - will allow employees to create new access requests, respond to access requests for which you are an approver, and get notified on requests that have been created from your messaging app. You can also add multiple Slack/Teams connections for the same system.
  • Ticketing system (Jira, Zendesk) - will allow employees to link existing tickets from your ticketing system to access requests.
  • On-call (Opsgenie, PagerDuty) - will allow effective incident resolution, real-time alerts, and on-call scheduling to help organizations handle digital operations effectively. Entitle currently supports only these two on-call applications.
  • Directories (Google, Okta, etc…) - will allow you to sync all your directory users and groups into entitle, and use your organization entities inside the application. These groups will be used both for the Approval workflows and the Birthright policies. Below you will find a list of the supported IdPs and references to their directory connection guides:
  • HR Systems (BambooHR, etc…) - Will allow you to populate the direct manager for your organization, and allow more complex approval workflows.

This section has multiple uses (from left to right):

  1. In the Application column, you can find the full list of applications with which Entitle can integrate.
  2. In the Status column, you can find the status of each app integration with Entitle - either Connected or Not Connected.
  3. Using the right column, you can either Disconnect an integration that has been created already or Connect a new one.
  4. For the directories, you will have an additional column called Edit Connection. In case the current setup needs to be updated i.e., there's an expired directory token, you can edit the connection and provide a renewed token to the existing connection.

Identity providers

This section provides you with a list of your organization’s SAML connections which enables employees to log in to Entitle. Using the Add button on the right, you can add SAML connections.

At the moment, SAML login is natively defined for Google and Microsoft, and you can add Okta in that section following this guide.

API tokens

This section allows you to manage the API tokens to automate the Entitle administration easily. Here are two general guides regarding Entitle’s API for you:

Using the Add button on the right, you can add a token for a new tenant or otherwise use the Revoke button for one that is no longer in use.

In the Token Duration column, you will be able to find the Expiration date of your token.

Agents tokens

This section allows you to keep track of the Entitle Agents that you have created for your organization, and generate new ones using the Add button on the right. Entitle Agent is the local agent that communicates directly with all the managed applications and is hosted by the customers.

Follow this guide to set up Entitle's Agent in your chosen Kubernetes cluster.

Admins

This section allows you to Add organization admins using the button on the right, or remove any from your Entitle application.

Allowed permission durations

This section controls the durations for which an employee can request an ‘Entitlement’. You can choose as little or as many as you wish.

Audit logs webhooks

In this section, you can Add using the button on the right, or remove webhooks from different SIEM tools that you have integrated with Entitle. Follow this guide to learn how to create a webhook in Entitle.

Access request forwards

In this section, you can set up request forwarding from one employee (All approval requests from) to another (should be redirected to), using the Add button on the right. This means that all the requests that should be approved by the original employee will instead be redirected, and require the new approver.

Access review forwards

In this section, you can set up Access Review forwarding from one employee (All access reports assigned to) to another (should be redirected to), using the Add button on the right. This means that all the access reports that are assigned to the original employee will instead be redirected, and require the new approver’s review.

Timezone

In this section, you can change the time zone in which Entitle will record the time of the events in the system.

Access review immediate revocation

This section allows you to enable the immediate revocation of all newly created access reviews.

Pending requests reminder

This section enables the creation of reminders for Pending requests, for specific days and times. The approvers will receive a Slack or Teams message on access requests that they have yet to respond to.

Access reports reminders

This section enables the creation of reminders for Access Reports, for specific days and times. The approvers will receive a Slack or Teams message on access reviews that they have yet to respond to.