Contact us
Request a demo

The role model - Episode 1

Memority offers an extremely powerful role model for managing delegated administration capabilities, application access, hardware allocations or any other link between an identity and a resource.

Memority offers an extremely powerful role model for managing delegated administration capabilities in the Memority portal, as well as access to applications, hardware allocations or any other link between an identity and a resource.


We've put together a series of articles to help you understand how we've managed this fundamental aspect of rights management.

As its name suggests, Identity and Access Management (IAM) is used within an organization to manage the identities required to access resources. Historically, authorizations were granted in a more or less controlled way, according to more or less known processes, and sometimes with more or less embarrassing oversights of rights. To control and simplify the management of authorizations, it's important to define a role model that will make it possible to record the rules for publication, conditions of access and, above all, withdrawal of these roles when the time comes!


A role allows you to assign one or more rights to a resource to a user (#definition). This defines a first level of abstraction and automatism with regard to unitary technical rights, and controls at least that two users with the same role will have the same rights in the same application. But when you have to manage thousands of different types of resources, you need to organize and conceptualize rights in a role model that will ensure similar operation, and enable everyone to make requests easily: the self-service user, his manager, the application manager or other stakeholders.

Le modèle de rôle

A very open role model

Memority's role model is very open , allowing you to manage administration rights within Memority, access to applications, hardware allocations, business roles, contracts, etc. In short, anything that can be represented as a resource assigned to a user. In short, anything that can be represented as a resource assigned to a user. Different concepts are used for this purpose:


  • Resource: the representation of the resource for which you wish to obtain rights (e.g. Memority, ServiceNow, a cell phone, etc.).
  • The right: the representation of a technical right linking a resource to a role, enabling provisioning actions or effective access to an application, for example.
  • Role: the role assigned to users, comprising one or more rights, or one or more other roles in the case of business roles.
  • Dimensions: additional information or constraints on the right that can be defined when assigning a role to an identity, in order to provide additional information (for example, a user's license dimension in the Salesforce application). We will devote a separate article to dimensions.
Le modèle de rôle

Different types of resources and roles

Thanks to these concepts, it's very easy to define several types of resources and roles, allowing you to have a specific data model to implement them, with their own attributes.


For example, it's possible to define "Application" and "Hardware" resource types, and "Application Role", "Administration Role", "Business Profile", "Hardware Staffing" and "Contracts" roles, with their dedicated publishing and assignment rules (we'll devote another article in our series to publishing and assignments 😉 ). These roles can be presented differently depending on their type, and with different administrators.

Le modèle de rôle
Le modèle de rôle

Now that we know how to define a Memority role model, the next articles in this series will go into more detail:


  • How to define publishing rules and assign roles to users?
  • How to use dimensions?
  • How do we recertify our users' roles?

So please be patient, and look forward to the next episode in our series dedicated to roles!

Published by

Alexandre Pallueau

Role model

Alexandre has been an IDaaS specialist at Memority for over 10 years. Through a wide range of client contexts, he has developed sharp expertise that he brings to training, plugin definition and pre-sales, covering the full product lifecycle.

Recent articles

AI agent as a non-human identity accessing enterprise systems
AI agents are becoming new non-human identities to govern

IAM at a turning point: toward more visible, intelligent and dynamic identity management

Calendrier

September 10, 2026

IAM must now govern all identities, including service accounts and AI agents. Discover the three key evolutions (Visible, Intelligent, Dynamic) and why IAM is converging with the SOC to address Zero Trust. Alexis de Calan explains it all in video.

Main robotique et main humaine interagissant avec des icônes d'identité numérique, d'accès et de données, illustrant les agents IA et les identités non humaines

Non-Human Identities and AI Agents: Why IAM Governance Must Expand Its Scope

Calendrier

September 10, 2026

Service accounts, software bots, autonomous AI agents: a new class of identities is spreading across enterprise systems, one that traditional IAM was never built to govern.

Digital identity management in healthcare facilities: How Memority supports HospiConnect compliance

Calendrier

September 8, 2026

See how Memority, an IAM platform, helps healthcare facilities and hospital groups achieve HospiConnect compliance.