Get started with resource collections
Early Access release. See Enable self-service features.
A resource collection is a set of apps, entitlements, Okta groups, and push groups. Admins can directly assign resource collections to users. Admins can use them to model roles in an org. They can also use them to create access request conditions that allow users to request access to collections through the End-User Dashboard.
The ability to add Okta groups, push groups, and non-Entitlement Management (EM) apps to a resource collection is only available if the Extend resource collections with Okta groups, Okta push groups, and non-Entitlement Management apps feature is enabled on your org. See Enable self-service features.
Before you begin
- Sign in as a super admin or an admin with the following permissions:
- Manage applications
- Manage collections
- Edit application's user assignments
-
Edit groups' application assignments or Edit users' application assignments.
See Custom admin roles and Role permissions.
- Ensure that you're assigned to the Okta Access Requests app.
Setup and maintenance tasks
Initial setup tasks
As a super admin or a user with the appropriate permissions and app assignments, follow this sequence of tasks to create and configure resource collections.
|
Admin task |
Description |
|---|---|
| Create a resource collection | Create a resource collection. |
| Manage resources in a collection | Set which resources are included in a resource collection. |
| Access request conditions | Understand how access request conditions can streamline the task of requesting and granting access to a resource collection. |
| Create an access request condition for a resource collection | Define which users can request access to a collection, how long should they have access, and who should approve their access request. |
| Enable a condition | Enable your access request condition, making it active. Enabling a condition allows users to request access to a collection from their End-User Dashboard. |
| Past Access Requests (Conditions) report | View who has requested access to resources and related data points, including whether access was granted and by whom. You can set the Access Scope Type filter value as Collection. |
| Manage resource collection assignments | Assign collections to users, unassign them from users, and set when a user's access to a collection ends. |
| Manage resource collection details | Edit the names and descriptions of resource collections, and delete unnecessary collections. |
| Create resource campaigns or Create identity campaigns |
Certify access to resource collections to ensure that your users have the right level of access. Note:
Certify resource collections - Resource campaigns and Certify resource collections - User campaigns are Early Access features. See Enable self-service features. |
| Customizable reviewer context | Customize your campaigns to include contextual information that enables campaign reviewers to make informed decisions. |
| Understand remediation | Learn more about how Access Certifications remediates user access based on a reviewer's decision and the method used to assign access to the user. You must manually remediate access to resource collections. |
User experience
Learn about the tasks that users perform.
|
User task |
Description |
|---|---|
| Create requests | Understand how your requesters can request access to a collection directly from their dashboard after conditions are enabled for a collection. |
| Manage requests | Understand how request assignees can manage access requests for a resource collection. |
| Manage tasks | Understand how request approvers can approve or deny requests. |
| Review campaigns | Understand how reviewers can review the items assigned to them. |
Limits
The following table lists the limits that apply to resource collections.
| Limit | Maximum |
|---|---|
| Resource collections in an org | 500 |
| Total number of apps, Okta groups, and push groups in a collection | 50 |
| Number of entitlement values that can be added per Entitlement Management-enabled app in a collection | 100 |
| Number of users that can be assigned to a collection | no limit |
Existing limits also apply for Access Certifications and Access Requests .