Configuring the Governance console for business users

As an administrator, you can configure security, dashboards, views, and workflows for Governance console.

Remember: The user interface in Governance console might appear different than what is shown in the OpenPages documentation.

Configuring security for Governance console

Governance console uses a role-based security model to provide a way for administrators to control user and group access to objects. By assigning a role to a user or group at a specific security context point in the object hierarchy, you can control access to objects. Roles represent the usual or expected function that a user or group plays within an organization. Some examples of roles are: Finance Reviewer, Tester, External Auditor, System Administrator, Control Owner, Risk Assessor.

For more information, see Role-based security model.

Security rules provide an extra level of security that works with role-based security. You define security rules for individual object types. After you define them, the rules are applied to all system components, including Reporting, FastMap, Triggers, Reporting Periods, and all available views.

You can create two levels of security by using security rules:

For more information about security rules, see Security rules.

Assigning profiles

Assign user profiles to your business users based on their set of governance goals. For example, if the user needs administrative access to the object types for model risk governance to provide them with insight into business processes and regulations, assign them the watsonx.governance MRG Master profile.

A profile provides users with a view of information that is directly related to their responsibilities. It gives users and groups access to object types, fields, and views. When you change a setting in a profile, the change is dynamic and the change is immediate.

For more information about profiles, including descriptions of the predefined profiles, see Solution components in Governance console.

Defining dashboards for profiles

Define dashboards in the UI that apply to specific profiles so that users see a default dashboard based on the profile that they belong to. Users can still customize their dashboard by adding their own dashboard panels or hiding default dashboard panels.

For more information, see Defining a dashboard for a profile.

Configuring views

Configure views to control what information is displayed to users and to determine how users interact with Governance console. You design the content and layout of a view by using the View Designer.

For more information about configuring views, see Views and Using the View Designer.

Enabling questionnaires

To enable users to answer questionnaires, set up access to object types for users, configure the email server, and customize the landing page. For more information, see Getting started with questionnaire assessments.

You can create or edit questionnaires, and you can set up questions in a questionnaire so that they perform specific actions based on the answers. For example, you can configure a response action that creates or copies objects, or sets the value of fields on objects.

For more information, see Questionnaire templates.

Enabling tags

Enable the tagging feature and create tags that business users can apply to objects in Governance console to categorize them. When tags are applied to objects, business users can use a search to find objects that belong to a specific category.

For more information, see Creating tags.

Viewing workflows

Each solution includes workflows. A workflow represents a business process and describes the tasks that are involved in the process. A workflow is defined for one object type. An object type can have multiple workflows. For example, the Model object has a Model Validation workflow and Model Deployment workflow. The two workflows reflect two different business processes for Models.

To view a list of workflows, click Settings icon > Solution Configuration > Workflows.

To design and create workflows, see Configuring GRC Workflow.

Configuring calculations

Configure calculations to automatically set values on fields. For example, a calculation can set a field when one of the following events occurs:

  • An object is created.
  • Calculation input fields are updated.
  • Object associations are made.
  • A workflow action starts that runs a calculation.

For more information, see Setting up GRC Calculations.

Assigning inventories to business entities

By default, use cases are synced to the default inventory in watsonx.governance, but you can change this configuration. You can configure the use cases of a business entity to sync with a specific inventory.
Note: You must use an inventory, not a catalog.
To assign an inventory to a business entity, do the following steps:
  1. In watsonx.governance, click AI governance > Inventories. Click the options menu next to the inventory that you want to use. Click Copy ID.
  2. In Governance console, open the task view of the business entity and update the Inventory ID (MRG-BusEnt:Catalog ID) field.

If the inventory ID is not specified, or the specified inventory ID does not exist, use cases are synced to the default inventory.

Synchronizing model groups with approaches

You can enable the synchronization of model groups in Governance console with approaches in watsonx.governance.

An approach captures the facets of a solution to a business problem, which is defined in a use case. Like model groups, approaches are versioned. The same version number is applied to all assets in an approach. If you have a stable version of an asset, you might maintain that version in an approach and create a new approach for the next round of iteration and experimentation.

Note: To synchronize model groups, the Governance console solutions schema must have the Model Group object type. Click Settings icon > Solution Configuration > Object Types and verify that Model Group is listed. If it's not listed, you need to update the watsonx.governance Model Risk Governance (MRG) solution.

The object type hierarchy is: Use case → Model groups (one or more) → Models (one or more)

When synchronization is enabled, the following actions occur:
  • When you create a model group in Governance console, a corresponding approach is created in watsonx.governance. When you update a model group, the changes are reflected in the approach.

    For synchronization to occur, the model group must have only one use case as its parent and the use case must be the primary parent of the model group.

    Tip: The model group can have other non-primary parents. For example, a model group can have the HR Chat bot use case as its primary parent and the HR and Finance business entities as non-primary parents.
  • When you create an approach for a use case in watsonx.governance, a corresponding approach is created in Governance console. When you update an approache, the changes are reflected in the model group.

To enable synchronization, you need Administrator level access to the watsonx.governance instance.

Do the following steps:
  1. Open watsonx.governance.
  2. Click Navigation Menu Navigation Menu icon, and then click Administration > Configuration and settings.
  3. Click Governance console integration.
  4. Click Synchronize model groups.
Note the following issues and limitations with synchronized model groups and approaches:
Deleting a model group

Problem: When you delete a model group, the approach is no longer synchronized with Governance console.

Solution: Unlink the models that are under the approach, create a new approach, and link the models to the new approach. This creates a new model group and restores the synchronization.

Disassociating a model group from a use case

Problem: When you disassociate a model group from its parent use case, the model group and approach are no longer synchronized.

Solution: Unlink the models under the approach, create a new approach, and link the models to the new approach.

Deleting approaches

Problem: In Governance console, you can delete or disassociate all model groups from a use case. But in watsonx.governance, a use case must have at least one approach.

If you delete or disassociate all model groups from a use case, an approach still remains in watsonx.governance but it is no longer synchronized.

Solution: In watsonx.governance, create a new approach under the use case and track models under the new approach.

Model Reassociation

Problem: If you disassociate a model from a model group and then associate it with a different model group, the change is not reflected in watsonx.governance.

Solution: In watsonx.governance, unlink the model from the approach, then track it under the required approach.

Viewing deployments

Problem: If a deployment exists under a model that is associated with a model group (and not the use case), the deployment isn’t displayed in use case task views.

Solution: To see deployments, use the model group task view instead of the use case task view.