Configuring the Governance console for business users
As an administrator, you can configure security, dashboards, views, and workflows for Governance console.
Configuring security for Governance console
Governance console uses a role-based security model to provide a way for administrators to control user and group access to objects. By assigning a role to a user or group at a specific security context point in the object hierarchy, you can control access to objects. Roles represent the usual or expected function that a user or group plays within an organization. Some examples of roles are: Finance Reviewer, Tester, External Auditor, System Administrator, Control Owner, Risk Assessor.
For more information, see Role-based security model.
Security rules provide an extra level of security that works with role-based security. You define security rules for individual object types. After you define them, the rules are applied to all system components, including Reporting, FastMap, Triggers, Reporting Periods, and all available views.
You can create two levels of security by using security rules:
- Record level security allows administrators to control access to individual objects in a folder.
- Field level security allows administrators to control access to individual fields within an object.
For more information about security rules, see Security rules.
Assigning profiles
Assign user profiles to your business users based on their set of governance goals. For example, if the user needs administrative access to the object types for model risk governance to provide them with insight into business processes and regulations, assign them the watsonx.governance MRG Master profile.
A profile provides users with a view of information that is directly related to their responsibilities. It gives users and groups access to object types, fields, and views. When you change a setting in a profile, the change is dynamic and the change is immediate.
For more information about profiles, including descriptions of the predefined profiles, see Solution components in Governance console.
Defining dashboards for profiles
Define dashboards in the UI that apply to specific profiles so that users see a default dashboard based on the profile that they belong to. Users can still customize their dashboard by adding their own dashboard panels or hiding default dashboard panels.
For more information, see Defining a dashboard for a profile.
Configuring views
Configure views to control what information is displayed to users and to determine how users interact with Governance console. You design the content and layout of a view by using the View Designer.
For more information about configuring views, see Views and Using the View Designer.
Enabling questionnaires
To enable users to answer questionnaires, set up access to object types for users, configure the email server, and customize the landing page. For more information, see Getting started with questionnaire assessments.
You can create or edit questionnaires, and you can set up questions in a questionnaire so that they perform specific actions based on the answers. For example, you can configure a response action that creates or copies objects, or sets the value of fields on objects.
For more information, see Questionnaire templates.
Enabling tags
Enable the tagging feature and create tags that business users can apply to objects in Governance console to categorize them. When tags are applied to objects, business users can use a search to find objects that belong to a specific category.
For more information, see Creating tags.
Viewing workflows
Each solution includes workflows. A workflow represents a business process and describes the tasks that are involved in the process. A workflow is defined for one object type. An object type can have multiple workflows. For example, the Model object has a Model Validation workflow and Model Deployment workflow. The two workflows reflect two different business processes for Models.
To view a list of workflows, click .
To design and create workflows, see Configuring GRC Workflow.
Configuring calculations
Configure calculations to automatically set values on fields. For example, a calculation can set a field when one of the following events occurs:
- An object is created.
- Calculation input fields are updated.
- Object associations are made.
- A workflow action starts that runs a calculation.
For more information, see Setting up GRC Calculations.
Assigning inventories to business entities
- In watsonx.governance, click . Click the options menu next to the inventory that you want to use. Click Copy ID.
- In Governance console, open the task view of
the business entity and update the Inventory ID (
MRG-BusEnt:Catalog ID) field.
If the inventory ID is not specified, or the specified inventory ID does not exist, use cases are synced to the default inventory.
Synchronizing model groups with approaches
You can enable the synchronization of model groups in Governance console with approaches in watsonx.governance.
An approach captures the facets of a solution to a business problem, which is defined in a use case. Like model groups, approaches are versioned. The same version number is applied to all assets in an approach. If you have a stable version of an asset, you might maintain that version in an approach and create a new approach for the next round of iteration and experimentation.
The object type hierarchy is: Use case → Model groups (one or more) → Models (one or more)
- When you create a model group in Governance console, a corresponding approach is created
in watsonx.governance. When you update a model
group, the changes are reflected in the approach.
For synchronization to occur, the model group must have only one use case as its parent and the use case must be the primary parent of the model group.
Tip: The model group can have other non-primary parents. For example, a model group can have theHR Chat bot
use case as its primary parent and theHR
andFinance
business entities as non-primary parents. - When you create an approach for a use case in watsonx.governance, a corresponding approach is created in Governance console. When you update an approache, the changes are reflected in the model group.
To enable synchronization, you need Administrator level access to the watsonx.governance instance.
- Open watsonx.governance.
- Click Navigation Menu
, and then click .
- Click Governance console integration.
- Click Synchronize model groups.
- Deleting a model group
-
Problem: When you delete a model group, the approach is no longer synchronized with Governance console.
Solution: Unlink the models that are under the approach, create a new approach, and link the models to the new approach. This creates a new model group and restores the synchronization.
- Disassociating a model group from a use case
-
Problem: When you disassociate a model group from its parent use case, the model group and approach are no longer synchronized.
Solution: Unlink the models under the approach, create a new approach, and link the models to the new approach.
- Deleting approaches
-
Problem: In Governance console, you can delete or disassociate all model groups from a use case. But in watsonx.governance, a use case must have at least one approach.
If you delete or disassociate all model groups from a use case, an approach still remains in watsonx.governance but it is no longer synchronized.
Solution: In watsonx.governance, create a new approach under the use case and track models under the new approach.
- Model Reassociation
-
Problem: If you disassociate a model from a model group and then associate it with a different model group, the change is not reflected in watsonx.governance.
Solution: In watsonx.governance, unlink the model from the approach, then track it under the required approach.
- Viewing deployments
-
Problem: If a deployment exists under a model that is associated with a model group (and not the use case), the deployment isn’t displayed in use case task views.
Solution: To see deployments, use the model group task view instead of the use case task view.
