Written by fabio
The main purpose of identity management systems is to manage user and role provisioning.
Provisioning will occur on a certain external resource every time the operation involves users or roles assigned to that resource.
By the way, Apache Syncope empowers the possibility to control the existence of users/roles on external resources giving the possibility to manage remote provisioning directly.
In fact, an authorized user (or an internal task - a sync task, for instance) can ask for
Apache Syncope gives the possibility to create and remove a sort of soft linking between users/roles and resources.
This kind of link doesn't imply any propagation at link creation/deletion time.
Apache Syncope gives the possibility to directly provision and de-provision users/roles on/from resources, without any link in place.
This provisioning feature (disjoint from the resource link mechanisms) is often very useful in case of reclaims.
Apache Syncope gives the possibility to create and remove a sort of hard linking between users/roles and resources.
This kind of link implies propagation at link creation/deletion time: it is the composition between link/unlink and provision/de-provision operations.