Administrator guide
Fulfilment and manual tasks
How approved access reaches the engine or a person, how manual tasks work, and how to deal with work that failed.
When a request is approved, Warde puts each line on its fulfilment queue. The queue sends it to the engine, or raises a ServiceNow catalog task for a person when the engine cannot do it. A request reads done only when the change is confirmed.
When a task is raised
Warde raises a catalog task instead of calling an engine when:
- the collection is Unmanaged, so no engine is bound;
- the engine cannot grant or remove that kind of access;
- the access cannot be removed through the engine, for example a role the engine gives from an attribute;
- the person has no account on the engine yet. Warde does not create accounts, so the task asks for the account first.
The task
| Field | Value |
|---|---|
| Short description | Grant <access> to <person> or Remove <access> from <person> |
| Description | The fulfilment instructions from the entitlement or collection, then the facts: person, account, access, request number |
| Assignment group | The collection's support group, or the fallback group from Guided Setup step 8 if that group is missing, inactive or empty |
| Template | The entitlement's task template, else the collection's, else the instance default from Guided Setup step 8 |
| Due date | From the collection's provisioning window, counted in business days on the Warde fulfilment hours schedule |
Tasks are ordinary sc_task records under the requested item, so they follow your existing assignment rules, notifications and SLAs. The fulfiller role lets the people working them see the Warde records behind the task.
Closing a task
Do the work in the target system, then close the task.
| Task state | What Warde does |
|---|---|
| Closed Complete | The change is recorded as done. Warde records the access as granted or removed. |
| Closed Incomplete, Closed Skipped | The operation fails, and the access stays as it was |
Warde checks open manual tasks every hour (x_66256_warde.queue.manual_poll_mins, default 60), so the request updates within the hour after the task closes. Warde does not tell the engine about manual work: the engine's next import reads the change.
Complete manually on a fulfilment operation records the change at once, for when the work was done some other way. The task stays open for you to close.
Watching the queue
The Admin Workspace's Operations lists and the Fulfilment operations dashboard show the queue:
| List | What is in it |
|---|---|
| Failed or parked | Work that needs a person. Start here. |
| Awaiting manual fulfilment | Open tasks, with how long they have been waiting |
| Waiting to retry | Engine calls that failed and will be tried again |
| Past the retry deadline | Engine calls that ran out of retries |
| Queued or with the engine | Work in flight |
When an engine call fails
Warde retries a failed engine call with a growing delay, starting at x_66256_warde.queue.retry_base_secs (60 seconds) and giving up after x_66256_warde.queue.retry_window_mins (240 minutes). If the engine is out of service, its work is held and sent again when the engine recovers.
Work that still cannot be done is parked, and Warde raises a task for the Group for failed grants and removals from Guided Setup step 8. If that group is not set, the task goes to the collection's support group, then the fallback group.
On a failed or parked operation, an administrator can:
| Action | What it does |
|---|---|
| Retry operation | Puts it back on the queue for the next run |
| Retry now | Sends it again at once |
| Cancel operation | Stops it. The request line shows it was cancelled. |
| Complete manually | Records the change as done, when it was done outside Warde |
An operation nobody acts on is abandoned after x_66256_warde.queue.abandon_after_days (7 days, at most 30).
When an engine does not answer
If an engine accepts a grant but never confirms it, Warde looks for the request in the engine by Warde's own reference and adopts it rather than sending it twice. If it cannot find it, the work goes to a person after 30 minutes. Each connector guide describes what that engine does.
Promised dates
When Tell requesters when to expect access is on (Guided Setup step 8), the requester is told when to expect the access:
- for manual work, the collection's provisioning window in business days, or the instance default of 2;
- for an engine that runs on a schedule, the collection's automated window in hours;
- otherwise, that the access is set up automatically.
The business days are counted on the Warde fulfilment hours schedule, or a collection's own schedule. Set the schedule's time zone, or Warde counts the hours in UTC.