Define the rules, define the groups, Enterprise User Management does the rest.™
Administration Delegation
Restricted administration delegation enables flexible administrative boundaries. Conventional systems such as Microsoft Active Directory assume a hierarchy of administrative control, and thus cannot express non-hierarchical trust relationships.
The Enterprise User Management on the other hand models real social relationships (thanks to the Unified Enterprise Database™) so it can model a hierarchy (i.e. a manager trusts his employees in certain ways), or it can allow setting up arbitrary trusts that are not part of the hierarchy. You are not required to align Virtual Environments with organizational units for delegation of administration.
The Enterprise User Management system allows easy delegation of administrative tasks with precise resolution. These restricted administrators are then only allowed to manage access to a subset of the systems that are protected by the Enterprise User Management system.
Administration delegation can be defined with precise resolution by using any combination of Systems, Virtual Environments, Groups and Users. This varying level of resolution enables the definition of powerful delegation matrixes using the drill down web based user interface.