Migration Workbench: traceable, reversible imports from your legacy system
FeatureSecurity
- Migration Workbench expanded: imports from your legacy system’s export file, such as SAP IDM, can be limited to individual object types (roles, composite roles, identities, assignments). The dry run now shows the same numbers as the import: existing assignments appear as skipped, invalid dates and unknown references as errors
- After the import, the audit and provisioning logs capture what was written, and the final report lists the records that were not imported, with the reason. A rollback reverts the import in Nova; it is now faster, and even an interrupted rollback leaves no orphaned records
- Admin chat: the AI assistant uses the same interfaces and checks as the user interface. Around 100 actions classified as destructive run only after a preview and a confirmation in a later message, and the audit log records them with the origin “AI chat”. New via the chat: assign or revoke an SAP role for many accounts in one step, with a preview
- Exports from the chat: answers and lists as PDF, Excel, CSV, Markdown or plain text. Every export and every download is recorded in the audit log, files expire after seven days, and cell contents are escaped against formula injection in Excel
- Change journal for all connectors: in addition to LDAP/AD, it now also records writes to SAP, SCIM, Keycloak and Entra ID accounts with before and after values, with passwords redacted centrally. As before, LDAP/AD changes and Entra group memberships can be reverted
- Four-eyes principle in requests: without admin rights, nobody can approve a step that concerns their own access, not even as role owner or deputy. New “Role admin” entitlement for role management without full admin rights; Nova’s own entitlements remain reserved for admins. An account in a target system can now be linked to only one identity, and the database enforces this even for direct SQL access
- Role mining rebuilt: each run breaks assignments down layer by layer into base, organizational, functional and special roles. The computation runs without AI; the AI names and describes the proposals and can veto individual ones. Before business roles are created, a dry run shows the effect
- Provisioning and lifecycle: attributes for source and target systems can be concatenated, set conditionally and transformed with expressions, with an AI suggestion and a live preview against a sample identity. Movers and leavers can be processed directly from the dashboard. Fixed: a position change from the HR source triggers the mover process again
- Operations: a send monitor for all notifications, modeled on SAP transaction SOST, with status and actions to send now, requeue or discard. Sending can be paused, and a per-recipient hourly limit applies
- Acceptance testing against real systems: SAP provisioning passed 34 of 34 test variants against an SAP system, LDAP provisioning 56 of 56 against our own LDAP servers, each in two test rounds. Fixed along the way: composite roles with changed child roles, and the length and leading characters of SAP passwords during automatic account creation