Attachment 0017- AMPS Procedures for Users and Administrators.pdf
PDF 4 MB Posted
- Attached to
- Water Storage Distribution System (Solicitation) Federal contract opportunity
- Solicitation number
- W56HZV21R0011
About this file
This federal solicitation seeks proposals for the integration, assembly, and logistics packages for up to 123 Water Storage Distribution Systems, including 87 systems with a 100,000 gallon capacity and 36 split systems with two 50,000 gallon units each. The U.S. Army Contracting Command-Detroit Arsenal intends to award five indefinite-delivery, indefinite-quantity contracts for initial testing, then select a single contractor to receive orders for full production as well as up to 150 spare 350 gallon per minute fluid distribution pumps. The resulting IDIQ contracts will have a five-year base period and two one-year options. This procurement is reserved entirely for small businesses. The buyer is listed as Jon Kaercher, who can be reached at (586) 282-0328.
View the file
Other files for this federal contract opportunity
Show all 50
Water Storage Distribution System (Solicitation) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
User Guide AMPS Procedures for Users and Administrators
Version 1.2 ● January 9, 2014
Account Management and Provisioning System (AMPS) User Documentation: User Guide
AMPS Development Contract No. SP470312C0005/SP470312C0017 AMPS User Guide Ver 1.2.docx
- 2 -
Table of Contents Overview AMPS Documentation
How to Open the AMPS Documentation Screen Launching AMPS
How to Launch AMPS: CAC-enabled Users AMPS Home: Quick Tour Disable the Compatibility View Feature in Internet Explorer
My Profile How to Check Your Role Status How to View and Manage Your AMPS Information
Role Request Process How to Request a Role: Internal User
Role Request Subprocesses How to Update Organization Information How to Update Your Supervisor How to Browse for a Role
Role Request Approval Process How to Approve a Role Request
Separation of Duties Review Supervisor Approval Security Officer Approval Data Owner Approval Information Assurance Officer Approval
What Comes After the Final Approval?
Role Request Approval Subprocesses
How to Reject a Role Request How to Suspend a Role Request How to Resume Approval of a Suspended Request How to Delegate a Role Request How to Extend a Role Request Deadline
Provisioning Process: Total AMPS How to Provision a Role through Total AMPS
Role Removal How to Request Removal of a Role How to Approve a Role Removal Request
Document Information Index
Overview AMPS is an account provisioning system that sets up your access to computer application resources or provides information to a provisioner for manual setup. Access is based on the approval of your request for one or more application roles.
Application users, both internal (civilians, military, and contractors) and external (vendors, public), can have AMPS accounts that enable them to submit requests for these roles. When a role is approved, the user has access to the application resource.
AMPS User Guide The AMPS User Guide furnishes provides you with the procedures and instructions for completing AMPS tasks to get your access rights started:
• End users will find instructions for creating and submitting role requests, as well as removing roles.
• Approvers—including Supervisors, Security Officers, Data Owners, and Information Assurance Officers—will find instructions for handling approvals.
• A short section on Total AMPS provisioning is also included.
AMPS URL
Getting access to AMPS is easy; just open a browser and navigate to this URL:
https://amps.dla.mil/oim
Common User Access (CAC) Authentication At present, the DLA is running two versions of AMPS: Legacy AMPS and New AMPS.
Legacy AMPS, the existing system, is being replaced in stages by New AMPS. For the tasks and procedures outlined in this guide, you will use New AMPS solely.
Please note that the system may require CAC-enabled users to select a CAC certificate twice. This condition will continue until Legacy AMPS is retired and all users have migrated to New AMPS.
Enterprise Help Desk Users who need assistance with AMPS should contact the Enterprise Help Desk:
Telephone: 1-855-352-0001 Email Address: DLAEnterpriseHelpDesk@dla.mil
- 3 -
AMPS Documentation The AMPS team provides this user guide to acquaint users with AMPS procedures. We will update screen images, procedures, notification messages, and new functions periodically as AMPS is enhanced. Check the version number and date on the User Guide title page to ensure you have the latest copy. The latest versions of the User Guide and other job aids will be available through the AMPS Home page.
After launching AMPS, all users have access to a link to an AMPS Documentation page. The documentation on this page takes the place of all past guides, job aids, and other documents.
All documents listed on this page are distributed in Adobe PDF format and require Acrobat Reader to view. See the section entitled How to Launch AMPS: CAC-enabled Users on page 4 for instructions on starting AMPS.
How to Open the AMPS Documentation Screen
1. Click the AMPS Documentation link.
AMPS displays the documentation page (see Figure 2).
Figure 1: Sample Home Page - AMPS Documentation Link
2. Click the link for the document you want to download and view.
For PDF documents, AMPS opens Acrobat Reader automatically and displays the selected document or video file.
Figure 2: AMPS Documentation Page
- 4 -
Launching AMPS What you can do: As a Web-based application, AMPS is available through a browser, such as Internet Explorer (version 8 or later) that supports DLA web site access.
Getting access to AMPS is as simple as opening a browser instance and entering the AMPS URL.
Internal users: CAC authentication External users: User ID and password
Where to start: Start Internet Explorer or other approved browser.
How to Launch AMPS: CAC-enabled Users
1. In the URL address field, enter the following
URL:
https://amps.dla.mil/oim
2. Click the arrow icon in the browser, or press your keyboard’s Enter key.
AMPS displays a security certificate request (see Figure 4).
Figure 3: Sample Browser Page – AMPS URL
3. Select a certificate and click OK.
AMPS displays a Single Sign-on Authentication screen (see Figure 5).
Figure 4: Security Dialog – Certificate
2 1 https://amps.dla.mil/oim
- 5 -
4. Read the conditional statement for information system access and click OK to acknowledge your understanding and agreement.
AMPS displays the Single Sign-on Authentication screen.
5. Click OK to acknowledge consent and proceed to AMPS.
AMPS opens the Home screen (see Figure 6).
Figure 5: Single Sign-on Authentication - Acknowledgement Confirmation
Note:
The sample shown in Figure 6 displays the commands available to any user. Certain AMPS administrator roles have additional commands that enable them to complete tasks within AMPS.
Check the AMPS Home: Quick Tour section for more information about the Home screen.
Figure 6: AMPS Home Screen - Sample User
- 6 -
AMPS Home: Quick Tour A. Main Menu: Provides access to common tasks you perform in
AMPS.
B. Tabbed screens provide parallel access to multiple task types.
For example, you can open your My Information page, update attributes in your profile, and then start the role request process without having to close the My Information tab first.
C. Sign Out command and login ID: Sign Out provides a method for exiting AMPS. The User ID displayed shows the identity of the currently logged in user.
D. Navigation buttons: furnish the method for proceeding forward and backward through a series of task screens on a tab page.
E. Close button: click the Close button on any tab page to close the current tab without completing the task on that page.
Figure 7: Sample Home Page
F. Required fields: fields that require you to enter information before you proceed are marked with an asterisk (*).
G. “Train” screen navigation tool: some tasks, such as Role Request, furnish a connected series of screen names called a “train.” If you are familiar with the “breadcrumb trail” as a navigation tool in Web sites, you will find that the AMPS “train” works in a similar way. As you proceed through the series of screens in a task process, AMPS turns each screen name in the train into a link you can click to reopen the corresponding screen. If you need to display a previously viewed screen, click any active screen name in the train to jump backward or forward. Using the train links as a screen navigation tool, you can skip multiple screens in the sequence.
For example, when you reach the Summary page in Role Request, you can skip the previous screens and jump back to User Information without having to navigate backward through every screen in sequence.
The “train” is a time-saving way to help you view and change any screen before you complete a process such as requesting a role.
B A
D
F
C
E
- 7 -
Disable the Compatibility View Feature in Internet Explorer When you launch AMPS in Internet Explorer (IE), you may see a Compatibility View message.
The Compatibility View is meant for users who run applications developed for IE 7 and prior versions. The Compatibility View in IE 8 or later can affect the display of certain screen elements, such as action buttons, in some New AMPS screens. Follow these instructions to turn off Compatibility View and prevent IE from displaying this message again.
1. In the Message from webpage box, click OK to close the message.
AMPS displays the Home screen in Internet Explorer.
Figure 8: Compatibility View Message
2. In the IE Command Bar, click Tools.
3. Click Compatibility View Settings.
AMPS opens the Compatibility View Settings dialog (see Figure 10).
Figure 9: Internet Explorer - Tools Menu
- 8 -
4. Review any entries in the text area labeled Websites you’ve added to Compatibility View.
5. If your Compatibility View Settings dialog contains any entries for dla.mil, dfas.mil, or other Web sites, select each entry and click the Remove button.
IE removes the specific Compatibility View setting from all sites in dla.mil or dfas.mil.
Figure 10: Compatibility View Settings: Remove All Web Sites
6. Locate the checkbox for option to Display intranet sites in Compatibility View.
Figure 11: Compatibility View Settings – Deselect the Compatibility View Option
4 5
- 9 -
7. Click the checkbox to deselect the option.
8. Click Close.
IE closes the Compatibility View Settings dialog and returns to the AMPS home screen.
After you make this change, opening AMPS in IE will not force the display of the application into Compatibility View for AMPS or any other application in dla.mil or dfas.mil.
Figure 12: Internet Explorer - Deselect the Option to Display in Compatibility View
- 10 -
My Profile What you can do: The menu section labeled My Profile enables you to view and manage information about yourself, your roles, and your accounts.
If you need to . . . Navigate this path to this specific screen . . .
Identify the roles you have through AMPS My Profile > My Information > Application & Roles tab > Current Roles Check the status of a pending role request My Profile > My Information > Application & Roles tab > Pending Roles/Requests Review or modify basic information or contact data My Profile > My Information > User Information > User Information
My Profile > My Information > User Information > Contact Information Manage your password or challenge questions (external users only) My Profile > My Information > Change Password
My Profile > My Information > Challenge Questions Update your Organization My Profile > My Information > User Information > Organization Change your Supervisor Internal users: My Profile > My Information > User Information > Supervisor View your Direct Reports (Supervisors only) My Profile > My Information > Direct Reports
Where to start: Launch AMPS
How to Check Your Role Status
1. Launch AMPS.
The user ID entry indicates the identity of the currently logged-in user.
2. Under the My Profile menu on the Home screen, click My Information.
AMPS displays the My Information screen (see Figure 14).
3. Click the Applications & Roles tab.
AMPS displays the Applications & Roles tab
Figure 13: AMPS Home Screen My Profile Menu
Figure 14: Role Status Screen - Application Roles Tab
- 11 -
4. Review the Current Roles section to view the roles you are currently assigned.
AMPS displays the following data:
- Role name
- Application
- Environment (Production)
- Role Type (User or Admin)
5. Review the Pending Roles section to check the status of a role request according to SAAR number.
AMPS displays the following date:
- SAAR ID
- Role Name
- Status
- Current Approver
- Request Date
- Expiry Date
- Last Activity Date
By checking this data, you can determine the current approval status, the expiration date of the current SAAR, and the date of the last approver’s action.
6. Review the SAAR History section to review SAARs that have been completed, rejected, or otherwise terminated.
Figure 15: Applications & Roles Tab Page
- 12 -
How to View and Manage Your AMPS Information
1. Log in to AMPS.
AMPS displays the Home screen. Your ID is displayed to indicate you are the logged-in user.
AMPS displays the My Information screen.
Figure 16: AMPS Home Screen My Profile Menu
3. Enter changes or new entries in the modifiable data fields.
Fields marked with an asterisk (*) are required entries.
Any of the bordered fields in User Information and Contact Information are modifiable. To modify data in nonmodifiable fields, contact the Enterprise Help Desk.
Click the search icon beside the Organization Name field to update your Organization. The IA Officers and Security Officers listed correspond to the selected Organization.
Click the search icon beside the Supervisor Name field to update your Supervisor name and information.
The Direct Reports tab (not pictured) is for Supervisors who have staff members reporting directly to them. A Supervisor handles all approval requests and other changes to AMPS records for staff members listed under Direct Reports.
4. Click Save to save your changes.
Figure 17 : User Information Screen
- 13 -
Role Request Process What you can do: The Role Request process enables you to select and enter information required to submit a role request. The process displays several information entry screens in sequence. At the top of each role request screen is a series of screen names that help you trace your location in the sequence. Click the name of any screen already visited to return to it, and add or correct information before submitting the request. The current screen’s name is displayed in bold text:
Figure 18: Role Request Navigation
Where to start: Start the Role Request process by launching AMPS to display the Home screen.
Note that any field marked with an asterisk (*) is a required field.
How to Request a Role: Internal User
AMPS displays the Home screen. Your ID is displayed to indicate you are the currently logged-in user.
2. In the Requests menu on the Home screen, click Request Role.
Figure 19: AMPS Home Screen
- 14 -
3. Enter your Cyber Awareness Certificate date (required).
4. Select your User Type from the following choices (required):
∗ Internal user selections:
i. Military: select your Branch and
Rank from the fields displayed when you select this User Type.
ii. Civilian: select your Grade in the field displayed when you select this User Type (required).
iii. Contractor: enter your Contract Number, Contract Company, and Contract Expiration date in the fields displayed when you select this User Type.
5. Update your Organization, as needed, and note the contact information for the Security Officers and the IA Officers.
(See How to Update Organization Information on page 19 for more instructions.)
6. Update your Supervisor, as needed.
(See How to Update Your Supervisor on page 22 for more instructions)
7. Click Next.
Figure 20: Request Role - User Information
- 15 -
AMPS Displays the Select Roles Screen
8. In the Select Roles screen’s Search Roles section, enter all or part of any search criteria you have available.
For example, if you have the role name, you can enter part of the name in the Role Name field (see Figure 21).
9. Click the Search button.
AMPS displays the names of all roles having a name or other criteria that match the Search string.
10. Locate the role you want to request in the Select Roles Role Name list:
a. To verify your choice, click the Expand button (>) to display details about the role.
b. EBS users: If you select an Additional role without first requesting and receiving a related Primary role, AMPS displays an error message.
11. Select the role and click the right arrow button.
AMPS copies the role name to the Select Roles list panel on the right.
To request multiple roles, repeat steps 8-10 if you do not require, or already have, a primary role.
12. Click Next.
Figure 21: Request Role - Select Roles
- 16 -
AMPS displays the Justification screen.
13. In the Justification screen, fill in the following information:
a. Enter comments in the Justification text area to clarify the request (required).
b. As an option, you can enter further comments in the Optional Information text area to supply additional information that supports your request.
14. Click the Browse button to locate and attach a supporting document. Repeat this procedure to attach an additional two documents, as needed.
Note that attachments must be formatted as Adobe Portable Document Format (PDF) files of two megabytes or less in size.
15. Click Next.
Figure 22: Request Role – Justification
AMPS displays the Summary screen.
16. Review the information in the Summary screen.
- Click the Back button to return to previous screens and make corrections, as needed.
- After making corrections, click the Next button or the Summary node in the train to return to the Summary screen.
17. Click Submit to complete the role request.
Figure 23: Request Role – Summary
13a
13b
- 17 -
AMPS submits the role request for approval.
18. Note that the SAAR number is listed here, along with role and status information on the Role Request Confirmation screen.
Your status notifications and Pending Role records will refer to this SAAR number.
19. Click the OK button on the confirmation
Figure 24: Confirmation
- 18 -
AMPS returns to the Home screen.
20. From the Home screen (see Figure 19), select
My Information to display User Information and Applications & Roles tab page selections.
21. Click Applications & Roles and view the Pending Roles section to check the status of your request as it proceeds through the Approval process.
Figure 25 illustrates the status of the sample SAAR created in this process. Initially, the SAAR goes to the Supervisor first, unless the customer’s organization requires a prior Separation of Duties (SOD) review.
A user can check Pending Roles to determine the location of a SAAR in the approval process.
Figure 25: Sample Pending Roles Screen
- 19 -
Role Request Subprocesses What you can do: Follow this procedure if you are a User submitting a new role request and your need to correct your Organization information.
Where to start: Begin the process of creating a role and start on the User Information screen.
How to Update Organization Information Find the Update Organization command.
1. Click the Update Organization command on the User Information.
AMPS displays the Find an Organization dialog (see Figure 27).
Figure 26: User Information - Update Organization
- 20 -
2. Enter all or part of an Organization name in the Name field.
3. Click Search.
AMPS displays matching names in the Search Results area (Figure 28).
Figure 27: Select Organization - Search
4. Select the name you want to use in the Organization section.
5. Click OK.
AMPS enters the selected name and corresponding information in the Organization Information section of the Role Request’s User Information screen (see Figure 29).
Figure 28: Select Organization - Search Results
- 21 -
6. Review the Organization update and proceed with the role request.
When you update the Organization, AMPS automatically identifies the updated organization name and populates the Security Officer(s) and IA Officer(s) listings with the names of the current organization’s Security Officers and IAOs.
Figure 29: Update Organization - Selected Organization Entered
- 22 -
How to Update Your Supervisor What you can do: Follow this procedure if you are a User submitting a new role request and you need to correct your Supervisor designation. AMPS updates this information in your New
AMPS profile. The following business rules apply to the process of selecting a Supervisor:
• Every Organization must have one or more Supervisors to handle role request approvals for their users.
• Each user who requests a role must have a Supervisor assigned in AMPS. Use the Update Supervisor function to select a Supervisor if the Supervisor Information area is blank.
• Internal users can select only another internal user as a Supervisor.
• A user cannot select a contractor as a Supervisor. Only government employees can be Supervisors in AMPS. AMPS controls the selection process by restricting the display of Supervisor names to government employees, either Civilian or Military.
• A user can select an internal user from another Organization as a Supervisor.
• All Supervisors must request and be granted the AMPS Supervisor role. However, a user can select a user who does not have the Supervisor role. For a Supervisor who does not have the appropriate role, AMPS tells the assigned Supervisor of the need to request this role in the Pending Approvals list under the My Tasks tab.
Where to start: Begin the process of creating a role and start on the User Information screen.
Locate the Update Supervisor command on the User Information screen.
1. Click Update Supervisor.
AMPS displays the Find a Supervisor dialog (see Figure 30).
Figure 30: User Information - Update Supervisor Command
- 23 -
2. Enter all or part of any of the following user designations:
a. Last Name,
b. First Name, or
c. Login Name
3. Click Search.
AMPS displays matching names in the Search Results area.
Figure 31: Find a Supervisor - Search by Last Name
4. Click the name you want from the Search results.
5. Click OK.
AMPS enters the selected name and corresponding information in the Supervisor Information section of the role request’s User Information screen.
Figure 32: Supervisor Search Results
- 24 -
6. Review the Supervisor Information section to ensure you selected the correct supervisor.
Proceed with the role request for the selected user (see page14).
Figure 33: User Information - Supervisor Updated
- 25 -
How to Browse for a Role What you can do: Follow this procedure if you are a User browsing for a role name, rather than using the Search function.
Follow this procedure if you are a Supervisor submitting a new role request for a subordinate and you want to browse for a role, rather than use the Search function.
Where to start: Begin the process of creating a role, starting on the User Information screen, and navigate to the Select Roles screen.
1. In the Select Roles screen’s
Browse Roles by Application section, expand the application category that contains your application name.
AMPS displays the names of all roles associated with the category in the Select a Role area.
2. Select your application.
AMPS displays all roles associated with the application in the Select a Role area.
3. Locate the role you want to request.
a. To verify your choice, click the Expand button (>) to display details about the role.
b. If you select an Additional role without first selecting a related Primary role, AMPS displays an error message.
4. Select the role and click the right arrow button (-- >). AMPS copies the role name to the Select Roles list panel on the right.
5. To request multiple roles, repeat steps 1-4. (EBS users must have a primary role assigned before proceeding.)
6. Click Next to proceed with your role request.
Figure 34: Request Role Select Roles
1-2
- 26 -
Role Request Approval Process New AMPS handles notifications and the role request approval process by modeling and supporting DD 2875 approval business processes similar to Legacy AMPS. As in Legacy AMPS, role requests are approved in sequence, from the Security Reviewer, as needed, to the Supervisor, Security Officer, Data Officer, and Information Assurance Officer. The Security Officer will see only the first role request from a user until the user’s account is submitted for revalidation or otherwise flagged for the Security Officer’s attention.
All other approvers receive notifications, and each approver has 20 days to act before a role request expires. AMPS handles the sequential submission for approval to each approver automatically, and then submits the approved request for provisioning.
Approval Process Summary The procedures in this section describe how each approver handles the approval of a role request in New AMPS. The procedures include the text of sample email notifications that
AMPS sends to users and approvers at each stage of the approval process. Only users who have been assigned one of the AMPS roles identified in Table 1 can follow these procedures.
Although the New AMPS screens look different, the process is very similar to Legacy AMPS. In New AMPS, the approver
• Receives a notification that an action is required on a role request.
• Logs in to New AMPS and navigates to a list of pending tasks.
• Selects the pending task to open the approval decision screen.
• Selects or enters data in required and optional fields.
• Approves, rejects, or cancels the role request.
Table 1 summarizes approvers and their tasks.
Table 1: Role Request Approvers and Provisioners This Approver… Is assigned… Notes For more information… Separation of Duties (SOD) Reviewer
To your organization The SOD Reviewer provides a point of entry to the approval process for customers who require a Separation of Duties check for each role request.
Users:
• Separation of Duties Review (see Figure 38).
Separation of Duties Reviewers:
• Separation of Duties Review on page 28.
Supervisor To your account when the account is created initially.
However, if a change occurs that is not reflected in AMPS, you can change your Supervisor in AMPS during the role request process.
Users:
• How to Update Your Supervisor on page 22.
Supervisors:
• Supervisor Approval on page 28.
• How to Reject a Role Request on page 45.
• How to Suspend a Role Request on page
Security Officer To the Organization to which you belong.
You cannot change this assignment. However, Organizations may have two or more Security Officers assigned. You can identify them during the role request process.
Users:
• How to Request a Role, page 13.
• How to Update Organization Information on page 19.
Security Officers:
• Security Officer Approval on page 36.
• How to Reject a Role Request on page 45.
• How to Suspend a Role Request on page
Data Owner To the application associated with the role you are requesting.
Data Owners see all role requests for access to their application data.
Users: See your Supervisor if you have questions about the Data Owner.
Data Owners:
• Data Owner Approval on page 39.
• How to Reject a Role Request on page 45.
• How to Suspend a Role Request on page 49.
Information Assurance Officer
(IAO)
To the Organization to which you belong.
You cannot change this assignment. However, Organizations may have two or more IAOs assigned. You can identify them during the role request process.
Users:
• How to Request a Role on page 13.
IAOs:
• Information Assurance Officer Approval on page 42.
• How to Reject a Role Request on page 45.
• How to Suspend a Role Request on page 49.
- 27 -
Required Approvals and Time Limits
The AMPS process for submitting and approving a user’s role request is called a “workflow.” A workflow automates the process of sending notifications of required actions and of forwarding action items to approvers in sequence. The AMPS approval workflow automatically tracks and reports on the status of each approval request.
After a user submits a role request, AMPS forwards the request to the approval workflow.
During the workflow process, several approvers review the request before the role is provisioned to the user’s account.
The number of approvers who review a request is defined in AMPS, and the number may vary according to which application and role make up the request. As AMPS forwards the request to each approver, AMPS also sends each user email notifications indicating the request’s current status and pending approval requirements. Each approver receives email notifications from AMPS for role requests that require his or her action.
Approval Period and Automatic Cancellation
From the time an approver receives the initial email notification for a role request approval, AMPS provides 20 days for the approver to complete an action on the request: either approve or deny. After the initial notification, AMPS delivers additional email notifications every 2 days to the current approver until the request is approved or denied, or the 20-day approval period expires.
If approvers do not act on a request before the end of the approver’s time limit, the SAAR expires. AMPS then notifies the requestor that the request has expired. If the requestor still needs the role, he or she should consult a Supervisor and, if necessary, submit a new request.
The following chart summarizes approvers in the workflow, approval requirements, and approval time limits.
Table 2 : Required Approvals and Time Limits
Required Approvals Role/Application Reminder Notifications Time Limit for Approval
Separation of Duties (SOD) Reviewer
All role requests for applications that require an SOD Review to ensure Separation of Duties policies are enforced before the role request is approved.
Every two days after initial notification. 20 days
Supervisor All role requests for all applications Every two days after initial notification. 20 days
Security Officer
All initial role requests for all applications.
All role requests from users flagged for an additional Security Officer Review.
Every two days after initial notification. 20 days
Data Owner All role requests. Every two days after initial notification. 20 days
Information Assurance Officer All role requests. Every two days after initial notification. 20 days
Information Assurance manager Requests for an IAO role Every two days after initial notification. 20 days
Provisioners (System Administrators, Database Administrators)
All Total AMPS Solution requests approved during the approval workflow
No reminders issued. No expiration of the ticketed provisioning request.
- 28 -
How to Approve a Role Request What you can do: Follow this procedure if you are a designated reviewer or approver and have received an email notification indicating a SAAR awaits your action in AMPS.
Where to start: To begin the process of reviewing or approving a role, review relevant email notifications, log in to AMPS, and click the Pending Approvals command.
Separation of Duties Review A Separation of Duties (SOD) Review is an optional stage in the approval workflow, required only by certain customers and organizations, such as DFAS. If your organization does not require an SOD review as part of the approval workflow, you can skip this section and go to the Supervisor Approval section.
The following procedure explains how to complete an SOD review of a role request in AMPS for compliance with SOD business practices
1. After a User requests a Role, AMPS sends an email notification confirming the request submission and indicating the role request is waiting for the SOD Reviewer’s approval.
Sample User Notification: Confirmation Subject: Notification: SAAR #6213 - Request User Access for Draco Teck (TEC_USER_254) (DFAS Columbus) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
Your request for role DFAS Prompt Pay Prod - View Only PRPY-007 with access to DFAS Prompt Pay (SAAR 6213) has been submitted for approval.
Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
2. AMPS also sends an email notification to the user indicating the role request is waiting for the Supervisor’s approval.
Sample User Notification: Status Subject: Notification: SAAR #6213 - Request User Access for Draco Teck (TEC_USER_254) (DFAS Columbus) (DFAS Prompt Pay) Dec 12, 2013 11:01 a.m.
Body:
SAAR #6213 is awaiting Separation of Duties approval of your request for the following role: DFAS Prompt Pay Prod - View Only PRPY-007 with access to DFAS Prompt Pay. This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
No action on your part is required.
AMPS provides this message for notification only.
Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
3. After a User requests a Role, AMPS sends an email notification to the User’s Supervisor indicating that a SAAR has been submitted for the Supervisor’s approval.
Sample Review Notification Subject: Action Required: SAAR #6213 - Request User Access for Draco Teck (TEC_USER_254) (DFAS Columbus) (DFAS Prompt Pay) Dec 12, 2013 11:01 a.m.
Body:
SAAR #6213 has been submitted for Separation of Duties approval on behalf of Draco Teck regarding a request for the following role: DFAS Prompt Pay Prod - View Only PRPY-007 with access to DFAS Prompt Pay.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
Please visit AMPS at this URL:https://amps.dla.mil/oim.
Review your Pending Approvals to locate the SAAR and complete the approval task.
This task expires on Jan 1, 2014 11:01 a.m. AMPS provides this message for notification only.
Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
- 29 -
4. On the AMPS Home screen under the Requests menu heading, click Pending Approvals.
AMPS displays the Approval Details screen. By default, this screen opens with the My Tasks tab displayed (Figure 36): “My Tasks” refers to the tasks assigned to the logged-in user.)
Figure 35: Requests Menu
5. On My Tasks, click the SAAR entry indicated in the email notification.
AMPS displays the Application Access Decision screen for the specified SAAR (see Figure 37).
Figure 36: Approval Details - My Tasks Tab
- 30 -
6. Fill in the required Comments fields:
Enter comments to support the decision. AMPS passes these comments to the next approver when they are entered.
7. Click Complete.
AMPS automatically . . .
• Sends the SAAR to the Supervisor and
• Removes the SAAR as assigned to the SOD Reviewer from the My Tasks tab.
Figure 37: Separation of Duties Reviewer Screen
- 31 -
8. After the approval is submitted, AMPS sends an email notification to the user regarding the approval’s status.
Sample User Notification: Status Subject: Notification: SAAR #6213 - Request User Access for Draco Teck (TEC_USER_2254) (DFAS Columbus) (DFAS) Dec 12, 2013 11:01 a.m.
Body:
The Security Oversight Officer has completed an approval task for SAAR #6213 regarding your request for the following role: DFAS Prompt Pay Prod - View Only PRPY-007 with access to DFAS Prompt Pay.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
9. In addition, AMPS displays SAAR information and status in the user’s Pending Approvals’ Applications & Roles screen.
The status shows the SAAR has been forwarded to the Supervisor for approval.
Figure 38: Sample User – My Information > Applications & Roles – Pending Roles
- 32 -
Supervisor Approval The following procedure explains how to approve a role request by starting at the AMPS Home page. This procedure pertains to New AMPS only.
1. After a User requests a Role, AMPS sends an email notification confirming the request submission and indicating the role request is waiting for the Supervisor’s approval.
Sample User Notification: Confirmation Subject: Notification: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
Your request for role AMPS BASIC TEST ROLE with access to AMPS (SAAR 6129) has been submitted for approval. AMPS provides this message for notification only.
Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
2. AMPS also sends an email notification to the user indicating the role request is waiting for the Supervisor’s approval.
Sample User Notification: Status Subject: Notification: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR #6129 is awaiting Supervisor approval of your request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
No action on your part is required.
AMPS provides this message for notification only.
Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
3. After a User requests a Role, AMPS sends an email notification to the User’s Supervisor indicating that a SAAR has been submitted for the Supervisor’s approval.
Sample Approver Notification Subject: Action Required: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR #6129 has been submitted for Supervisor approval on behalf of Dinah Teck regarding a request for the following role: AMPS BASIC TEST ROLE with access to
AMPS.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
Please visit AMPS at this URL:https://amps.dla.mil/oim.
Review your Pending Approvals to locate the SAAR and complete the approval task.
This task expires on Jan 1, 2014 11:01 a.m. AMPS provides this message for notification only.
Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
- 33 -
4. On the AMPS Home screen under the Requests menu heading, click Pending Approvals.
AMPS displays the Approval Details screen. By default, this screen opens with the My Tasks tab displayed (Figure 36): “My Tasks” refers to the tasks assigned to the logged-in user.)
Figure 39: Requests Menu
5. On My Tasks, click the SAAR entry indicated in the email notification.
AMPS displays the Supervisor Application Access Decision screen for the specified SAAR (see Figure 37).
Figure 40: Approval Details - My Tasks Tab
- 34 -
6. Fill in the required fields.
a. Start Date (auto-filled) : this entry must be no earlier than the current date.
b. End Date (auto-filled) : adjust as needed. This field entry is required.
c. Comments: as an option, enter comments to support the decision. Comments are not required for an approval, but AMPS passes them to the next approver when they are entered.
7. Click Approve.
• Sends the SAAR to the next approver and
• Removes the SAAR as assigned to the Supervisor from the My Tasks tab.
Figure 41: Supervisor Approval Screen
- 35 -
8. After the approval is submitted, AMPS sends an email notification to the user regarding the approval’s status.
Sample User Notification: Status Subject: Action Required: SAAR#6129 - Request User Access for Dinah Teck (TEC_USER_205) (DLA Aviation (AMPS) Dec 12, 2013 11:01 a.m.
Body:
The Supervisor has completed an approval for SAAR#6129 regarding your request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
The outcome for this task is APPROVED.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
9. In addition, AMPS displays SAAR information and status in the user’s Pending Approvals screen.
The status shows the SAAR has been forwarded to the Security Officer for approval, if the current request is the requestor’s initial role request for the application.
Figure 42: Sample User – My Information > Applications & Roles – Pending Roles
- 36 -
Security Officer Approval The following procedure for Security Officers explains how to approve a role request by starting at the AMPS Home page.
1. After a User’s Supervisor approves a Role Request, AMPS sends an email notification to the user with the request’s status, indicating the role request is waiting for the Security Officer’s approval.
Sample User Notification: Status Subject: Notification: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR #6129 is awaiting Security Officer approval of your request for the following role: AMPS BASIC TEST ROLE with access to AMPS. This request was submitted in AMPS on Dec 12, 2013 11:01 a.m. No action on your part is required. AMPS provides this message for notification only. Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
2. After a Supervisor approves a Role Request, AMPS sends an email notification to the user’s appointed organization Security Officer indicating that a SAAR has been submitted for the Security Officer’s approval.
Sample Approver Notification Subject: Action Required: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR #6129 has been submitted for Security Officer approval on behalf of Dinah Teck regarding a request for the following role: AMPS BASIC TEST ROLE with access to AMPS. This request was submitted in AMPS on Dec 12, 2013 11:01 a.m. Please visit AMPS at this URL:https://amps.dla.mil/oim. Review your Pending Approvals to locate the SAAR and complete the approval task. This task expires on Jan 1, 2014 11:01 a.m. AMPS provides this message for notification only. Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
3. On the AMPS Home screen under the
Requests menu heading, click Pending Approvals.
AMPS displays the My Tasks tab in the Approval Details screen (Figure 40). “My Tasks” refers to the tasks assigned to the logged-in user.
Figure 43: Requests Menu
4. In the My Tasks tab, click the SAAR number indicated in the email notification.
AMPS displays the Security Officer Application Access Decision screen (see Figure 41).
Figure 44: Approval Details – My Tasks Tab
- 37 -
5. Fill in the required and optional fields:
a. IT Level Designation: select the requestor’s IT level from the drop-down list.
b. Clearance Level: select the requestor’s Clearance Level from the drop-down list.
c. Type of Investigation: select the investigation type conducted for the requestor from the drop-down list.
d. Date of Investigation: select or enter the requestor’s investigation date.
e. Comments: as an option, enter comments to support the decision.
Comments are not required for an approval, but AMPS passes them to the next approver when they are
6. Click Approve.
• Sends the SAAR to the next approver and
• Removes the SAAR as assigned to the Security Officer from the My
Figure 45: Security Officer Approval Screen
- 38 -
7. AMPS sends an email notification to the user regarding the approval’s status. Sample User Notification: Status
Subject: Notification: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation (AMPS) Dec 12, 2013 11:01 a.m.
Body:
The Security Officer has completed an approval for SAAR #6129 regarding your request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
The outcome for this task is APPROVED.
AMPS provides this message for notification only. Please do not respond to this message. If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
8. In addition, AMPS displays SAAR information and status in the user’s Pending Approvals screen.
The status shows the SAAR has been forwarded to the Data Owner for approval.
Figure 46: Sample User’s Pending Roles
- 39 -
Data Owner Approval The following procedure explains how to approve a role request by starting at the AMPS Home page. This procedure pertains to New AMPS only.
1. After the Security Officer approves a Role Request, AMPS sends an email notification to the user with the request’s status.
Sample User Notification: Status Subject: Action Required: SAAR#6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR#6129 is awaiting Data Owner approval of your request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
No action on your part is required.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
2. After the Security Officer approves a Role Request, AMPS sends an email notification to the application’s Data Owner, indicating that a SAAR has been submitted for the Security Officer’s approval.
Sample Approver Notification Subject: Action Required: SAAR#6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR#6129 has been submitted for Data Owner approval on behalf of Dinah Teck regarding a request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
Please visit AMPS at this URL:https://amps.dla.mil/oim. Review your Pending Approvals to locate the SAAR and complete the approval task. This task expires on Jan 1, 2014 11:01 a.m.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
3. On the AMPS Home screen under the Requests menu heading, the Data Owner clicks Pending Approvals.
Figure 47: Requests Menu
4. On the My Tasks tab, click the SAAR number indicated in the email notification.
AMPS displays the Data Owner Application Access Decision screen for the SAAR (see Figure 45).
Figure 48: Approval Details - Administrative Tasks Tab
- 40 -
5. In the Data Owner Application Access Decision screen, complete entries for the required fields.
a. Start Date (auto-filled): Required entry. The Start Date must not be earlier than the current date.
b. End Date (auto-filled): Required entry.
c. Comments: As an option, enter comments to support the decision.
Comments are not required for an approval, but AMPS passes them to the next approver when they are entered.
6. Click Approve.
AMPS automatically . . .
• Sends the SAAR to the next approver and
• Removes the SAAR as assigned to the Data Owner from the My Tasks tab.
Figure 49: Data Owner Approval Screen
- 41 -
7. After the approval is submitted, AMPS sends an email notification to the user regarding the approval’s status.
Sample User Notification: Status Subject: Notification: SAAR#6129 - Request User Access for Dinah Teck (TEC_USER_207) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
The Data Owner has completed an approval for SAAR#6129 regarding your request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
The outcome for this task is APPROVE.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
8. In addition, AMPS displays SAAR information and status in the user’s Pending Approvals screen.
The status shows the SAAR has been forwarded to the Information Assurance Officer for approval.
Figure 50: Sample User’s Pending Roles
- 42 -
Information Assurance Officer Approval The following procedure explains how to approve a role request by starting at the New AMPS Home page. This procedure pertains to New AMPS only.
1. After the Data Owner approves a Role Request, AMPS sends an email notification to the User with the request’s status.
Sample User Notification: Status Subject: Action Required: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_213) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR#123 is awaiting Information Assurance Officer approval of your request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
No action on your part is required.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
2. After the Data Owner approves a Role Request, AMPS sends an email notification to the User’s Information Assurance Officer (IAO), indicating that a SAAR has been submitted for the IAO’s approval.
Sample Approver Notification Subject: Action Required: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_213) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
SAAR#123 has been submitted for Information Assurance Officer approval on behalf of Dinah Teck regarding a request for the following role: AMPS BASIC TEST ROLE with access to AMPS.
This request was submitted in AMPS on Dec 12, 2013 11:01 a.m.
Please visit AMPS at this URL: https://amps.dla.mil/oim. Review your Pending Tasks to locate this SAAR and complete the task. This task expires on Jan 1, 2014 11:01 a.m.
AMPS provides this message for notification only. Please do not respond to this message.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
3. On the AMPS Home screen under the Requests menu heading, click Pending Approvals.
Figure 51: Requests Menu
4. In the My Tasks tab, click the SAAR number indicated in the email notification.
Figure 52: Approval Details - My Tasks
- 43 -
5. In the Information Assurance Officer Application Access Decision screen, fill in the required fields:
a. Cyber Awareness Training Date
(auto-filled from user record, if available): Enter or select a correct date for the requestor’s Cyber Awareness Training Date, as needed.
b. Comments: As an option, enter comments to support the decision.
Comments are not required for an approval, but AMPS passes them to the next approver when they are
• Removes the SAAR as assigned to the Information Assurance Officer from the My Tasks tab.
• Provides the customer’s provisioning service per the service agreement.
Figure 53: Information Security Officer Approval Screen
- 44 -
7. AMPS sends an email notification to the user regarding the approval’s status. Sample User Notification: Status
Subject: Action Required: SAAR #6129 - Request User Access for Dinah Teck (TEC_USER_213) (DLA Aviation) (AMPS) Dec 12, 2013 11:01 a.m.
Body:
The Information Assurance Officer has completed an approval for SAAR#6129 regarding your request for the following role: AMPS BASIC TEST ROLE with access to
AMPS.
The outcome for this task is APPROVE.
If you have any questions about this notification, please contact the Enterprise Help Desk at 855.352.0001.
What Comes After the Final Approval?
At this stage, the role approval process is complete. The next stage involves provisioning the role, which includes the following processes:
• Creating the user’s account in the application.
• Assigning the appropriate permissions…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .