Business Analysis Case Study: Access Management Prototype
Key Concepts:
- Business Analysis
- Requirements Gathering (Workshops, Interviews)
- Business Process Model and Notation (BPMN)
- Workflow Automation
- Prototype Development
- Access Management
- User Tasks
- Gateways (Decision Points)
- Forms (User Interface)
- Variables
- Process Execution
1. Introduction: The Access Management Challenge
Company A is experiencing rapid growth, leading to an increased number of employees. This growth necessitates a more structured approach to access management, as manually tracking application access rights becomes increasingly difficult and poses security risks. A group of business analysts identified the need for a digital solution to manage access requests and approvals. The goal is to develop a software prototype that allows employees to request access rights for applications, which are then reviewed by their line managers.
2. Requirements Gathering
The first step involves gathering detailed requirements through workshops and interviews. The outcome of these sessions includes the following key requirements:
- Employee Access Request: Employees must be able to request access to specific applications.
- Line Manager Review: Line managers must be able to review access requests.
- Review Outcomes: The review process should have three possible outcomes:
- Approval: The request is granted.
- Rejection: The request is denied.
- Rework: The request is sent back to the employee for modification.
- Prototype Scope: The prototype will be a single-user executable software, and automated download of approved applications and role-based access control will be excluded for simplicity.
3. Business Process Modeling with BPMN
The gathered requirements are then modeled using the BPMN (Business Process Model and Notation) standard. BPMN is a globally recognized standard for visually representing business processes and workflows. The video utilizes a tool called Flowable to model and execute the BPMN diagram.
3.1. BPMN Elements:
- Start Event: Indicates the beginning of the process (represented by a single thin circle).
- End Event: Indicates the end of the process (represented by a thick circle).
- Activity/Task: Represents a specific action or task to be performed (represented by a rectangle). In this case, "Request Access" and "Review Request" are key tasks.
- Gateway: Represents a decision point in the process, allowing the flow to branch based on specific conditions (represented by a diamond).
3.2. Process Flow:
- Request Access: An employee initiates the process by submitting an access request.
- Review Request: The line manager reviews the request and decides on an outcome.
- Gateway (Outcome of Review): Based on the line manager's decision, the process follows one of three paths:
- Approved: The request is approved, and the process ends.
- Rejected: The request is rejected, and the process ends.
- Rework: The request is sent back to the employee for modification.
4. Form Creation and User Interface
Forms are created within the Flowable tool to facilitate user interaction at each task.
4.1. Request Access Form:
- Application (Select Single Dropdown): A dropdown menu allowing the employee to select the application they need access to (e.g., PowerPoint, Excel, Word). Predefined values are used to populate the dropdown.
- Justification (Multi-Line Text): A text field where the employee provides a reason for requesting access.
- Welcome Message (Text Display): A welcome message displaying the name of the user initiating the request (using the
initiatorvariable).
4.2. Review Request Form:
- Application (Select Single Dropdown): Displays the application requested by the employee. The value is dynamically populated from the "Request Access" form using the variable name
application. The field is set to read-only. - Justification (Multi-Line Text): Displays the justification provided by the employee. The value is dynamically populated from the "Request Access" form using the variable name
justification. The field is set to read-only. - Welcome Message (Text Display): A welcome message displaying the name of the current user (the reviewer) and indicating who made the request (using the
initiatorvariable). The variablecurrent user.display nameis used to display the reviewer's name. - Outcomes (Outcomes): Presents three buttons: "Approve," "Reject," and "Rework." These buttons determine the outcome of the review process.
5. Implementing Decision Logic with Gateways
The Gateway element in BPMN is used to implement the decision logic based on the outcome of the review.
5.1. Conditional Flows:
- Approved: If the "Approve" button is clicked, the process follows the "Request Approved" path. The condition is
review request forms equals approve. - Rejected: If the "Reject" button is clicked, the process follows the "Request Rejected" path. The condition is
review request forms equals reject. - Rework: If the "Rework" button is clicked, the process loops back to the "Request Access" task. This is implemented as the default flow, meaning it's triggered if neither "Approve" nor "Reject" is selected.
6. Process Execution and Testing
The video demonstrates the execution of the modeled process within the Flowable tool. Different scenarios are tested to ensure that the process flows correctly based on the selected outcomes (approve, reject, rework). The history of each process instance is tracked, showing the path taken through the BPMN diagram.
7. Conclusion
The video successfully demonstrates how to build a prototype for an access management system using BPMN and a workflow automation tool. By modeling the business process, creating user interfaces, and implementing decision logic, a functional prototype is created that meets the initial requirements. The prototype allows employees to request access, line managers to review requests, and the system to route requests based on the review outcome. The video emphasizes the importance of understanding the requirements and using a standardized notation like BPMN to model and automate business processes.
AI summaries can miss context or contain errors. Check important details against the original video.