Skip to main content

Procedure for migrating rights from STM V4 to STM V5 (Workflows)

Written by Nicolas Beal

1. General Context

As part of the transition from STM V4 to STM V5, the permission management system is evolving towards a workflow-based model.

This change involves significant updates to the way user permissions are managed.


2. STM V5 Operating Principle

A V4 permission becomes a V5 workflow.

A workflow includes:

  • Product restrictions

  • Quotas

Access controls also exist, but they are managed separately. They allow you to define:

  • Machine restrictions

  • Time periods

⚠️ Key STM V5 rule:
A user can only have one workflow.

Objectives:

  • Avoid inconsistencies

  • Eliminate permission conflicts


3. Role of SAM in the Migration

The SAM system is able to:

  • Recreate V4 permissions as V5 workflows

  • Assign these workflows to users

⚠️ Very important point

SAM recreates all permissions as workflows, whether they are used or not.

  • Unassigned permissions are also recreated

  • No selection is possible

👉 Operating rule:
SAM recreates either all permissions or none.


4. Migration Cases

Case no. 1: User with a Single Permission

✅ Simple situation

  • The permission is converted into a workflow

  • The workflow is automatically assigned

  • No adjustment is required


Case no. 2: User with Multiple Permissions

⚠️ Complex situation

Problem

  • In V4: multiple permissions are possible

  • In V5: only one workflow is allowed

Consequence

During migration:

  • SAM can only assign one workflow

  • It is not possible to automatically merge multiple permissions

Applied rule

👉 The assigned workflow corresponds to:

  • the oldest permission

Impact

  • Loss of the other permissions

  • Non-optimized operation if no action is taken


🔎 Decision to Be Made After the Assessment

Following the company assessment provided by SAM, a strategic choice must be made.

Option 1 — Start from Scratch (Recommended)

  • Recreate clean and consistent workflows

  • Adapt permissions to actual usage

  • Optimize access management

👉 The most reliable and sustainable solution


Option 2 — Keep an “ISO V4 Permissions” Operating Model

  • Keep an operating model close to the existing one

  • Based on a single workflow derived from the oldest permission

  • Without any real optimization

⚠️ This option results in:

  • A loss of business logic

  • Permissions that may be incomplete or unsuitable

  • A suboptimal operating model


5. Actions to Be Planned by the Client / Distributor

Request an assessment.

SAM can provide Excel files containing:

  • List of users with their current permissions

  • List of users whose permissions will not be fully migrated


6. How to Obtain This Information

👉 Contact:

  • The SAM sales representative

or

  • SAM Customer Service


7. Recommendations

  • Identify users with multiple permissions

  • Analyze actual usage

  • Prioritize a clean reconstruction of workflows

  • Plan a reconfiguration phase


8. Conclusion

  • Automatic permission migration, all or nothing

  • Limitation to one workflow per user

  • Need for arbitration in complex cases

👉 Preparation and decision-making in advance are essential to ensure a successful transition.


Example Attached Below

Explanation of the Example

The top table represents an assessment of permissions in STM V4.

  • Users could have multiple permissions

  • These permissions could sometimes conflict with each other

  • This was how STM V4 worked, but it was not optimal

With the transition to STM V5:

  • Permissions become workflows

  • A user can only have one workflow

👉 During migration:

  • If a user had multiple permissions

  • They only keep one

This workflow corresponds to:

  • the oldest permission

⚠️ Important:

  • This is not an addition of permissions

  • The user does not recover all of their initial authorizations

👉 Result:
Access rights and restrictions may be different after migration compared with before.


Please Note

All permissions are recreated identically as workflows.

However, some workflows may not be assigned to users because those users will already have another one.

Did this answer your question?