The Challenge
Built-in tools in Notes/Domino administration generally provide insufficient support for the complex workflows of user, group, or database management. Employees with high qualifications and far-reaching access rights are forced to carry out numerous individual steps manually, document some of them by hand, and repeatedly consult with end users. Today's security and compliance requirements are also not adequately met by standard Domino administration procedures.
Affirmatic for Domino (formerly BCC AdminTool) automates user and group management for HCL Domino, provides audit-proof traceability, and reduces administration costs.
It makes your administration processes simpler, faster, and more secure. The broad functional scope, the architecture continuously developed over more than 10 years, and near-unlimited flexibility make Affirmatic for Domino the ideal complement for identity and access management in your HCL Domino environment.
Affirmatic for Domino streamlines Domino identity and directory management with a proven, server-based framework
Processes and Workflows
Affirmatic for Domino provides a process-oriented environment for managing Notes/Domino users, groups, and mail-in databases. It covers the entire process, from a new user request, through approval, group assignment, and granting of database access, all the way to configuring the Lotus Notes client. Affirmatic for Domino enables order-based automation of processes, order verification prior to execution, and seamless monitoring, logging, and error notification. It can be fully configured for individual requirements and processes, including multi-domain environments.
Domino User Lifecycle
Affirmatic for Domino enables automation and monitoring of all user management processes, e.g. import or creation of new users, name and certifier changes, ID renewal, home server relocation, suspension, deletion, archiving, restoration, and password recovery.
Managing Groups and Mail-In Databases
All tasks involved in managing these objects are supported and automated by AdminTool, including delegation functions, provisioning of request forms and approval workflows, e.g. creation, renaming, deletion, and attribute modification, whether permanent or temporary (i.e. for a defined period).
Integration with External Systems
The highest degree of automation for your Domino user management is achieved through integration with enterprise-wide identity management systems. AdminTool allows connection to numerous systems, e.g. personnel management (SAP R/3, SAP HR, RACF, etc.), LDAP (MS Active Directory, MetaDir), identity and access management/IAM (IBM Tivoli Identity Manager, Siemens Metadirectory, Novell e-directory, SUN Identity Management), as well as to existing Lotus Notes databases.
Support for Infrastructure Projects
Affirmatic for Domino reliably supports bulk changes as part of infrastructure projects such as server consolidations, but also as a result of organizational changes such as mergers or renaming, quickly, securely, and cost-effectively.
Delegation and Distributed Responsibility
Organizations can hand off individual user management tasks to a help desk or to end users themselves. No technical know-how or administrative rights in the Domino Directory are required, just a web browser. The complete separation of user management from Domino administration ensures compliance with security standards for processes and helps meet audit requirements. IDs and passwords are stored and distributed separately.
With Affirmatic for Domino administrative activities do not require access to certifier IDs. These are imported once and stored in encrypted form. The risk of unauthorized use or disclosure of these sensitive files is minimized, since every access is logged and is only possible through Affirmatic. All generated user IDs are likewise stored encrypted. Access to the automatically generated random passwords is handled separately and is available only to designated password administrators.
Detailed Documentation
Affirmatic for Domino logs every security-relevant action in detail. All requests and configuration changes are recorded in a traceable manner, providing reliable documentation for audit and verification purposes.
Monitoring and Extended Management
Affirmatic also provides additional administration functions, e.g. event-based monitoring of the AdminP process, an EventEngine for user-defined actions during request execution, and functions for "cleaning up" the Domino Administration Database (admin4.nsf).
Secure Management of Domino Objects
With Affirmatic for Domino, administrative activities do not require access to certifier IDs. These are imported once initially and stored in encrypted form. The risk of unauthorized use or disclosure of these sensitive files is minimized, since every access is logged and only possible through Affirmatic. All generated user IDs are likewise stored encrypted. Access to the automatically generated random passwords is separate and available only to designated password administrators.
Lower Total Cost of Ownership
Replaces manual, ad hoc Domino administration with standardised, automated workflows, cutting administration costs and reducing total cost of ownership across the environment.
Why BCC Affirmatic for Domino?
- Reduce total cost of ownership (TCO) through standardized processes (organizational and technical) and automated workflows
- Meet business requirements in day-to-day administration and infrastructure projects
- Establish process security through defined standards and audit-proof documentation
- Close security gaps by improving system and process security
- Delegate user management tasks to other departments through strict separation of responsibilities
- Simplify the system landscape through complete automation when connecting to external systems
Systems & Objects
- HCL Domino
- Active Directory & Exchange
- Microsoft 365 / Entra ID & Teams
- Coexistence
- Self-Service Portal
HCL Domino
- Runs as a Domino server add-in task, with no separate server and no third-party middleware in the mail or directory path
- Periodically reads the Domino directory and identifies groups, distribution lists and security lists to synchronise, by category, naming convention or a configurable selection rule
- Full Domino user lifecycle: registration, activation/deactivation, name and certifier changes, ID renewal and distribution, home-server moves, locking, deletion, archiving and restore
- Domino security objects (Certifier IDs, generated user IDs) are imported once and stored encrypted, so administrative work never requires direct Certifier-ID access
- Generated random passwords are stored separately from user IDs and accessible only to designated password administrators, keeping credential distribution auditable
- Event-based monitoring of the Domino AdminP process, with an EventEngine for custom actions during request execution and tools to keep the Domino administration database (admin4.nsf) clean
Active Directory & Exchange
- Synchronisation and alignment of user, group, contact, mail-in and resource objects between Domino and Active Directory
- Management of on-premises Exchange objects (distribution groups, security groups, mailboxes)
- Attribute mapping and rule-based processing, with controlled provisioning and status/error tracking
Microsoft 365 / Entra ID & Teams
- Group members matched by translating Domino group membership into SMTP addresses and matching against Entra ID / Exchange Online
- Creates Microsoft 365 groups directly, or traditional Exchange distribution lists and security groups, configurable per group
- Management of Azure AD, Exchange Online and Teams objects for hybrid and cloud-only environments
Coexistence
-
Affirmatic for Domino keeps Domino directories, groups and distribution lists in step with Active Directory, Exchange and Microsoft 365 for as long as Domino and Microsoft 365 need to run side by side. For the mail-routing side of a coexistence project, see the companion BCC Coexistence Gateway product.
Self-Service Portal
- Web-based Service Portal for delegated, browser-only administration, with no Domino Directory access or Domino know-how required; user IDs and passwords are stored and distributed separately, keeping user administration cleanly separated from Domino administration for audit purposes
- REST API for integration with your own service management or ITSM tooling
