About Role request

We have a role in IIQ that is requestable. When a user tries to submit a request for that role, the request initially appears to be successful and gets completed after some time.But all the fields are empty, and the role is not assigned to the user’s profile.

Hi,

Can you Check two things:

  1. In the Business Role, make sure the IT Role is added as Required, not just Permitted — only Required IT Roles get provisioned automatically.
  2. In the IT Role, confirm the entitlement is correctly added in its Profile for the right application.

If both are correct and fields are still blank, check the application’s Provisioning Policy — missing required attributes there can cause an empty plan even when the entitlement mapping is fine.

Welcome back, Arun.

Your screenshot shows the request is still Executing with Approval Status: Pending, so I would check Track Request Details first and see which approval is still pending. In IIQ, Executing means the request has not completed yet.

The IdentityIQ → assignedRoles → Add entry is the expected internal role-assignment request.

If the request later shows Completed but the role is still missing, please share the IdentityRequest XML for request 813298 and the related iiq.log entries. That should help identify whether the issue is in the role-assignment plan or a workflow/customization.

@ARUNPALANI i have seen this behavior when a provisioning policy is configured in the rule and it is missing some key attributes that fails the request. Could you please if do you also have a prov policy attached to your role and in case yes, does it have all required attributes?

We have a Business Role that contains an IT Role and an Entitlement. The Business Role is marked as Requestable, and the Assignment Rule contains a Match List.

Since the Business Role is requestable, any eligible user should be able to submit a request for the role, including the owner of the Business Role.

when the Business Role owner submits a request for himself or someone submits request for him, the request is created successfully at first. After some time, the request becomes completely empty, and the associated role/entitlement information is no longer displayed

Hello Arun. This looks more like an LCM approval/workflow issue than the Business Role Match List. Match Lists are for automatic role assignment, requestable roles go through the LCM request flow.

Since the assignedRoles Add item is present initially and later disappears, check the master ApprovalSet before Process Approval Decisions. In OOTB LCM, rejected items and items with no approval decision are removed from the provisioning plan.

I would check:

  • approvalScheme
  • any approvalAssignmentRule
  • any custom owner/self-approval logic

There is a similar case where a custom approval rule returned an empty approval list and nothing was provisioned.

As a quick test, request the same role for someone who is not the Business Role owner. If that works, please share the approval configuration and iiq.log entries around Process Approval Decisions. That should show why the item is being removed.

We have a Business Role that contains an IT Role and an Entitlement. The Business Role is marked as Requestable, and the Assignment Rule contains a Match List.

Since the Business Role is requestable, any eligible user should be able to submit a request for the role, including the owner of the Business Role.

when the Business Role owner submits a request for himself or someone submits request for him, the request is created successfully at first. After some time, the request becomes completely empty, and the associated role/entitlement information is no longer displayed

Hi @ARUNPALANI ,

This issue usually arises when the role definition or its provisioning structure is incomplete or misconfigured, leading the Provisioning Engine to evaluate an empty plan. IdentityIQ marks empty plans as “processed” and the request as completed, but no target account actions or role assignments are committed to the user’s Identity Cube.

So, check once if the target IT role is set to Permitted instead of Required, so no entitlements are compiled into the request.

Hi @ARUNPALANI ,

First verify that the IT Role and entitlement are configured correctly under the Business Role, especially that the IT Role is marked as Required.

Then, check the Provisioning Plan during the request flow to see whether the role/entitlement is being removed before provisioning. If the plan becomes empty, review the LCM workflow/approval rules, particularly any custom logic related to the Business Role owner or self-approval.

This should help identify whether the issue is with the role configuration or the approval/provisioning workflow.

@ARUNPALANI It’s not a good practice to have a dynamic role to be available in access request or certification. Please see this comment: Removing Role via LCM - IdentityIQ (IIQ) / IIQ Discussion and Questions - SailPoint Developer Community

I would recommend you to create two different roles, one for dynamic assignment and other for manual requests. Possibly your assignment logic is conflicting with the LCM assignments.