Best way for both managers & governance group to review same access in certification campaign

:bangbang: Please be sure you’ve read the docs and API specs before asking for help. Also, please be sure you’ve searched the forum for your answer before you create a new topic.

My client asked if a certification campaign can be assigned to both an identity’s manager, and also a governance group. Their reasoning is HR managers are aware of appropriate application access such as from SAP sources; but there are agency coordinators within departments who assign AD groups for distribution lists & logon script functionality that also need review. There is some overlap between that access though, so creating search queries that filter by entitlement (SAP vs AD) would not be perfect.

They will be utilizing search query created campaigns in the UI; when creating them I can only select one (manager, individual or governance group; all radio buttons not check boxes) and not two or more reviewers, which I expected. My thought is to let them know they should have a primary owner for the review and manager would be ideal; and managers should be trained to reassign any access they are unfamiliar with to an AACA. I believe they will come back with the concern about rubber-stamping access though. The other option that I was told would be to have two campaigns, staggered; manager first, then agency coordinator 2 weeks later.

If I can get confirmation that (a) it’s not possible to assign a search-query based campaign to two types of reviewers and (c) if the best option is choosing manager OR governance group; or to run two campaigns that are staggered, that would be appreciated.

Hi @MichaelAAskins

This is correct, not possible out of the box.

Is there a reason why they need to be staggered instead of running at the same time? You could have the same exact certification, one for managers & another for governance group running at the same time, basically fulfilling the requirement. The only problem is that both will need to complete the review. You could put some automation in place that automatically approves the other one, but I think that’s too complex for your use case.

Honestly, I would try to make the argument that managers know all the access his/her direct report have and are the decision makers on this instead of allowing others to decide. But if that leads nowhere, then I think your multi-campaign approach is the best option.

Thank you for the fast reply! That was just a thought to avoid overlapping approvals/revokes; if a manager revoked a piece of access at the same time the agency coordinator is approving it, there was concern about it being handled incorrectly somewhow.

You are 100% correct and I am going to push for mangers to be first reviewers; then if they are unsure, re-assign a piece of access review to the agency coordinator(s) for their department. The client is concerned about rubber-stamping, which I’ve also seen in many orgs I’ve been in, from the managers though. They often do not know/remember the access required and just ‘approve all’ to avoid work distruption.

Ah, gotcha! There wouldn’t be any issue connector-wise with two certifications running with the same access. Even if both were to revoke, the connector would see it’s already removed and not initiate anything. The only concern I would see is if auditors see the governance group owner denied and the manager approved, that may be evidence of rubber stamping and you may get dinged for that.

I think your staggered approach should do the trick!

The same can be said about governance group owners :wink:

True! The governance group members are agency coordinators; basically department super-users who are more day-to-day and assign mostly AD groups for department-specific access. They’ll know their user’s access a little better than managers is the feeling I’m getting; but with multiple apps and overlap, hence their ask for both to review yup. Appreciate the confirmations very much, very helpful!