# Certificate event customization

**URL:** <https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298>\
**Category:** IIQ Discussion and Questions\
**Tags:** adaptive-approvals, identityiq, certifications, workflows, rules\
**Created:** [June 2, 2026, 5:03am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298 "2026-06-02T05:03:33Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Riyazuddin99](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Riyazuddin99](https://developer.sailpoint.com/discuss/u/Riyazuddin99)\
**Post date:** [June 2, 2026, 5:03am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/1 "2026-06-02T05:03:33Z")

</div>

Hello Developer

I have a requirement at my organization for the certificate event,  
we need to create a certificate during the mover process, I am able to create a certificate during the mover process by adding the same filter for mover process.

_ **main requirement is within the certificate event process, where the approval should go to only to the new manager and later it should go to the entitlement owner for the approval.** _  
as this requirement should be similar to the access request workflow. where we have the same approach on it.

with the default certificate event it is going to both manager old and new manager of the user.

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/6/7/6786d93ec2a20264a0b2498d509b79d2691c0ba9.png)

attaching the current configuration for references.

please suggest me how can we customizes the approval workflow in the certificate event.

thanks in advance.  
Riyazuddin

---

<div class="post-metadata">

**Author:** ![SanjeevIAM](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sanjeeviam/32/21695_2.png) [@SanjeevIAM](https://developer.sailpoint.com/discuss/u/SanjeevIAM)\
**Post date:** [June 3, 2026, 9:58am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/2 "2026-06-03T09:58:17Z")

</div>

If you plan to use Certification Events then for manager change it will always assign the approvals to old and new manager. If you need to change this behavior then you will have to create a Lifecycle Event and attach a workflow that needs to be customized to kick off certification s using APIs. Here is a thread which has sample for your reference.  
[https://community.sailpoint.com/t5/IdentityIQ-Forum/Launching-Certification-Using-IIQ-API/m-p/108442](https://community.sailpoint.com/t5/IdentityIQ-Forum/Launching-Certification-Using-IIQ-API/m-p/108442)

---

<div class="post-metadata">

**Author:** ![ymail145](https://avatars.discourse-cdn.com/v4/letter/y/f9ae1b/32.png) [@ymail145](https://developer.sailpoint.com/discuss/u/ymail145)\
**Post date:** [June 3, 2026, 12:23pm UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/3 "2026-06-03T12:23:34Z")

</div>

Only possible via LifeCycle event with custom workflow to achieve you requirement and you can use spiltApproval for entitlement owner approve certification event workflow(OOTB) can’t be customized

If Attribute Change event already configured, add additional condition to check manager attribut or create new event for manager change

---

<div class="post-metadata">

**Author:** ![neel193](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neel193/32/34038_2.png) [@neel193](https://developer.sailpoint.com/discuss/u/neel193)\
**Post date:** [June 5, 2026, 11:40am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/4 "2026-06-05T11:40:08Z")

</div>

@Riyazuddin99 we achieved this with a custom rule in the past. Mover worflow was setting an identity attribute and we used to had a separate rule runner task to launch a single cert campaign for the given day for all users with movers.

To add an application approval post manager, you can write a CertificationSignOffApprover rule which will take care of adding another layer of approval.

---

<div class="post-metadata">

**Author:** ![Riyazuddin99](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Riyazuddin99](https://developer.sailpoint.com/discuss/u/Riyazuddin99)\
**Post date:** [July 13, 2026, 7:26am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/5 "2026-07-13T07:26:51Z")

</div>

Hello @neel193 ,

can you please share a sample code for certificationsignoff approver rule.

---

<div class="post-metadata">

**Author:** ![neel193](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neel193/32/34038_2.png) [@neel193](https://developer.sailpoint.com/discuss/u/neel193)\
**Post date:** [July 13, 2026, 1:52pm UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/6 "2026-07-13T13:52:29Z")

</div>

@Riyazuddin99 Here are couple of example of CertificationSignOffApprover rules from the Rules doc:

This example CertificationSignOffApprover rule forwards the certification to the certifier’s manager for approval. This process continues with this rule until the certifier does not have a manager (e.g. all the way up the managerhierarchy).

```auto
import sailpoint.object.Identity;

// This requires approval all the up the manager hierarchy. Once we get

// to the most senior manager, approvals stop.

Identity identity = certifier.getManager();

if (identity != null) {

Map results = new HashMap();

results.put("identity", identity);

return results;

} else {

return null;

}

```

Since every signer is added to the certificationSignOffHistory immediately after the certificationSignOffApprover rule runs, this rule could be limited to only require one level of secondary signoff by checking the certification signoff history like this:

```auto
import sailpoint.object.Certification;

import sailpoint.object.Identity;

// if cert signoff history indicates it has already been signed off once,

// do not submit to any other levels of

approval

List history = certification.getSignOffHistory();

if (history == null || history.isEmpty()){

Identity identity = certifier.getManager();

Map results = new HashMap();

results.put("identity", identity);

return results;

}

else

return null;

}

```

---

<div class="post-metadata">

**Author:** ![Riyazuddin99](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Riyazuddin99](https://developer.sailpoint.com/discuss/u/Riyazuddin99)\
**Post date:** [July 15, 2026, 4:48am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/7 "2026-07-15T04:48:50Z")

</div>

Hello @neel193 ,

I have added the below code to redirect the certificate towards the entitlement owner.  
but it’s not redirect towards that.  
and right after we click on sign off the cert is getting closed.

```import
  import sailpoint.tools.Util;
  import sailpoint.object.ApprovalItem;
  import sailpoint.object.ApprovalSet;

  private String getManagedAttributeOwner(Application app, String name, String value ) {
    String owner = null;
    ManagedAttribute ma = ManagedAttributer.get(context, app.getId(), name, value);
    if ( ma != null ) {
      Identity maOwner = ma.getOwner();
      if ( maOwner != null ) 
        owner = maOwner.getName();
    }
    return owner;
  }

```

can you please have a look on this.

Thanks  
Riyazuddin

---

<div class="post-metadata">

**Author:** ![neel193](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neel193/32/34038_2.png) [@neel193](https://developer.sailpoint.com/discuss/u/neel193)\
**Post date:** [July 15, 2026, 5:53am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/8 "2026-07-15T05:53:39Z")

</div>

@Riyazuddin99 Have you printed the logs to make sure your rule is being triggered or not?

---

<div class="post-metadata">

**Author:** ![Riyazuddin99](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Riyazuddin99](https://developer.sailpoint.com/discuss/u/Riyazuddin99)\
**Post date:** [July 15, 2026, 5:54am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/9 "2026-07-15T05:54:46Z")

</div>

Hello @neel193 ,

nope I haven’t checked the loggs  
can you shared the logger if you know for both certificate and rules.

---

<div class="post-metadata">

**Author:** ![neel193](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neel193/32/34038_2.png) [@neel193](https://developer.sailpoint.com/discuss/u/neel193)\
**Post date:** [July 15, 2026, 5:59am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/10 "2026-07-15T05:59:23Z")

</div>

@Riyazuddin99 just add log.error(“your message key::”+your object name); in your rule .

```auto
 import sailpoint.tools.Util;
  import sailpoint.object.ApprovalItem;
  import sailpoint.object.ApprovalSet;

log.error("rule started");
  private String getManagedAttributeOwner(Application app, String name, String value ) {
log.error("inside method");
    String owner = null;
    ManagedAttribute ma = ManagedAttributer.get(context, app.getId(), name, value);
    if ( ma != null ) {
      Identity maOwner = ma.getOwner();
      if ( maOwner != null ) 
        owner = maOwner.getName();
    }
log.error("owner::"+owner);
    return owner;
  }

```

I have added few, feel free to add more based on your requirements.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 13, 2026, 5:59am UTC](https://developer.sailpoint.com/discuss/t/certificate-event-customization/211298/11 "2026-09-13T05:59:56Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
