I’m trying to understand the exact purpose of the Certification Entity Customization Rule in SailPoint IdentityIQ.
I created a sample Certification Entity Customization Rule and, in the rule, I modified/updated some attributes of the CertificationEntity object. I can confirm that the CertificationEntity object is getting updated when the rule executes.
However, I’m not seeing any obvious change in the Certification UI, so I’m trying to understand what this rule is actually intended to accomplish.
My questions are:
What exactly is the purpose of the Certification Entity Customization Rule?
What is the expected impact of modifying the CertificationEntity object?
Which attributes of CertificationEntity are normally customized using this rule?
Where are those customized values consumed/displayed?
Is this rule mainly intended for changing the certification UI representation, or does it have some other purpose in the certification lifecycle?
Could someone provide a real-world scenario where this rule would be useful?
I have tested this with a simple sample script where the CertificationEntity object is successfully updated, but I want to understand the actual business/technical use case behind updating this object. Sample Code:
log.warn("Entity Type is:- " +entity.getType());
if (certifiableEntity instanceof Identity) {
Identity identity = (Identity) certifiableEntity;
if ("Application".equals(identity.getAttribute("department"))) {
entity.setCustom1(" Employee");
entity.setCustom2("Having Admin Access");
Map customMap = new HashMap();
customMap.put("Location", "India");
entity.setCustomMap(customMap);
}
} else {
return null;
}
@RajGopal The Certification Entity Customization Rule runs during certification generation and lets you modify the CertificationEntity object before it’s persisted. Its primary purposes are:
Adding contextual metadata to certification entities (via custom1, custom2, and customMap) that reviewers can use when making access decisions.
Driving conditional logic downstream — other rules, workflows, or reports can read those custom fields to alter behaviour (e.g. escalation, filtering, notifications).
Feeding custom columns in the certification UI or exported reports, provided your deployment has been configured to surface those fields (more on that below).
Out of the box, custom1, custom2, and customMap values are not automatically rendered in the certification detail view. To make them visible you typically need to add those columns from the UI → Columns → Add the new column .
Could you please check in your certification if you see these new columns in the dropdown or not?
The Certification Entity Customization Rule runs once per CertificationEntity, while the certification is being built.
It is used to calculate values for the entity’s custom fields and save modified CertificationEntity object in DB.
By default it won’t change the certification ui.
To render it in ui, have o create a custom xhtml page.
Otherwise can use CertificationEntityRefresh rule to set those custom attributes for CertificationEntity and display it.
We added a Job Title column to Entitlement Owner certifications:
Rule: We created a Certification Entity Customization Rule that fills in the Job Title value when the certification is generated.
Certification definition: We attached the rule to the Entitlement Owner certification definition. It affects only certifications generated after we attached it.
UIConfig: We added the new field to the column configuration for the certification item view.
The Job Title column is now available in every Entitlement Owner certification item view. It’s hidden by default, and certifiers can turn it on from the column selector.