Finding the campaign of a revoked access

Hi,

Our client has launched a hundred or more certification campaigns annually. For annual certifications, when a reviewer has failed to give a decision for the items and the admin decides to close the campaign after the due date, the admin chooses to revoke the accesses of those undecided items to compel those items to be requested again and verify that the accesses are still necessary.

Now users are asking why their access has been revoked and my objective is to find from which campaign it was revoked. I won’t be able to find it per campaign ID since there are too many campaigns. The closest I can use is by reviewer and to list all campaigns under that reviewer using List Identity Campaign Certifications. Is there an easier way or any API available to search by the affected identity and revoked access? I am able to find the certification Activity ID when checking for the account activity but there is no link to which campaign it is.

Welcome to the SailPoint Developer Community, Ted.

Is your client using SailPoint IIQ or ISC Cloud?

1 Like

Hello Ted. Assuming this is ISC, since you already have the certification remediation Account Activity ID, I would start from there instead of searching campaigns by reviewer. Get the activity using: GET /account-activities/v1/{id}

Then check items[].requesterComment.body. For certification remediation, you can see text similar to:

Certification remediation for Identity: <id> Certification: <certificationId>

The value after Certification: is the individual certification ID. There is an example of this in this community thread.

From there, use: GET /certifications/v1/{certificationId}

The response should give you the parent campaign ID and name. If you need the full campaign details, you can then call: GET /campaigns/v1/{campaignId}

So the path is basically: Account Activity → Certification → Campaign

The certification ID is coming from the free-text requesterComment.body, not a dedicated certification or campaign field, so I would not rely on fixed text positions when parsing it.

I do not see a direct API filter to search the certification history by the affected identity and revoked access, so starting from the Account Activity you already have looks like the easier reverse lookup in this case. If this comes up regularly across your many campaigns, you could also store the identity, revoked item, and campaign details when each campaign ends, so later questions become a single lookup.

This thread is under General Feedback, so you may get more eyes on it by posting under SHF Discussion and Questions instead. And since there is no native way to search revocations by affected identity today, it would be worth raising in the SailPoint Ideas portal as a feature or enhancement request so it can be tracked for a future release.

1 Like

Hi Vamsee,

Our client is using ISC Cloud.