Are there any best practices for handling access item owners when they are terminated, placed on leave, or moved into a different role?
We are looking for a reliable way to quickly identify when an access item owner is no longer the appropriate owner, so we can reassign ownership to the correct identity before it becomes an issue.
So far, I have not been able to build a workflow that fully handles this. The main challenge is that determining or evaluating access item owners within workflows does not seem to work the way we need it to. Has anyone found a workaround for this?
I am also curious what methods other organizations are using to manage this. I assume we are not the first organization to run into this problem.
If there are proactive methods for addressing this, I would be very interested in those as well. Any insight, recommendations, or examples would be greatly appreciated.
At this point, I have been able to create a scheduled search that sends me a list of access item owners who are terminated or on LOA, but that does not account for changes to role code or role name. Ideally, we would like a way to detect those types of changes as well and determine whether ownership should be reviewed or reassigned.
I believe they are same thing. The ISC Governance connector is the out of the box version of that same Colab SaaS connector. I would recommend you use the OOTB version instead of any Colab based connector so you can automatically receive product updates in case SailPoint releases new functionality or bug fixes.