I am trying to certify roles in my organization and manager of the user has to certify those roles. But looks like only individual, role owner or governance group can only certify a role certification. Has anybody implemented this before and if yes, what was the workaround? Thank you for your insights.
When you mention “Role Certification,” could you please clarify what exactly you intend to certify?
Is it the role assignments to users, or
The role configuration/composition itself?
In Identity Security Cloud (ISC), Role Composition Certification refers to reviewing the configuration of a role , not the users assigned to it. Since managers typically don’t manage role configuration, they can’t be assigned as reviewers for these campaigns.
If you’re looking to review roles assigned to identities, that can be done using a search-based access certification campaign.
A few important points to note:
Only roles not provisioned via birthright rules can be certified.
Roles assigned via birthright rules can only be acknowledged, not certified.
You can find detailed steps in the documentation here.