# Manager Correlation not working

**URL:** <https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928>\
**Category:** SHF Discussion and Questions\
**Tags:** correlation, identity-security-cloud\
**Created:** [January 17, 2025, 8:12pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928 "2025-01-17T20:12:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijitha](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vijitha](https://developer.sailpoint.com/discuss/u/Vijitha)\
**Post date:** [January 17, 2025, 8:12pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/1 "2025-01-17T20:12:03Z")

</div>

Hi,

We have manager correlation configured in our authoritative sources as following and they are working now without any issues.

| Identity Attribute | Account Attribute |
| --- | --- |
| Employee Number | manager\_employee\_id |

Now we want to use manager\_email from our authoritative source instead of manager\_employee\_id for the correlation logic. so, we changed the manager correlation as this.

| Identity Attribute | Account Attribute |
| --- | --- |
| Work Email | manager\_email |

After the change, when we aggregate the authoritative source, the new identities are having manager tagged only if both the authoritative source attributes (manager\_employee\_id and manager\_email) are having values. The manager correlation is not working with only manager\_email value.

Can anyone help us on this? Aren’t we supposed to change the manager correlation logic?

---

<div class="post-metadata">

**Author:** ![vasanthrajsp29](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vasanthrajsp29/32/20713_2.png) [@vasanthrajsp29](https://developer.sailpoint.com/discuss/u/vasanthrajsp29)\
**Post date:** [January 18, 2025, 4:45am UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/2 "2025-01-18T04:45:32Z")

</div>

Hi @Vijitha,

You need to run full aggregation and it will fix the correlation issue

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/4/a/4a3ba2c1d95e00e7ae30b7d032ea5a5419815de7.png)

Please refer this link [Loading Account Data - SailPoint Identity Services](https://documentation.sailpoint.com/saas/help/accounts/loading_data.html)

-Vasanth

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [January 18, 2025, 1:52pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/3 "2025-01-18T13:52:42Z")

</div>

Hi @Vijitha ,

Try running an unoptimized aggregation.  
Use the following endpoint: [import-accounts | SailPoint Developer Community](https://developer.sailpoint.com/docs/api/beta/import-accounts/)

Thanks! ~ Gokul

---

<div class="post-metadata">

**Author:** ![Vijitha](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vijitha](https://developer.sailpoint.com/discuss/u/Vijitha)\
**Post date:** [January 21, 2025, 3:22pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/4 "2025-01-21T15:22:41Z")

</div>

@GOKUL_ANANTH_M @vasuvasanth

Thanks for the help.

I tried to run “Aggregate source without optimisation” on authoritative source and it did not work. Our authoritative source is configured with “full Aggregation” always.

Here is what happened.

1. Initially the manager correlation logic is this:  
**Identity Attribute - Account Attribute**  
Employee Number- manager\_employee\_id

When we aggregate the authoritative source, the identity created for that source account has been tagged with manager. (manager correlation was success). Please find the result.

| Source Account | manager\_employee\_id | manager\_email | Manager correlation success? |
| --- | --- | --- | --- |
| Source Account 1 | 108 | | Yes |
| Source Account 2 | 226 | | Yes |
| Source Account 3 | 1457 | | Yes |

1. We changed the manager correlation logic to

**Identity Attribute - Account Attribute**  
Work Email - manager\_email

Now we aggregated the source without optimization and the source also has the following records as the input . The first 3 accounts which already got aggregated has the manager\_email populated along with ,manager\_employee\_id now and next three accounts are only populated with manager\_email and the following are the test results.

| Source Account | manager\_employee\_id | manager\_email | Manager correlation success? |
| --- | --- | --- | --- |
| Source Account 1 | 108 | [manager1@domain.com](mailto:manager1@domain.com) | Yes |
| Source Account 2 | 226 | [manager2@domain.com](mailto:manager2@domain.com) | Yes |
| Source Account 3 | 1457 | manager3@domain | Yes |
| Source Account 4 | | [manager4@domain.com](mailto:manager4@domain.com) | No |
| Source Account 5 | | [manager2@domain.com](mailto:manager2@domain.com) | No |
| Source Account 6 | | [manager2@domain.com](mailto:manager2@domain.com) | No |

**After we did the “Aggregate source without optimization” (We are doing through VS Code), we don’t see the manager tagged for the source accounts (4,5,6).**

---

<div class="post-metadata">

**Author:** ![Arshad](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@Arshad](https://developer.sailpoint.com/discuss/u/Arshad)\
**Post date:** [January 21, 2025, 5:34pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/5 "2025-01-21T17:34:13Z")

</div>

@Vijitha, To my understanding, you cannot fix the account correlation automatically on the source which already had another pre-existing correlation logic and user accounts were already aggregated and correlated. Rather what you need to do is perform a remove all accounts API on your source and then perform full account aggregation again so that your new correlation criteria on manager email is re-evaluated and changes are reflected rightly.

Use the below API :

- https://{ **your tenant** }.api.identitynow.com/beta/sources/{ **your source id** }/remove-accounts

> **[delete-accounts-async | SailPoint Developer Community](https://developer.sailpoint.com/docs/api/beta/delete-accounts-async/)**
>
> \<Heading

---

<div class="post-metadata">

**Author:** ![jkalle](https://avatars.discourse-cdn.com/v4/letter/j/ac8455/32.png) [@jkalle](https://developer.sailpoint.com/discuss/u/jkalle)\
**Post date:** [January 22, 2025, 2:02pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/6 "2025-01-22T14:02:28Z")

</div>

@Arshad, In production environment, Its not a wise decision to remove the accounts from source to complete the aggregation and correlation. This may cause unexpected issues that may disrupt their business. I’m sure there will be another solution without removing the accounts. Just my two cents.

---

<div class="post-metadata">

**Author:** ![Arshad](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@Arshad](https://developer.sailpoint.com/discuss/u/Arshad)\
**Post date:** [January 22, 2025, 2:19pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/7 "2025-01-22T14:19:46Z")

</div>

@jkalle I am definitely with you on the point that this might not be the best solution on PROD systems . But these are workarounds to the unusual behavior of the tool.

And be rest assured, if you’re resetting the accounts on a source, they will not be propagated back to the actual end target application. We’re just resetting the accounts on source level on ISC side only. Which has no connection whatsoever with provisioning. Once you re-aggregate the source, correlation in ISC system is re-evaluated and fixed as needed. I have had this same experience on a staging environment and had to do this process to overcome the behavior mentioned by the author.

But definitely, SailPoint has to bring in more flexibility in terms of config changes and reflecting those changes on the tenant for such edge cases.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [March 23, 2025, 2:20pm UTC](https://developer.sailpoint.com/discuss/t/manager-correlation-not-working/97928/8 "2025-03-23T14:20:36Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
