Member of workgroup has forwarding user

I created an application owner certification in IdentityIQ for application “ABCD”.

Because the authorizations of the application owners themselves are also included in the certification, I created a workgroup WG-1 to which the certification can be assigned. This allows the application owners to review each other’s work.
Workgroup WG-1 consists of two application owners, person-1 and person-2.
Person-2 is on vacation during the certification period and has therefore set person-3 as a forwarding user.

What happens:
The certification runs and is assigned to workgroup WG-1.

An email is sent to person-1 and person-2 notifying them of the assignment to WG-1.
In other words, the workgroup membership is only used to send the email; it is not checked whether a workgroup member has set up a forwarding user.

Consequence:
The authorization of person-1 cannot be checked without administrator intervention.

I think it would be logical that in this case, certification would be awarded to the working group and its members, and thus to any forwarding user of a working group member.
Is that a feasible idea?

1 Like

Since the certification is assigned to workgroup, another person who is not in the workgroup will not be able to access the certification and take any action on it. So I believe its working as expected. If you have specific requirement to allow forwarding user set for a workgroup member to be able to take action in their absence you may have to rely on something custom which may not be desirable or recommended. One such option can be a rule runner task that runs every few hours that checks for forwarding user set on all workgroup members and set them as member of the workgroup. The same task will need to remove the member from the workgroup on the forwarding user end date using another task/workflow scheduled to run on the end date.