I created an application owner certification in IdentityIQ for application “ABCD”.
Because the authorizations of the application owners themselves are also included in the certification, I created a workgroup WG-1 to which the certification can be assigned. This allows the application owners to review each other’s work.
Workgroup WG-1 consists of two application owners, person-1 and person-2.
Person-2 is on vacation during the certification period and has therefore set person-3 as a forwarding user.
What happens:
The certification runs and is assigned to workgroup WG-1.
An email is sent to person-1 and person-2 notifying them of the assignment to WG-1.
In other words, the workgroup membership is only used to send the email; it is not checked whether a workgroup member has set up a forwarding user.
Consequence:
The authorization of person-1 cannot be checked without administrator intervention.
I think it would be logical that in this case, certification would be awarded to the working group and its members, and thus to any forwarding user of a working group member.
Is that a feasible idea?