I need a workflow that forward all pending certifications of a user to his manager’s manager when manager of the user is terminated.
suppose user is xyz—abc(xyz’s manager)—-lmn(abc’s manager)
Now when the abc is terminated (lifecycle state becomes terminateddisabeled) then all the pending certification should automatically forwarded to lmn(abc’s manager) please guide
you might want to take a look at deploying the ISC Governance Connector, and using its Reassignment settings:
when the governance connector account (and thus the identity) is disabled, it can perform this action.
Ive also done very similar (and then some!) in a presentation I did for Developer Days 2025
if you need this in a workflow, high level:
trigger: identity attribute changed (lifecyclestate >> inactive)
call list-identity-certifications | SailPoint Developer Community
with the query param for the reviewer-identity, and possible filter for completed eq false and phase eq active
check if that result is null
check if the identity has a manager
then loop over those certifications, and reassign them
you run a risk here however on if that identity has more than 250 active Certifications (note: not certification campaigns, just certifications)
but that should reassign up to 250 active certifications to the manager.
@StephenHolinaty are u talking about below connector: if yes then it is configured already in my tenant and aggregation is also done (1 lac account) now pls let me know how the certification will be reassigned to manager’ manager when manager is terminated through this connector ?
Overall:
* set up that connector and aggregate
on the connector, under “Reassignment settings”, select the certifications checkbox, to reassign
Identity profile > lifecycle state provisioning (“Inactive” most likely), set it to Disable the “Identity security cloud governance” source’s account
so:
HR terminates someone
Lifecycle state moves to Inactive
Inactive triggers a Disable on the governance connector
Governance connector reassigns certifications that are in-progress from “fired guy” to “his manager”.
that is the intention.
if you Disable the account on the “ISCGovernanceConnector” in a specific LCS, this will trigger if you configure the governance connector to do so.