SailPoint IIQ: How to report failed provisioning for a connected app to a business owner

My use case

We have applications connected to SailPoint IdentityIQ where provisioning happens automatically (no manual tickets, no human in the middle).

Sometimes a provisioning request fails — meaning SailPoint tried to give someone access, but it didn’t actually go through.

What I need to build:

  • Find all the provisioning requests that failed for a given application.
  • Put them together into a simple report, once a day.
  • Automatically email that report to a business owner (TPO) so they know something needs attention.

What I’d like help with

  • Where in IdentityIQ should I look to find out if a provisioning request failed or succeeded?
  • What’s the best way to run this check every day automatically — a scheduled Task, or a Report?
  • What’s the simplest way to send an email automatically once the report is ready?

This is my first task working solo on IdentityIQ, so simple explanations are very welcome. Thanks in advance!

@kazi_1234 You can configure a Provisioning Transaction Report and let it run once a day → also configure the recipients who should be receiving this report.

@kazi_1234 Please check this post for sample report; Report column does not populate properly in IdentityIQ - IdentityIQ (IIQ) / IIQ Discussion and Questions - SailPoint Developer Community

Hello Kazi Umar. @neel193 has pointed you to the right report.

You can view failed provisioning under Gear → Administrator Console → Provisioning → Failure. Open a transaction to see its status and applicable error message.

For the daily report, go to Intelligence → Reports → Provisioning Transaction Object Report, save a copy, and set:

  • Application = your application
  • Status = Failed
  • Type = Auto

Use the Detailed Provisioning Transaction Object Report if you need attribute-level details.

Set the TPO identity or workgroup under Email Recipient, select CSV/PDF under Email Attachment Format, enable Don’t email empty reports, and schedule the report daily. No separate custom Task or email rule is required.

If you only want new failures from each day, the standard date filter is static, so you will need a custom dynamic date filter on a copy of the report.