Which Workflow or Sub process is called during certification item revocation?

Which IIQ version are you inquiring about?

Version 8.3

Share all details related to your problem, including any error messages you may have received.

Hi Team,

For ex : I have 2 application called App1 and App2 (both are web service connector)

I have a requirement in which i need to de-provision entitlements from both App1 and App2 when manager opt for revoking entitlement of App1 in target access review. I thought to implement it inside after provision rule but i don’t want to use provisioner api. Whats the best approach to handle this scenario.

Is it possible to handle it within any certifications workflow or sub process ?

1 Like

Your approach of afterprovisioning Rule seems fine for me, just check the source as Certification and have your conditions.

Can I reason why you don’t want to go through provisioner API, if you are looking for audit purpose you can create Custom Audit events during the removal from API to track these removals of second App or Call LCM provisioning workflow using plan with removal details where you will have an identity Request ID, either of this can help you with the audit tracking for reason

2 Likes

No - IIQ Certification process is calling directly provisioner - there’s no LCM (or any other workflow) involved in this process.

The only way I can imagine solving this problem would be before provisioning rule where you can just add provisioning request to the second application if it’s needed.

Certifications do not run in a Workflow. They run a Script on the background.

I would create a Before Provisioning that call a workflow to handle the removal of the extra entitlements.;

1 Like

When you say you don’t want to user provisioner api, what do you mean exactly? You can use LCM prov. workflow in case you want to create request for it for tracking.

1 Like

Not sure about your whole use-case , how about having the role created with this composition and you run review on role .

1 Like

Otherwise only option is after provisioning rule , but again you need to add specific condition based on source and then use provisioner API from one application to take action on another application .

1 Like

This is what i have implemented currently but was looking for better solution

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.