Skip to content

Violation Reports

If your organization has licensed SailPoint Access Intelligence Center (AIC), you can use Separation of Duties (SoD) data to create visualizations that help you correct, manage, or audit your compliance program.

You can build reports that include information about SoD policies, violations of those policies, and mitigating controls that you use to reduce risk.

  1. Go to MySailPoint Dashboard > Access Intelligence Center > Access Intelligence Center.
  2. Scroll across the options at the top of the page and select Separation of Duty, which focuses on specific SoD policies, violations, and mitigating controls.
  3. Use the SoD Chart Selections Menu to focus your view on departments, identity, violation owners, access items, or policies and controls.
  4. You may filter the data to further focus your view.
  5. Right click on a table to download the filtered data you need.
  6. If you have an author license you can select Duplicate to create a copy of the sheet and customize it for your own usage.

Note

To view SoD data in AIC, you must be assigned either the Admin or Report Admin user level with the Access Intelligence Center Reader or Author user level.

Deprecation Notice

If your organization has not licensed Access Intelligence Center, you can use the legacy functionality to view violation data. Go to Admin > SoD Policies and select Policy Violations from the left navigation. To export violations for a policy, select that policy’s name in the Policy Violated column, then select Actions > Export.

Policies

The following SoD Policy information is available in the Access Intelligence Center.

Name Description
SOD Policy Name The name of the policy.
SOD Policy Description The description of the policy.
SOD Policy Owner Name The name of the identity listed as this policy’s owner.
SOD Policy Owner Email The work email address of the policy owner.
SOD Policy Creator Display Name The display name of the identity that added this policy to Identity Security Cloud.
SOD Policy Creator Email The work email address of the identity that added this policy to Identity Security Cloud.
SOD Policy Modified Date The date this policy was last modified.
SOD Policy Modifier Display Name The display name of the most recent identity to modify this policy.
SOD Policy Modifier Email The work email address of the most recent identity to modify this policy.
SOD Violation Owner Name The name of the identity or governance group listed as the violation owner for this policy.
SOD Violation Owner Email If the violation owner of this policy is an identity, the work email address of that identity.
Risk Level Critical, high, medium, low, or none.
Policy State State of the policy: enforced or disabled.
Policy Type The type of policy, such as SoD policy or general policy.
Rule Definition Definition of what criteria cause something to be flagged with conflicting criteria.
Controls Mitigating controls that are allowed for the given policy.

Violations

SoD violation reporting focuses on tracking violations, sources, and trends. The following SoD violation information is available in the Access Intelligence Center.

Name Description
Violation ID Identifier for the violation.
Policy Reference Name of the violated policy.
Object Reference Name of the object in violation, such as an identity or account.
SOD Violation Owner Name The name of the identity or governance group listed as the violation owner for this policy.
SOD Violation Owner Email If the violation owner of this policy is an identity, the work email address of that identity.
User in Violation The user in violation of this SoD policy.
Email of User in Violation Email address of the identity who is in violation of this policy.
Violation Status Status of this violation, such as Open, Mitigated, Closed, Reopened.
Status Changed Date Date of the most recent change in this violation’s status.
Trending Violations Recently trending violations.
Conflicting Criteria Structured criteria in conflict.
Conflicting Summary Summary of conflicts.
Access in Violation Access items, such as entitlements, roles, and access profiles, that conflict under the policy.
Latest Violation Date Time The most recent date any new violation was detected for this policy.
Applied Mitigating Controls Mitigating controls applied to this violation. Includes mitigator, mitigation date, effective date, mitigation expiration, and re-mitigation dates.

Mitigating Controls

Name Description
SOD Mitigating Control Name Name of the mitigating control.
SOD Control Description Instructions for what to do if a policy violation is unavoidable.
SOD Control Owner Name The name of the identity or governance group listed as the owner for this mitigating control.
SOD Control Owner Email If the owner of this mitigating control is an identity, the email address of that identity.
Action Type Type of action that this mitigating control can trigger to remediate risk.
Expiration Expiration date or relative duration for this mitigating control.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.