# SailPoint Human Fabric User Help > SailPoint Human Fabric User Help # SailPoint Identity Security Cloud User Help # SailPoint Human Fabric User Help SailPoint Human Fabric gives you access to the applications and tools you need. With access requests and certifications, you can ensure everyone in your organization has the access they need, when they need it. Getting Started Requesting Access Managing\ Passwords Reviewing\ Certifications Completing Tasks Troubleshooting You can use the **SailPoint Solution Center** icon in the upper-left corner to quickly access your other SailPoint products. # Using SailPoint Harbor Pilot Harbor Pilot is SailPoint's *AI agent* that can help you find documentation and create access requests in SailPoint Human Fabric. As Harbor Pilot processes your natural language entries, it also displays the AI's logic and plan for its next actions. Harbor Pilot has some [limitations](#limitations) and can make mistakes. As SailPoint receives more feedback, Harbor Pilot will continue to evolve. If Harbor Pilot has been enabled by an administrator, you can start a session by selecting the **Harbor Pilot** icon . ## Creating and Managing Access Requests You can use Harbor Pilot to: - Identify the entitlement, access profile, or role that best meets your needs - View the results of your access request search and choose which items Harbor Pilot should request for you - Request access for yourself - If [enabled](https://documentation.sailpoint.com/saas/help/requests/requests_for_others.html), request access for others - Identify which account to request access for when multiple accounts exist on a source - Specify the start and end dates for the access - Cancel pending access requests The details of your request are displayed in the Harbor Pilot chat and in the [Request Center](https://documentation.sailpoint.com/saas/user-help/requests/tracking_access.html#request-center). ## Starting New Conversations To clear your current conversation and start a new session with Harbor Pilot, select the **Menu** icon in the chat window and choose **New Conversation**. ## Limitations Harbor Pilot is currently in its early stages, and while it’s already capable of handling important tasks, it’s still learning and evolving. It can make mistakes, so it's important to always review and validate the information it provides. You can use the and icons to provide instant feedback on Harbor Pilot's responses. SailPoint evaluates that data to refine and improve Harbor Pilot's model. Some current limitations include: - Harbor Pilot is supported and tested for English only. - Due to limitations in AWS regional support, Harbor Pilot is only available for customers in AWS regions where the AWS Bedrock LLM that SailPoint employs is supported. If you consistently receive error messages from Harbor Pilot that something wrong happened, you can contact your admin or [Support](https://community.sailpoint.com/t5/Working-With-Support/ct-p/WorkWithSupport) for help. ## Tips for Creating Effective Prompts Harbor Pilot understands natural language requests. You can select the **Menu** icon in the chat window and choose **Explore Prompts** to view commonly used queries for searching documentation and creating access requests. To get the best benefits from Harbor Pilot: - Use clear, concise language. Avoid jargon or overly complex wording. - Focus the prompt on a specific topic or task. - Provide an example of the type of input or response you’re looking for. - Use action-oriented language that encourages engagement, such as “Tell me about...” or “Describe...”. - Keep prompts short - typically just a sentence or two. Overly lengthy prompts can be confusing. # Launchpad The Launchpad allows you to manually initiate interactive processes and activate Just-In-Time entitlements made available to you by your administrator. You can do the following on the Launchpad: - [Initiate interactive processes](#managing-interactive-processes) defined by your administrator to enable you to complete a task. - [Activate Just-In-Time entitlement access](#managing-just-in-time-entitlement-access) when needed to complete specific activities. ## Managing Interactive Processes An interactive process is a workflow defined by your administrator to enable you to complete a task. Once initiated, progress messages are displayed as the process is performed and might display forms for you to fill out. The interactive processes can be searched by name in the search bar and sorted into ascending or descending order by name using the **Sort** button. ### Initiating Interactive Processes All interactive processes assigned to you are displayed on the Launchpad under **Interactive Processes**. **To initiate an interactive process:** 1. Go to **Home > Launchpad > Interactive Processes**. 1. Find the interactive process you want to initiate. 1. Select **Launch**. This initiates an interactive process. You can follow its progress and provide input as needed. Note You can only initiate an interactive process when the workflow associated with it is enabled by an administrator. If the Launch button is disabled, it means the workflow has been disabled. ### Viewing Interactive Processes On the Launchpad, you can initiate interactive processes, view the status of previously initiated interactive processes, and continue any interactive processes that have not completed. - **All** - All interactive processes assigned to you. - **In Progress** - Interactive processes that are currently running. Select **View** to open an interactive process and view its current step and status, or to continue running it to completion. - **Recently Completed** - Interactive processes that are no longer running. Interactive processes that are no longer running include those that finished successfully, encountered errors, or were canceled before completion. Select **View** to open an interactive process and review the completed status. Note You cannot restart an interactive process from the Recently Completed view. ## Managing Just-In-Time Entitlement Access Just-In-Time entitlement access allows you to activate an entitlement for a defined duration in order to complete specific activities. The access is then automatically removed when the activation period ends or is deactivated by the user. On the Launchpad, you can view the Just-In-Time entitlements assigned to you, as well as [activate](#activating-just-in-time-entitlements), [deactivate](#deactivating-just-in-time-entitlements), or [extend](#extending-just-in-time-entitlement-activation) entitlement activations. Caution Ensure that any changes you make while working with Just-In-Time entitlement access are saved before the activation period expires. When the activation expires, the privileges that the entitlement grants will be removed. Unsaved changes may result in unexpected behavior. If you require more time, you can [extend your activation duration](#extending-just-in-time-entitlement-activation). You can search for Just-In-Time entitlements or filter the list by the following: - **All** - All Just-In-Time entitlements assigned to you. - **Active** - Just-In-Time entitlements that are currently active. - **Last 30 Days** - Just-In-Time entitlements that were deactivated within the last 30 days. ### Activating Just-In-Time Entitlements **To activate a Just-In-Time entitlement:** 1. Go to **Home > Launchpad > Just-In-Time Access**. 1. Find the Just-In-Time entitlement you want to activate. 1. Select the activation duration. To select a duration that is not listed, select **Other** and choose a duration from the dropdown list. 1. Select **Activate**. Notes - Just-In-Time entitlements can take several minutes to activate. You will receive an email notification once the entitlement becomes active. - You can view the amount of time remaining for each activation period in its associated card. - You will receive an email notification 15 minutes before the activation period expires. The email notification contains a link that allows you to [extend the duration](#extending-just-in-time-entitlement-activation). ### Deactivating Just-In-Time Entitlements If you no longer need access before an entitlement activation automatically expires, you can manually deactivate it. Caution Ensure that all changes you make are complete before deactivating the entitlement. When the activation expires, the privileges that the entitlement grants will be removed. Unsaved changes may result in unexpected behavior. **To deactivate active Just-In-Time entitlements:** 1. Go to **Home > Launchpad > Just-In-Time Access**. 1. Find the Just-In-Time entitlement you want to deactivate. 1. Select **Deactivate**. 1. Select **Deactivate** in the confirmation message. ### Extending Just-In-Time Entitlement Activation If you need more time to complete your activity, you can extend the duration of your activation. The duration of time that you can extend your activation for is set by your administrator. Note The option to extend your entitlement activation becomes available when there are 30 minutes or less remaining in the activation period. **To extend your Just-In-Time entitlement access period:** 1. Go to **Home > Launchpad > Just-In-Time Access**. 1. Find the Just-In-Time entitlement access you want to extend the duration for. 1. Select **Extend**. # Using the Password Manager The Password Manager allows you to manage and review your passwords in one place. On this page, you can view your applications and see which share the same password. This way, when you change a password, you can see what other applications it might affect. Note This topic describes the process for updating passwords in your Password Manager. To update the password for your SailPoint Human Fabric account, refer to [Managing your Account Password](https://documentation.sailpoint.com/saas/user-help/accounts/passwords.html). **To update your passwords in the Password Manager:** 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, select **Password Manager**. Note If you do not see the **Password Manager** option in your menu, your organization may not support this feature. Contact your administrator for more information. 1. Find the application you want to change passwords for. The application will appear in one of the following groups: - **Password Group** - A group of applications that share a password. Your administrator can add sources to a [password sync group](https://documentation.sailpoint.com/saas/help/pwd/sync_grps.html), so all sources in that group share the same password. Changing the group's password will change the shared password for all of the applications included in this group. - **Multi-Application Source** - A source with numerous applications that share a password. For example, you may have a source called Amazon that contains the Amazon and Amazon Web Services apps. Changing this password will change the shared password for these applications. - **Applications** - An application that does not share a password with other applications. Changing this password won't affect other applications. 1. Select **Change Password** for the application or group of applications. 1. Complete any authentication. Your organization may require you to answer security questions or use a third-party authenticator. 1. Enter and confirm your new password. 1. Select **Change password** to update your password. # Using the Task Manager The Task Manager allows you to review and manage tasks that you must complete in an external system. For example, you may need to create or update an account within your organization's HR system. In your Task Manager, you can review all the details you need to finish the task and mark it as complete. ## Completing Tasks If you are assigned a manual task, you will receive an email and in-app notification detailing the required change. The manual task will ask you to perform one of the following actions: | Task | Definition | | ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------- | | Add an Attribute | Add a value to an attribute | | Create an Account | Create a new account on the source | | Certification Items Revoked by | Remove all entitlements listed in the task. This task is generated when a reviewer revokes items in an access review or certification. | | Delete an Account | Delete an account on the source. **Caution**: Deleting an account is a permanent action. Deleted accounts cannot be restored. | | Disable an Account | Temporarily disable an account on the source. The user won't have access to this account. | | Enable an Account | Enable a disabled account | | Remove an Attribute | Remove a value from an attribute | | Set an Attribute | Change the current value of an attribute to a new value | | Unlock an Account | Unlock a user's locked account | **To complete a task:** 1. From your Dashboard, select the **My Tasks** widget. You can also select **Task Manager** from the navigation menu. 1. Select a task from the list to review the details of that task. For example, if you need to add an attribute, you'll see a list of attributes and values to define for the account. Note For some sources, you may need to select **Show Details** for additional information about the task. You can also select the **Identity** tab to display more information about the identity. 1. Complete the task as described. 1. Upload a .csv file that includes the change you completed for the task. An [aggregation](https://documentation.sailpoint.com/saas/help/accounts/loading_data.html#manually-aggregating-accounts-from-a-flat-file) will automatically start. 1. Select **Mark Complete** to mark the task as complete. Note If the task is marked complete before an aggregation runs, the source owner has 24 hours to update the .csv file and trigger an aggregation. Otherwise, a second manual work item will be created. After you have completed your task, it will appear in the **Completed** tab. You can use the information in this tab to help your organization keep records of completed work. ## Reassigning Tasks You can reassign a task to another user if they are better suited for the task. Choose the task to reassign and then select the **Reassign** button. In the **Reassign To** field, select the user to reassign the task to. Enter comments about the task in the **Add Comments** field and then select **Reassign**. # Troubleshooting Having an issue? We're here to help. Check out the following FAQs for solutions to common issues. ## Account and Password Issues ### Why can't I reset my password? When you [reset your password](https://documentation.sailpoint.com/saas/user-help/accounts/resolving_issues.html#resetting-your-password), you'll receive an error message if your password contains a prohibited word or character. Your administrator has determined that certain words or characters are not secure and should be avoided in passwords. To complete your password change, choose a new password that meets the requirements. Tip Avoid using common words, personal information, or words found in the dictionary to make your password more secure. ### How do I know if my password is about to expire? Depending on your organization's settings, you may receive an email a few days prior to your password's expiration date. You will receive an email every subsequent day until you [reset your password](https://documentation.sailpoint.com/saas/user-help/accounts/resolving_issues.html#resetting-your-password) or your password expires. ### Why am I being asked to provide my old password? If you change your password on a different device than the one you normally use or if you change it outside of SailPoint Human Fabric, you'll be prompted to provide your old password as part of the reset process. This is a security measure designed to prevent unauthorized password changes. ### I can't authenticate my account. What should I do? If you try to [reset your password](https://documentation.sailpoint.com/saas/user-help/accounts/resolving_issues.html#resetting-your-password) or [update your preferences](https://documentation.sailpoint.com/saas/user-help/accounts/preferences.html), you will be prompted to verify your identity. If you forgot your authentication information, reach out to your administrator. Note If configured by your organization, you can also authenticate your identity by retrieving a code from your organization's Helpdesk. # Managing your SailPoint Human Fabric Account You can help protect your organization from cyber risks by keeping your account secure and up to date. You can improve the security of your account by: - updating your [SailPoint Human Fabric password](https://documentation.sailpoint.com/saas/user-help/accounts/passwords.html) regularly. - keeping your [contact information](https://documentation.sailpoint.com/saas/user-help/accounts/preferences.html#updating-your-contact-information) up to date. - setting up [multifactor authentication](https://documentation.sailpoint.com/saas/user-help/accounts/mfa.html) to add additional verification methods. If you encounter issues logging into your account, you can also [unlock your account](https://documentation.sailpoint.com/saas/user-help/accounts/resolving_issues.html#unlocking-your-account) or [retrieve a forgotten username](https://documentation.sailpoint.com/saas/user-help/accounts/resolving_issues.html#retrieving-your-username). # Managing Multifactor Authentication Your organization may require you to set up *multifactor authentication* to keep your account and identity secure. Multifactor authentication helps to ensure that the correct person is signing in to the right account. ## Setting Up Multifactor Authentication Note Before you can set up multifactor authentication, you must download and install an authenticator app (like Google Authenticator or Microsoft Authenticator) for your mobile device. 1. Sign in to SailPoint Human Fabric. 1. Open an authenticator app on your mobile device and scan the QR code from your tenant. You'll receive a verification code on your mobile device. If you are unable to scan the QR code, select the **Can't scan?** option. Enter the provided **Setup Key** into your authenticator app. The app will provide you with a verification code. 1. Enter your verification code and select **Verify**. The next time you log in, you'll be asked to enter an authentication code. ## Resetting Multifactor Authentication In the event you lose or get a new mobile device, you’ll need to reset your multifactor authentication to keep your account secure. 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, select **Preferences**. 1. Select **MFA Reset** from the left pane. 1. Select **Sign out and Reset MFA**. 1. In the confirmation window, select **Reset** to reset your multifactor authentication. You’ll be signed out of your account and taken to the login page. After you sign in, you’ll receive the QR code to [set up your multifactor authentication](#setting-up-multifactor-authentication). # Managing Non-Employee Accounts You can use non-employee accounts to create records for contractors, interns, and other non-employees in your organization. You can then use these accounts to track and manage their access to your enterprise systems and data. ## Requesting Non-Employee Accounts Have an intern or contractor joining your team soon? You can request a non-employee account to manage their access to your organization's applications and roles. Note Only non-employee account managers or system administrators can request non-employee accounts. 1. Go to your Dashboard. 1. Select the **Manage Non-Employees** widget. 1. Select the group or data source the new account belongs in. 1. On the right side of the table, select **+ Request Account**. 1. Enter the required information for the new account. 1. (Optional) Select the **Add Another** checkbox to request another account. 1. Select **Add** to request the non-employee account. Depending on your organization, this request may need user approval. You'll receive an email and in-app notification when your account request has been reviewed. ## Updating Non-Employee Accounts A source's non-employee account manager will receive an email and in-app notification when a non-employee's end date is approaching. If their contract or internship will be extended, the source's account managers or a system administrator can change the non-employee's end date to prevent them from potentially losing access. 1. Go to your Dashboard. 1. Select the **Manage Non-Employees** widget. 1. Select the group the user belongs in. 1. Select the account to edit. 1. In the new window, select a new end date for this user. 1. Select **Save** to save these changes. ## Reviewing Non-Employee Account Requests If you are designated as an account reviewer, you will be tasked with reviewing and approving account requests for non-employees. 1. From the navigation menu, select **Approvals**. 1. In the **Requested Items** tab, locate the request for the non-employee account. Tip Filter by **Non-Employee Account Requests** to only view requests for non-employee accounts. 1. Select the request card to view details about the request. 1. Respond to the request: - To approve the request, select **Approve**. - To deny the request, select the **Comments** tab and include a comment for denying the request. Select **Deny**. If you are the final reviewer, the user will be granted an account. If more reviewers are required, the account request is automatically sent to the next reviewer in the queue. # Managing Your Account Password Whether your password is about to expire or your account has been compromised, you can secure your account by changing your password. Note This topic describes the process for updating the password for your SailPoint Human Fabric account. To update passwords for other applications through the Password Manager, refer to [Using the Password Manager](https://documentation.sailpoint.com/saas/user-help/password_manager.html). ## Updating Your Account Password 1. Select the **User** icon in the upper-right corner of the page. 1. From the dropdown list, select **Update Password**. Note If you do not see the **Update Password** option in your main menu, reach out to your administrator for help. 1. Complete any authentication. Your organization may require you to answer security questions or use a third-party authenticator like Okta Verify. 1. Enter and confirm your new password. 1. Select **Change password** to update your password. # Updating Your Preferences You can update your account and security settings on the Preferences page. ## Updating Your Contact Information Your work phone and email address are set by your organization and cannot be edited. If your work phone or email address change, your organization will update your information. Depending on your administrator's configurations, you may also view and update your personal contact information on this page. You can use these as authentication methods to reset your password. **To update your personal contact information:** 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, select **Preferences**. 1. Complete any authentication. 1. Under **General Settings**, enter or change your contact information. 1. Select **Save** to save your changes. ## Updating Your Security Settings Keep your account and data secure by managing your security settings. 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, select **Preferences**. 1. Complete any authentication. 1. Select **Security Settings**. 1. For the **Select Method** field, select the authentication method you want to use. 1. Enter any required information. 1. Select **Save** to save your changes. ## Using Dark Mode You can use dark mode for supported pages in Identity Security Cloud. Note Custom branding colors are not enabled in dark mode. 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, toggle **Dark Mode** to **On**. # Resolving Account Issues Can't access your account? Don't worry. We're here to help. Use the following steps to get your account back up and running. ## Resetting Your Password Forgot your password? We’ve got you covered. You can change your password on the login page. 1. On the login page, select **Problems signing in?**. 1. Select **Reset password**. 1. When prompted, enter your username and select **Continue**. 1. Complete any authentication. Your organization may require you to answer security questions or use a third-party authenticator like Okta Verify. 1. Enter and confirm your new password. 1. Select **Change password**. You can now sign in to your account with your new password. ## Retrieving Your Username If you forget your username, you can easily retrieve it by following these steps. 1. On the login page, select **Problems signing in?**. 1. Select **Forget user name**. 1. Enter the email address associated with your account. 1. Select **Send email**. 1. Check your email for a notification that contains your username. You can now sign in with your username. ## Unlocking Your Account You may get locked out of your account if you have too many failed password attempts. If this happens, you'll receive an email notifying you of the attempts and an estimated time for when your account will be unlocked. If you don't feel like waiting, you can easily unlock your account by verifying your identity. **To unlock your account:** 1. On the login page, select **Problems signing in?**. 1. Select **Unlock account**. 1. When prompted, enter your username and select **Continue**. 1. Choose an authentication method to verify your identity and select **Continue**. After you’ve successfully completed the verification method, your account is immediately unlocked. # Setting Work Reassignments You can use work reassignments to automatically redirect your work to other users. For example, you may use this feature if you’re going on vacation and know you’ll need to review access requests. If you are a manager, you may also configure work reassignments for your direct reports. You can set up work reassignments for access request reviews, manual tasks, and certifications. ## Configuring Work Reassignments for Yourself Note Work reassignments only apply to work assigned to you after the reassignment period starts. 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, select **Preferences**. 1. Select **Work Reassignment** from the left panel. 1. Choose the type of work item to reassign. Caution Adding a new reassignment for the same type of work item will replace the previous reassignment. 1. From the **Assign To** list, select the identity to receive the work reassignment. 1. Specify a start date and time for when the reassignment should begin. To start the work reassignment immediately, select the **Start Now** toggle. 1. Specify an end date and time for when the reassignment should end. To omit an end date, select the **No end date** toggle. This makes the reassignment permanent until it is manually removed. Notes - When the reassignment period ends, new work will no longer be reassigned. Previously reassigned work will not be returned to you. - Take Daylight Saving Time into account when selecting the time for your reassignments. 1. Choose a time zone for your specified start and end times. This defaults to your browser’s time zone. 1. Select **Add Reassignment**. Notes - The system prevents users from creating loops in reassignment chains, where work gets assigned back to a user already in the chain. If this occurs, an error message lists all the users in the sequence, so you can work with them to correct the problem. - For access requests, when the assigned reviewer is a governance group, work reassignments are applied for each identity within the group. For certifications, however, if the assigned governance group contains multiple identities, reassignments configured for the members are not applied. Both you and the other user will receive an email and in-app notification about the new work reassignment. 1. Repeat these steps to add work reassignments for other types of work items. You can only add one reassignment for each type of work item. To delete a reassignment from the Scheduled Reassignments list, select **Delete** next to the reassignment. ## Configuring Work Reassignments for Your Team Note Work reassignments only apply to work assigned after the reassignment period starts. 1. From your Dashboard, select your **My Team** widget. 1. Select an identity from your list of team members. Inactive identities, such as identities who are on leave or who have left your organization, may not appear in this list. 1. Select the **Work Reassignment** tab. 1. Choose the type of work item to reassign. Caution Adding a new reassignment for the same type of work item will replace the previous reassignment. 1. From the **Assign To** list, select the identity to receive the work reassignment. 1. Specify a start date and time for when the reassignment should begin. To start the work reassignment immediately, select the **Start Now** toggle. 1. Specify an end date and time for when the reassignment should end. To omit an end date, select the **No end date** toggle. This makes the reassignment permanent until it is manually removed. Notes - When the reassignment period ends, new work will no longer be reassigned. Previously reassigned work will not be returned to your direct report. - Please take Daylight Saving Time into account when selecting the time for your reassignments. 1. Choose a time zone for your specified start and end times. This defaults to your browser’s time zone. 1. Select **Add Reassignment**. The reassignment displays in the Scheduled Reassignments list. Notes - The system prevents users from creating loops in reassignment chains, where work gets assigned back to a user already in the chain. If this occurs, an error message lists all the users in the sequence, so you can work with them to correct the problem. - For access requests, when the assigned reviewer is a governance group, work reassignments are applied for each identity within the group. For certifications, however, if the assigned governance group contains multiple identities, reassignments configured for the members are not applied. 1. Repeat these steps to add work reassignments for other users and work items. You can only add one reassignment for each type of work item. Emails and in-app notifications will be sent to both your direct report and the recipient of the new work reassignment. To delete a work reassignment from the Scheduled Reassignments list, select **Delete** next to the reassignment. ## Viewing Your Reassignment History If your work has been reassigned, you can view details about each work item, including the new assignee and the date of the reassignment, in the Reassignment History page. This page displays your reassignments from the past 90 days. Note Contact your administrator for a list of reassignments beyond the 90-day period. 1. Select the **User** icon from the upper-right corner of the page. 1. From the dropdown menu, select **Preferences**. 1. Select **Work Reassignment** from the left panel. 1. Select **Reassignment History**. Note The **Assignee** column displays the first identity specified in the reassignment configuration. Further reassignments are not listed. # Approvals Overview Some actions in an organization require someone to review and approve the action. If your organization needs you to review and approve something, you will receive an email and in-app notification with instructions to check your **Approvals** in the navigation menu. On the Approvals page, you can review and approve the following: - [Access Requests](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_access.html) - Review requests for access and access removals. - [Account Requests](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_accounts.html) - Review requests for the deletion of human, machine, and uncorrelated accounts. - [Non-Employee Account Requests](https://documentation.sailpoint.com/saas/user-help/accounts/non_employee.html) - Review account requests for non-employees. - [GenAI Entitlement Descriptions](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_descriptions.html) - Review generated descriptions and approve them to apply those descriptions to the associated entitlements. - [Other Requests](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_other_requests.html) - Review requests outside of the access request flow, including task-based requests such as creating an AD group or activating and deactivating AI agents, depending on your tenant’s configuration. # Reviewing Access Requests Depending on how your org is configured, you may be asked to review requests for access and access removals. When a request is approved, the user’s access for an access profile, role, or entitlement is granted or removed, depending on the type of request. If you deny a request, the approval process stops, and no access is granted or removed. ## Reviewing Requests When you need to review a request, you will receive an email notifying you that it's ready for your review. Note If someone else in your governance group has already reviewed an access request, it will disappear from your list. Only one person per group needs to approve or deny access. 1. From the navigation menu, select **Approvals** to open your requests. The view defaults to the Access Requests tab. To [review other requests](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_other_requests.html), meaning any request that is not an access request or entitlement description, select **Other** from the left navigation. Tip When reviewing access requests, pay attention to the words **Grant**, **Remove**, or **Modify** next to the role name to stay aware of whether you are approving new access, the removal of access, or a modification to the access start or end dates. Modification request cards also have the header **Access Date Change**. 1. In the **Requested** tab, select a request card to review details about the request. Request cards may include: - **Privileged badge** - Entitlements typically grant access to sensitive data. When there is a Privileged badge on the request card, consider carefully whether the user should have that elevated access. - **Review Violations** - When the request would violate separation of duties (SoD) policies, you can select **Review Violations** at the top right side of the card for more information. Violations are also listed in the request details overlay. If your organization has Just-In-Time and Privilege, a banner on the bottom of the card lets you know if the request will grant standing access, which is continuously available until revoked, or Just-In-Time access, which requires the user to activate it before each use. Tip Depending on your tenant’s configuration, additional data may display in access requests that can be used to help inform your decisions. For example, the following data may be available in requests for entitlements and access profiles: - **Popularity** - The percentage of the identity's team members who have this access. - **Usage popularity** - The percentage of the identity's team members who have used this access item's source in the past 90 days. This data is updated every 4 hours. 1. Review the identity details, violations, and any comments about this request. If the request includes a form, start date, or end date, it will be included in the request details. Access start and end times shown in the approval details are displayed in the approver's browser time zone. - If there are violations, select the down arrow for full details, including the policy violated, policy description, policy level, mitigation advice, remediation advice, and mitigating controls. Warning A machine account may be used by more than one machine identity or agent. Your approval may change access for identities not shown in the request. Confirm you understand the impact before approving. 1. Select **Approve** or **Deny**. If you deny a request, you may be prompted to enter the reason you are denying the request. If you believe someone else is better suited to review this request, select **Reassign** to [reassign the request](#reassigning-requests) to them. Note If reauthentication is required and you are not an SSO-authenticated user, you cannot approve the request. You can only deny the request or reassign the item for approval by an SSO-authenticated user. When you approve a request, the following can occur: - If the access item requires reauthentication, you will be prompted for a business justification comment and then redirected to your SSO system to reauthenticate. - If the request requires multiple reviewers, it is sent to the next reviewer in the queue. - If you're the last reviewer in the review process for this request, the human or machine identity's access is added on the access start date or right away, depending on requested start date, or revoked, depending on the type of request. After you deny a request where you are the single approver, the approval process ends. If there are multiple reviewers in the queue, the process follows its defined workflow. If your administrator has configured an escalation policy, you may receive reminder emails until you review the request. The request may be reassigned to another reviewer, such as your manager, if you do not review it within the time designated in the policy. By default, requests that have not been fully approved after 90 days will be automatically denied and expired. Contact your administrator for more information. To view access requests you've already approved or denied, select the **Reviewed** tab. Select a request to view its details, your comments, the original requester's comments, and any reassignment-related comments. ## Reassigning Requests You may need to reassign requests to another user if they are better suited for that approval. You can reassign requests to ensure users get access to the data and applications they need. 1. Select **Approvals** from the navigation menu. 1. In the **Requested** tab, locate the request you want to reassign and select **Reassign**. 1. In the **Reassign To** field, enter the name or email address of the new reviewer. 1. In the **Add Comments** field, enter the reason you're reassigning this access request to the new reviewer or any other comments related to the request. 1. Select **Reassign** to reassign the request. The new reviewer will receive an email that the access request has been reassigned to them. # Reviewing Account Requests Depending on your tenant's configuration, you may be asked to review requests to create or delete human, uncorrelated, or machine accounts. When a request is approved, the account is created or deleted. If you deny a request, the approval process stops, and no action is taken. When you need to review a request, you will receive an email notifying you that it's ready for your review. To review an account request: 1. From the navigation menu, select **Approvals** to open a list of requests. 1. Select **Account Requests** from the left panel. 1. In the **Requested** tab, select a request card to review details about the request. Tip When reviewing account requests, pay attention to the words **Create** or **Delete** next to the name to stay aware of whether you are approving a new account or approving the deletion of an account. 1. Review the details and any comments about this request. Note The final account name may not be available until provisioning, so the name you see in a request and in notifications will be formatted as [subtype name] - [source name]. For example, a request may say Create: SVC - Active Directory rather than Create: svc.dev.account001. 1. Select **Approve** or **Deny**. You may be prompted to enter a reason for approving or denying the request. If you believe someone else is better suited to review this request, select the **Reassign** icon to [reassign the request](#reassigning-account-requests) to them. When you review a request, the following may occur: - If you approve a request that requires multiple reviewers, the request is sent to the next reviewer in the queue. - If you're the last reviewer in the review process and approve the request, the account is created or deleted. - If you are the single approver and deny a request, the approval process ends. If there are multiple reviewers in the queue, the process follows its defined workflow. If your administrator has configured an escalation policy, you may receive reminder emails until you review the request. The request may be reassigned to another reviewer, such as your manager, if you do not review it within the time designated in the policy. Contact your administrator for more information. To view account requests you've already reviewed, select the **Reviewed** tab. Select a request to view its details, your comments, the original requester's comments, and any reassignment-related comments. ## Reassigning Account Requests You may need to reassign an account request to another user if they are better suited for that approval. 1. From the navigation menu, select **Approvals** to open a list of requests. 1. Select **Account Requests** from the left panel. 1. In the **Requested** tab, select the request you want to reassign. 1. Select the **Assign to a different reviewer** icon in the lower-left corner of the window. 1. In the **Reassign To** field, enter the name or email address of the new reviewer. 1. In the **Add Comments** field, enter the reason you're reassigning this account request to the new reviewer or any other comments related to the request. 1. Select **Reassign** to reassign the request. The new reviewer will receive an email and in-app notification that the request has been reassigned to them. # Reviewing Descriptions You may be asked to review and approve a GenAI entitlement description. Entitlements are the access rights an account has on a source. Entitlement descriptions should provide useful information about the entitlement and its access. To ensure that a GenAI entitlement description is accurate, approval by a reviewer is required before the suggested description can be applied to the entitlement. When you need to review an entitlement description, you will receive an email and in-app notification that it's ready for your review. 1. From the navigation menu, select **Approvals > Entitlement Descriptions** to open your reviews. Proposed descriptions are listed on cards. 1. Review the proposed description. 1. Select **Approve** or **Deny**. 1. To edit the proposed description, select **Edit**. You can make changes to the proposed description and then select **Approve**. If you approve a description, it is updated on the entitlement. # Reviewing Other Approval Requests When you need to review a request for items outside of the access request flow, you will receive an email and in-app notification that it's ready for your review. These include task-based requests such as creating an AD group or activating and deactivating AI agents, depending on your tenant’s configuration. Go to the **Approvals** page in the top navigation, then select **Other** from the left navigation. The Other approvals page defaults to a table view, but you may use the toggle at the right to view the same information on cards. Use the options above the table or cards to filter for All, Pending, or Completed requests. By default, the requests are sorted by age, with the newest at the top. To complete a review request: 1. Locate a request. Each approval request includes the request name, description, requester, requesting for, assigned to, date, priority, status and actions. 1. From the request card, you can Approve or Deny the request, or select **Menu** to see request details, identity, comments, and accounts. 1. Review the request. Optionally, if you believe someone else is better suited to review this request, you can select **Reassign** to [reassign the request](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_access.html#reassigning-requests) to them. 1. Select **Approve** or **Deny**. If you deny a request, you may be prompted to enter the reason you are denying the request. When you approve a request, the following can occur: - If the request requires multiple reviewers, it is sent to the next reviewer in the queue. - If you're the last reviewer required for this request, the request is granted appropriate to the type of request. For example, if you review and approve a request to create a new AD group, and you are the last required approver, the new AD group is created. After you deny a request where you are the single approver, the approval process ends. If there are multiple reviewers in the queue, the process follows its defined workflow. Note If the approval was marked to require reauthentication, you will be asked to reauthenticate through your SSO provider to complete the approval. If your administrator has configured an escalation policy, you may receive reminder emails and in-app notifications until you review the request. The request may be reassigned to another reviewer, such as your manager, if you do not review it within the time designated in the policy. Contact your administrator for more information. To view access requests you've already approved or denied, select the **Reviewed** tab. Select a request to view its details and any comments about the request. # Reviewing Privilege Classification You may be asked to review and approve an entitlement's privilege classification. Entitlements are the access rights an account has on a source. Privilege classification levels help you quickly identify high-risk entitlement access. To ensure that an entitlement's privilege classification is accurate, approval by a reviewer may be required before the suggested classification can be applied. When you need to review privilege classification, you will receive an email and in-app notification that it's ready for your review. 1. From the navigation menu, select **Approvals > Privilege Classification** to open your reviews. Proposed classifications are listed on cards. 1. Review the proposed classification. 1. Select **Approve** or **Deny**. 1. To edit the proposed classification, select **Edit**. You can make updates, then select **Approve**. If you approve a classification, it is updated on the entitlement. Phased Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Certifications Overview To be successful and secure within your organization, you need to know who has access to what and whether that access is correct. You can review your users' access to roles, access profiles, entitlements, and apps through *certifications*. Certifications allow designated people, such as managers or system owners, to review and certify users’ access. These designated users, also known as certifiers, will determine whether this access is appropriate for those users or should be revoked. Certifiers will [review certifications](https://documentation.sailpoint.com/saas/user-help/certs/reviewing/index.html), approve or revoke access, and sign off on decisions. Limited Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Certifications Overview To be successful and secure within your organization, you need to know who has access to what and whether that access is correct. You can review your users' access to roles, access profiles, entitlements, and apps through *certifications*. Certifications allow designated people, such as managers or system owners, to review and certify users’ access. These designated users, also known as certifiers, will determine whether this access is appropriate for those users or should be revoked. Certifiers will [review certifications](https://documentation.sailpoint.com/saas/user-help/certs/reviewing/index_la.html), approve or revoke access, and sign off on decisions. Phased Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Reassigning Certifications If you need to reassign certifications to a user who is better suited to review that access, you can do so on the Certifications page. You can review and reassign certifications by users, known as identities, or by access items. 1. Select **Certifications** from the navigation menu. 1. In the **Active** tab, select the certification you want to reassign. 1. Choose how you want to reassign the contents of the certifications: - **By Identity** - From the list of identities, select the checkbox for the identity you want to reassign and select **Reassign**. You can reassign multiple identities at a time. - **By Access Item** - In the main body of the certification, select the checkboxes next to the line items you want to reassign. Select **More Options** in the **Decision** column and then select **Reassign**. To reassign one item at a time, select that item's row. In the new window, select **Reassign Decision**. Note If you reassign an access item in the **Identities** or **Uncorrelated Identities** tab, you are only reassigning that access item for the selected identity or identities. To reassign the entire identity, you must view certifications by identities and reassign an identity from the left panel. - **By Uncorrelated Account** - From the list of uncorrelated identities, select the checkbox for the uncorrelated identity you want to reassign and select **Reassign**. You can reassign multiple uncorrelated identities at a time 1. In the **Reassign To** field, enter the name or email address of the new reviewer. You can reassign the certification to multiple users. 1. In the **Add Comments** field, enter the reason you're reassigning this certification and any other comments related to the certification. Best Practice Include your name as well as the reason for the reassignment. The new reviewer may need to contact you with questions. 1. Select **Reassign Decision** to reassign the certification. Repeat these steps for additional certifications that you want to reassign. Reviewers will receive an email and in-app notification about the reassignment and can see the certification in their list of active certifications. Limited Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Reassigning Certifications If you need to reassign certifications to a user who is better suited to review that access, you can do so on the Certifications page. You can review and reassign certifications by users, known as identities, or by access items. 1. Select **Certifications** from the navigation menu. 1. In the **Active** tab, select the certification you want to reassign. 1. Choose how you want to reassign the contents of the certifications: - **By Identity** - From the list of identities, select the checkbox for the identity you want to reassign and select **Reassign**. You can reassign multiple identities at a time. - **By Access Item** - In the main body of the certification, select the checkboxes next to the line items you want to reassign. Select **More Options** in the **Decision** column and then select **Reassign**. To reassign one item at a time, select that item's row. In the new window, select **Reassign Decision**. Note If you reassign an access item in the **Identities** or **Uncorrelated Identities** tab, you are only reassigning that access item for the selected identity or identities. To reassign the entire identity, you must view certifications by identities and reassign an identity from the left panel. - **By Uncorrelated Account** - From the list of uncorrelated identities, select the checkbox for the uncorrelated identity you want to reassign and select **Reassign**. You can reassign multiple uncorrelated identities at a time 1. In the **Reassign To** field, enter the name or email address of the new reviewer. You can reassign the certification to multiple users. 1. In the **Add Comments** field, enter the reason you're reassigning this certification and any other comments related to the certification. Best Practice Include your name as well as the reason for the reassignment. The new reviewer may need to contact you with questions. 1. Select **Reassign Decision** to reassign the certification. Repeat these steps for additional certifications that you want to reassign. Reviewers will receive an email and in-app notification about the reassignment and can see the certification in their list of active certifications. Phased Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Working with Certifications Your administrator may create a certification campaign containing access items or identities you're responsible for. When this happens, you'll receive an email and in-app notification that certifications are ready for your review. You may continue to receive reminder notifications about the certification until you complete your review. ## Reviewing Certifications Note Certification reviews are supported on tablets. Phones are not supported as they are not capable of displaying the UX optimally. For more information, refer to [Supported browsers and operating systems](https://documentation.sailpoint.com/saas/user-help/getting_started/supported_browsers.html). 1. Select **Certifications** from the navigation menu. 1. In the **Active** tab, select the certification you want to work on. 1. Review the contents of the certification. The page will differ based on the type of certification: - **Identity access certifications** Select **Identities** and choose an identity from the list. You'll see a list of access items for that user. Select the **Filter** icon to review their access for role, access profile, or entitlement. Select an access item to view its details. You can also select **Access Items** and choose a role, access profile, or entitlement from the list. Review the identities who have that access. - **Role composition certifications** Select the role you want to review from the list of roles. Review the role's associated access profiles, membership criteria, and details. - **Uncorrelated accounts certifications** An [uncorrelated account](https://documentation.sailpoint.com/saas/help/accounts/correlation.html#resolving-uncorrelated-accounts) is a source account that is not associated with an authoritative identity. A single uncorrelated account is generally represented by an uncorrelated identity. In rare cases, multiple uncorrelated accounts may belong to the same uncorrelated identity and be grouped together. To review these certifications, select **Uncorrelated Identities** and choose the uncorrelated identity you want to certify from the list. Review the access items associated with the uncorrelated identity. You can also select **Access Items** and choose an access item from the list. Review the uncorrelated accounts associated with that access item. - **Machine accounts certifications** A machine identity is a representation of a business application or process that machine accounts, like service accounts, bots, or other types of non-human accounts, are grouped within. For example, Automated Teller service accounts may be grouped and correlated to a Automated Teller machine identity. To review these certifications, select **Machine Identities** and choose an identity from the list. You'll see a list of access items for that machine identity. Review their access within the **Entitlements** tab. Select an access item to view its details. You can also select **Access Items** and choose an entitlement from the list. Review the machine identities that have that access. 1. In each section, beside each item, select **Approve** icon to approve access or **Revoke** to revoke access. Notes - Roles that were automatically assigned to identities through membership criteria may only be acknowledged. In these cases, select **Acknowledge** to review this access. - If you revoke an access profile that contains an entitlement that is also assigned to a user through another access profile, all entitlements within the access profile will be revoked, except for the common entitlement. Some reviews may require that you include a comment explaining your decision. For example, if you choose to revoke an item in a role composition certification, you must enter a comment that explains why and how the role should be changed. The system will send a task with these comments to the role owner to update the associated role. Select **Submit** to submit your comment and complete your review for this access. While completing your review, you can [reassign the certification](https://documentation.sailpoint.com/saas/user-help/certs/reassign_certs.html) if you feel there is a user who is better suited to review this access. Tips for reviewing certifications - Your certifications may contain [access flags](#access-flags) and additional data from other SailPoint products and services your organization has licensed. This information can help you make more informed decisions about whether to approve or revoke each access item. - If configured by your administrator, you can also view additional attributes for entitlements to help make decisions on access. To do so, select an entitlement and view the Additional Attributes section within its details. You can also select individual entitlements within an access profile to view their additional attributes. Select **More Options** to leave comments with your decision, [reassign the certification](https://documentation.sailpoint.com/saas/user-help/certs/reassign_certs.html), or choose a revocation date. In the new window, enter the revocation date or comments about the certification and submit your decision. Note You cannot set a revocation date for entitlements. You can change your decision, add or modify a revocation date, or add additional comments until you sign off on the certification. In the **Completed** tab of an identity or access item, select **Revisit Decision** for the decision you want to update. After you complete a certification, you can add or modify a revocation date, add additional comments, or change your decision by selecting **More Options** . To save your changes, select **Exit Certification** in the upper-right corner of the page. You can return at any time to continue your work You can save and return to your work at any time by selecting **Exit Campaign** in the upper-right corner of the page. After you've reviewed each item, you can submit your decisions and [complete the certification](#completing-certifications). ### Access Flags When you review an access item for a certification, an icon may display in the **Flags** column. This icon alerts you of information you should consider when approving access. You may encounter the following flags: | Name | Icon | Definition | | --------------------------- | ---- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | New Access | | The access has not been certified previously. | | Birthright Access | | The access has been granted by automated rules, such as lifecycle states. | | High Privilege (Overridden) | | The entitlement's privilege level has been manually changed to indicate it grants access to sensitive data with high security risks. | | Contains Privileged Access | | The access profile or role contains an access item with privileged entitlements. Privileged entitlements may grant access to sensitive data with high security risks. | | Timebound Access | | The access has a set end date. | | Comments | | There are comments associated with this access. | | Cloud Enabled | | This access relates to [cloud infrastructure](https://documentation.sailpoint.com/saas/user-help/certs/reviewing/viewing_cloud_details.html). | | Critical Data Access | | This access contains critical data. | ### Viewing Critical Data If your organization has [SailPoint Data Access Security](https://documentation.sailpoint.com/das/help/index.html), you can view the impact score, policies, and data categories for entitlements. The Impact Score is calculated by combining the perceived sensitivity of the data it grants access to with the number of instances of that data type. For example, an entitlement that grants access to 1000 social security numbers will have a higher Impact Score than an entitlement that grants access to 20 email addresses. The Impact Score can be High, Medium, or Low. The Policies columns lists the policies associated with the data. The tags within the Data Categories column describe the types of critical data the user will maintain access to if their access is approved. ### Viewing Recommendations If your organization has the [Recommendations](https://documentation.sailpoint.com/saas/help/ai/recommendations.html) service, select the **Recommended** or **Not Recommended** icon in the Decision column to view the reasons behind the recommendation. You can use this data to help guide your decision-making process. ### Viewing Source Activity If your organization has [Activity Insights](https://documentation.sailpoint.com/saas/help/ai/activity_insights/index.html), you can gather account information and activity data from the source. You can use this information to determine how often the identity used the source and if they should still retain access to the entitlement. ## Completing Certifications After you've reviewed each item, you'll be taken to a page to complete your certification. Select **Finish**. The certification moves to the **Completed** tab. If you aren't ready to submit your decisions, you can save **Save and return later**. Important Before you complete your review, ensure your decisions are correct and final. You will not be able to make any changes after you've submitted your decisions, and any access marked as revoked will be removed. Note If the approval was marked to require reauthentication, you will be asked to reauthenticate through your SSO provider to complete the approval. If you receive the **Unable to sign off** message, select **Reassign** to choose a user who can complete the authorization. Limited Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Working with Certifications Your administrator may create a certification campaign containing access items or identities you're responsible for. When this happens, you'll receive an email and in-app notification that certifications are ready for your review. You may continue to receive reminder notifications about the certification until you complete your review. ## Reviewing Certifications Note Certification reviews are disabled on phones and tablets. For more information, refer to [Supported browsers and operating systems](https://documentation.sailpoint.com/saas/user-help/getting_started/supported_browsers.html). 1. Select **Certifications** from the navigation menu. 1. In the **Active** tab, select the certification you want to work on. 1. Review the contents of the certification. The page will differ based on the type of certification: - **Identity access certifications** Select **Identities** and choose an identity from the list. You'll see a list of access items for that user. Select the **Filter** icon to review their access for role, access profile, or entitlement. Select an access item to view its details. You can also select **Access Items** and choose a role, access profile, or entitlement from the list. Review the identities who have that access. - **Role composition certifications** Select the role you want to review from the list of roles. Review the role's associated access profiles, membership criteria, and details. - **Uncorrelated accounts certifications** An [uncorrelated account](https://documentation.sailpoint.com/saas/help/accounts/correlation.html#resolving-uncorrelated-accounts) is a source account that is not associated with an authoritative identity. A single uncorrelated account is generally represented by an uncorrelated identity. In rare cases, multiple uncorrelated accounts may belong to the same uncorrelated identity and be grouped together. To review these certifications, select **Uncorrelated Identities** and choose the uncorrelated identity you want to certify from the list. Review the access items associated with the uncorrelated identity. You can also select **Access Items** and choose an access item from the list. Review the uncorrelated accounts associated with that access item. - **Machine accounts certifications** A machine identity is a representation of a business application or process that machine accounts, like service accounts, bots, or other types of non-human accounts, are grouped within. For example, Automated Teller service accounts may be grouped and correlated to a Automated Teller machine identity. To review these certifications, select **Machine Identities** and choose an identity from the list. You'll see a list of access items for that machine identity. Review their access within the **Entitlements** tab. Select an access item to view its details. You can also select **Access Items** and choose an entitlement from the list. Review the machine identities that have that access. 1. In each section, beside each item, select **Approve** icon to approve access or **Revoke** to revoke access. Notes - Roles that were automatically assigned to identities through membership criteria may only be acknowledged. In these cases, select **Acknowledge** to review this access. - If you revoke an access profile that contains an entitlement that is also assigned to a user through another access profile, all entitlements within the access profile will be revoked, except for the common entitlement. Some reviews may require that you include a comment explaining your decision. For example, if you choose to revoke an item in a role composition certification, you must enter a comment that explains why and how the role should be changed. The system will send a task with these comments to the role owner to update the associated role. Select **Submit** to submit your comment and complete your review for this access. While completing your review, you can [reassign the certification](https://documentation.sailpoint.com/saas/user-help/certs/reassign_certs_la.html) if you feel there is a user who is better suited to review this access. Tips for reviewing certifications - Your certifications may contain [access flags](#access-flags) and additional data from other SailPoint products and services your organization has licensed. This information can help you make more informed decisions about whether to approve or revoke each access item. - If configured by your administrator, you can also view additional attributes for entitlements to help make decisions on access. To do so, select an entitlement and view the Additional Attributes section within its details. You can also select individual entitlements within an access profile to view their additional attributes. Select **More Options** to leave comments with your decision, [reassign the certification](https://documentation.sailpoint.com/saas/user-help/certs/reassign_certs_la.html), or choose a revocation date. In the new window, enter the revocation date or comments about the certification and submit your decision. Note You cannot set a revocation date for entitlements. You can change your decision, add or modify a revocation date, or add additional comments until you sign off on the certification. In the **Completed** tab of an identity or access item, select **Revisit Decision** for the decision you want to update. After you complete a certification, you can add or modify a revocation date, add additional comments, or change your decision by selecting **More Options** . To save your changes, select **Exit Certification** in the upper-right corner of the page. You can return at any time to continue your work You can save and return to your work at any time by selecting **Exit Campaign** in the upper-right corner of the page. After you've reviewed each item, you can submit your decisions and [complete the certification](#completing-certifications). ### Access Flags When you review an access item for a certification, an icon may display in the **Flags** column. This icon alerts you of information you should consider when approving access. You may encounter the following flags: | Name | Icon | Definition | | --------------------------- | ---- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | New Access | | The access has not been certified previously. | | Birthright Access | | The access has been granted by automated rules, such as lifecycle states. | | High Privilege (Overridden) | | The entitlement's privilege level has been manually changed to indicate it grants access to sensitive data with high security risks. | | Contains Privileged Access | | The access profile or role contains an access item with privileged entitlements. Privileged entitlements may grant access to sensitive data with high security risks. | | Timebound Access | | The access has a set end date. | | Comments | | There are comments associated with this access. | | Cloud Enabled | | This access relates to [cloud infrastructure](https://documentation.sailpoint.com/saas/user-help/certs/reviewing/viewing_cloud_details_la.html). | | Critical Data Access | | This access contains critical data. | ### Viewing Critical Data If your organization has [SailPoint Data Access Security](https://documentation.sailpoint.com/das/help/index.html), you can view the impact score, policies, and data categories for entitlements. The Impact Score is calculated by combining the perceived sensitivity of the data it grants access to with the number of instances of that data type. For example, an entitlement that grants access to 1000 social security numbers will have a higher Impact Score than an entitlement that grants access to 20 email addresses. The Impact Score can be High, Medium, or Low. The Policies columns lists the policies associated with the data. The tags within the Data Categories column describe the types of critical data the user will maintain access to if their access is approved. ### Viewing Recommendations If your organization has the [Recommendations](https://documentation.sailpoint.com/saas/help/ai/recommendations.html) service, select the **Recommended** or **Not Recommended** icon in the Decision column to view the reasons behind the recommendation. You can use this data to help guide your decision-making process. ### Viewing Source Activity If your organization has [Activity Insights](https://documentation.sailpoint.com/saas/help/ai/activity_insights/index.html), you can gather account information and activity data from the source. You can use this information to determine how often the identity used the source and if they should still retain access to the entitlement. ## Completing Certifications After you've reviewed each item, you'll be taken to a sign-off page to complete your certification. To complete your review, select **Finish**. The certification moves to the **Completed** tab. If you aren't ready to submit your decisions, you can save **Save and return later**. Important Before you complete your review, ensure your decisions are correct and final. You will not be able to make any changes after you've submitted your decisions, and any access marked as revoked will be removed. Note If the approval was marked to require reauthentication, you will be asked to reauthenticate through your SSO provider to complete the approval. If you receive the **Unable to sign off** message, select **Reassign** to choose a user who can complete the authorization. Phased Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Viewing Cloud Access Details If the entitlement is related to cloud access, you might be able to view information about the cloud entitlements, resources, privileges, and access paths to cloud infrastructure an identity or machine account has. ## Viewing Cloud Entitlements When certifying access profiles, you can select the access profile name to view its entitlements. Select the entitlement name to view more details. If the entitlement is cloud enabled, you might be able to select **View Details** to display more granular information about the cloud attributes. When certifying entitlements, you can select **View Details** in the Cloud Enabled column to view cloud access information. If your organization has licensed SailPoint CIEM, you can also view the identity's access to cloud resources and privileges on those resources. This includes activity data on whether they used the entitlement, what access level they used (read/write/admin), and timestamps of previous activity and actions. You can search for and select an entitlement in the **Entitlement** field to view all accessible cloud resources across the user's cloud entitlements. You can also select **All** to view the total access the user has in the cloud environment. Notes - Last Accessed and Last Activity data refer to the last time the resource was accessed by the user and whether that activity was a read, write, or admin action. - Last access dates and activity are only displayed for AWS resources that write to CloudTrail. ## Viewing Access Paths From the Cloud Details page, you can select **View Access** in the Access Paths column to view the access paths from scoping objects like groups, policies, and projects granting the user access to the selected resource. The **Entitlement Path** tab displays the access path from the entitlement under review, or you can select **All Paths** to display all access paths across the identity's entitlements to the resource. Note If your organization has licensed [Machine Identity Security](https://documentation.sailpoint.com/saas/help/machine/index.html), you can also view the effective access for machine identities that use Microsoft Azure Service Principles and Google Cloud Infrastructure Service Accounts. Note If a user can access a resource through paths other than the entitlement, they might still be able to access that resource even if you revoke the entitlement. If a user has multiple of the same type of access at the same scope, such as multiple role assignments that lead to the same management group, you can select the node to display the access leading to the resource. Use the **Collapse** icon to collapse all nodes. Limited Availability Functionality available to select customers. Visit [New Capability: SailPoint next generation certification](https://developer.sailpoint.com/discuss/t/new-capability-sailpoint-next-generation-certification/92674) for more information. # Viewing Cloud Access Details If the entitlement is related to cloud access, you might be able to view information about the cloud entitlements, resources, privileges, and access paths to cloud infrastructure an identity or machine account has. ## Viewing Cloud Entitlements When certifying access profiles, you can select the access profile name to view its entitlements. Select the entitlement name to view more details. If the entitlement is cloud enabled, you might be able to select **View Details** to display more granular information about the cloud attributes. When certifying entitlements, you can select **View Details** in the Cloud Enabled column to view cloud access information. If your organization has licensed SailPoint CIEM, you can also view the identity's access to cloud resources and privileges on those resources. This includes activity data on whether they used the entitlement, what access level they used (read/write/admin), and timestamps of previous activity and actions. You can search for and select an entitlement in the **Entitlement** field to view all accessible cloud resources across the user's cloud entitlements. You can also select **All** to view the total access the user has in the cloud environment. Notes - Last Accessed and Last Activity data refer to the last time the resource was accessed by the user and whether that activity was a read, write, or admin action. - Last access dates and activity are only displayed for AWS resources that write to CloudTrail. ## Viewing Access Paths From the Cloud Details page, you can select **View Access** in the Access Paths column to view the access paths from scoping objects like groups, policies, and projects granting the user access to the selected resource. The **Entitlement Path** tab displays the access path from the entitlement under review, or you can select **All Paths** to display all access paths across the identity's entitlements to the resource. If a user has multiple of the same type of access at the same scope, such as multiple role assignments that lead to the same management group, your certifiers can select the node to display the access leading to the resource. Note If your organization has licensed [Machine Identity Security](https://documentation.sailpoint.com/saas/help/machine/index.html), you can also view the effective access for machine identities that use Microsoft Azure Service Principles and Google Cloud Infrastructure Service Accounts. Note If a user can access a resource through paths other than the entitlement, they might still be able to access that resource even if you revoke the entitlement. If a user has multiple of the same type of access at the same scope, such as multiple role assignments that lead to the same management group, you can select the node to display the access leading to the resource. Use the **Collapse** icon to collapse all nodes. # Completing a Form When your administrator needs more information from you, they can assign you a form to fill out. You will receive an email and in-app notification with a link to the form. This link is your access, and it opens your assigned form. You cannot save the form and return to it. You can also be required to complete a form when requesting access. As you select access items, complete any forms that are required for the items in your request. After you have finished filling out the form, select **Submit**. Note The form might be configured with conditions that make more fields appear based on your entries. You might only see a few fields initially, but the form could become more complex as you fill it out. # Getting Started SailPoint Human Fabric is a modern SaaS-based identity security solution that provides you with the tools for your organization to secure your systems and manage your users’ access. To get started, you’ll first need to [access SailPoint Human Fabric](https://documentation.sailpoint.com/saas/user-help/getting_started/registering.html) on a [compatible system](https://documentation.sailpoint.com/saas/user-help/getting_started/supported_browsers.html). After you’ve signed in, you can view your tasks, approvals, access requests, and more on your [home page](https://documentation.sailpoint.com/saas/user-help/getting_started/dashboard.html). # Supported Country Codes If you have chosen to receive text or voice messages for [strong authentication](https://documentation.sailpoint.com/saas/user-help/accounts/preferences.html#updating-your-security-settings), you must have a phone number with a supported country code. Your administrator can work with [Support](https://community.sailpoint.com/t5/Working-With-Support/ct-p/WorkWithSupport) to add additional country codes. Notes - Regulations in China prevent many automated phone calls from being delivered, including strong authentication voice calls. For this reason, Chinese country codes are not supported for voice calls. - SMS messages are not sent to users on the India Do Not Call (DNC) registry. - SMS messages are not sent from 9 PM - 9 AM for users who live in India. ## Supported Country Codes for Voice Messages | | | | | --------------------------------------- | ------------------------------- | -------------------------------- | | United States & Canada  (+1) | Albania  (+355) | American Samoa (+684) | | Andorra  (+376) | Anguilla (+1264) | Antigua and Barbuda (+1268) | | Argentina (+54) | Armenia (+374) | Aruba (+297) | | Australia/Cocos/Christmas Island  (+61) | Austria  (+43) | Bahamas (+1242) | | Bangladesh (+880) | Barbados (+1246) | Belarus  (+375) | | Belgium  (+32) | Belize (+501) | Bermuda (+1441) | | Bolivia (+591) | Bosnia and Herzegovina  (+387) | Brazil  (+55) | | Bulgaria  (+359) | Cayman Islands (+1345) | Chile (+56) | | Colombia (+57) | Costa Rica (+506) | Croatia  (+385) | | Czech Republic  (+420) | Denmark  (+45) | Dominica (+1767) | | Dominican Republic (+1829, 1809, 1849) | Ecuador (+593) | Egypt  (+20) | | Estonia  (+372) | Faroe Islands  (+298) | Fiji (+679) | | Finland/Aland Islands  (+358) | France  (+33) | Germany  (+49) | | Gibraltar  (+350) | Greece  (+30) | Greenland (+299) | | Grenada (+1473) | Guam (+1671) | Guatemala (+502) | | Haiti (+509) | Hong Kong  (+852) | Hungary  (+36) | | Iceland  (+354) | India  (+91) | Indonesia (+62) | | Ireland  (+353) | Israel  (+972) | Italy  (+39) | | Japan  (+81) | Jamaica (+1876) | Jordan (+962) | | Kenya (+254) | Korea Republic of (+82) | Kosovo (+383) | | Latvia  (+371) | Liechtenstein  (+423) | Lithuania  (+370) | | Luxembourg  (+352) | Macedonia  (+389) | Malaysia (+60) | | Malta  (+356) | Mexico  (+52) | Moldova  (+373) | | Monaco (+377) | Montserrat (+1664) | Netherlands  (+31) | | Netherlands Antilles (+599) | New Zealand  (+64) | Nigeria (+234) | | Northern Mariana Islands (+1670) | Norway  (+47) | Panama (+507) | | Philippines (+63) | Poland  (+48) | Portugal  (+351) | | Puerto Rico  (+1787, +1939) | Romania  (+40) | Russia/Kazakhstan (+7) | | San Marino  (+378) | Saudi Arabia  (+966) | Serbia  (+381) | | Singapore  (+65) | Slovakia  (+421) | Slovenia  (+386) | | South Africa  (+27) | Spain  (+34) | St. Kitts and Nevis (+1869) | | St. Lucia (+1758) | St. Vincent Grenadines (+1784) | Sweden  (+46) | | Switzerland  (+41) | Taiwan  (+886) | Thailand (+66) | | Trinidad and Tobago (+1868) | Turkey (+90) | Turks and Caicos Islands (+1649) | | Ukraine  (+380) | United Kingdom  (+44) | Vatican City  (+379) | | Vietnam  (+84) | Virgin Islands, British (+1284) | Virgin Islands, U.S. (+1340) | ## Supported Country Codes for Text Messages | | | | | --------------------------------- | ----------------------------------------- | --------------------------------------- | | United States & Canada  (+1) | Argentina  (+54) | Australia/Cocos/Christmas Island  (+61) | | Austria  (+43) | Azerbaijan (+994) | Bahamas  (+1242) | | Bahrain (+973) | Belarus (+375) | Belgium (+32) | | Bermuda  (+1441) | Botswana (+267) | Brazil  (+55) | | Brunei (+673) | Bulgaria  (+359) | Cayman Islands  (+1345) | | Chile  (+56) | China  (+86) | Colombia (+57) | | Costa Rica  (+506) | Croatia  (+385) | Czech Republic  (+420) | | Denmark  (+45) | Egypt  (+20) | Finland/Aland Islands  (+358) | | France  (+33) | Georgia (+995) | Germany  (+49) | | Ghana (+233) | Greece  (+30) | Guam  (+1671) | | Guatemala  (+502) | Guernsey/Jersey (+44) | Hong Kong  (+852) | | Hungary  (+36) | Iceland  (+354) | India  (+91) | | Iran (+98) | Ireland  (+353) | Isle of Man (+44) | | Israel  (+972) | Italy  (+39) | Jamaica  (+1876) | | Japan  (+81) | Jordan (+962) | Kenya (+254) | | Korea Republic of (+82) | Kosovo (+383) | Latvia (+371) | | Lebanon (+961) | Lithuania (+370) | Luxembourg (+352) | | Malta (+356) | Malawi (+265) | Malaysia  (+60) | | Mauritius (+230) | Mexico  (+52) | Morocco/Western Sahara (+212) | | Mozambique (+258) | Namibia (+264) | Nepal (+977) | | Netherlands  (+31) | New Zealand  (+64) | Norway  (+47) | | Pakistan (+92) | Peru  (+51) | Philippines (+63) | | Poland  (+48) | Portugal  (+351) | Puerto Rico  (+1787) | | Qatar (+974) | Republic of North Macedonia (+389) | Romania (+40) | | Russia/Kazakhstan  (+7) | Saudi Arabia  (+966) | Serbia (+381) | | Singapore  (+65) | Slovakia (+421) | Slovenia (+386) | | South Africa  (+27) | Spain  (+34) | Swaziland (+268) | | Sweden  (+46) | Switzerland  (+41) | Taiwan (+886) | | Thailand  (+66) | Turkish Republic of Northern Cyprus (+90) | Turkiye  (+90) | | Turks and Caicos Islands  (+1649) | Uganda (+256) | Ukraine (+380) | | United Arab Emirates (+971) | United Kingdom  (+44) | Virgin Islands, U.S.  (+1340) | | Zambia (+260) | | | # Understanding Dashboards After you've signed in to your account, you'll be taken to the home dashboard. Here, you can see the panels that can help you track your work and access. These panels, called tiles, display information related to you and your work. By default, a small set of tiles are displayed. You can add or remove tiles from your home dashboard to view the information most relevant to you. ## Using Your Home Dashboard You can edit which tiles appear on your home dashboard so that it reflects the things that matter to you. **To add or remove tiles:** 1. From the home dashboard, select the **Edit Current Dashboard** icon in the upper right corner. 1. On the **Available Tiles** tab, select the **+ Add** button beside the tiles you want to add to this dashboard. 1. On the **Current Tiles** tab, select **Remove** to remove a tile from your home dashboard. Your dashboard is saved automatically and updated based on your selections. Note The **Available Widgets** tab will be empty. Widgets are applied by admins to [managed dashboards](#using-managed-dashboards). 1. On your home dashboard, drag and drop the tiles on this page to reorder them. Your administrator might make changes to your default home page, overwriting any customizations you've made. You can edit your home page again and save your changes to reapply your configurations. If you're also an administrator, you can see additional tiles and widgets based on the features you use in your tenant. Refer to [Audit Reports and Monitoring](https://documentation.sailpoint.com/saas/help/common/audit-reports.html#reporting-overview) for details about the other information you might see on the home dashboard. ## Using Managed Dashboards In some cases, your administrator might assign additional dashboards to you based on your access. These *managed dashboards* contain widgets that provide detailed information about specific types of activity in your system. Note Managed dashboards can't be edited or reordered. **To view a managed dashboard:** 1. Select the dropdown list beside **Current Dashboard** on the home dashboard. 1. Select the dashboard you want to view. The managed dashboard and its associated widgets are displayed. To change the default dashboard, open the **Current Dashboard** dropdown list and select the **Mark as favorite** icon to set which dashboard is displayed when you sign in or refresh the page. Only one dashboard can be marked as your favorite. You can also: - Select the **Menu** icon beside the graph on a widget to view additional options for the data in the widget. For example, you can export the chart as a .csv file, download it as a .png file, or view it in full screen. - Select the label beside a legend to hide or show data in a pie chart. Now that we have you set up, let's get you [the access](https://documentation.sailpoint.com/saas/user-help/requests/request_center.html) you need. # Accessing SailPoint Human Fabric Use SailPoint Human Fabric to get access to the applications and tools you need. Depending on your role, you may also review access requests and certifications for other users to ensure everyone has what they need to succeed. To get started, you’ll first need to access your SailPoint Human Fabric tenant. If you received an email invitation from your administrator, you must [register with SailPoint Human Fabric](#registering-for-identity-security-cloud) before you can use the product. If you did not receive an email invitation, you may immediately be able to access your tenant through your organization’s SSO or by using pass-through authentication. Contact your administrator if you’re unsure about your registration process or how to access your tenant. ## Registering for SailPoint Human Fabric 1. Open the email invitation. 1. Select **Register Now**. 1. Enter your password twice, making sure to meet all the password requirements. 1. Select **Change Password** to log into SailPoint Human Fabric. 1. You will be prompted to enter additional information required for a password reset. 1. Select **Learn More** to be redirected to the preferences page to enter the required additional information. 1. Enter your contact information and provide answers for the security questions. If you do not provide this information, you will receive a warning on future logins. 1. Select **Save**. After you've signed in to your account, you can start [requesting access](https://documentation.sailpoint.com/saas/user-help/requests/request_center.html) to applications and roles and [reviewing certifications](https://documentation.sailpoint.com/saas/user-help/certs/reviewing/index.html). # Supported Browsers and Operating Systems Before you get too far, let's make sure your browser and operating system (OS) meet the following requirements. ## Desktop Browsers and Operating Systems | Browser | OS | Support policy | | ------- | ------------- | -------------------------- | | Chrome | Windows/MacOS | Most recent stable version | | Firefox | Windows/MacOS | Most recent stable version | | Edge | Windows/MacOS | Most recent stable version | | Safari | MacOS | Most recent stable version | Check out to see whether you're using the latest version of your browser. ## Mobile Browsers and Operating Systems Mobile browsers are supported on their native OS. | Browser | OS | Support policy | | ------------- | ------- | ----------------------------------------------------------------------- | | Mobile Chrome | Android | Most recent stable version of Android and previous major three releases | | Mobile Safari | iOS | Most recent stable version of iOS | Note the following about mobile devices: - **Phones** - Some end-user capabilities are supported on phones. For example, users can complete access requests and manage non-employee accounts. Admin capabilities are not supported on phones. - **Tablets** - Most end-user and admin capabilities are supported on tablets. # Supported Languages SailPoint Human Fabric supports more than 20 languages, with American English being the default. The language in the user interface and strong authentication codes delivered by voice and SMS is based on your browser's language settings. Note Territory language distinctions in locales are not recognized. For example, if you specify the locale as 'en-US' or 'en-GB', your system will behave as if the locale is 'en'. **The only exception is Chinese. Simplified Chinese will always default to 'zh-CN', and traditional Chinese will always default to 'zh-TW'.** The following languages are supported: | Language | Locale | | --------------------- | ------- | | Chinese (Simplified) | 'zh-CN' | | Chinese (Traditional) | 'zh-TW' | | Czech | 'cs' | | Danish | 'da' | | Dutch | 'nl' | | English | 'en' | | Finnish | 'fi' | | French | 'fr' | | German | 'de' | | Hungarian | 'hu' | | Italian | 'it' | | Japanese | 'ja' | | Korean | 'ko' | | Lithuanian | 'lt' | | Norwegian | 'no' | | Polish | 'pl' | | Portuguese (Brazil) | 'pt' | | Russian | 'ru' | | Spanish | 'es' | | Swedish | 'sv' | | Thai | 'th' | | Turkish | 'tr' | # Requesting Machine Accounts Depending on your tenant’s configuration, you may request machine accounts on a specific source. You may need to request an entitlement that allows you to request machine accounts on a specific source. In the Request Center, locate the entitlement Machine Account Creation - [source name]/[subtype name]. The entitlement that grants access to request new machine accounts may be included in a role or access profile. Once this entitlement is granted, you can submit requests to create machine accounts for entitlements that you have access to. 1. Start creating a new machine account from one of three places: - From the navigation menu, select the **Create** icon , then **Machine Account**. - From the dashboard, select the **My Ownership** tile, then **Machine Accounts > Create Machine Account**. - Admins can go to **Admin > Identity Management > Accounts > Machine Accounts** and select **Create Machine Account**. 1. In the **Details** section, complete the following: - Select the source that the machine account will reside on. If the source is not listed, contact your administrator for assistance. - Select the subtype for the machine account. Subtypes are defined by org admins for sources on your tenant. They may indicate the type of account and what it’s used for. - Choose an account owner. - Optionally, you can add a description. - Select **Continue**. 1. The next section includes the fields that have been configured for your tenant, which may include business justification, account name, region, and expiration date. 1. Select **Continue**. 1. (Optional) In the Entitlements tab, select **Add Entitlements** to add one or more entitlements on the source that will be assigned to the new account. - Locate entitlements by searching or scrolling. Arrows are available at the lower right to change pages. - Select the checkbox for all entitlements that you want to add, up to a maximum of 20. - Select **Add Entitlements**. Note If you want to remove entitlements, select **Add Entitlements** to return to the entitlements selection page, then deselect the appropriate checkbox(es). Select **Add Entitlements** again to return to the entitlements page on the Create Machine Account interaction. 1. Select **Create Account**. If no approval is required for account creation, the account will be created. If approval is required, the request is submitted to an approver. The machine account will go through the approval process defined by your administrators and you’ll receive notifications as approvers review your request. If entitlements were assigned to the account, these access items will also go through the approval process defined at their entitlement level after the account is approved. If an approver denies an entitlement, the account will still be created without that entitlement. You can review the status of your account requests by going to **Request Center > My Requests > Account Requests**. Locate a request and select **Details**. From there, you can select the tabs to review progress through the approval process, details about the request, the form associated with the request, and entitlements. Once an account request is approved and successfully provisioned, you can also track any entitlements that were selected on the Access Requests page. Refer to [Tracking Requests](https://documentation.sailpoint.com/saas/user-help/requests/tracking_access.html). # Ownership In your role, you may become responsible for machine accounts and identities. You can view and manage these items through the **My Ownership** tile. Note If the **My Ownership** tile is not automatically included on your Home dashboard, you can [add](https://documentation.sailpoint.com/saas/user-help/getting_started/dashboard.html#using-your-home-dashboard) the tile. ## Viewing Your Machine Accounts and Identities You can review the machine accounts and identities you are responsible for by selecting the **My Ownership** tile on your dashboard. 1. On your dashboard, select the **My Ownership** tile. 1. On the My Ownership page, select the tile for the type of machine account or identity you want to view. The items you’re responsible for will be displayed. You can complete the following actions for items you own: - [Update a machine account](https://documentation.sailpoint.com/saas/help/machine/accounts.html#updating-machine-accounts) and its attributes. - [Update an application identity](https://documentation.sailpoint.com/saas/help/machine/identity.html#updating-application-identities). - [Update an AI agent](https://documentation.sailpoint.com/saas/help/agent/agent_mgmt.html#updating-ai-agents). - Copy or [reveal the password](#revealing-passwords-for-machine-accounts) of a machine account. ### Revealing Passwords for Machine Accounts As an account owner, you can copy and reveal the system-generated passwords for machine accounts that were created through account requests. 1. On your dashboard, select the **My Ownership** tile. 1. On the My Ownership page, select the **Machine Accounts** tile. 1. Find the machine account and select **Actions** **> Reveal Password**. Tip You can also view the password for a machine account by selecting **Actions > Reveal Password** on the account’s details page. 1. In the **Reveal Password** window, select **Copy** to copy the password or select **Reveal** to reveal the masked password. 1. Select **Close** to close the window. # Access Requests Overview You can submit access requests to get access to the entitlements, roles, and access profiles you need to perform your job. Requests can be submitted in the [Request Center](https://documentation.sailpoint.com/saas/user-help/requests/request_center.html) or, depending on licensing and enablement, through [Harbor Pilot](https://documentation.sailpoint.com/saas/user-help/harbor_pilot.html). During the access request process, you may: - [Submit an access request](https://documentation.sailpoint.com/saas/user-help/requests/request_center.html) for yourself. Depending on how your org is configured, you may also submit access requests for other human users and machine identities. If you’re a manager, you can even submit [access removal requests](https://documentation.sailpoint.com/saas/user-help/requests/requesting_access_removal.html). - [Track your request](https://documentation.sailpoint.com/saas/user-help/requests/tracking_access.html) through the approval and provisioning processes. - Wait for a reviewer to approve or reject your request. If you are responsible for reviewing access, you may [review requests](https://documentation.sailpoint.com/saas/user-help/approvals/reviewing_access.html) from other users. After your request has been reviewed, you'll receive an email and in-app notification about the reviewer’s decision. If approved, your access to the application or access item is granted or removed, depending on the type of request. # Working with Access Requests You can use access requests to gain access to entitlements, roles, and access profiles. With an approval process that kicks off automatically, you can quickly access the systems and apps you need to perform your job. Your system may be configured so you can also request access for new teammates, employees, or machine identities. You can request access to the following: - **Roles** - A bundle of access based on your position in your company. For example, if you are an accountant, you can request access to the Accountant role. - **Entitlements** - Access rights, such as group memberships or access permissions, granted to a user. For example, you can request to be added to a specific distribution list or Active Directory group in your organization to receive the access permissions granted to that group. - **Access Profiles** - Depending on your org's configuration, you may be able to submit access requests for access profiles. An *access profile* is a bundle of access entitlements that represent a specific set of access. For example, if you are an engineer and need access to Jira, you may select the Engineering access profile to gain the required entitlements. - **Applications** - A set of access related to a specific application within your company. When you request access for an app, you’ll be asked to select an access profile. Note If the access profiles list is empty, you may not be configured to use access profiles on that app. ## Requesting Access in the Request Center (Legacy) Legacy Instructions below describe the legacy Request Center experience. 1. Select **Request Center** from the navigation menu. 1. Select who you are requesting access for. Note If you only have permission to request for yourself, you do not need to choose who to request access for and will go directly to step 3. Depending on your configured permissions, you may have the following options: - **Request for Myself** - Make an access request for yourself. - **Request for Your Team** - Make an access request on behalf of your direct reports. - **Request for Others** - Make an access request on behalf of someone in your org. Choose the identities who need this access from the **Select Identities** dropdown list. Inactive identities, such as identities who are on leave or who have left your organization, may not appear in this list. After you’ve added all identities, select **Request for These Identities** to continue. - **Request for Machine Identities** - Make an access request on behalf of machine identities in your org. Confirm that you understand the impact of your request, then select which machine identities you are requesting access for. Warning A machine account may be used by more than one machine identity or agent. Your request may change access for identities that are not shown in the request. Confirm that you understand before submitting. 1. On the Request Access Page, select items for your request. Use the left navigation to choose the type of items to view: - **Applications** - Choose an application, then select the access profiles you want to request for that application. - **Access Items** - Select from a combined list of Roles, Entitlements, and Access Profiles, or select one of these subcategories to narrow your search. Note If you are requesting access for a machine identity, you can only select from the entitlements related to sources where the selected machine identity already has one or more accounts. If you are requesting for multiple machine identities, only entitlements from sources where all selected identities hold accounts are listed. - If your organization has the Recommendations service, select **Recommended** from the left panel to view your recommended access items. The Recommended option only displays if you’re requesting access for yourself and there are active recommendations. You can request or ignore a recommendation. Use the search field at the top of the page to search for applications or access items. You can search by any set of characters from the item's name or description. Additionally, on the Access Items page and its sub-pages, you can search by source name or application name. - Entering a source name or partial source name returns all entitlements and access profiles associated with that source. - Entering an application name or partial application name returns all access profiles associated with that application. Select **Details** on a card to view more information. A running count of your selected items appears just below the search field. You can switch between viewing the full list of options and reviewing just those you have selected using the **View** toggle. If you want to adjust the list of identities you are requesting access for, select the **Pencil** icon in the header, then add or remove people. 1. If you are using the Recommendations page, choose your options and then select **Request**. If you would like to dismiss any recommendations, select **Ignore**. Add comments as required and select **Submit** to submit each request. 1. If you are using the Applications or Access Items pages, use the **Select** button to add any item to your request. - If you request access to an application, select the appropriate access profiles on the access items panel, then select **Save Selections**. - If the request requires a comment, add a comment about the request to help reviewers understand why this access is needed. Select **Save** to save your comment. - If the request requires an end date or comment, the Edit Request Details interaction appears. If it is not required but you want to add an end date and time, select **Edit Request Details**. Optionally, you can also add an access start date and time. Select start and end dates and times to the nearest quarter hour. You can select a time zone; the default is your browser's time zone. If required, add comments about your request. Select **Save** to save your selection and close the overlay. Note If a maximum duration has been set for the access item, that constraint will be shown and enforced on Edit Request Details. Any configured max duration requirement is applied for the access end date based on the selected start date and time, if one is set, or the moment of request if there isn't one. - As you select access items, complete any forms that are required for the items in your request. If no forms have been configured for the access items, none will be shown. Note Up to 25 forms may be included in each access request submission. If you are requesting more than 25 access items that require form inputs, you will need to submit additional requests. Note Forms attached to access requests automatically include the start date, end date, and comments fields. - Use the **Review Request** button at the upper right to review your selections. Note You can request access for multiple access objects at once. Entitlements are limited to 25 at a time for up to 10 users, but there is no limit for roles or access profiles. - Use the review page to verify or adjust your request. - Select **Edit Request Details** to add or edit the start and end dates for an access item or any form inputs that you have provided. Tip Once an item has been assigned with a start or end date, you can change those dates by submitting another access request with different dates. The new request, once approved, will supersede the prior assignment. You can also edit dates on the My Team page or My Access page to initiate a date change request. - Select **Submit Request**. End dates and deprovisioning End dates include a time component. SailPoint Human Fabric automatically starts the deprovisioning process at the end date and time specified. If SailPoint Human Fabric is directly connected to the source system, the access is automatically deprovisioned. The end date is not sent to the source system as an account attribute. If SailPoint Human Fabric is not connected to the source system, a manual task to remove this access is created and assigned to the source owner. 1. Once you submit a request, the confirmation page includes the **Submit another request** button that returns you to the Request Access page. From there, you can submit another request for the same audience or review your request. - You can adjust the list of people you are requesting for using the **Pencil** icon . - On the Request Access page, view your submitted requests by selecting **My Requests** from the left navigation. The system validates the access request and sends the requester an email and in-app notification identifying which requests were successfully and unsuccessfully submitted. For example, if you request access for an access item you've already been assigned, that specific request *will not proceed forward*. If requests for other items in that access request were successfully submitted, those requests *will move forward*. If your request does not require approval and does not have a future start date, you may receive access immediately. This may take longer if the access must be manually provisioned. If your request requires approval, the request is sent to a reviewer or multiple reviewers. Each reviewer must approve your request before you are granted access. Your administrator may configure your org to reassign your request to another reviewer if the assigned reviewer does not review it by a set time. Items in a request are individually provisioned as they are approved. You will receive an email and in-app notification when your request is approved or denied. If your request is denied, you can contact the reviewer who denied the request for more information. Note By default, requests that have not been fully approved after 90 days will be automatically denied and expired. ## Requesting Access Using Harbor Pilot If Harbor Pilot has been enabled by an administrator, you can select the **Harbor Pilot** icon and enter a natural language request for help submitting access requests. Refer to [Using SailPoint Harbor Pilot](https://documentation.sailpoint.com/saas/user-help/harbor_pilot.html) for more information. ## Canceling a Pending Request You can cancel a pending access request before it has finished approval. Important Items with the same access request ID will always be canceled together, meaning that when you cancel one item from the request, they will all be canceled. But in most cases, even when requested items are submitted together, they are still processed as separate requests and assigned separate access request IDs. For items with separate access request IDs, canceling one item from a request will not affect other items requested with it. 1. Go to **Request Center > Review > My Requests** and locate the pending request that you want to cancel. 1. Select **Cancel**. 1. Enter comments about why you are canceling the request. 1. Select **Submit**. A success message confirms that the request has been canceled and the request card status updates to Canceled. An email and in-app notification confirming the cancellation is sent to the recipient and the requester. # Requesting Access in the Request Center (Limited Availability) Limited Availability Instructions below describe the Limited Availability release of Request Center available to select customers who opt in. If your organization has not opted in, refer to the [legacy documentation](https://documentation.sailpoint.com/saas/user-help/requests/request_center.html#requesting-access-in-the-request-center-legacy). To request access in the Request Center: 1. Select **Request Center** from the navigation menu. 1. Under **Request Access**, select who you are requesting access for. Note If you only have permission to request for yourself, you do not need to choose who to request access for and will go directly to step 3. Depending on your configured permissions, you may have the following options: - **For Self** - Make an access request for yourself. - **For Others** - Make an access request on behalf of someone in your org. Scroll, search, or filter based on manager and other public identity attributes to find the identities who need this access and use **Select** to add them to your request. When searching, you can use a comma-separated identity list to find multiple identities in a single query. Inactive identities, such as identities who are on leave or who have left your organization, may not appear in this your filtered list or search results. After you’ve added all identities, select **Continue**. - **For Machine Identities** - Make an access request on behalf of machine identities in your org. Confirm that you understand the impact of your request, then scroll, search, or filter to find the machine identities that need access and use **Select** to add them to your request. Warning A machine account may be used by more than one machine identity or agent. Your request may change access for identities that are not shown in the request. Confirm that you understand before submitting. 1. On the **Find Access** page, find the items you want to request. Use the keyword search and the **Access Type** dropdown to choose the type of items to view: - **Applications** - Choose an application, then select the access profiles you want to request for that application. - **Access Profiles** - Select from a list of access profiles. - **Entitlements** - Select from a list of entitlements. - **Roles** - Select from a list of roles. Note If you are requesting access for a machine identity, you can only select from the entitlements from sources where the selected machine identity already has one or more accounts. If you are requesting for multiple machine identities, only entitlements from sources where all selected identities have accounts are listed. Access items may have the following indicators: - **Recommended** - If your organization has the Recommendations service, an icon on the upper right side of a card indicates recommended access items. The **Recommended** icon only displays if you’re requesting access for yourself and there are active recommendations. You can request those items or ignore the recommendations. To view all available recommendations, select the **Recommended** tab below the search bar. - **Privileged Access** - Depending on your configuration, access items that are designated as privileged may have a **Privileged Access** tag on their cards, which may also indicate the privilege level. Use the search field at the top of the page to search for applications or access items. You can search by any set of characters from the item's name, description, source, application, owner, privilege, metadata, or keywords related to roles in a bundled entitlement. To search for a phrase, rather searching by individual words, add quotation marks around it. Search results are sorted alphabetically. - Entering a source name or partial source name returns all entitlements and access profiles associated with that source. - Entering an application name or partial application name returns all access profiles associated with that application. Select the **Information** icon on a card to view details about the access item. A running count of your selected items appears at the top right side of the page. You can switch between viewing the full list of options and reviewing just those you have selected using by toggling between **All** and **Selected**. If you want to adjust the list of identities you're requesting access for, select the **back arrow** next to the page name, then add or remove people. 1. Use the **Select** button to add any item to your request. - If you request access to an application, select the appropriate access profiles on the access items panel, then select **Save Selections**. - If the request requires a comment, add a comment about the request to help reviewers understand why this access is needed. Select **Save** to save your comment. - If the request requires an end date or comment, the Edit Request Details interaction appears. If it is not required but you want to add an access start or end date and time, select the **Edit** icon . Select start and end dates and times to the nearest quarter hour. You can select a time zone; the default is your browser's time zone. If required, add comments about your request. Select **Save** to save your selection and close the modal. Note If a maximum duration has been set for the access item, that constraint will be shown and enforced on **Edit Request Details**. Any configured maximum duration requirement is applied for the access end date based on the selected start date and time, if one is set, or the moment of request if there isn't one. - As you select access items, complete any forms that are required for the items in your request. If no forms have been configured for the access items, none will be shown. Notes - Up to 25 forms may be included in each access request submission. If you are requesting more than 25 access items that require form inputs, you will need to submit additional requests. - Forms attached to access requests automatically include the start date, end date, and comments fields. 1. Select **Continue**. 1. On the Review page, review your selections and verify or adjust your request. Note You can request access for multiple access objects at once. Entitlements are limited to 25 at a time for up to 10 users, but there is no limit for roles or access profiles. - Select the **Edit** icon to add or edit the start and end dates for an access item or any form inputs that you have provided. Tip Once an item has been assigned with a start or end date, you can change those dates by submitting another access request with different dates. The new request, once approved, will supersede the prior assignment. You can also edit dates on the **Request Center > Review > My Team** page or **My Access** page to initiate a date change request. - To remove an identity or access item from a request, select the **Delete** icon . To add an identity or access item, use the **back arrow** next to the page name to return to a previous page and make additional selections. 1. Select **Submit Request**. End dates and deprovisioning End dates include a time component. Identity Security Cloud automatically starts the deprovisioning process at the end date and time specified. If Identity Security Cloud is directly connected to the source system, the access is automatically deprovisioned. The end date is not sent to the source system as an account attribute. If Identity Security Cloud is not connected to the source system, a manual task to remove this access is created and assigned to the source owner. 1. Once you submit a request, the confirmation page includes the option to **View Requests** or **Start Another Request**. - **View Requests** takes you to the Access Requests page, where you can review the status and details of your requests. - **Start Another Request** lets you choose whether to submit another request yourself, for others, or for machine identities. The system validates the access request and sends the requester an email and in-app notification identifying which requests were successfully and unsuccessfully submitted. For example, if you request access for an access item you've already been assigned, that specific request *will not proceed forward*. If requests for other items in that access request were successfully submitted, those requests *will move forward*. If your request does not require approval and does not have a future start date, you may receive access immediately. This may take longer if the access must be manually provisioned. If your request requires approval, the request is sent to a reviewer or multiple reviewers. Each reviewer must approve your request before you are granted access. Your administrator may configure your org to reassign your request to another reviewer if the assigned reviewer does not review it by a set time. Items in a request are individually provisioned as they are approved. You will receive an email and in-app notification when your request is approved or denied. If your request is denied, you can contact the reviewer who denied the request for more information. Note By default, requests that have not been fully approved after 90 days will be automatically denied and expired. ## Canceling a Pending Request You can cancel a pending access request before it has finished approval. Important Items with the same access request ID will always be canceled together, meaning that when you cancel one item from the request, they will all be canceled. But in most cases, even when requested items are submitted together, they are still processed as separate requests and assigned separate access request IDs. For items with separate access request IDs, canceling one item from a request will not affect other items requested with it. 1. Go to **Request Center > Review > My Requests** and locate the pending request that you want to cancel. 1. Select **Cancel**. 1. Enter comments about why you are canceling the request. 1. Select **Submit**. A success message confirms that the request has been canceled and the request card status updates to Canceled. An email and in-app notification confirming the cancellation is sent to the recipient and the requester. # Requesting Access Removal You can submit revocation requests for your own access to entitlements, roles, and access profiles from the **Request Center > Review > My Access** page. Managers can request the revocation of a team member’s access to entitlements, roles, and access profiles from the **Request Center > Review > My Team** page. For example, your team member may be switching to a different team or project and no longer requires that access. If you have the [Access Revoker](https://documentation.sailpoint.com/saas/help/common/users/user_levels.html#access-revoker-user-level) user level, you can submit a revocation request for any user to remove [entitlements](https://documentation.sailpoint.com/saas/help/access/entitlements.html#revoking-entitlements), [roles](https://documentation.sailpoint.com/saas/help/access/roles.html#revoking-requested-roles), and [access profiles](https://documentation.sailpoint.com/saas/help/access/access-profiles.html#revoking-access-profiles). Notes You cannot submit access revocation requests for the following: - Roles granted by membership criteria - Access profiles granted through role membership If removed, these roles and access profiles are automatically reassigned upon nightly refresh. Refer to [Automating Role Assignment](https://documentation.sailpoint.com/saas/help/provisioning/role_assignment.html) for more information. ## Requesting Role or Entitlement Revocation Roles and entitlements may be revoked if they are granted by an access request. Those granted by criteria assignment may not be revoked. 1. From the top navigation, select **Request Center > Review > My Access** to revoke your own access or **Request Center > Review > My Team** to revoke access from a team member. 1. If you selected My Team, select an identity from the list of your team members. 1. On the identity details page, select the **Roles** or **Entitlements** tab, depending on what you want to request to have revoked. 1. Select the name of the role or entitlement that you want to request revocation of. 1. On the left navigation, select an **Assignment** to review its details, including which accounts it was assigned to. 1. If a role assignment was granted by a request, it is revocable. If an entitlement is not granted through a role, it is revocable. Select **Revoke Assignment**. 1. Enter a comment explaining why this access should be removed. Removal requests require comments. 1. Select **Submit Request**. If the request doesn't require approval, the identity’s access removal will be triggered. If the request requires approval, the request will be sent to a reviewer. You’ll receive an email and in-app notification when they have approved or denied your request. ### Adding or Editing a Role or Entitlement Start and End Dates If a role or entitlement is configured to allow start and end dates, you can submit a request to add or change a user's access dates. 1. From the top navigation, select **Request Center > Review > My Access** to change your own access dates or **Request Center > Review > My Team** to change access dates for a team member. 1. If you selected My Team, select an identity from the list of your team members. 1. Select the Entitlements or Roles tab. 1. Select an access item. 1. Select an assignment from the left navigation. 1. On the **Assignment Details** page, locate the Start Date and End Date fields and select **Add** or **Edit**. 1. Select a new start or end date and time. 1. Add comments if required. 1. Select **Save**. If your tenant is configured to require approval for this type of access request, your request to change the start or end date is shown to approvers as a date modification to be clear about what they are reviewing. ## Requesting Access Profile Revocation Access profiles that are not connected to a role assignment may be revoked. Because access profiles can only be assigned once per identity, the access profile flow is simpler, displaying the item details in an overlay that includes a revoke option if the assignment is revocable. 1. From the top navigation, select **Request Center > Review > My Access** to revoke your own access or **Request Center > Review > My Team** to revoke access from a team member. 1. If you selected My Team, select an identity from the list of your team members. 1. On the identity details page, select the **Access Profiles** tab. 1. Select the name of the access profile you want to request to have revoked. Note Access profiles that are marked as not revocable are included as part of a role assignment. They cannot be revoked because the role's requirements would cause them to be automatically reassigned upon nightly refresh. 1. Select **Revoke Access Profile**. 1. Enter a comment explaining why this access should be removed. Removal requests require comments. 1. Select **Submit** to submit your access removal request. If the request doesn't require approval, the identity’s access removal will be triggered. If the request requires approval, the request will be sent to a reviewer. You’ll receive an email and in-app notification when they have approved or denied your request. ### Adding or Editing an Access Profile Start and End Dates If an access profile is configured to allow start and end dates, you can submit a request to add or change a user's access dates. 1. From the top navigation, select **Request Center > Review > My Access** to change your own access dates or **Request Center > Review > My Team** to change access dates for a team member. 1. If you selected My Team, select an identity from the list of your team members. 1. Select the **Access Profiles** tab. 1. In the Start Date or End Date column, select **Add End Date**, **Add Start Date**, or **Edit**. 1. Select a new start or end date and time. 1. Add comments if required. 1. Select **Save**. If your tenant is configured to require approval for this type of access request, your request to change the start or end date is shown to approvers as a date modification to be clear about what they are reviewing. # Tracking Requests After you request access to an item, you can track your requests from the following locations. ## Dashboard 1. Go to your Dashboard. 1. View the **Pending Requests** tile. Your total number of pending access requests and the date of your last request are displayed here. Select the tile to view additional information about these requests. ## Request Center 1. From the navigation menu, select **Request Center > Review > My Requests**. 1. Select the type of request from the left panel. Your requests and their statuses are displayed. For each request card, you can: - Select **Cancel** to cancel a pending request. - Select the **Comments** icon to review comments on a request. - Hover over the access request ID, then select the **Copy** icon to copy an ID to provide to an admin. You can also select **Details** on a request card to see more details in the Request Status Tracker. Note The Assignment Type field indicates whether this is standing access, which is continuously available until revoked, or Just-In-Time access, which requires the user to activate it before each use. Refer to [Just-In-Time Entitlements](https://documentation.sailpoint.com/saas/user-help/requests/jit_access_provisioning.md#just-in-time-entitlements). ## Request Status Tracker 1. From the navigation menu, select **Request Center > Review > My Requests**. 1. Select the type of request from the left panel. 1. Select **Details** for one of your requests. The Request Status Tracker appears to the right with details about each step in the review process. You can also see any errors that may have occurred during the request process. To cancel a request that is pending approval, select **Cancel Request**.