Request Details

Use this page to recertify the roles, accounts, and groups of a user. When the activity is locked by another user, some fields on this page are disabled or are not displayed.

Request type
Displays the type of the request.
Submission date
Displays the date and time when the request was submitted.
Due date
Displays the date and time by which the activity needs to be completed. An activity that passes this date either forwards to a defined escalation participant if one exists, terminates automatically, or remains available as an overdue activity item.
Requested for
Displays the user for whom the request was submitted. Click the name of the user to view the user's personal profile.
Requested by
Displays the user who submitted the request.
Activity status
Displays the status of the activity.
Instructions
Displays detailed instructions for the activity. To view the instructions, click the twisty icon.
Reviewer Action tables
Use these tables to recertify roles, accounts, and groups (which include access items). The tables contain a list of roles and a list of account and group items associated with the user.
Roles table
Lists the roles.

This table might or might not be displayed, depending on the configuration of the user recertification policy, and whether the user has any roles. The table contains these columns:

Roles
Identifies the name of the role.
Description
Provides additional information about the role.
Still Required
Select whether the user needs one or more roles.

If the user still requires the role, select Yes to recertify the role. If the user no longer requires the role, select No to reject the role.

Select All to recertify all roles.

Select None to reject all roles.

Accounts and Groups table
Lists the accounts and groups. A group that is defined as an access is displayed with the access name and description rather than with the group name and description. Only accounts and groups that require a recertification decision are displayed.
This table might not be displayed, depending on:
  • The configuration of the user recertification policy.
  • The accounts and groups, if any, that are owned by the user.
The table contains these columns:
Accounts and Groups
Identifies the accounts and any groups associated with each account. Accounts are identified using the user ID and the name of the service on which they reside.

Click the collapse all icon to collapse the table and list accounts only. Click the expand all icon to expand the table and list all accounts and the groups associated with each account. You can also expand or collapse by account. These options are displayed only if there are one or more groups associated with an account.

Ownership Type
Displays the ownership type specified for the account. Ownership types are governed by the provisioning policy of the service.
Description
Provides additional information about the account or group.
Still Required
Select whether the user needs one or more accounts and groups.

If the user still requires the account or group, select Yes to recertify the account or group. If the user no longer requires the account or group, select No to reject the account or group. Because of the relationship that exists between accounts and groups, an account recertification selection of No applies to all groups associated with the account.

Select All to recertify all accounts and groups. You can also select All for each account to select the account and all groups associated with the account.

Select None to reject all accounts and groups. You can also select None for each account to reject recertification on the account and all groups associated with the account.

Note: Some accounts might be displayed in the table for information purposes if groups on the accounts require recertification, but the accounts themselves are required by the user and are not subject to recertification. In other words, the account is included on the page, but you cannot act on it.
Preview the impact of your selections
Click to view the impact that your selections have on the roles, accounts, and groups of the user being recertified. Impacted items can include roles, accounts, and groups that are not included in the recertification activity. For example, when you select a role as not required, it might affect accounts and groups owned by the user. It might also affect accounts and groups owned by the user that are not part of the recertification activity.
Comments
Provide additional comments and justification for your actions.

To complete the activity, click Submit.

To save your current selections and return to the Approve and Review Requests page without submitting the activity, click Save as Draft. When you or another user returns to complete the activity, the activity displays the selections that were previously made. However, if the activity passes its due date before the activity is completed, an automatic timeout action treats the activity as if no selections were made.

To return to the list of activities and cancel your action, click Close.