Create an identity profile certification
The identity profile certification template lets you certify identities directly, independent of their access. This template helps you conduct a review of external users, such as business partner users, contractors, and artificial intelligence (AI) agents.
When a certifier finalizes the review and signs off, Identity Governance automatically submits a request to update the user’s record. This request goes through an approval workflow before the changes take effect. By default, Identity Governance assigns the approval task to the certifier and the user’s manager.
The following table lists the areas to configure for each campaign template type:
| Section | Description |
|---|---|
General details of the template, such as the name, description, and a default certifier. |
|
The items to be certified. |
|
The cadence in which the review process is kicks off (campaign). |
|
The end users responsible for certifying the items in the campaign. |
|
(Optional) Set up email notifications based on various events that take place during the certification process. |
|
(Optional) Various configurations to allow during the campaign, such as bulk actions on line items or self-certification. |
|
Summary of configured sections. |
Details
Use these steps to configure the campaign details for the identity profile certification template:
-
In the Advanced Identity Cloud admin console, click Certification > Templates > New Template.
-
Click Identity Profile Certification.
-
Click Next.
-
On the Campaign Details page, complete the following fields:
Field Description Certification Name
Display name for the certification. This certification name displays on both the Certifications tab and the End-User Tasks dashboard.
Define a date variable in the name of the certification to identify which campaign is running. Identity Governance supports the use of moment.js to format the date. For example, if you have a certification that’s scheduled to run every 2 weeks, appending the date to the name lets you know which campaign you’re working on. The certification name can include the date (year, month, day), time (hour, minute), and time of day (AM or PM):
Campaign name: {{YYYY-MM-DD-hh:mma}}When you launch a template into a campaign, an example of the name is:
Campaign name: 2025-12-12-08:18pmAfter the campaign starts, you can’t modify the name.
Description
Enter a general description for the certification. Your organization should follow a convention to describe each certification.
This field is limited to 1000 characters.
Campaign Owner
Enter the owner of the campaign. Only campaign owners can fully control their certifications, including certification decisions, certifier assignment changes, and sign-off.
Enable Campaign Staging
Enable certification staging to create the campaign without making it visible to certifiers. As a compliance officer, you can then review the campaign content, decision items, and other details before activating or deleting the campaign.
-
Click Next.
What to certify
Use these steps to define the scope of the certification by selecting which organizations and users to include:
-
Complete the following fields:
Field Description Organizations
Certify one of the following:
-
All Organizations: Certify every organization.
-
Specific Organizations: Create a filter to certify specific organizations.
Users
Certify one of the following:
-
All users: Certify every user.
-
A single user: Certify a single user.
-
Users matching a filter: Create a filter to certify specific users.
(Optional) Show advanced filters
Filter users based on the outcome of their most recent certification. For example, filter to include only users whose last decision was Certify or Revoke.
-
-
Click Next.
When to certify
Use these steps to specify when to launch the review process (campaign) and what to do in the event the campaign expires.
-
Complete the following fields:
Field Description Schedule
Specify whether this template runs on a recurring schedule. If you want to set a schedule, select Run on a schedule and complete the options below.
Options include:
-
Run Every: Run the certification every specified number of days, weeks, months, or years.
-
Start: Specify a date and start time when this campaign kicks off for the first time.
-
End: Run the certification on its defined periodic basis until the campaign reaches this date and time.
-
Time Zone Offset: Set the time zone offset from GMT for the schedule.
Campaign Duration
Specify the amount of time each access review (campaign) has before expiration. You can specify the duration in days, weeks, months, or years.
-
-
Click Next.
Who will certify
Use these steps to assign certifiers to the campaign. If a user has no assigned certifier, you can configure a default certifier as a fallback:
-
Complete the following fields:
Field Description Certifier Type
Specify who can review and certify users by selecting one of the following:
-
User: Select a single user to review and make a decision on every record. When you select User, the Select user modal opens. Select the user who certifies the campaign.
-
Role: Select a role whose members can review every record. When you select Role, the Select a role modal opens. Select a role from the list of created roles in Advanced Identity Cloud.
-
Manager: The direct manager reviews and certifies each user record.
-
Organization Admin: The organization administrator reviews and certifies each user record.
-
Custom Certifier: A user attribute value determines the certifier. Select the attribute from the list of available user attributes.
Enable default certifiers
Select a default certifier for users in the campaign that have no assigned certifier. For example, if the manager is the certifier type and a user doesn’t have a manager, Identity Governance assigns the specified default certifier to the review for that user.
-
-
Click Next.
Notifications
Use these steps to configure email notifications for campaign events, such as when a campaign is triggered or when a certifier is reassigned.
|
Before selecting a notification, define an email template for each notification type. In the Advanced Identity Cloud admin console, go to Email > Templates. Learn more in Email templates. Identity Governance includes preset email templates for certification campaigns. Use these as a base, copy the template, and customize them to suit your needs. To reference variables in your email templates for Identity Governance, the object is nested an additional level:
|
To complete this section, do the following:
-
Select any notifications you want to enable and configure the following fields:
Field Description Send initial notification
Send a notification to the certifiers when the campaign is triggered. Select an email template.
Send reassign notification
Send a notification to the new reviewers when an item is reassigned or forwarded to them. Select an email template.
Send expiration notification
Send a notification to the certifiers when the certification expires. Configure the following:
-
Email Template: Select the email template to use.
-
Expiration timing: Select when to send the notification.
Send reminders
Send certifiers reminders: Configure the following:
-
Email Template: Select the email template to use.
-
every: Enter the interval and select the time unit (days, weeks, and so on).
-
-
Click Next.
Identity Governance sends notification emails using an email template. If an email fails to send because of API rate limits, Identity Governance resends it.
Additional options
This optional section allows you to configure other options for a campaign, such as performing bulk certifications or reassigning tasks to another user or group.
To complete this section, do the following:
-
Complete the following optional fields:
Field Description Enable line item reassignment and delegation
Allow the certifier to reassign or forward a line item to another user.
When you select this box, you can choose the following options:
-
Forward - Allow certifiers to forward their access review (campaign) to another certifier. When forwarding an access review, other certifiers are removed from the access review in its entirety. Learn more in forward line items.
-
Reassign - Select the privileges the current certifier can assign to the new certifier:
-
Add Comment
-
Make Decision
-
Reassign/Forward
-
Sign off
Learn more in reassign line items.
-
Require justification on revoke
Require a mandatory comment or reason for the revocation.
Require justification on exception
Require a mandatory comment or reason for any allowed exception.
Allow exceptions
Allow certifiers to continue to certify line items assigned to them after the campaign expires. Select a duration in days, months, weeks, or years.
Allow bulk-decisions
Allow certifiers to make line item decisions in bulk.
This includes:
-
Making a decision (certify, revoke, exception).
-
If Enable line item reassignment and delegation is enabled, then you can bulk Reassign or Forward line items.
As an administrator, most access reviews require an in-depth look on each line item. This is to ensure accuracy of each item. Bulk-decisions allow for a certifier to make a decision on many items at once, which could lead to inaccurate data. Use caution when selecting this option. Allow partial sign-off
Allow a certifier to sign-off on an access review before their assigned line items have a decision made on them.
Process remediation
Revokes the end user’s access in the target application when a certifier revokes (denies) the line item. Select a workflow to run either immediately after revocation of access or after a duration.
To ensure end-user access is removed when revoking a line item, you must enable this property. Enable escalation
Enable certification escalation.
Define the behavior when the campaign expires:
-
Close: Select Revoke, Certify, or allow exception to. Open items immediately or after a duration.
-
Reassign: Select Role or User, then select the role or user.
-
Do Nothing: Take no action when the campaign expires.
-
-
Click Next.
Customization
Use these steps to configure the default table columns for the reviewers.
-
Complete the following optional fields:
Field Description User
Select the user attributes to display as columns in the certification review table. For example, select
First NameandEmail Addressto show those columns to certifiers.Review
Add Flags and Comments to include these fields in the access review table.
-
Click Next.
Summary
The Summary section is the final section in creating a template. It gives a breakdown of each section in the template, allowing for a review.
Summary steps:
-
Review each section.
-
Click Save to complete the certification template.
Under the What to Certify review section, ensure that the Total Decision Items is greater than 0. If you identify that this is 0, this means that the template did not identify items to be certified. Therefore, if you create the campaign off of the template, the system will immediately cancel the campaign. If you identify this to be 0, go back to the What to Certify section and adjust your settings.