Role composition certification
The role composition certification lets certifiers review the makeup of roles, including their attributes, entitlements, and membership rules, to ensure each role is correctly defined. Use this procedure to create a role composition certification template and launch the review campaign. This template helps you verify that each role’s definition is accurate before certifiers approve it.
When a certifier rejects a role composition and finalizes the review, Identity Governance automatically submits a modify role request to the certifier or role owner. A modify role request is a workflow task that asks the recipient to update the role’s definition.
|
Before you begin, assign a role owner to each role you plan to certify. Role owners are responsible for the role, including its members and metadata. To assign a role owner:
|
The following table lists the areas to configure for each campaign template type:
| Section | Description |
|---|---|
General details of the template, such as the name, description, and a default certifier. |
|
The items to be certified. |
|
The cadence at which the review process kicks off (campaign). |
|
The end users responsible for certifying the items in the campaign. |
|
(Optional) Set up email notifications based on various events that take place during the certification process. |
|
(Optional) Various configurations to allow during the campaign, such as bulk actions on line items or self-certification. |
|
Summary of configured sections. |
Details
Use these steps to configure the campaign details for the role composition certification template:
-
In the Advanced Identity Cloud admin console, click Certification > Templates > New Template.
-
Click Role Composition Certification.
-
Click Next.
-
On the Campaign Details page, complete the following fields:
Field Description Certification Name
Display name for the certification, shown on the Certifications tab and the End-User Tasks dashboard.
For recurring templates, avoid static names that produce identical campaign titles across review periods. Instead, include dynamic date/time variables wrapped in double curly braces ({{…}}) so each campaign and report has a unique, time-stamped name. Advanced Identity Cloud formats these placeholders at launch using standard, case-sensitive Moment.js tokens.
You can use placeholders anywhere in a certification name:
Template Name Input Resulting Campaign Name at Launch Description Role Review - {{YYYY-MM-DD}}Role Review - 2026-10-15ISO date format
Role Review {{MMMM YYYY}}Role Review October 2026Full month and year
Role Review {{Q}} {{YYYY}}Role Review Q4 2026Quarter and year
Bi-weekly Role Review ({{YYYY-MM-DD-hh:mma}})Bi-weekly Role Review (2026-10-15-08:30am)Date, 12-hr time with minutes, and AM/PM indicator
After the campaign starts, you can’t modify the name.
Description
Optional. Enter a description for the certification up to 1,000 characters. This text is visible to certifiers during the review.
Best practice: Establish an internal description convention that outlines the compliance purpose, the scope of roles being evaluated, reviewer instructions (such as criteria for approving or revoking access), and an internal tracking or ticket reference.
Example: "Quarterly SOX audit for Finance admin roles. Reviewers must verify that assigned entitlements match current job responsibilities. Revoke access if the user has changed roles. Ticket: IAM-2026-Q4."
Campaign Owner
Enter the owner of the campaign. Only campaign owners can fully control their certifications, including certification decisions, certifier assignment changes, and sign-off.
Enable Campaign Staging
Enable certification staging to create the campaign without making it visible to certifiers. As a compliance officer, you can then review the campaign content, decision items, and other details before activating or deleting the campaign.
-
Click Next.
What to certify
Use these steps to choose the roles and access details that this certification reviews:
-
Complete the following field:
Field Description Roles
Certify one of the following:
-
All roles: Certify every role.
-
Roles matching a filter: Create a filter to certify specific roles.
If you create a governance glossary attribute and enhance roles with the attribute, you can filter on that attribute. Learn more in Manage governance glossary.
-
-
(Optional) Click Show advanced filters, then complete the following field:
Field Description Filter by last certification decision
Filter roles based on the outcome and metadata of their most recent certification review.
Define one or more conditions based on decision properties, such as:
-
Campaign ID: The identifier of the previous review campaign.
-
Decision: The action taken during the last review, such as
certifiedorrevoked. -
Completion date: When the previous review was finalized.
-
-
Click Next.
When to Certify
Use these steps to specify when to launch the review process (campaign) and what to do in the event the campaign expires.
To complete this section, do the following:
-
Complete the following fields:
Field Description Schedule
Define whether the template launches on a periodic basis. If selected, input various choices to define the schedule.
Select the Run on a schedule checkbox to define a schedule for the template.
Options include:
-
Run Every: Run the certification every specified number of days, weeks, months, or years.
-
Start: Specify a date and start time when this campaign kicks off for the first time.
-
End: Run the certification on its defined periodic basis until this date and time is reached.
Campaign Duration
Specify the amount of time each access review (campaign) has before it expires. You can specify the duration in days, weeks, months, or years.
-
-
Click Next.
Who will certify
Use these steps to specify who reviews and makes decisions on each role in the campaign:
-
Complete the following fields:
Field Description Certifier Type
Specify who can review and certify roles by selecting one of the following:
-
User: Select a single user to review and make a decision on every record. When you select User, the Select user modal opens. Select the user who will certify the campaign.
-
Role: Select a role whose members can review every record. When you select Role, the Select a role modal opens. Select a role from the list of created roles in Advanced Identity Cloud.
-
Role Owner: The individual who manages the role. Learn more in assign a role owner.
Enable default certifiers
Select a default certifier for roles in the campaign that have no assigned certifier. For example, if the role owner is the certifier type, and a role doesn’t have a role owner, Identity Governance assigns the specified default certifier to the access review for that role.
-
-
Click Next.
Notifications
Use these steps to configure email notifications for campaign events, such as when a campaign is triggered or when a certifier is reassigned:
|
Before selecting a notification, define an email template for each notification type (Email > Templates). Identity Governance includes preset templates for certification campaigns that you can copy and customize. Unlike standard platform email templates where user attributes sit directly under an object (such as {{object.mail}}}}), Identity Governance emails contain multiple entities. You must prefix attributes with the specific entity name:
|
To complete this section, do the following:
-
Select any notifications you want to enable and configure the following fields:
Field Description Send initial notification
Send a notification to the certifiers when the campaign is triggered. Select an email template.
Send reassign notification
Send a notification to the new reviewers when an item is reassigned or forwarded to them. Select an email template.
Send expiration notification
Send a notification to the certifiers when the certification expires. Configure the following:
-
Email Template: Select the email template to use.
-
Expiration timing: Select when to send the notification.
Send reminders
Send certifiers reminders: Configure the following:
-
Email Template: Select the email template to use.
-
every: Enter the interval and select the time unit (days, weeks, and so on).
-
-
Click Next.
If a burst of campaign notifications temporarily triggers API rate limits, Identity Governance queues the emails and automatically retries delivery until all messages are sent. You don’t need to resend them manually.
Additional options
Use these steps to configure other options for a campaign, such as performing bulk certifications or reassigning tasks to another user or group:
-
Complete the following optional fields:
Field Description Enable line item reassignment and delegation
Allow the certifier to reassign or forward a line item to another user.
When you select this box, you can choose the following options:
-
Forward: Allow certifiers to forward their access review (campaign) to another certifier. When forwarding an access review, other certifiers are removed from the access review in its entirety. Learn more in forward line items.
-
Reassign: Select the privileges the current certifier can assign to the new certifier:
-
Add Comment
-
Make Decision
-
Reassign/Forward
-
Sign off
-
Learn more in reassign line items.
Require justification on revoke
Require a mandatory comment or reason for the revocation.
Require justification on exception
Require a mandatory comment or reason for any allowed exception.
Allow exceptions
Allow certifiers to continue to certify line items assigned to them after the campaign expires. Select a duration in days, months, weeks, or years.
Allow bulk-decisions
Allow certifiers to make line item decisions in bulk.
This includes:
-
Making a decision (certify, revoke, exception).
-
If Enable line item reassignment and delegation is enabled, then you can bulk Reassign or Forward line items.
As an administrator, most access reviews require an in-depth look of each line item. This is to ensure accuracy of each item. Allow partial sign-off
Allow a certifier to sign-off on an access review before their assigned line items have a decision made on them.
Process remediation
Revokes the end user’s access in the target application when a certifier revokes (denies) the line item. Select a workflow to run either immediately after revocation of access or after a duration.
Enable escalation
Enable certification escalation.
Define the behavior when the campaign expires:
-
Close: Select Revoke, Certify, or allow exception to. Open items immediately or after a duration.
-
Reassign: Select Role or User, then select the role or user.
-
Do Nothing: Take no action when the campaign expires.
-
-
Click Next.
Customization
Use these steps to configure the review grid displayed to certifiers. Selecting default columns, such as display names, descriptions, risk flags, and reviewer comments, ensures that certifiers have the necessary business context to evaluate role definitions without having to inspect each item individually.
-
Complete the following optional fields:
Field Description Application
Select a value for
application, such asDescriptionandName.Entitlement
Select a value for
entitlement, such asDescriptionandDisplay Name.Review
Enter
FlagsandCommentsto add fields to the access review table. -
Click Next.
Summary
Use these steps to review what you configured:
|
In the What to Certify review section, ensure that the Total Decision Items is greater than 0. If Total Decision Items is 0, the template didn’t identify items to be certified, so if you create the campaign off of the template, the system immediately cancels the campaign. If Total Decision Items is 0, go back to the What to Certify section and adjust your settings. |
Summary steps:
-
Review each section.
-
Click Save to complete the certification template.