Identity Governance reports
Advanced Identity Cloud provides new, pre-built reports for the Identity Governance service. You can’t directly edit these reports.
|
Advanced Identity Cloud add-on capability
Contact your Ping Identity representative to add PingOne® Identity Governance to your Advanced Identity Cloud subscription. |
Available reports
If you use Identity Governance, you have access to the following reports. These reports help you understand and manage your identity governance data:
-
Account certification: Details account certification decisions during a campaign.
-
All campaign summary: Summarizes all certification campaigns, providing an overview of their status and results.
-
All requests: Lists all access requests, showing their current status and details.
-
Application accounts: Details accounts associated with each application, helping you track user access.
-
Application entitlements: Shows entitlements granted within a specific application.
-
Entitlement assignment certification: Provides certification data for assigned entitlements.
-
Entitlement grants: Displays all grants for specific entitlements.
-
Entitlements with inactive owners: Identifies entitlements where the assigned owner is inactive.
-
Entitlements with no owners: Highlights entitlements that currently lack an assigned owner.
-
Identity certification accounts: Presents certification details for user accounts.
-
Identity certification entitlements: Presents certification details for identity entitlements.
-
Identity certification role memberships: Shows certification information for user role memberships.
-
Orphan accounts: Lists accounts that don’t have an associated identity.
-
Request tasks: Details individual tasks related to access requests.
-
Role entitlement details: Provides comprehensive information about each role.
-
Role membership certification: Offers certification data for role memberships.
-
Role membership with decision details: Generates a report on all role memberships.
-
Roles with no or inactive managers: Identifies roles that currently lack an assigned owner.
-
Users with no or inactive managers: Lists users who don’t have an active manager.
Account certification
The "Account certification" report provides a detailed list of decisions made for user accounts during a specific certification campaign. This report helps administrators and compliance managers verify that account access is regularly reviewed and that all decisions are documented for compliance.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Account certification.
-
In the Run Report tab, enter the Campaign ID.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the certification campaign. |
|
Name of the application where the account exists. |
|
Display name of the account being reviewed. |
|
Type of account (for example, |
|
First name of the user associated with the account. |
|
Last name of the user associated with the account. |
|
Email address of the user. |
|
Login name of the user associated with the account. |
|
Method by which the account was granted. |
|
User who made the decision in the previous certification cycle. |
|
Decision from the previous certification cycle. |
|
Date and time of the last certification decision. |
|
User responsible for reviewing and making a decision on the account access. |
|
Action taken during the review (for example, |
|
User who made the final decision. |
|
Current status of the remediation action (for example, |
|
Date and time any remediation action was completed. |
All campaign summary
The "All campaign summary" report provides an overview of all certification campaigns. This report helps you assess the status, progress, and key details of each campaign to track compliance and governance efforts.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select All campaign summary.
-
In the Run Report tab, enter the campaign type. Options are:
-
identity
-
entitlement
-
roleMembership
-
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Type of certification campaign. |
|
Name of the certification campaign. |
|
Type of certification being performed (for example, |
|
User responsible for overseeing the campaign. |
|
Date and time campaign was initiated. |
|
Date and time campaign officially began. |
|
Date and time by which campaign must be completed. |
|
Current state of the campaign (for example, |
|
Date and time campaign was officially closed. |
|
Indicates if remediation actions are enabled for campaign. |
|
Number of reviews completed or total reviews. |
|
Number of items currently under review. |
|
Number of items that have been signed off. |
All requests
The "All requests" report provides a detailed log of every access request submitted across the organization. This report helps with auditing, troubleshooting, and understanding access patterns. It captures who requested what, for whom, and the final outcome of each request.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select All requests.
-
In the Run Report tab, enter the following:
-
Request Status: Select a status. Options are:
-
In Progress: The request is currently active and awaiting action or approval.
-
Complete: The request has been fully processed, and a final outcome has been reached.
-
Canceled: The request was withdrawn or canceled before a final decision was made.
-
Suspended: The request is temporarily paused, often pending further information or action.
-
-
Request Type: Select a request type. Options are:
-
GrantRoleMembership: Grants a user membership to a role.
-
ModifyEntitlement: Modifies an existing entitlement for a user.
-
GrantEntitlement: Grants a user a new entitlement.
-
RevokeAccount: Revokes a user’s account.
-
CreateAccount: Creates a new user account.
-
CreateEntitlement: Creates a new entitlement.
-
CreateUser: Creates a new user.
-
DeleteUser: Deletes an existing user.
-
RevokeRoleMembership: Revokes a user’s membership to a role.
-
RevokeEntitlement: Revokes an existing entitlement from a user.
-
-
Timeframe: Select a time frame for the report. Options are:
-
Today
-
Yesterday
-
Last 7 days
-
Last 30 days
-
Custom: Enter the Start Date and End Date of the date range.
-
-
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Current state of the request within its lifecycle (for example, |
|
Type of access being requested (for example, |
|
Requested date and time for the access to become active. |
|
Requested date and time for the access to expire. |
|
User who initiated the request. |
|
User for whom the access was requested. |
|
Specific entitlement or role being requested. |
|
Date and time when the access request was created. |
|
Date and time when the request was fully approved, rejected, or cancelled. |
|
Date and time the request officially began. |
|
Date and time the request officially ended. |
|
Current lifecycle state of the request, such as: |
|
Final result of the request, such as |
|
Final decision made on the request: |
|
Unique identifier for the request from an external system, if applicable. |
Application accounts
The "Application accounts" report provides a comprehensive inventory of all accounts (correlated, orphan, or machine) within specific applications. This report helps with auditing access, identifying account statuses, and ensuring that account privileges align with security policies.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Application accounts.
-
In the Run Report tab, select the Application Name from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the application where the account exists. |
|
User responsible for managing the application. |
|
Indicates if access to the application can be requested. Values are: |
|
Full name of the account holder. |
|
Login name for the account within the application. |
|
Type of account (for example, |
|
More specific classification of the account type. |
|
Date and time the account was created. |
|
Date and time the account was last modified. |
|
Most recent decision made during an access certification campaign for this account. Values are: |
|
User who made the last certification decision. |
|
Date and time of the last certification decision. |
|
Indicates if the account is currently active or disabled. |
|
Indicates if the account has elevated or administrative privileges. |
|
Date and time of the last successful login to the account. |
|
Date and time the account’s password was last changed. |
Application entitlements
The "Application entitlements" report provides a detailed list of all entitlements available within a specific application. This report helps administrators review and manage the permissions and access rights that can be granted to users, ensuring that access policies are correctly implemented.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Application entitlements.
-
In the Run Report tab, select the Application Name from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the application where the entitlement is defined. |
|
User-friendly name of the entitlement. |
|
User or group responsible for managing the entitlement. |
|
Brief explanation of what access the entitlement provides. |
|
Classification or category of the entitlement. |
|
Name of the parent entitlement if this is a nested entitlement. |
|
Indicates if users can request this entitlement. Values are: |
Entitlement assignment certification
The "Entitlement assignment certification" report provides a detailed record of the access review decisions made during access certification campaigns for entitlements. This report helps auditors and administrators verify that user access rights are reviewed periodically and that all decisions are tracked for compliance with security policies.
Steps
-
To locate a campaign ID:
-
In the Advanced Identity Cloud admin console, go to Governance > Certification.
-
Click the Campaigns tab.
-
Select an entitlement certification from the list.
-
In the URL, copy the campaign ID.
-
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Entitlement assignment certification.
-
In the Run Report tab, enter the Campaign ID.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the certification campaign. |
|
Name of the application associated with the entitlement. |
|
Display name of the account being reviewed. |
|
User-friendly name of the entitlement under review. |
|
Brief explanation of the entitlement’s purpose. |
|
Login name of the user whose access is being certified. |
|
First name of the user. |
|
Last name of the user. |
|
Score indicating the confidence level that the access is appropriate. |
|
User responsible for reviewing and making a decision on the access. |
|
Method by which the entitlement was granted (for example, |
|
Action taken during the review (for example, |
|
User who made the final decision. |
|
Date and time the decision was recorded. |
|
Current status of any remediation actions taken (for example, |
|
Date and time the remediation was completed. |
Entitlement grants
The "Entitlement grants" report provides a detailed list of all users who’ve been granted a specific entitlement. This report helps administrators and auditors verify who has access to what, track provisioning methods, and review any decisions made about that access.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Entitlement grants.
-
In the Run Report tab, enter:
-
Application Name: Select the application from the list.
-
Entitlement Display Name: Enter the entitlement.
-
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the application where the entitlement exists. |
|
Name of the entitlement. |
|
User-friendly name of the entitlement. |
|
Brief explanation of the entitlement’s purpose. |
|
First name of the user who was granted the entitlement. |
|
Last name of the user who was granted the entitlement. |
|
Score indicating the confidence level that the access is appropriate. |
|
Method by which the entitlement was granted (for example, |
|
Username of the user who was granted the entitlement. |
Entitlements with inactive owners
The "Entitlements with inactive owners" report identifies a key governance risk: entitlements managed by users whose accounts are inactive. This report helps ensure that all access rights have active oversight and helps reassign ownership to maintain security and accountability.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Entitlements with inactive owners.
-
In the Run Report tab, select the Application Name from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the application where the entitlement is defined. |
|
User-friendly name of the entitlement. |
|
Inactive user or group assigned as the owner. |
|
Brief explanation of what access the entitlement provides. |
|
Classification or category of the entitlement. |
|
Name of the parent entitlement if this is a nested entitlement. |
|
Indicates if users can request this entitlement. |
Entitlements with no owners
The "Entitlements with no owners" report identifies a governance gap where entitlements lack an assigned owner. This report helps ensure that all access rights are properly managed and that there is clear accountability for each entitlement.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Entitlements with no owners.
-
In the Run Report tab, select the Application Name from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the application where the entitlement is defined. |
|
User-friendly name of the entitlement. |
|
User or group responsible for managing the entitlement. This is blank for items in this report. |
|
Brief explanation of what access the entitlement provides. |
|
Classification or category of the entitlement. |
|
Name of the parent entitlement if this is a nested entitlement. |
|
Indicates if users can request this entitlement. |
Identity certification accounts
The "Identity certification accounts" report provides a detailed audit trail of certification decisions made for user accounts during a campaign. This report helps administrators and compliance managers verify that account access is regularly reviewed and that all decisions are documented.
Steps
-
To locate a campaign ID:
-
In the Advanced Identity Cloud admin console, go to Governance > Certification.
-
Click the Campaigns tab.
-
Select an entitlement certification from the list.
-
In the URL, copy the campaign ID.
-
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Identity certification accounts.
-
In the Run Report tab, enter the Campaign ID.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the certification campaign. |
|
Name of the account being reviewed. |
|
Type of certification being performed. |
|
Name of the application where the account exists. |
|
Login name of the user associated with the account. |
|
User who completed the review item. |
|
Date and time the review item was completed. |
|
Action taken during the review (for example, |
|
User who made the final decision. |
|
User who made the decision in the previous certification cycle. |
|
Decision from the previous certification cycle. |
|
Date and time of the last certification decision. |
|
User responsible for reviewing and making a decision on the account access. |
|
Type of reviewer assigned (for example, |
|
Date and time any remediation action was completed. |
|
Current status of the remediation action (for example, |
Identity certification entitlements
The "Identity certification entitlements" report provides a detailed list of decisions made for user entitlements during a specific certification campaign. This report helps administrators and compliance managers verify that entitlement assignments are regularly reviewed and that all decisions are documented for compliance.
Steps
-
To locate a campaign ID:
-
In the Advanced Identity Cloud admin console, go to Governance > Certification.
-
Click the Campaigns tab.
-
Select an entitlement certification from the list.
-
In the URL, copy the campaign ID.
-
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Identity certification entitlements.
-
In the Run Report tab, enter the Campaign ID.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the certification campaign. |
|
Name of the certification campaign. |
|
Name of the application associated with the entitlement. |
|
Display name of the account being reviewed. |
|
User-friendly name of the entitlement under review. |
|
Brief explanation of the entitlement’s purpose. |
|
Login name of the user whose access is being certified. |
|
First name of the user. |
|
Last name of the user. |
|
User responsible for reviewing and making a decision on the access. |
|
Score indicating the confidence level that the access is appropriate. |
|
Method by which the entitlement was granted (for example, |
|
Current status of any remediation actions taken (for example, |
|
Action taken during the review (for example, |
|
User who made the final decision. |
|
Any comments or justifications provided during the review. |
|
Date and time the decision was recorded. |
Identity certification role memberships
The "Identity certification role memberships" report provides a detailed audit log of decisions made for user role memberships during a specific certification campaign. This report helps administrators and compliance managers verify that role assignments are regularly reviewed and that all decisions are documented for compliance.
Steps
-
To locate a campaign ID:
-
In the Advanced Identity Cloud admin console, go to Governance > Certification.
-
Click the Campaigns tab.
-
Select an entitlement certification from the list.
-
In the URL, copy the campaign ID.
-
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Identity certification role memberships.
-
In the Run Report tab, enter the Campaign ID.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the certification campaign. |
|
Name of the certification campaign. |
|
Name of the role being reviewed. |
|
Brief explanation of the role’s purpose. |
|
Login name of the user whose role membership is being certified. |
|
First name of the user. |
|
Last name of the user. |
|
How the user was assigned to the role (for example, |
|
User responsible for reviewing and making a decision on the role membership. |
|
Action taken during the review (for example, |
|
User who made the final decision. |
|
Any comments or justifications provided during the review. |
|
Date and time the decision was recorded. |
|
User who made the decision in the previous certification cycle. |
|
Decision from the previous certification cycle. |
|
Date and time of the last certification decision. |
Orphan accounts
The "Orphan accounts" report identifies user accounts within applications that are no longer linked to a known identity in the system. This report helps administrators find and remediate these unmanaged accounts, which can pose a security risk.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Orphan accounts.
-
In the Run Report tab, select the Application Name from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the application where the orphan account exists. |
|
User responsible for managing the application. |
|
Indicates if access to the application can be requested. |
|
Full name associated with the orphan account. |
|
Login name for the orphan account within the application. |
|
Type of account (for example, |
|
More specific classification of the account type. |
|
Date and time the account was created. |
|
Date and time the account was last modified. |
|
Most recent decision made during an access certification campaign for this account. |
|
User who made the last certification decision. |
|
Date and time of the last certification decision. |
|
Indicates if the account is currently active or disabled. |
|
Indicates if the account has elevated or administrative privileges. |
|
Date and time of the last successful login to the account. |
|
Date and time the account’s password was last changed. |
Request tasks
The "Request tasks" report provides a detailed breakdown of individual tasks associated with access requests, such as approvals. This report helps administrators track the progress of a request, identify bottlenecks, and audit the decision-making process for each step.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Request tasks.
-
In the Run Report tab, select a request type from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the parent access request. |
|
User who initiated the original request. |
|
Type of access being requested. |
|
User for whom the access was requested. |
|
Specific entitlement or role being requested. |
|
User assigned to approve or deny this specific task. |
|
Action taken on the task (for example, |
|
Date and time the decision was made for this task. |
|
User who completed this task. |
|
Final result of the overall access request (for example, |
|
Overall decision made on the entire access request. |
|
Type of task being performed (for example, |
|
Current state of the individual task (for example, |
|
Any comments or justifications provided for the task. |
|
User who added the comment. |
|
Date and time the comment was added. |
Role entitlement details
The "Role entitlement details" report provides a granular breakdown of the entitlements that constitute a specific role. This report helps administrators and role owners understand the exact permissions granted by a role, verify its composition, and ensure it aligns with the principle of least privilege.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Role entitlement details.
-
In the Run Report tab, enter a Role Name.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the role being examined. |
|
Brief explanation of the role’s purpose. |
|
Any time-based restrictions applied to the role’s activation. |
|
Specific conditions or rules that must be met for the role to be active. |
|
Indicates if users can request this role. |
|
User or group responsible for managing the role. |
|
User-friendly name of an entitlement included in the role. |
|
Brief explanation of what access the entitlement provides. |
|
Name of the application where the entitlement is defined. |
Role membership certification
The "Role membership certification" report provides a detailed list of decisions made for user role memberships during a specific certification campaign. This report helps administrators and compliance managers verify that role assignments are regularly reviewed and that all decisions are documented for compliance.
Steps
-
To locate a campaign ID:
-
In the Advanced Identity Cloud admin console, go to Governance > Certification.
-
Click the Campaigns tab.
-
Select an entitlement certification from the list.
-
In the URL, copy the campaign ID.
-
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Role membership certification.
-
In the Run Report tab, enter the Campaign ID.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Unique identifier for the certification campaign. |
|
Name of the role being reviewed. |
|
User or group responsible for managing the role. |
|
Indicates if users can request this role. |
|
Brief explanation of the role’s purpose. |
|
Login name of the user whose role membership is being certified. |
|
How the user was assigned to the role (for example, |
|
Score indicating the confidence level that the access is appropriate. |
|
User responsible for reviewing and making a decision on the role membership. |
|
Action taken during the review (for example, |
|
User who made the final decision. |
|
Date and time the decision was recorded. |
|
User who made the decision in the previous certification cycle. |
|
Decision from the previous certification cycle. |
|
Date and time of the last certification decision. |
|
Method by which the role membership was granted. |
|
Date and time any remediation action was completed. |
|
Current status of the remediation action (for example, |
Role membership with decision details
The "Role membership with decision details" provides a comprehensive view of who is a member of a specific role. The report includes the latest certification decision for that membership and helps administrators and auditors verify role compositions and review historical access decisions.
Steps
-
In the Advanced Identity Cloud admin console, go to Reports.
-
In the list of reports, find and select Role membership with decision details.
-
In the Run Report tab, select the Role Name from the list.
-
Click Run Report to generate the report.
-
Click View Report to open it.
Report reference
Details
| Field | Description |
|---|---|
|
Name of the role being examined. |
|
Display name of the role. |
|
Brief explanation of the role’s purpose. |
|
Indicates if users can request this role. |
|
User or group responsible for managing the role. |
|
Login name of the user who is a member of the role. |
|
Email address of the role member. |
|
First name of the role member. |
|
Last name of the role member. |
|
Method by which the role membership was granted. |
|
Last action taken during a review (for example, |
|
User who made the last decision. |
|
Date and time of the last certification decision. |
|
Date and time the last decision was recorded. |
Roles with no owners
The "Roles with no owners" report identifies a governance gap where roles lack an assigned owner. This report helps ensure that all roles are properly managed and that there is clear accountability for each one.
Users with no or inactive managers
The "Users with no or inactive managers" report identifies users whose managers are either not assigned or are marked as inactive in the system. This report helps maintain data integrity and ensures that approval workflows and certification campaigns can be correctly routed.