T Techclick ← All lessons
SailPoint · Evidence desk · Interactive lesson

Prove the request / cert completed — first tool + proof field

02:10. Slack: “Did SailPoint even finish?” Finance never got the tile. A Q3 campaign “already revoked it.” The VA looks green. A screenshot of Request Center is not proof. This desk is five official surfaces — identity cube, access request Status, certification Sign Off / Revoke Completed, aggregation / task result, Search audit — each mapped to one ticket, one first click, and one field you paste before you change anything.

~20 min read · L2 primary · Quiz at end · Pair · Factory

⚡ Quick Answer

How you prove a SailPoint access request or certification actually completed: identity cube, Approval Management Status, campaign Sign Off / Revoke Completed, Aggregation History, Search audit. Five tickets, first tool + one proof field.

After this page you can

Quick answer (say this out loud)

The identity cube (IdentityIQ name; Identity Security Cloud path is Admin → Identity Management → Identities) answers “does this person even exist, and in what state?” Approval Management Status answers “did the access request finish — or is it still executing?” A certification Sign Off Date plus Revoke Completed answers “did the campaign actually take the access?” Aggregation History Status answers “did the last load succeed?” Search audit (Request Access Processed, type:access_request, Account Activity Status) answers “did the write land?” Pending is not down. Completed is not a healthy account. A clicked Revoke without Sign Off is not a revoke.

1. Why “did it complete?” is five questions

Operators collapse five failures into one sentence. The identity was never built. The request is still on a manager. The campaign revoked it and signed off. Aggregation never ran. Approval finished and provisioning failed. Those are five first clicks.

This page is the night-shift desk for proof. The factory taught the stations: identity → request → approval (people) → provision (connector) → cert / revoke. Here you learn the five tools you actually open, in order, when someone asks whether the request or the cert completed.

Hero · directory in, decision log out
Directory sync feeding an access-review board that stamps Approve or Revoke into a decision log
Notice: aggregation feeds the cube. The review board is a decision. The close is the decision log — Status, Sign Off, Revoke Completed — not the stamp on the screenshot.
Interview line

If they say “prove SailPoint finished,” do not say “I opened Admin.” Say: “I prove the cube with Status and Lifecycle State, the request with Approval Management Status, the campaign with Sign Off Date and Revoke Completed, the load with Aggregation History Status, and the write with Search Request Access Processed or Account Activity Status.”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you restart a healthy VA at 02:00.

Concept: five proof surfaces. Path: ticket → first tool → one field. Do: Side A/B/C and the five tickets.

1 · Identity cube

IIQ: Identity Cube, built by identity aggregation from the authoritative source. ISC: Admin → Identity Management → Identities. Proves Status + Lifecycle State + manager. Incomplete identities cannot request or certify.

2 · Access request Status

ISC: Admin → Dashboard → Approval Management. Proves whether the request is still executing. Official Status values include Pending, Partial Provisioning, Failed, Error, Canceled, Denied, Completed. Pending = executing.

3 · Certification

ISC: Admin → Certifications → Campaigns → Download Reports. Proves Decision + Sign Off Date + Revoke Completed. Unsigned Revoke is not applied. Remediation Status Finished is the write.

4 · Aggregation / task

ISC: source Aggregation History, or Admin → Connections → Aggregation Activity (90 days). Proves Status (success / warning / error / terminated) + accounts scanned. Connected is not lastAgg.

5 · Search audit

Search Events: "Request Access", type:access_request, type:certification, type:provisioning. Account Activity: Status Complete / Failure / Incomplete / Pending. Events are the audit. Account Activity is the write.

Hard words, once

Status (identity) ≠ Lifecycle State. Pending = executing, not crashed. Sign Off applies the revoke. Revoke Completed / remediation Finished is the deprovision. IIQ Last Refresh is the cube timestamp.

Flow 1 · five tools, one question each
Write identity + item + UTC first · then pick the tool Did the request / cert complete? five questions, not one Identity cube Does this person exist? Status + Lifecycle Identities / View Identity IIQ cube · ISC identity not a request verdict Request Status Did this request finish? Status + Assigned to Days old + ID Approval Management Pending = executing Certification Did the revoke land? Sign Off Date Revoke Completed Campaigns → Reports unsigned ≠ applied Agg / task Did the load succeed? History Status accounts scanned Sources · History Connected ≠ lastAgg Search audit Did the write land? Processed / Status Events + Activity Search · Activities Completed ≠ account Empty request list is data. Incomplete cubes never appear in My Requests. Do not invent a connector outage from a missing tile. Start at the cube, then Status.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the cube, then the request Status, then the Sign Off, then the last aggregation, then the Search write. I do not restart a VA, overwrite an approver, or re-provision a signed revoke until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open the VA, the Create Account profile, or a new campaign until a diamond says so.

Path · pick the branch before the menu
Abstract identity path splitting into request, certify, aggregate, and audit branches
Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Person even there? or already in flight? Missing / new hire Identity cube Status + Lifecycle Tile never came Approval Mgmt Status + Assigned to Lost mid-quarter Campaign reports Sign Off + Revoke Source green, stale Agg History Status + scanned Approved, no tile Search Activity Processed / Status Incomplete / missing cube → stop. There is no request Status to chase. Fix authoritative data + aggregation. Then re-open Approval Management. Diamond = decision. Do not Overwrite Current Approver from the bottom box. IIQ sibling: View Identity / Task Results / Audit Search. Same five questions.

Read the diamond first. Mid-quarter vanish never starts on a VA. Approved-but-no-tile never starts on Remind User. Missing cube never starts on Request Access Processed.

4. How to choose — first tool + proof field

Print this next to Admin. If you cannot recite the proof field, you are not ready to change anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
New hire / “this person is not in SailPoint” ISC: Admin → Identity Management → Identities. IIQ: View Identity (Identity Cube) Identity Status (Active / Incomplete / Error / …) + Lifecycle State + manager. IIQ also: Last Refresh A VA restart, or a new access request
“Pending two days” / tile never appeared ISC: Admin → Dashboard → Approval Management → Access Requests. User: Request Center → My Requests Status (Pending = executing) + Assigned to / Current Owner + Days old + Access Request ID Aggregation, Create Account, VA
Access vanished after a campaign started Admin → Certifications → Campaigns → Actions → Download Reports Campaign Status: Decision + Decision Date + Revoke Completed. Sign Off Report: Sign Off Date. Remediation: Status = Finished Silent re-provision of the tile
Source looks Connected; hire or entitlement still missing Source → Aggregation History, or Admin → Connections → Aggregation Activity Aggregation Status (success / warning / error / terminated) + start/stop + accounts scanned Approval Management on a person who is not on the source
Request Status is Completed (or Concluded) and the tile is still missing Search Events + Account Activity, or Admin → Identity Management → Activities Request Access Processed (or type:access_request) + Account Activity Status (Complete / Failure / Incomplete / Pending) + Stage Remind User on a finished approval
Status words that lie if you mix them

Identity Status is the ISC account (Active, Disabled, Error, Incomplete, Locked, Not Invited, Pending, Registered, Warning). Approval Management Status is the request (Pending, Completed, Canceled, Denied, Provisioning Failed, Partial Provisioning). Account Activity Status is the write (Complete, Failure, Incomplete, Pending). Campaign Decision Made is Open / Complete / Error. Quote the column and the tool, or you are mixing four dictionaries.

5. Runbook Side A → B → C

Side A proves the cube and the request. Side B proves the campaign and the revoke. Side C proves the load and the write. On a messy Sev-2, do them in this order until a field lights up.

Side A — Cube, then request Status (ISC + IIQ)

  1. Open the identity before the request

    Path: Admin → Identity Management → Identities. Search account ID, username, display name, email, first or last name. Official: Working with Identities. Filter Incomplete Identities if the hire “is not in SailPoint.” Incomplete = missing UID, email, or last name — those identities cannot sign in and cannot be used in access requests or certifications until they are completed.

  2. Quote Status, then Lifecycle State, then manager

    Identity Status is the ISC login/account state. Lifecycle State is the employment stage (new identity profiles include pre-hire, active, leave of absence, terminated, archived). Path to change it is Actions → Set Lifecycle State — that is change-control. On IIQ, open the Identity Cube (View Identity); Last Refresh is the cube timestamp after identity aggregation / Identity Refresh.

  3. Open Approval Management, not the VA

    Path: Admin → Dashboard → Approval Management → Access Requests. Paste the Access Request ID in the search bar (comma-separated IDs allowed). Columns: Access Name, Access Request ID, Assigned to, Access for, Requested by, Days old, Status, Actions. Official: Approvals Administration. Filter Status: Pending (executing), Completed, Canceled, Denied, Provisioning Failed.

  4. Read Process / Assignees / Details before you write

    Select the Access Name. Process shows each approval step and dates. Assignees lists people (governance groups show as Multiple). Details shows created date, optional start / end, Status. Isolate actions: Remind User, View Details. Change-control: Reassign, Overwrite Current Approver, Cancel Request. Overwrite is this step only, not the whole workflow.

lab.identitynow.example · Admin → Identity Management → Identities → user@lab.example
Training mock · not live

Admin / Identity Management / Identities / user@lab.example

user@lab.example

DetailsAccountsAccessActivity
Active
active · pre-hire → active
manager@lab.example
2026-08-15 23:52 UTC
IIQ CUBE EQUIVALENT (same job, different noun):
Identity Cube built by identity aggregation from the authoritative source.
Last Refresh · entitlements · correlated accounts.
Incomplete (ISC): missing UID / email / last name → not requestable, not certifiable.

Source: SailPoint Help — Working with Identities; Setting Up Lifecycle States; Processing Identity Data (Details → Modified); IdentityIQ Identity Correlation (Identity Cubes). Lab identities only. Training mock · not live.

lab.identitynow.example · Admin → Dashboard → Approval Management → Access Requests
Training mock · not live

Admin / Dashboard / Approval Management / Access Requests · filter Pending

Grant: Finance-SaaS-User

DetailsProcessAssigneesIdentity
AR-1042
Pending · executing
manager@lab.example
2
Access NameIDAssigned toDays oldStatus
Finance-SaaS-UserAR-1042manager@lab.example2Pending
Finance-SaaS-UserAR-09885Completed
AD-CreateAR-10111Failed

Source: SailPoint Help — Approvals Administration (Status includes Pending, Partial Provisioning, Failed, Error, Canceled, Denied, Completed; Pending = executing; Actions: View Details, Reassign, Remind User, Cancel Request). Lab IDs only.

Side B — Certification (did the revoke actually complete?)

  1. Open the campaign, not the connector

    Path: Admin → Certifications → Campaigns. Select All in the left pane if you need completed campaigns. Official: Understanding Certifications; Certification Campaign Status Information and Reports.

  2. Download the three reports that close a revoke ticket

    Actions → Download Reports. Campaign Status Report: Decision (approved / revoked / acknowledged), Decision Made (Open / Complete / Error), Decision Date (GMT), Revoke Completed. Certification Sign Off Report: Sign Off Date — the reviewer selected Sign Off. Campaign Remediation Status Report (after an admin completes the campaign): revocation Status is Finished when the item is revoked on a connected source or the manual Task Manager / service-desk ticket is marked complete.

  3. Refuse unsigned Revoke as proof

    Official: revoke decisions that are not signed off will not be applied. At campaign completion, unsigned certifications are treated as though no decisions were made. The campaign option then auto-approves undecided items or lets the admin choose. Automated remediation is immediate on a provisioning-capable source. Manual remediation becomes a source-owner task.

Certification — fields you write in the ticket
Path:            Admin → Certifications → Campaigns → Download Reports
Campaign:        CERT-Q3 (lab)
Quote:           Decision + Decision Date + Sign Off Date + Revoke Completed
If completed:    Remediation Status Report → Status = Finished (GMT Completed)
If unsigned:     Revoke is not applied — do not re-provision a decision that never landed

Side C — Aggregation / task + Search audit (did the load and the write land?)

  1. Quote Aggregation History, not the Connected badge

    Path: Admin → Connections → Sources → the source → Aggregation History → Account Aggregations. Official columns: who started it (manual), date/time, objects scanned, current Status (success, warning, error, terminated), optimization on/off. Tenant-wide last 90 days: Admin → Connections → Aggregation Activity. In-flight jobs: Admin Dashboard → Dashboard → Monitor → Active Jobs (ACCOUNT_AGGREGATION, REFRESH_IDENTITIES, SYNCHRONIZE_IDENTITIES). IIQ sibling: Account Aggregation task result.

  2. If Approval Management Status is already Completed, switch to Search

    Events query: "Request Access" (quotes) then AND the username. Official event names: Request Access Started, Approved, Rejected, Cancelled, Processed, Escalated. Type filters: type:access_request, type:certification, type:provisioning, type:approval_request. Approval-request technical names include APPROVAL_REQUEST_APPROVED, APPROVAL_REQUEST_REJECTED, APPROVAL_REQUEST_TIMED_OUT. Column Chooser: Details + Source Name.

  3. Read Account Activity Status for the write

    Path: Search → Account Activity, or Admin → Identity Management → Activities (60 days; Pending stored longer). Quote Status (Complete / Failure / Incomplete / Pending), Action, Stage (Completed / Executing / Terminated), Sources, Last Modified. Open the row for account-request result: Pending, Committed, Finished, Failed, Retry, Manual Task Created. Official warning you may see: “Delayed provisioning due to an existing provisioning request for creating an account on the same source with the same nativeId.”

  4. Manual tasks are a completion path, not an outage

    Flat-file / disconnected sources create Task Manager items. Path: Admin → Dashboard → Tasks. Filters: To Do / Completed. Actions: Reassign, Mark as Complete. A cert revoke on a disconnected source is Finished only when that task or the service-desk ticket is complete.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

TicketSymptomFirst toolProof field
SPED-01New hire “not in SailPoint”Identities / Identity CubeStatus + Lifecycle State (+ IIQ Last Refresh)
SPED-02Finance-SaaS pending two daysApproval ManagementStatus = Pending · Assigned to · Days old
SPED-03Tile vanished after CERT-Q3Campaign reportsSign Off Date + Revoke Completed / Finished
SPED-04Source Connected, hire still missingAggregation HistoryStatus + accounts scanned + start/stop
SPED-05Request Completed, tile still goneSearch Events + Account ActivityRequest Access Processed + Activity Status

SPED-01 — Prove the cube (identity)

01:42 · P2. HR says the joiner started yesterday. L1 already drafted a new access request. Someone wants the VA bounced because “IdentityNow is empty.”

First tool: Admin → Identity Management → Identities. Search the hire. On IIQ, View Identity — that screen is the Identity Cube.

If missing or Incomplete: quote Status. Incomplete = missing UID, email, or last name. Official: those identities must be completed before they can sign in or be used in access requests and certifications. Next check is authoritative source data + last aggregation — not AR-1042.

If Active + lifecycle still pre-hire: you proved the cube. Birthright may still be waiting on the lifecycle change. That is not a connector outage.

Trap

Do not submit a request against an Incomplete identity. Do not delete and rebuild the cube on night shift — delete is temporary if the person still exists on the authoritative source, and the new cube gets a new internal ID.

SPED-02 — Prove the request (Approval Management Status)

02:05 · P3. User: “SailPoint is down — Finance-SaaS-User has been pending two days.” Source is Connected. L1 wants aggregation restarted.

First tool: Admin → Dashboard → Approval Management. Paste AR-1042.

Proof field: Status = Pending (official meaning: the request is executing), Assigned to = manager@lab.example, Days old = 2. Open Process to show the live approval step. Isolate = Remind User or call the manager. Overwrite Current Approver is change-control.

Close

I would not restart aggregation. I would quote Pending + Assigned to + Days old. Pending is not down. Default 90-day deny/expire is irrelevant on day two.

SPED-03 — Prove the cert (Sign Off + Revoke Completed)

02:20 · P2. User lost Finance-SaaS after Q3 started. L1 wants the access profile put back tonight.

First tool: Admin → Certifications → Campaigns → CERT-Q3 → Download Reports.

Proof field: Campaign Status Report Decision = revoked, Decision Date, Revoke Completed. Sign Off Report Sign Off Date. If the campaign is already completed by an admin, Remediation Status Report Status = Finished (connected write, or Task Manager / service-desk ticket complete).

If Decision = revoked but there is no Sign Off Date, official rule: the revoke is not applied. Do not argue with the owner about access that the campaign never took.

Trap

Silent re-provision undoes a signed governance decision. Automated roles can only be acknowledged — the role model still owns them. Access profiles granted by a role or lifecycle state do not appear as individual cert items.

SPED-04 — Prove the load (Aggregation History)

02:40 · P2. New hire missing. AD source tile is Connected. L1 says “SailPoint is up, so the person must be there.”

First tool: source → Aggregation History → Account Aggregations (or Aggregation Activity, last 90 days).

Proof field: last row Status, start/stop, accounts scanned, optimization on/off. Connected is the connector. History Status is the load. A success 36 hours ago with no hire on the source account list is an HR / authoritative-data ticket. A warning or terminated row is the aggregation ticket. Info icon on the badge names the error or who terminated it.

Close

Quote History Status + timestamp. Do not open AR-1042 first on a “never existed in AD” story. Optimized aggregation will not re-evaluate correlation on unchanged accounts — that is official, not a bug.

SPED-05 — Prove the write (Search audit)

03:00 · P2. Manager approved last night. Approval Management Status is Completed. Tile still missing. L1 wants a blind retry.

First tool: Search"Request Access" AND user@lab.example, then Account Activity (or Admin → Identity Management → Activities).

Proof field: event Request Access Processed (or Approved only — then provisioning never started). Account Activity Status Failure / Incomplete, plus the account-request result (Failed, Retry, Manual Task Created) and the official unique-constraint / nativeId delay string if present.

Trap

Account Activity Status Complete after a rejected request still shows Completed — official: no account actions took place. Quote the Action, not the green badge. Events are the audit trail (stored about a year). Account Activity is the 60-day write log.

7. Traps + close-the-ticket proof

Proof · named field, then Closed
Operations desk with named proof checks after Status, Sign Off, and aggregation are quoted
Notice: the close is a named column on a timestamp, not a screenshot of the user’s missing Finance tile.
You seeWeak closeStrong close
Incomplete identity“SailPoint is down” / new requestQuote Status Incomplete (UID / email / last name). Fix source mappings, then re-agg
Approval Status = PendingRestart VA / re-run aggregationQuote Assigned to + Days old. Remind User. Pending = executing
Approval Status = Completed“SailPoint finished”You only proved the request. Open Search Account Activity Status
Revoke clicked, no Sign OffRe-provision the tileOfficial: unsigned revoke is not applied. Show empty Sign Off Date
Sign Off + Revoke CompletedPut Finance-SaaS back tonightTake the signed decision to the owner. Re-provision is change-control
Source Connected“Data is fresh”Aggregation History Status + accounts scanned + timestamp
Activity Status Complete on a deny“Provisioning succeeded”Official Complete-on-reject. Read Action, not the badge
nativeId delay warningBlind retry three timesWait for the first create; unique-constraint is a target collision
IIQ cube Last Refresh oldBounce the task serverQuote Last Refresh + last Account Aggregation task result
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. The cube proves the person. Approval Management Status proves the request. Sign Off Date and Revoke Completed prove the cert. Aggregation History Status proves the load. Search Processed / Account Activity Status proves the write. I do not restart a VA, overwrite an approver, or undo a signed revoke until that field is on the ticket. Factory model: PendingApproval is a people problem.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

User: “Finance-SaaS has been pending two days. SailPoint is down.” You have not opened Admin yet. First proof?

Correct: b. Official Approval Management path. Pending means the request is executing. Re-read Side A steps 3–4 and SPED-02.
Q2

A user lost Finance-SaaS after CERT-Q3 started. Which proof field closes “did the cert actually complete?”

Correct: a. Official Campaign Status / Sign Off / Remediation reports. Unsigned Revoke is not applied. Re-read Side B and SPED-03.
Q3

New hire is missing. The AD source tile shows Connected. First tool + field?

Correct: c. Official Aggregation History / Aggregation Activity. Connected ≠ last aggregation succeeded. Re-read Side C step 1 and SPED-04.
Q4

Approval Management Status is already Completed. The tile is still missing. First tool + proof?

Correct: b. Completed is the request, not the write. Official event names + Account Activity Status. Re-read Side C steps 2–3 and SPED-05.
Q5

Identities list shows Status = Incomplete (missing last name). What is that allowed to mean?

Correct: d. Official Working with Identities. Incomplete = missing UID, email, or last name. Re-read Side A steps 1–2 and SPED-01.
Q6

A reviewer marked Revoke but never selected Sign Off. CERT-Q3 is still Active. What is that sentence allowed to mean?

Correct: a. Official Understanding Certifications. At completion, unsigned items follow the campaign option (default maintain / auto-approve). Re-read Side B step 3 and SPED-03.

Sources

Related: Pair · SailPoint session factory · Access requests & SoD · Access certifications · Connectors, sources & aggregation · SailPoint Identity Security hub