Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

What is the purpose of setting owner rank for entitlements?

Nathan
New Contributor
New Contributor

As the title states, I cant find any information on this topic.

Functionally speaking, what difference in the system would we observer by setting someone as Primary vs Secondary certifier.

Also with rank 1 through 25, how does that manifest in the system?

9 REPLIES 9

rushikeshvartak
All-Star
All-Star

 

  • Multi-level approval campaigns: In organizations with complex workflows, access rights might need to be certified first by the direct manager (Rank 1), then by the role owner (Rank 2), and finally by the security administrator (Rank 3).

  • Risk-based certifications: Certifications with higher sensitivity or critical access rights might involve more certifiers (e.g., up to Rank 10 or higher), while lower-risk access might only require a single certifier.

  • Primary vs. Secondary Certifiers:

    • Primary Certifier: The individual designated as the Primary Certifier is the main person responsible for reviewing and certifying access rights during a certification campaign. They are the first to receive the certification request and have the authority to approve or reject the access entitlements.

    • Secondary Certifier: A Secondary Certifier acts as a backup or additional reviewer. If the Primary Certifier does not take action (e.g., within a certain time window), the system may escalate the certification task to the Secondary Certifier. Alternatively, in some workflows, the Secondary Certifier might be consulted after the Primary Certifier makes a decision, depending on the configuration of the campaign.

 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

"If the Primary Certifier does not take action (e.g., within a certain time window), the system may escalate the certification task to the Secondary Certifier. Alternatively, in some workflows, the Secondary Certifier might be consulted after the Primary Certifier makes a decision, depending on the configuration of the campaign."

where do I see these settings in the certification configuration.

In terms of configuration who performs the review, all i see are: 

1. Default certifier - Which is who reviews go to when there is an inactive certifier

2. Campaign owner - I'm not sure if they have a functional purpose

3. A field that allows to select all certifiers/select from a query/select from a list.

  • Saviynt does not support auto escalate to secondary certifier in certification

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Then how would I use "Secondary Certifier" if its set. 

Secondary Certifier

For identity objects such as entitlements, roles, service accounts, and endpoints, you can add a primary and a secondary certifier as owners. A secondary certifier can take actions on the certification but they cannot lock the campaign. Only the primary certifier can lock the campaign.

The secondary certifier can perform actions on certifications, but those actions can be reviewed and overwritten by the primary certifier. The actions taken by the primary certifier are considered final.

https://docs.saviyntcloud.com/bundle/EIC-User-v24x/page/Content/06-mang-cert/cert-pers-bsd-cert.htm 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

So the secondary certifier automatically gets access to the campaign, and can make decisions, but cannot lock?

  • Yes he can make decision and can't lock

Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

And for rank1 to rank25, those are more like meta data. Its up to the workflows how those are consumed by the system?

Yes used mainly for workflow purpose


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.