6.2 The Purpose of Common Certification Rules
Key Takeaways
Exclusion (CertificationExclusion), Pre-delegation (CertificationPreDelegation), Who Do You Want to Certify (CertificationScheduleEntitySelector), and Certifier rules run while the certification is generated.
CertificationPhaseChange rules run when the Active, Challenge, Revocation, or End period begins.
WorkItemEscalationRule rules transfer an overdue access review or revocation to someone else.
A CertificationSignOffApprover rule runs at sign-off and returns the next approver (identity or identityName) to create multi-level sign-off.
A CertificationAutomaticClosing rule runs when automatic closing starts, after the other phases end.
The Purpose of Common Certification Rules
Objective 3.2 asks you to understand the purpose of common certification rules. The exam usually gives a requirement and asks which rule type satisfies it, or where in the certification timeline it runs. The documentation lists the certification rules in the order they run.
The Rules in Execution Order
| UI field | Rule type | When it runs | Purpose |
|---|---|---|---|
| Exclusion Rule | CertificationExclusion | During generation | Removes items from the certification |
| Pre-delegation Rule | CertificationPreDelegation | During generation | Delegates, or in non-targeted certifications reassigns, reviews before reviewers see them |
| Who Do You Want to Certify (Targeted only) | CertificationScheduleEntitySelector | During generation | Selects the identities to certify |
| Group Factory: Certifier | Certifier | During Advanced (group factory) generation | Assigns the certifier for each group's review |
| Active Period Enter Rule | CertificationPhaseChange | Start of Active | Open-ended custom logic |
| Certification Escalation Rule | WorkItemEscalationRule | At the escalation trigger if the review is unsigned | Transfers the review, often to the certifier's manager or the certification owner |
| Challenge Period Enter Rule | CertificationPhaseChange | Start of Challenge, or once per revocation when revokes are processed immediately | Open-ended |
| Closing Rule | CertificationAutomaticClosing | When automatic closing begins | Open-ended, often custom decisions on undecided items |
| Sign-off Approver Rule | CertificationSignOffApprover | When a reviewer signs off | Sends the review to the next-level approver |
| Revocation Period Enter Rule | CertificationPhaseChange | Start of Revocation | Open-ended |
| Revocation Escalation Rule | WorkItemEscalationRule | At the revocation escalation trigger | Transfers the revocation work item, often to the revoker's manager or the application owner |
| End Period Enter Rule | CertificationPhaseChange | Start of End | Open-ended |
Other rule types appear on certification pages. Certifier rules pick the primary certifier in targeted certifications. EmailRecipient rules add reminder and escalation recipients. SailPoint ships starting-point examples in examplerules.xml.
Exclusion Rule
Use it to keep noise out of reviews, such as a birthright entitlement every employee has, or to skip whole identities, such as inactive users or executives. The rule receives the entity being certified (for identity-based certifications, an Identity), the list of items that would be certified, and an empty itemsToExclude list. It moves items from one list to the other and returns an optional explanation string that appears on the exclusions list.
import sailpoint.object.Identity;
String explanation = "";
Identity person = (Identity) entity;
if (person.isInactive()) {
itemsToExclude.addAll(items);
items.clear();
explanation = "Not certifying inactive identities";
}
return explanation;
Select Save Exclusions on the certification to keep the excluded items for reporting.
Pre-Delegation Rule
A pre-delegation rule runs during generation and can send part or all of a review to someone else before the reviewer sees it. For example, every privileged account could go to the security team. In targeted certifications, the documentation notes that pre-delegation rules still support delegation and forwarding, but reassignment components are ignored. Use a Certifier rule in the Primary Certifier field to control reassignments instead. Pre-delegation and pre-reassignment rules are not meant to run together with the Fallback Forwarding User rule.
Sign-Off Approver Rule: Multi-Level Sign-Off
When a reviewer signs off, this rule decides whether someone else must approve the decisions. It receives the certification and the certifier who signed. It returns a Map with either identity or identityName for the next approver, or nothing to end the chain. The process repeats until the rule returns no approver:
import java.util.HashMap;
import java.util.Map;
Map result = new HashMap();
if (certifier.getManager() != null) {
result.put("identity", certifier.getManager());
}
return result;
With a challenge period, the sign-off approver can override only approval decisions. Revocations the access holder has already seen in a challenge work item cannot be changed in the approver's view.
Phase-Change, Escalation, and Closing Rules
- CertificationPhaseChange rules are hooks for custom actions at the start of a phase, such as opening a ticket when the revocation period starts or emailing a summary when the End period starts.
- WorkItemEscalationRule rules run when an escalation is due and transfer ownership, not just send email.
- A CertificationAutomaticClosing rule runs at the start of automatic closing, after the Active phase (or Challenge phase, if enabled) and the configured delay. It can apply more complex logic than the simple "revoke/approve/exception" action on undecided items.
Building and Testing Certification Rules Safely
- Start from the samples. Import the examples in
examplerules.xmland copy the one closest to your need, so the rule type and input variables are right. - Keep generation rules fast. Exclusion, pre-delegation, entity-selector, and certifier rules run for every entity during generation. A slow database lookup inside them can make a large certification take hours. Load reference data once, for example from a Custom object, instead of querying repeatedly.
- Test on a staged certification. Enable staging (section 6.1) so the rule's effect (excluded items, delegations, certifier assignments) can be inspected before any reviewer is notified.
- Log what the rule decides. Use
log.debugwith a dedicated logger (section 14.1) and return a meaningful exclusion explanation so auditors can see why items were left out.
Choosing the Right Rule
| Requirement | Rule type |
|---|---|
| "Never show the All-Employees AD group in reviews" | CertificationExclusion |
| "Send all privileged-account items to the security team" | CertificationPreDelegation (or a Certifier rule in targeted certifications) |
| "Certify only people hired in the last 90 days" | CertificationScheduleEntitySelector (targeted), or a population |
| "After a manager signs, their director must approve" | CertificationSignOffApprover |
| "If a reviewer ignores the review for 10 days, give it to their manager" | WorkItemEscalationRule |
| "Open a ServiceNow ticket when revocations start" | CertificationPhaseChange (Revocation Period Enter) |
Managers complain that every access review includes the Domain Users group that all employees receive. Which rule type removes it from reviews?
CertificationExclusion
CertificationSignOffApprover
CertificationPhaseChange
WorkItemEscalationRule
After a manager signs off an access review, the manager's own manager must also review the decisions. Which rule type and return value provide this?
CertificationPreDelegation returning a delegation map during generation
CertificationAutomaticClosing returning the manager's name
CertificationSignOffApprover returning a Map with the next approver as identity or identityName
Certifier returning null
A targeted certification uses a pre-delegation rule that tries to reassign reviews to regional leads, but the reassignments never happen. Why?
Pre-delegation rules run only after sign-off.
In targeted certifications, pre-delegation rules support delegation and forwarding but ignore reassignment; a Certifier rule should control reassignment.
Pre-delegation rules can only be used in Role Composition certifications.
The rule must be of type CertificationPhaseChange to reassign.
When does a Revocation Period Enter rule run?
When the certification is first generated
Each time a reviewer clicks Revoke
At the start of the revocation period, which follows the Active period, or the Challenge period if one is enabled
Only when automatic closing is enabled
Sections you finish are checked off in the contents.