17.1 Common IdentityIQ Data Objects

Key Takeaways

  • Identity is the identity cube; Link is one account on one application; Application is the connector configuration with its schemas.

  • ManagedAttribute is an Entitlement Catalog entry, including account groups; IdentityEntitlement records an entitlement or role an identity holds.

  • Bundle is the class for every role type, and role entitlements are defined in its Profiles.

  • Workflow is a definition, WorkflowCase is a running instance, WorkItem is a task for a person, and IdentityRequest tracks an LCM request.

  • TaskDefinition defines a task or report, TaskResult records a run, and configuration lives in objects such as Rule, Form, EmailTemplate, ObjectConfig, UIConfig, and SystemConfiguration.

Last updated: September 2026

Common IdentityIQ Data Objects

Objective 7.5 asks you to know the common IdentityIQ data objects and what they represent. Object class names appear everywhere: in the Debug pages' class list, console commands (list link, get identity ...), filters, and the API (section 9.3). Knowing them lets you go straight to where data lives.

Identity and Account Data

ObjectRepresentsWhere you meet it
IdentityThe identity cube for a person or non-human identity, with attributes, manager, roles, capabilities, scopes, and risk. Workgroups are also Identity objects, flagged as workgroups.Identity Warehouse, Debug, and every rule
LinkOne account on one application, holding its native identity, application, attributes, and entitlementsApplication Accounts tab, aggregation, correlation
ApplicationA configured connector: connection settings, Schemas (account and group), provisioning policies, correlation config, and rulesApplication Definition
ManagedAttributeAn Entitlement Catalog entry: an entitlement value or an account group, with owner, description, requestable flag, and classificationsEntitlement Catalog, group aggregation, LCM
IdentityEntitlementA record of an entitlement or role an identity holds, with details such as how it was obtained and whether it is connected, requested, or certifiedIdentity Entitlements tab; reports join to it for assignedRoles and detectedRoles
ResourceObjectThe in-memory account or group a connector returns during aggregation, before it becomes a Link or ManagedAttributeCustomization, BuildMap, and correlation rules
IdentitySnapshotA point-in-time copy of an identity, for history and certificationsMaintain identity histories, console snapshot

Role Model

ObjectRepresents
BundleEvery role, whatever its type (organizational, business, IT, or custom). Holds assignment rules, required, permitted, and inherited links, and profiles.
ProfileThe entitlement definition inside a role: an application plus attribute rules and permissions. Profiles are not shared between roles.
RoleChangeEventRecords role changes for propagation (section 16.2)

Governance

ObjectRepresents
CertificationGroupThe campaign-level container that ties certifications from one schedule together
CertificationOne access review, with a certifier, phase, and dates
CertificationEntityThe thing being certified within a review, such as an identity, a role, or an account group
CertificationItemOne line item, such as a role, entitlement, or policy violation, with its decision (action)
PolicyA policy definition with its rules (section 7.1)
PolicyViolationA detected violation with status and mitigation (allowed-until) information
MitigationExpirationTracks when an allowed exception expires

Processes and Requests

ObjectRepresents
WorkflowA business process definition
WorkflowCaseA running workflow for one target, carrying its WorkflowContext state
WorkItemA task in someone's inbox: approval, form, manual action, remediation, and so on
IdentityRequestThe tracking record of an LCM request, categorized as an access request, password request, identity change request, or identity request. It survives after the workflow's TaskResult is pruned.
TaskDefinitionA task or report definition (reports are TaskDefinitions of type LiveReport)
TaskResultThe outcome of a task, report, or workflow run
Request / RequestDefinitionBackground work items, such as partitions and retries, and their per-type processing settings (threads and hosts)
ProvisioningPlan / ProvisioningProjectThe requested change, and the compiled per-application plan (section 4.2)

Configuration Objects

ObjectHolds
RuleBeanShell logic, including rule libraries
FormShared forms for workflows and provisioning
EmailTemplateNotification content (section 11.1)
ObjectConfigExtended-attribute definitions per class: Identity, Link, Application, Bundle, ManagedAttribute, CertificationItem
UIConfigUI settings such as columns and account icons
Configuration (SystemConfiguration and others)Global settings, such as email, syslog, and retention
Capability / ScopeRights bundles and visibility boundaries (section 3.3)
DynamicScope / QuickLink / QuickLinkOptionsQuickLink populations and links (section 5.2)
GroupFactory / GroupDefinition / GroupIndexGroups and populations (section 17.3)
CustomFree-form key/value data for rules

Infrastructure Objects

ObjectHolds
ServerOne per IdentityIQ instance: heartbeat and statistics (section 2.1)
ServiceDefinitionConfiguration of background services and the hosts they run on
AuditEvent (audit records) and syslog eventsAudit trail (section 8.3) and captured errors (section 14.2)

Finding Objects Quickly

The same class names work across every tool:

  • Debug pages: choose the class in the Object Browser, for example Link or IdentityRequest, then search by name (section 15.1).
  • Console: list <class> [filter], count <class>, and get <class> <name>. Enter list with no arguments to see every class that can be listed (section 14.3).
  • Code and filters: context.getObjectByName(ManagedAttribute.class, ...) or Filter.eq("application.name", "AD") (section 9.3).
  • Reports: a report's data source names an object type, such as sailpoint.object.Link for the Uncorrelated Accounts report (section 8.1).

Some data that looks like a separate object is actually stored inside another one. Role assignments and detections, for example, are recorded on the Identity (and reflected in IdentityEntitlement records), not as separate top-level objects you list in the console. When you cannot find a class, look at the parent object's XML.

Using This Knowledge

When a question asks where to look, map the noun to the object:

  • "The account's current attribute values" → Link.
  • "Which entitlements a person holds and whether they were requested" → IdentityEntitlement.
  • "Owner and description of an AD group" → ManagedAttribute.
  • "Why a request is still pending" → IdentityRequest, then its WorkflowCase and WorkItems.
  • "What happened in last night's aggregation" → TaskResult.
Test Your Knowledge

An auditor asks for the owner and business description of an Active Directory group. Which IdentityIQ object stores them?

A

ManagedAttribute

B

Link

C

Profile

D

Bundle

Test Your Knowledge

Which object tracks the status of a Lifecycle Manager request even after the workflow's TaskResult has been pruned?

A

WorkItem

B

TaskDefinition

C

IdentityRequest

D

RequestDefinition

Test Your Knowledge

In the object model, what class represents a business role, an IT role, and an organizational role?

A

Role, BusinessRole, and ITRole respectively

B

ManagedAttribute

C

Profile

D

Bundle, for all role types

Test Your Knowledge

Where is the difference between a running workflow and its definition represented?

A

Both are stored in the same Workflow object.

B

The definition is a TaskResult, and the running instance is a WorkItem.

C

The definition is a Workflow object, and each running instance is a WorkflowCase.

D

The definition is a Rule, and the instance is an IdentityRequest.

Sections you finish are checked off in the contents.