17.1 Common IdentityIQ Data Objects
Key Takeaways
Identity is the identity cube; Link is one account on one application; Application is the connector configuration with its schemas.
ManagedAttribute is an Entitlement Catalog entry, including account groups; IdentityEntitlement records an entitlement or role an identity holds.
Bundle is the class for every role type, and role entitlements are defined in its Profiles.
Workflow is a definition, WorkflowCase is a running instance, WorkItem is a task for a person, and IdentityRequest tracks an LCM request.
TaskDefinition defines a task or report, TaskResult records a run, and configuration lives in objects such as Rule, Form, EmailTemplate, ObjectConfig, UIConfig, and SystemConfiguration.
Common IdentityIQ Data Objects
Objective 7.5 asks you to know the common IdentityIQ data objects and what they represent. Object class names appear everywhere: in the Debug pages' class list, console commands (list link, get identity ...), filters, and the API (section 9.3). Knowing them lets you go straight to where data lives.
Identity and Account Data
| Object | Represents | Where you meet it |
|---|---|---|
| Identity | The identity cube for a person or non-human identity, with attributes, manager, roles, capabilities, scopes, and risk. Workgroups are also Identity objects, flagged as workgroups. | Identity Warehouse, Debug, and every rule |
| Link | One account on one application, holding its native identity, application, attributes, and entitlements | Application Accounts tab, aggregation, correlation |
| Application | A configured connector: connection settings, Schemas (account and group), provisioning policies, correlation config, and rules | Application Definition |
| ManagedAttribute | An Entitlement Catalog entry: an entitlement value or an account group, with owner, description, requestable flag, and classifications | Entitlement Catalog, group aggregation, LCM |
| IdentityEntitlement | A record of an entitlement or role an identity holds, with details such as how it was obtained and whether it is connected, requested, or certified | Identity Entitlements tab; reports join to it for assignedRoles and detectedRoles |
| ResourceObject | The in-memory account or group a connector returns during aggregation, before it becomes a Link or ManagedAttribute | Customization, BuildMap, and correlation rules |
| IdentitySnapshot | A point-in-time copy of an identity, for history and certifications | Maintain identity histories, console snapshot |
Role Model
| Object | Represents |
|---|---|
| Bundle | Every role, whatever its type (organizational, business, IT, or custom). Holds assignment rules, required, permitted, and inherited links, and profiles. |
| Profile | The entitlement definition inside a role: an application plus attribute rules and permissions. Profiles are not shared between roles. |
| RoleChangeEvent | Records role changes for propagation (section 16.2) |
Governance
| Object | Represents |
|---|---|
| CertificationGroup | The campaign-level container that ties certifications from one schedule together |
| Certification | One access review, with a certifier, phase, and dates |
| CertificationEntity | The thing being certified within a review, such as an identity, a role, or an account group |
| CertificationItem | One line item, such as a role, entitlement, or policy violation, with its decision (action) |
| Policy | A policy definition with its rules (section 7.1) |
| PolicyViolation | A detected violation with status and mitigation (allowed-until) information |
| MitigationExpiration | Tracks when an allowed exception expires |
Processes and Requests
| Object | Represents |
|---|---|
| Workflow | A business process definition |
| WorkflowCase | A running workflow for one target, carrying its WorkflowContext state |
| WorkItem | A task in someone's inbox: approval, form, manual action, remediation, and so on |
| IdentityRequest | The tracking record of an LCM request, categorized as an access request, password request, identity change request, or identity request. It survives after the workflow's TaskResult is pruned. |
| TaskDefinition | A task or report definition (reports are TaskDefinitions of type LiveReport) |
| TaskResult | The outcome of a task, report, or workflow run |
| Request / RequestDefinition | Background work items, such as partitions and retries, and their per-type processing settings (threads and hosts) |
| ProvisioningPlan / ProvisioningProject | The requested change, and the compiled per-application plan (section 4.2) |
Configuration Objects
| Object | Holds |
|---|---|
| Rule | BeanShell logic, including rule libraries |
| Form | Shared forms for workflows and provisioning |
| EmailTemplate | Notification content (section 11.1) |
| ObjectConfig | Extended-attribute definitions per class: Identity, Link, Application, Bundle, ManagedAttribute, CertificationItem |
| UIConfig | UI settings such as columns and account icons |
| Configuration (SystemConfiguration and others) | Global settings, such as email, syslog, and retention |
| Capability / Scope | Rights bundles and visibility boundaries (section 3.3) |
| DynamicScope / QuickLink / QuickLinkOptions | QuickLink populations and links (section 5.2) |
| GroupFactory / GroupDefinition / GroupIndex | Groups and populations (section 17.3) |
| Custom | Free-form key/value data for rules |
Infrastructure Objects
| Object | Holds |
|---|---|
| Server | One per IdentityIQ instance: heartbeat and statistics (section 2.1) |
| ServiceDefinition | Configuration of background services and the hosts they run on |
| AuditEvent (audit records) and syslog events | Audit trail (section 8.3) and captured errors (section 14.2) |
Finding Objects Quickly
The same class names work across every tool:
- Debug pages: choose the class in the Object Browser, for example Link or IdentityRequest, then search by name (section 15.1).
- Console:
list <class> [filter],count <class>, andget <class> <name>. Enterlistwith no arguments to see every class that can be listed (section 14.3). - Code and filters:
context.getObjectByName(ManagedAttribute.class, ...)orFilter.eq("application.name", "AD")(section 9.3). - Reports: a report's data source names an object type, such as
sailpoint.object.Linkfor the Uncorrelated Accounts report (section 8.1).
Some data that looks like a separate object is actually stored inside another one. Role assignments and detections, for example, are recorded on the Identity (and reflected in IdentityEntitlement records), not as separate top-level objects you list in the console. When you cannot find a class, look at the parent object's XML.
Using This Knowledge
When a question asks where to look, map the noun to the object:
- "The account's current attribute values" → Link.
- "Which entitlements a person holds and whether they were requested" → IdentityEntitlement.
- "Owner and description of an AD group" → ManagedAttribute.
- "Why a request is still pending" → IdentityRequest, then its WorkflowCase and WorkItems.
- "What happened in last night's aggregation" → TaskResult.
An auditor asks for the owner and business description of an Active Directory group. Which IdentityIQ object stores them?
ManagedAttribute
Link
Profile
Bundle
Which object tracks the status of a Lifecycle Manager request even after the workflow's TaskResult has been pruned?
WorkItem
TaskDefinition
IdentityRequest
RequestDefinition
In the object model, what class represents a business role, an IT role, and an organizational role?
Role, BusinessRole, and ITRole respectively
ManagedAttribute
Profile
Bundle, for all role types
Where is the difference between a running workflow and its definition represented?
Both are stored in the same Workflow object.
The definition is a TaskResult, and the running instance is a WorkItem.
The definition is a Workflow object, and each running instance is a WorkflowCase.
The definition is a Rule, and the instance is an IdentityRequest.
Sections you finish are checked off in the contents.