17.2 Relationships Between Common Data Object Models
Key Takeaways
One Identity has many Links; each Link belongs to exactly one Application and at most one Identity; a Link with no identity is an uncorrelated account.
A Link's entitlement values correspond to ManagedAttributes of the same application, attribute, and value, and group aggregation creates those catalog entries.
Identities reference roles in two ways: assigned roles (from rules or requests) and detected roles (from matching IT role profiles to Link entitlements).
Roles relate to other roles through required, permitted, and inheritance links, and to entitlements through Profiles tied to an Application.
Governance and process objects (certifications, violations, requests, work items) always point back to an Identity and are driven by refresh, certification, and workflow processes.
Relationships Between Common Data Object Models
Objective 7.6 asks you to understand the relationship between common data object models. Section 17.1 named the objects. This section connects them, which is what scenario questions test: if X changes, what else changes, and which process makes it happen?
The Core Identity-Account-Entitlement Chain
| Relationship | Cardinality | Created or maintained by |
|---|---|---|
| Application → Link | One application, many accounts | Account aggregation |
| Identity → Link | One identity, many accounts. Each Link belongs to at most one identity. | Correlation (configuration or rule), creation from authoritative sources, manual correlation |
| Application → ManagedAttribute | One application, many catalog entries | Account group aggregation, Promote managed attributes, catalog import |
| Link entitlement value → ManagedAttribute | Matched by application + attribute + value | Aggregation, with the schema's Managed flag (section 12.2) |
| Identity → IdentityEntitlement | One identity, many entitlement records | Aggregation and refresh (connected state), requests, certifications |
| Identity → Manager (Identity) | Many identities, one manager | Manager correlation, and the manager identity attribute |
Correlation Results
- Authoritative application account with no match: a new Identity is created (Creation rule) and the Link is attached.
- Non-authoritative account with no match: the Link stays uncorrelated until correlation logic improves or someone manually correlates it. Manual correlation is permanent (section 12.1).
- Aggregation actions such as Correlate Reassign show a Link moving from one identity to another.
The Role Relationships
| Relationship | Meaning |
|---|---|
| Identity → Bundle (assigned) | Business roles granted by assignment rules (refresh), requests (LCM or batch), or administrators |
| Identity → Bundle (detected) | IT roles whose Profiles match the identity's Link entitlements (refresh) |
| Bundle → Bundle (required / permitted) | Business-to-IT links that drive provisioning or pre-approval |
| Bundle → Bundle (inheritance) | Deeper roles inherit shallower ones of the same type |
| Bundle → Profile → Application | Profiles define entitlement filters for one application |
How a change ripples: a new assigned business role leads, through required IT roles and profiles, to a provisioning plan for missing entitlements. Once the entitlements exist on the target, the next aggregation updates the Link, and refresh records the IT role as detected. Provisioning alone does not update role detections. A refresh is needed.
Governance and Process Relationships
| From | To | Notes |
|---|---|---|
| CertificationGroup → Certification → CertificationEntity → CertificationItem | Nested | Items reference the identity, Link, role, entitlement, or violation under review. Revocations create provisioning plans through Perform Maintenance or Process Revokes Immediately. |
| Policy → PolicyViolation → Identity | Many violations per policy | Created by refresh or aggregation with Check active policies |
| IdentityRequest → WorkflowCase → WorkItem | One request, one case, many work items | LCM requests (section 4.3) |
| TaskDefinition → TaskResult | One definition, many runs | Tasks, reports, and workflows |
| Identity (workgroup) → member Identities | Many-to-many | Workgroups share ownership, work items, capabilities, and scopes |
| Capability / Scope → Identity or workgroup | Many-to-many | Rights and visibility (section 3.3) |
| ObjectConfig → a class's extended attributes | One per class | Identity, Link, Application, Bundle, ManagedAttribute, CertificationItem |
Ownership and References
Many objects point to an owner, which is always an Identity, either a person or a workgroup:
- Application owner and revoker receive certifications, entitlement approvals, and revocations (section 12.1).
- ManagedAttribute owner approves entitlement requests and reviews entitlement owner certifications.
- Bundle owner approves role changes and role requests and reviews role certifications.
- Policy owner and policy violation owner maintain policies and act on violations (section 7.1).
Because these are references, deleting or deactivating an identity can leave objects without a working owner. That is why Rapid Setup's leaver process can reassign artifacts (applications, workgroups, policies) and identities (service accounts and bots) owned by a departing user, and why the Prune Identity Cubes task protects owners, managers, and identities with capabilities from deletion.
Reading Relationships in XML
In object XML, relationships appear as references by class and name or ID, for example <Reference class="sailpoint.object.Application" name="Active Directory"/> inside a Link or a Profile. When objects move between environments, references by name survive but database IDs do not. That is why -clean and -noids exist (section 3.1).
Walking a Scenario Through the Model
HR moves Maria from Sales to Finance.
- HR aggregation updates Maria's HR Link attributes and marks her identity as needing refresh.
- Identity Refresh promotes the new
departmentto her Identity through the identity mappings (section 16.3). - The same refresh re-evaluates assignment rules: the Sales Rep business role is removed and Finance Analyst is assigned.
- With Provision assignments, a ProvisioningPlan adds the Finance IT roles' entitlements and, unless retention options apply, removes Sales entitlements. Plans compile per Application.
- Process Events fires a mover lifecycle event, launching a WorkflowCase with a WorkItem for her new manager.
- Check active policies may create a PolicyViolation if old and new access conflict.
- The next aggregations confirm the target changes on her Links, and the next refresh updates detected roles and IdentityEntitlements.
Each step touches a different object, and each object relationship is maintained by a specific process. That is the core idea behind objective 7.6.
A non-authoritative AD account does not match any identity during aggregation. How is it represented in IdentityIQ?
A new Identity is always created for it.
As a Link with no owning identity (an uncorrelated account) until correlation succeeds or someone manually correlates it
As a ManagedAttribute in the Entitlement Catalog
It is discarded until the next full aggregation.
A new business role was assigned and its required entitlements were provisioned successfully, but the IT role does not yet appear as detected. Why?
Provisioning does not update role detections; a later aggregation and an Identity Refresh must record the entitlements and detect the IT role.
IT roles can never be detected after provisioning.
Detection happens only in certifications.
The business role must first be made requestable.
How does IdentityIQ relate an entitlement value on a Link to an Entitlement Catalog entry?
By the Link's native identity
By the identity's manager
By the role's Profile name
By matching the application, attribute, and value to a ManagedAttribute
Which chain correctly shows how certification data is nested?
Certification → CertificationGroup → CertificationItem → CertificationEntity
CertificationItem → Certification → CertificationGroup
CertificationGroup → Certification → CertificationEntity → CertificationItem
Policy → Certification → WorkItem
Sections you finish are checked off in the contents.