17.2 Relationships Between Common Data Object Models

Key Takeaways

  • One Identity has many Links; each Link belongs to exactly one Application and at most one Identity; a Link with no identity is an uncorrelated account.

  • A Link's entitlement values correspond to ManagedAttributes of the same application, attribute, and value, and group aggregation creates those catalog entries.

  • Identities reference roles in two ways: assigned roles (from rules or requests) and detected roles (from matching IT role profiles to Link entitlements).

  • Roles relate to other roles through required, permitted, and inheritance links, and to entitlements through Profiles tied to an Application.

  • Governance and process objects (certifications, violations, requests, work items) always point back to an Identity and are driven by refresh, certification, and workflow processes.

Last updated: September 2026

Relationships Between Common Data Object Models

Objective 7.6 asks you to understand the relationship between common data object models. Section 17.1 named the objects. This section connects them, which is what scenario questions test: if X changes, what else changes, and which process makes it happen?

The Core Identity-Account-Entitlement Chain

Loading diagram...
Core object relationships
RelationshipCardinalityCreated or maintained by
Application → LinkOne application, many accountsAccount aggregation
Identity → LinkOne identity, many accounts. Each Link belongs to at most one identity.Correlation (configuration or rule), creation from authoritative sources, manual correlation
Application → ManagedAttributeOne application, many catalog entriesAccount group aggregation, Promote managed attributes, catalog import
Link entitlement value → ManagedAttributeMatched by application + attribute + valueAggregation, with the schema's Managed flag (section 12.2)
Identity → IdentityEntitlementOne identity, many entitlement recordsAggregation and refresh (connected state), requests, certifications
Identity → Manager (Identity)Many identities, one managerManager correlation, and the manager identity attribute

Correlation Results

  • Authoritative application account with no match: a new Identity is created (Creation rule) and the Link is attached.
  • Non-authoritative account with no match: the Link stays uncorrelated until correlation logic improves or someone manually correlates it. Manual correlation is permanent (section 12.1).
  • Aggregation actions such as Correlate Reassign show a Link moving from one identity to another.

The Role Relationships

RelationshipMeaning
Identity → Bundle (assigned)Business roles granted by assignment rules (refresh), requests (LCM or batch), or administrators
Identity → Bundle (detected)IT roles whose Profiles match the identity's Link entitlements (refresh)
Bundle → Bundle (required / permitted)Business-to-IT links that drive provisioning or pre-approval
Bundle → Bundle (inheritance)Deeper roles inherit shallower ones of the same type
Bundle → Profile → ApplicationProfiles define entitlement filters for one application

How a change ripples: a new assigned business role leads, through required IT roles and profiles, to a provisioning plan for missing entitlements. Once the entitlements exist on the target, the next aggregation updates the Link, and refresh records the IT role as detected. Provisioning alone does not update role detections. A refresh is needed.

Governance and Process Relationships

FromToNotes
CertificationGroup → Certification → CertificationEntity → CertificationItemNestedItems reference the identity, Link, role, entitlement, or violation under review. Revocations create provisioning plans through Perform Maintenance or Process Revokes Immediately.
Policy → PolicyViolation → IdentityMany violations per policyCreated by refresh or aggregation with Check active policies
IdentityRequest → WorkflowCase → WorkItemOne request, one case, many work itemsLCM requests (section 4.3)
TaskDefinition → TaskResultOne definition, many runsTasks, reports, and workflows
Identity (workgroup) → member IdentitiesMany-to-manyWorkgroups share ownership, work items, capabilities, and scopes
Capability / Scope → Identity or workgroupMany-to-manyRights and visibility (section 3.3)
ObjectConfig → a class's extended attributesOne per classIdentity, Link, Application, Bundle, ManagedAttribute, CertificationItem

Ownership and References

Many objects point to an owner, which is always an Identity, either a person or a workgroup:

  • Application owner and revoker receive certifications, entitlement approvals, and revocations (section 12.1).
  • ManagedAttribute owner approves entitlement requests and reviews entitlement owner certifications.
  • Bundle owner approves role changes and role requests and reviews role certifications.
  • Policy owner and policy violation owner maintain policies and act on violations (section 7.1).

Because these are references, deleting or deactivating an identity can leave objects without a working owner. That is why Rapid Setup's leaver process can reassign artifacts (applications, workgroups, policies) and identities (service accounts and bots) owned by a departing user, and why the Prune Identity Cubes task protects owners, managers, and identities with capabilities from deletion.

Reading Relationships in XML

In object XML, relationships appear as references by class and name or ID, for example <Reference class="sailpoint.object.Application" name="Active Directory"/> inside a Link or a Profile. When objects move between environments, references by name survive but database IDs do not. That is why -clean and -noids exist (section 3.1).

Walking a Scenario Through the Model

HR moves Maria from Sales to Finance.

  1. HR aggregation updates Maria's HR Link attributes and marks her identity as needing refresh.
  2. Identity Refresh promotes the new department to her Identity through the identity mappings (section 16.3).
  3. The same refresh re-evaluates assignment rules: the Sales Rep business role is removed and Finance Analyst is assigned.
  4. With Provision assignments, a ProvisioningPlan adds the Finance IT roles' entitlements and, unless retention options apply, removes Sales entitlements. Plans compile per Application.
  5. Process Events fires a mover lifecycle event, launching a WorkflowCase with a WorkItem for her new manager.
  6. Check active policies may create a PolicyViolation if old and new access conflict.
  7. The next aggregations confirm the target changes on her Links, and the next refresh updates detected roles and IdentityEntitlements.

Each step touches a different object, and each object relationship is maintained by a specific process. That is the core idea behind objective 7.6.

Test Your Knowledge

A non-authoritative AD account does not match any identity during aggregation. How is it represented in IdentityIQ?

A

A new Identity is always created for it.

B

As a Link with no owning identity (an uncorrelated account) until correlation succeeds or someone manually correlates it

C

As a ManagedAttribute in the Entitlement Catalog

D

It is discarded until the next full aggregation.

Test Your Knowledge

A new business role was assigned and its required entitlements were provisioned successfully, but the IT role does not yet appear as detected. Why?

A

Provisioning does not update role detections; a later aggregation and an Identity Refresh must record the entitlements and detect the IT role.

B

IT roles can never be detected after provisioning.

C

Detection happens only in certifications.

D

The business role must first be made requestable.

Test Your Knowledge

How does IdentityIQ relate an entitlement value on a Link to an Entitlement Catalog entry?

A

By the Link's native identity

B

By the identity's manager

C

By the role's Profile name

D

By matching the application, attribute, and value to a ManagedAttribute

Test Your Knowledge

Which chain correctly shows how certification data is nested?

A

Certification → CertificationGroup → CertificationItem → CertificationEntity

B

CertificationItem → Certification → CertificationGroup

C

CertificationGroup → Certification → CertificationEntity → CertificationItem

D

Policy → Certification → WorkItem

Sections you finish are checked off in the contents.