8.1 Executing and Leveraging Reports
Key Takeaways
Reports are on Intelligence > Reports, with My Reports, Reports, Scheduled Reports, and Report Results tabs.
Adding filters to a standard report and saving it creates a customized instance on My Reports; the template itself stays on the Reports tab.
A report is a TaskDefinition of type LiveReport run by sailpoint.reporting.LiveReportExecutor, and its output is a TaskResult.
Previous Result Action (Delete, Rename Old, Rename New, Cancel) and Allow Concurrency control what happens when a report runs again.
Report data sources can be Filter, Java, or HQL; Filter is the simplest and runs a projection query.
Executing and Leveraging Reports
Objective 3.5 is execute and leverage reporting. Reports give auditors, managers, and administrators an at-a-glance view of IdentityIQ data, such as uncorrelated accounts, certification decisions, policy violations, and provisioning transactions. They can run on demand or on a schedule.
The Reports UI
Go to Intelligence > Reports:
| Tab | Contents |
|---|---|
| My Reports | Your customized report instances, meaning saved versions of templates with your parameters |
| Reports | All standard report templates, grouped by category, plus any custom report templates |
| Scheduled Reports | Reports scheduled for future or repeated runs |
| Report Results | Completed runs you are allowed to see |
Three Kinds of Report
- Report templates are the out-of-the-box reports on the Reports tab. You can run them directly or use them as a base.
- Custom reports are customer-specific reports built as a new TaskDefinition specification. Once imported, they also appear on the Reports tab.
- Customized report instances are your saved copies with preset parameters, shown on My Reports. If you add filters to a standard report and save it, you create an instance and the template does not change.
The documentation also groups output styles: Detailed reports (grid data you can export to CSV), and Archived and Summary reports (end-of-period audit information, best exported to PDF).
Running, Scheduling, and Distributing
- Run: right-click and choose Execute (progress window, then results) or Execute in background (check the Report Results tab later). Save and Preview lets you adjust the layout, including column order, sort order, and hiding the summary or detail section.
- Schedule: right-click and choose Schedule. Give the schedule a unique name and description so a scheduled run is not overwritten by someone running the same report ad hoc. Frequencies are once, hourly, daily, weekly, monthly, quarterly, or annually.
- Export: export the results to a file. Exported reports do not appear on the Report Results page.
- Delete: deleting a report also deletes its results.
Standard Report Properties
| Property | Purpose |
|---|---|
| Name (required) and Description | Identify the instance |
| Require Signoff | Creates sign-off work items for chosen signers. Results cannot be viewed or downloaded until sign-off is done. Choose a notification template and escalation style (None, Send Reminders, Reminders then Escalation, or Escalation only). |
| Previous Result Action | Delete (overwrite), Rename Old (default; the old result gets a number), Rename New, or Cancel (do not run if a result with this name exists) |
| Allow Concurrency | Lets two identical reports run at once, with the second renamed. Otherwise the second is cancelled. |
| Email Recipient, Email Attachment Format (PDF and/or CSV), Don't email empty reports | Distribution without logging in |
| Maximum results to display | Caps the rows, on some reports |
| Scope | Only identities that control the scope can see the results |
Searches from Advanced Analytics can also be saved as reports (section 8.2). They appear in the Search category on My Reports.
Reports Under the Hood
A report runs as a specialized task:
<TaskDefinition executor="sailpoint.reporting.LiveReportExecutor"
name="Uncorrelated Accounts Report" progressMode="Percentage"
resultAction="Rename" subType="Identity and User Reports"
template="true" type="LiveReport">
type="LiveReport"for all reports, including custom ones, andexecutor="sailpoint.reporting.LiveReportExecutor".template="true"puts the report on the Reports tab. Instances saved from it appear on My Reports.resultActionis the Previous Result Action: Rename, RenameNew, Cancel, or Delete.- Results are stored as TaskResult objects.
The report body, <LiveReport>, defines a DataSource, Columns made of ReportColumnConfig entries, and optional forms, charts, and scripts. Data sources come in three types:
- Filter – the simplest. It runs a projection query on an
objectType, such assailpoint.object.Link, using query parameters, and returns only the properties the columns need. - Java – a Java data source class for complex logic.
- HQL – a Hibernate query.
For example, the Uncorrelated Accounts Report queries Link objects where identity.correlated is false, and shows columns such as nativeIdentity and application.name. To study the real definitions, export them from the console with export taskDefs.xml TaskDefinition, or open them in the Debug pages.
Designing a Custom Report
When no template fits, copy the closest standard report's TaskDefinition and change it, instead of starting from nothing. A custom report has these parts:
- Report form – the parameters users fill in, built with the Forms API, such as applications or date ranges.
- DataSource – where the data comes from (Filter, Java, or HQL), with query parameters bound to the form inputs.
- Columns –
ReportColumnConfigentries with a field, a header message key, the property to read, and sort settings. - Optional scripts or rules – for validation, initialization, extended columns, and charts.
Import the XML (section 3.1) with template="true" and a subType that places it in the right category.
Choosing Reports for Common Needs
| Need | Example standard report or approach |
|---|---|
| Accounts not tied to any identity | Uncorrelated Accounts Report |
| Proof of reviewer decisions | Access review and certification reports, such as decision and sign-off reports |
| Current SOD exposure | Policy violation reports |
| What a role grants and who has it | Role details, role members, and role composition reports |
| Provisioning failures | Provisioning transaction reports, or the Administrator Console (section 15.2) |
| An ad hoc question that no template answers | An Advanced Analytics search saved as a report |
A user adds an application filter to the standard Uncorrelated Accounts Report and saves it. Where does the saved version appear?
On the My Reports tab as a customized report instance, while the standard template remains unchanged on the Reports tab
It replaces the standard template on the Reports tab.
On the Scheduled Reports tab only
Nowhere; filters cannot be saved on standard reports
A weekly scheduled compliance report must never be overwritten when someone runs the same report ad hoc mid-week. What does the documentation recommend?
Set Allow Concurrency so both reports run at the same time.
Give the schedule its own unique name and description so its results are kept separately.
Set the Previous Result Action to Delete.
Export the report instead of scheduling it.
How is a report represented in the IdentityIQ object model?
As a Workflow of type Report, with results stored in WorkItems
As a Rule of type LiveReport
As a TaskDefinition of type LiveReport, executed by LiveReportExecutor, with results stored as TaskResult objects
As an AuditEvent that is replayed when the report runs
Which report data source type runs a projection query against an object type, such as Link, and is the simplest to configure?
Java
HQL
JDBC
Filter
Sections you finish are checked off in the contents.