10.2 Workflow Steps That Generate Work Items

Key Takeaways

  • Approval steps, form steps, provisioning-form subprocesses, and manual-action subprocesses are the workflow constructs that put work items in someone's inbox.

  • A step holds either an action or an approval, never both.

  • Send lists pass workflow variables into the work item, and Return lists copy values back when it completes.

  • Approval mode (serial, serialPoll, parallel, parallelPoll, any) controls how multiple owners are asked; poll modes need AfterScript logic to decide the outcome.

  • Work item configuration on an approval can override the notification template and set reminders and escalation; child approvals inherit it unless they override it.

Last updated: September 2026

Workflow Steps That Generate Work Items

Objective 4.4 asks you to understand workflow steps that generate work items. A work item is a task in someone's IdentityIQ inbox (the bell icon). When a workflow needs a human decision or data, it creates a work item and waits. The WorkflowCase is saved so it can resume when the item is completed.

Which Workflow Constructs Create Work Items?

ConstructWork item typeExample
Approval step (a step containing <Approval>)ApprovalManager approval in LCM Provisioning
Form step (an approval that presents a form)FormAsk the requester for a business justification
Do Provisioning Forms subprocessFormAsk for missing account attributes (section 4.2)
Do Manual Actions subprocessManual ActionAsk an application owner to change a system with no connector
Policy violation handling (a violation business process)Policy ViolationViolation review from a workflow (section 7.2)

Other work item types exist outside workflows: Access Review, Challenge, Delegation, Remediation, Request Violation, Impact Analysis, and Signoff.

Approval Steps

A step holds either an action or an approval, never both. Add one in the Process Designer with right-click > Add Approval:

<Step icon="Approval" name="Manager Approval">
  <Approval mode="serial" owner="script:getManagerName(identityName, launcher, fallbackApprover);"
            send="approvalSet,identityDisplayName,identityName,policyViolations"
            renderer="lcmWorkItemRenderer.xhtml">
    <Arg name="workItemDescription" value="Manager Approval - Account Changes for User: $(identityDisplayName)"/>
    <Arg name="workItemNotificationTemplate" value="ref:managerEmailTemplate"/>
    <AfterScript>
      <Source>
        assimilateWorkItemApprovalSet(wfcontext, item, approvalSet);
        auditDecisions(item);
      </Source>
    </AfterScript>
  </Approval>
  <Transition to="Build Owner ApprovalSet"
      when="script:isApprovalEnabled(approvalScheme, &quot;owner&quot;)"/>
  <Transition to="end"/>
</Step>

This excerpt is from the documentation's LCM example, lightly trimmed. Its RuleLibraries declares Approval Library and LCM Workflow Library so that the AfterScript can call those methods.

Approval settingPurpose
OwnerWho receives the item: an identity or workgroup name from a string, reference, script, rule, or call. Several owners are allowed.
ModeHow multiple owners are asked (below)
SendComma-separated workflow variables copied into the work item
ReturnComma-separated variables copied back when the item completes
RendererJSF include used to display the item. Not needed with the default renderer.
DescriptionShown as the work item name in the inbox
ArgsValues that need transformation (script, rule, call) or reserved names such as workItemDescription
AfterScriptRuns after each completion. It records decisions, audits them, and for poll modes decides the outcome.

Approval Modes

  • serial: one owner at a time, in order. Any rejection rejects.
  • serialPoll: one at a time. All responses are collected, and the AfterScript decides.
  • parallel: all owners at once. Any rejection rejects.
  • parallelPoll: all at once. Responses are collected, and the AfterScript decides.
  • any: all at once. The first response decides for the group.

Child Approvals

Add Child Approval builds structured approvals. For example, one child approval could go to "any HR approver" (mode any) and another to the identity's manager. The parent then only organizes its children and is no longer an approval itself. Children inherit the parent's work item configuration unless they override it.

Work Item Configuration

On the approval's Work Item Configuration tab, choose Override Work Item Configuration to set the Initial Notification Email and an escalation style: None, Send Reminders, Reminders then Escalation (using an escalation owner rule), or Escalation Only. Override Electronic Signature Configuration requires an electronic signature on the decision.

Designing an Approval: A Checklist

  1. Who approves? Resolve the owner with a script or call (for example, the manager, with a fallback approver) so a missing manager does not leave the item without an owner.
  2. How do several approvers interact? Pick the mode. Use any for a pool such as "any HR partner," serial for a strict chain, and a poll mode only if you will write AfterScript logic.
  3. What does the approver need to see? Put those variables in Send, and add a clear workItemDescription using $() references.
  4. What must come back? List the decisions or comments in Return, or assimilate them in the AfterScript as LCM does with its approval set.
  5. What if nobody acts? Configure reminders and escalation on the Work Item Configuration tab.

Form Steps

Choose Add Form on a step to reference a shared Form object or create one inline. You set a Description, Send (variables used as initial field values), Return (fields copied back into variables), and an Owner. Fields use the same editor as provisioning policies, although Owner, Display Only, and Authoritative do not apply to workflow forms. Buttons define what happens on submit:

Button actionResult
NextAssimilates the data and advances. The approval is set to Approved.
BackAssimilates the data and returns. The approval is set to Rejected and the workflow advances.
CancelLeaves the page. The work item stays active.
RefreshAssimilates the data and regenerates the form. This is not a state change.

Work Item Settings Outside the Workflow

Global Settings > IdentityIQ Configuration > Work Items sets defaults: days before expiration, reminder timing and frequency, notices before escalation, assignment emails, priority editing, which work item types are archived, and rules such as the inactive user work item escalation rule, the global forwarding rule, and the self-certification forwarding rule. The Perform Maintenance task's Forward inactive user work items option forwards items owned by inactive users: by rule, otherwise to their manager, otherwise to the Administrator. Work item actions can be audited (section 8.3).

Test Your Knowledge

A workflow step must run a BeanShell script and also create an approval work item. How must it be built?

A

Put both the action attribute and the Approval element in the same step.

B

Use two steps, because a step can contain an action or an approval, but not both.

C

Use a step condition to combine them.

D

Put the script in the approval's Send list.

Test Your Knowledge

An approval uses parallelPoll mode with three owners. Two approve and one rejects. What determines the outcome?

A

The single rejection automatically rejects the item.

B

The first response received decides the outcome.

C

The logic in the approval's AfterScript, because poll modes collect responses without deciding automatically.

D

The item is approved because a majority approved.

Test Your Knowledge

What does the Return list on an approval or form step do?

A

It copies named values from the completed work item back into workflow variables.

B

It returns the work item to the previous owner.

C

It lists the steps to return to if the item is rejected.

D

It sets the work item's expiration date.

Test Your Knowledge

On a workflow form, which button action leaves the work item active without changing its state?

A

Next

B

Back

C

Refresh

D

Cancel

Sections you finish are checked off in the contents.