Skip to content
IT Canvass
Architecture · Lesson

Approval flow

Quick answer

Work items are generated for approvers based on ownership rules; approvals or rejections are recorded and drive the next step.

Key takeaways

  • Purpose: route access decisions to the right people and record them
  • Trigger: An access change needing sign-off
  • Outcome: A recorded approval or rejection that drives the next step
  • Where it fits in the SailPoint architecture

The approval flow governs how access decisions are routed to the right people, acted on, and recorded. Approvals are the human control point in provisioning and access requests, and the quality of their design determines whether sign-off is a meaningful check or empty ceremony.

What triggers an approval

Any access change that policy or configuration says needs sign-off generates approvals: an access request, a role assignment, a policy exception, or a sensitive lifecycle change. The change pauses until the approval is resolved.

Step by step

  • 1. Work item generation. The change creates one or more approval work items.
  • 2. Routing. Each work item goes to the correct approver, determined by ownership rules (role owner, application owner, the requester's manager) or workflow logic.
  • 3. Decision. The approver approves, rejects or forwards/reassigns the item, ideally with a comment.
  • 4. Escalation. If an approver does not act within a defined time, the item escalates, to a backup approver or up the chain, so inaction cannot stall the process indefinitely.
  • 5. Record and proceed. The decision is written to the audit trail and drives the next step, provisioning on approval, closure on rejection.

Designing approvals that mean something

Two design choices separate real governance from theatre:

  • Route to someone who can actually judge. The approver must have the context to decide, a role owner who understands what the role grants, not a distant manager clicking approve on everything.
  • Give the approver context. Show what the access is, why it was requested, and any policy warnings, so the decision is informed.

Escalation and accountability

Escalation is what keeps the process moving and, just as importantly, creates accountability, an unactioned approval is visible and gets reassigned rather than silently blocking a new hire's access for days. Every decision, and every escalation, is logged, which is what makes approvals defensible to auditors.

Common pitfalls

  • Approval fatigue leading to rubber-stamping; scope approvals to genuinely sensitive access.
  • Routing to uninformed approvers who cannot really judge the request.
  • No escalation, so a single unresponsive approver stalls the whole flow.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. What triggers the approval flow?

    • A. An access change needing sign-off
    • B. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
    • C. A recorded approval or rejection that drives the next step
    Show answer

    A. An access change needing sign-off

    An access change needing sign-off

  2. What is the outcome of the approval flow?

    • A. A recorded approval or rejection that drives the next step
    • B. An access change needing sign-off
    • C. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
    Show answer

    A. A recorded approval or rejection that drives the next step

    A recorded approval or rejection that drives the next step

  3. Where does this flow run?

    • A. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
    • B. An access change needing sign-off
    • C. A recorded approval or rejection that drives the next step
    Show answer

    A. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.

    Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.

Frequently asked questions

What does the term Approval flow refer to in SailPoint?

The approval flow governs how access decisions are routed to the right people, acted on, and recorded. Approvals are the human control point in provisioning and access requests, and the quality of their design determines whether sign-off is a meaningful check or empty ceremony.

Where do rules or workflows touch Approval flow?

1. Work item generation. The change creates one or more approval work items. 2. Routing. Each work item goes to the correct approver, determined by ownership rules (role owner, application owner, the requester's manager) or workflow logic. 3. Decision.

What is another point to note about Approval flow?

Any access change that policy or configuration says needs sign-off generates approvals: an access request, a role assignment, a policy exception, or a sensitive lifecycle change.

What tends to go wrong with Approval flow?

Routing to uninformed approvers who cannot really judge the request. No escalation, so a single unresponsive approver stalls the whole flow.
CallWhatsAppEnquire