Approval flow
Quick answer
Work items are generated for approvers based on ownership rules; approvals or rejections are recorded and drive the next step.
Key takeaways
- Purpose: route access decisions to the right people and record them
- Trigger: An access change needing sign-off
- Outcome: A recorded approval or rejection that drives the next step
- Where it fits in the SailPoint architecture
The approval flow governs how access decisions are routed to the right people, acted on, and recorded. Approvals are the human control point in provisioning and access requests, and the quality of their design determines whether sign-off is a meaningful check or empty ceremony.
What triggers an approval
Any access change that policy or configuration says needs sign-off generates approvals: an access request, a role assignment, a policy exception, or a sensitive lifecycle change. The change pauses until the approval is resolved.
Step by step
- 1. Work item generation. The change creates one or more approval work items.
- 2. Routing. Each work item goes to the correct approver, determined by ownership rules (role owner, application owner, the requester's manager) or workflow logic.
- 3. Decision. The approver approves, rejects or forwards/reassigns the item, ideally with a comment.
- 4. Escalation. If an approver does not act within a defined time, the item escalates, to a backup approver or up the chain, so inaction cannot stall the process indefinitely.
- 5. Record and proceed. The decision is written to the audit trail and drives the next step, provisioning on approval, closure on rejection.
Designing approvals that mean something
Two design choices separate real governance from theatre:
- Route to someone who can actually judge. The approver must have the context to decide, a role owner who understands what the role grants, not a distant manager clicking approve on everything.
- Give the approver context. Show what the access is, why it was requested, and any policy warnings, so the decision is informed.
Escalation and accountability
Escalation is what keeps the process moving and, just as importantly, creates accountability, an unactioned approval is visible and gets reassigned rather than silently blocking a new hire's access for days. Every decision, and every escalation, is logged, which is what makes approvals defensible to auditors.
Common pitfalls
- Approval fatigue leading to rubber-stamping; scope approvals to genuinely sensitive access.
- Routing to uninformed approvers who cannot really judge the request.
- No escalation, so a single unresponsive approver stalls the whole flow.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What triggers the approval flow?
- A. An access change needing sign-off
- B. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
- C. A recorded approval or rejection that drives the next step
Show answer
A. An access change needing sign-off
An access change needing sign-off
What is the outcome of the approval flow?
- A. A recorded approval or rejection that drives the next step
- B. An access change needing sign-off
- C. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
Show answer
A. A recorded approval or rejection that drives the next step
A recorded approval or rejection that drives the next step
Where does this flow run?
- A. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
- B. An access change needing sign-off
- C. A recorded approval or rejection that drives the next step
Show answer
A. Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.
Inside the IdentityIQ engine, coordinated by tasks, connectors and the provisioning subsystem.