IT CanvassTalk to an advisor
Architecture · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Approval flow

How approvals are routed, escalated and recorded for access changes.

Quick answer

Work items are generated for approvers based on ownership rules; approvals or rejections are recorded and drive the next step.

Key takeaways
  • Purpose: route access decisions to the right people and record them
  • Trigger: An access change needing sign-off
  • Outcome: A recorded approval or rejection that drives the next step
  • Where it fits in the SailPoint architecture

The approval flow governs how access decisions are routed to the right people, acted on, and recorded. Approvals are the human control point in provisioning and access requests, and the quality of their design determines whether sign-off is a meaningful check or empty ceremony.

What triggers an approval

Any access change that policy or configuration says needs sign-off generates approvals: an access request, a role assignment, a policy exception, or a sensitive lifecycle change. The change pauses until the approval is resolved.

Step by step

  • 1. Work item generation. The change creates one or more approval work items.
  • 2. Routing. Each work item goes to the correct approver, determined by ownership rules (role owner, application owner, the requester's manager) or workflow logic.
  • 3. Decision. The approver approves, rejects or forwards/reassigns the item, ideally with a comment.
  • 4. Escalation. If an approver does not act within a defined time, the item escalates, to a backup approver or up the chain, so inaction cannot stall the process indefinitely.
  • 5. Record and proceed. The decision is written to the audit trail and drives the next step, provisioning on approval, closure on rejection.

Designing approvals that mean something

Two design choices separate real governance from theatre:

  • Route to someone who can actually judge. The approver must have the context to decide, a role owner who understands what the role grants, not a distant manager clicking approve on everything.
  • Give the approver context. Show what the access is, why it was requested, and any policy warnings, so the decision is informed.

Escalation and accountability

Escalation is what keeps the process moving and, just as importantly, creates accountability, an unactioned approval is visible and gets reassigned rather than silently blocking a new hire's access for days. Every decision, and every escalation, is logged, which is what makes approvals defensible to auditors.

Common pitfalls

  • Approval fatigue leading to rubber-stamping; scope approvals to genuinely sensitive access.
  • Routing to uninformed approvers who cannot really judge the request.
  • No escalation, so a single unresponsive approver stalls the whole flow.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What triggers the approval flow?

Frequently asked questions

What does the term Approval flow refer to in SailPoint?
The approval flow governs how access decisions are routed to the right people, acted on, and recorded. Approvals are the human control point in provisioning and access requests, and the quality of their design determines whether sign-off is a meaningful check or empty ceremony.
Where do rules or workflows touch Approval flow?
1. Work item generation. The change creates one or more approval work items. 2. Routing. Each work item goes to the correct approver, determined by ownership rules (role owner, application owner, the requester's manager) or workflow logic. 3. Decision.
What is another point to note about Approval flow?
Any access change that policy or configuration says needs sign-off generates approvals: an access request, a role assignment, a policy exception, or a sensitive lifecycle change.
What tends to go wrong with Approval flow?
Routing to uninformed approvers who cannot really judge the request. No escalation, so a single unresponsive approver stalls the whole flow.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support