Skip to content
IT Canvass
Objects · Lesson

Approval

Quick answer

An Approval is a work item asking a person to approve or reject an access change, recorded for audit.

Key takeaways

  • What the Approval object represents
  • Key attributes and relationships
  • How it is created and maintained
  • Where it appears in governance

An Approval is a work item that asks a specific person to approve or reject an access change, and records their decision for audit. Approvals are the human checkpoint in access requests, provisioning and policy exceptions, and their design determines whether sign-off is a real control or a formality.

What an approval represents

Each approval is a pending decision routed to an approver. The approver can approve, reject, or forward/reassign it, ideally adding a comment. The outcome drives the next step, provisioning on approval, closure on rejection, and is written to the audit trail.

Routing and ownership

Approvals are routed by ownership or workflow logic: to a role owner, an application/resource owner, the requester’s manager, or a defined approver chain. The guiding principle is to route to someone with the context to actually judge the request, not a distant manager who will reflexively approve.

Escalation and accountability

If an approver does not act within a defined time, the approval escalates, to a backup or up the chain, so inaction cannot silently block a new hire’s access. Escalation also creates accountability: an unactioned item is visible and reassigned rather than lost.

Approvals as audit evidence

Every approval decision, with approver, timestamp and comment, is logged. This record demonstrates that access changes went through a controlled, human review, which is exactly what auditors want to see.

Common pitfalls

  • Approval fatigue leading to rubber-stamping; scope approvals to genuinely sensitive access.
  • Routing to uninformed approvers.
  • No escalation, letting one unresponsive person stall the process.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. What is an Approval?

    • A. A work item asking someone to approve or reject an access change.
    • B. Approve, reject or forward the request.
    • C. Their recorded outcomes are compliance evidence.
    Show answer

    A. A work item asking someone to approve or reject an access change.

    A work item asking someone to approve or reject an access change.

  2. What can an approver do?

    • A. Their recorded outcomes are compliance evidence.
    • B. Approve, reject or forward the request.
    • C. A work item asking someone to approve or reject an access change.
    Show answer

    B. Approve, reject or forward the request.

    Approve, reject or forward the request.

  3. Why do approvals matter for audit?

    • A. A work item asking someone to approve or reject an access change.
    • B. Approve, reject or forward the request.
    • C. Their recorded outcomes are compliance evidence.
    Show answer

    C. Their recorded outcomes are compliance evidence.

    Their recorded outcomes are compliance evidence.

Frequently asked questions

What does the term Approval object refer to in SailPoint?

An Approval is a work item that asks a specific person to approve or reject an access change, and records their decision for audit.

What else is worth knowing about Approval object?

The approver can approve, reject, or forward/reassign it, ideally adding a comment.

What is the practical takeaway on Approval object?

The outcome drives the next step, provisioning on approval, closure on rejection, and is written to the audit trail.

What tends to go wrong with Approval object?

Routing to uninformed approvers. No escalation, letting one unresponsive person stall the process.
CallWhatsAppEnquire