There is currently no data policy that can detect attribute changes.

User Access Reviews are currently not selectable for the microcertification action but this would make a lot of sense.

Sample: department change use case; trigger a user access review on department change, perhaps
taking the grace period into account; one could do this by an IDM indicator attribute but
it would be better do it this in IG alone.

Comments

  • This would help with a very important regulatory compliance use case. Most compliance frameworks, such as ISO27001, HITRUST, etc all require a review for the "mover" use case. From a data perspective, this will be identified by a change in specific attributes.

    Currently, we use Identity Manager to toggle a flag on the account to trigger a data policy. I'd prefer to not need this 'workaround' and have IG natively detect it.