Blog

Product Updates: Skippable Approvals, Profile Type Duplication Prevention

Author

  • jeff_lakey

    SailPoint

Skippable Approvals in NERM Workflows

The “Skippable Approvals” configuration option is intended to allow the workflow to bypass an Approval step if the Requester is also designated as an Approver. The intent of this feature is to eliminate a redundant step when the requester’s approval can be assumed.

However, there were certain scenarios where the approval was still being generated for the Requester when this option was enabled. Often this would happen if there was a workflow step between the request and the approval in which an action was performed by someone other than the Requester.

We have taken steps to correct this behavior to align with our stated functionality and user expectations.

After this update, when the Skippable Approvals option is enabled, the Requester will not receive an approval, even if preceded by one of the following actions:

  • Registration Invitation
  • Approval Action (when the approver is someone other than the Requester)
  • Fulfillment Form (when the performer is someone other than the Requester)
  • Duplication Prevention workflow action (when the performer is someone other than the Requester)
  • Contributors action (when a performer other than the Requester selects an owner/contributor)
  • Run workflow Action (when waiting for completion)

Duplication Checking in Profile Type Configuration

Profile Type Duplication Prevention will now behave similarly to the Duplication Prevention Workflow Action.

Previously, Profile Type Duplication Prevention action did not filter out blank values for attributes that were selected for Duplication Protection.

Example:

  • Duplication Protection Attributes: First Name, Middle Name, Last Name
  • Profile 1: “James”, “A”, “Smith”
  • Profile 2: “James”, “”, “Smith”

Prior to this update, these profiles would not have been flagged as potential duplicates.

After this update, these profiles will be flagged as potential duplicates. This is consistent with the way Duplication Prevention works in workflow actions – blank attribute values are ignored.

This change has the potential to expand potential duplicate result sets, as missing attribute data will broaden the scope. As a best practice, our recommendation would be to make any Attribute that is marked for Duplication Protection a required attribute on the profile.

These changes will be enabled in customer development/sandbox tenants the week of May 20th. Enablement in production will start the following week.