Filters and outputs for Identity Governance reports
Learn what filters and output are available for Identity Governance reports.
Staged campaign summary report
The following tables provide the available filters and outputs for the Staged campaign summary report.
Filters
| Field | Value |
|---|---|
| Campaign id | Enter the unique identifier for the campaign. You can find a campaign's ID from System Log events or from the URL for the campaign details page. |
| Campaign name | Enter the name of the campaign to include or exclude. |
| Campaign scheduled to end | Select a date if the operator is before or after. |
| Campaign scheduled to start | Select a date if the operator is before or after. |
| Resource type | Select the type of resource reviewed. |
| Stage Version | Select the stage version of the campaign to filter results by. |
Outputs
| Column header (UI) | Column header (in exported file) | Column description |
|---|---|---|
| Campaign name | campaign.name | Name of the campaign |
| Campaign description | campaign.description | Description of the campaign |
| Campaign id | campaign.id | Unique identifier of the campaign. You can find this in the System Log or from the URL on the campaign's page. |
| Campaign created | campaign.created | Date the campaign was created |
| Campaign scheduled to start | campaign.scheduledStart | Date the campaign is scheduled to launch |
| Campaign scheduled to end | campaign.scheduledEnd | Date the campaign is scheduled to end |
| Duration (days) | campaign.duration | Days between the campaign's scheduled start date and scheduled end date |
| Reviewer type | campaign.reviewerType |
Values indicate the reviewer type:
Note:
Resource owners is an Early Access feature. If your org has Resource owners enabled, Group Owner reviewer type setting is called Resource Owner. Group, app, entitlement, and entitlement bundle owners are considered as resource owners. |
| Resource type | campaign.resourceType |
Values indicate resource types included in the campaign scope:
|
| Resource count | campaign.resourceCount |
Number of resources included in the campaign. For resource campaigns, this field shows the number of resources scoped into the campaign. For user campaigns, this field shows the number of resources (apps and groups) being certified in the campaign. |
| Identity scope | campaign.userScope |
Values indicate if the campaign targets all identities or specific ones, and if any were excluded:
|
| Number of identities | campaign.userCount | Number of distinct identities included in the campaign scope |
| Number of review items | campaign.reviewItemCount | Number of reviews included in the campaign |
| Action if approved | campaign.approvedAction |
Values indicate the remediation action defined by the campaign owner or admin in the campaign wizard for when a reviewer approves access:
|
| Action if revoked | campaign.revokedAction |
Values indicate the remediation action defined by the campaign owner or admin in the campaign wizard for when a reviewer revokes access:
|
| Action if unreviewed | campaign.unreviewedAction |
Values indicate the remediation action defined by the campaign owner or admin in the campaign wizard for when a reviewer doesn't make a decision before the campaign ends:
|
| Transition policy | campaign.levelTransitionPolicy |
Level transition policy of the campaign that defines which review items move to the second level of review. This field is only defined for campaigns with multilevel reviews. Values include:
|
| Level 1 reviewer expression | campaign.level1ReviewerExpression | Reviewer expression of the campaign if Okta Expression Language (OEL) was used to define the Level 1 reviewer. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table. |
| Level 2 reviewer expression | campaign.level2ReviewerExpression | Reviewer expression of the campaign if Okta Expression Language (OEL) was used to define the Level 2 reviewer. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table. |
| Level 1 reviewer type | campaign.reviewerTypeLevel1 | Level 1 reviewer type of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table. |
| Level 2 reviewer type | campaign.reviewerTypeLevel2 | Level 2 reviewer type of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for the Reviewer type in this table. |
| Reviewer expression | campaign.reviewerExpression | Reviewer expression of the campaign if Okta Expression Language (OEL) was used to define the reviewer |
| Reviewer settings | campaign.reviewerSettings |
Values indicate the reviewer settings of the campaign:
|
| Level 1 reviewer settings | campaign.level1ReviewerSettings | Level 1 reviewer settings of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table. |
| Level 2 reviewer settings | campaign.level2ReviewerSettings | Level 2 reviewer settings of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table. |
| Campaign Available | campaign.campaignAvailable | Yes or No value that indicates whether the campaign is available for review. Campaigns are archived one year after their last update. |
| Stage Version | campaign.stageVersion | The stage version of the campaign |
Staged campaign details report
The following tables provide the available filters and outputs for the Staged campaign details report.
Filters
| Field | Value |
|---|---|
| Campaign id | Enter the unique identifier for the campaign. You can find a campaign's ID from System Log events or from the URL for the campaign details page. |
| Campaign name | Enter the name of the campaign to include or exclude. |
| Campaign scheduled to end | Select a date if the operator is before or after. |
| Campaign scheduled to start | Select a date if the operator is before or after. |
| Connected resource type | Select the type of AI agent connected resource that was reviewed. |
| Identity | Select one or more identities. |
| Resource | Select one or more apps or groups. Or, use the Resource name filter instead if you want to find resources that aren't apps or groups, such as service accounts and AI agent connections. |
| Resource name | Enter the name of the resource. Or, use this filter instead of the Resource filter if you want to find resources that aren't apps or groups, such as service accounts and AI agent connections. |
| Resource type | Select the type of resource that's under review. |
| Reviewer | Select one or more reviewers. |
| Reviewer delegated | Select Yes to filter for review items approved or revoked
by a delegate reviewer.
These results are available for this filter only if a delegate has been assigned for the user. |
| Reviewer email | Enter the reviewer's email address. |
| Reviewer reassigned | Select one or more options to indicate if the reviewer was reassigned or not. |
| Stage Version | Select the stage version of the campaign to filter results by. |
| User email | Enter the user's email address. |
| User Identity | Enter the identity's name or username to include or exclude. |
Outputs
| Column header (UI) | Column header (in exported file) | Column description |
|---|---|---|
| Campaign name | campaign.name | Name of the campaign |
| Campaign description | campaign.description | Description of the campaign |
| Campaign id | campaign.id | Unique identifier of the campaign. You can find this in the System Log or from the URL on the campaign's page. |
| Identity | reviewItem.principalUserFullName | Name of the user or AI agent under review |
| User email | reviewItem.principalUserEmail | Email of the user under review |
| Identity id | reviewItem.principalUserId | ID of the identity under review |
| Resource type | reviewItem.resourceType |
Values indicate the type of resource under review:
|
| Resource name | reviewItem.resourceName | Name of the resource under review |
| Resource global name | reviewItem.resourceGlobalName | Okta global name of the resource under review. For apps, this could be the official OIN name of the app or the app type. For example, OpenID Connect Client. |
| Resource id | reviewItem.resourceId | ID of the resource under review |
| App service account name | reviewItem.applicationServiceAccountName | Name of the application service account under review |
| Connected resource type | reviewItem.connectedResourceType | Type of connected resource under review |
| Connected resource details | reviewItem.connectedResourceDetails | Details of the connected resource that's under review |
| Entitlement | reviewItem.entitlementName | Name of the entitlement under review. This value is available only if the app being reviewed has entitlements, and entitlements are included in the resource scope for the campaign. |
| Reviewer | reviewItem.reviewerFullName | Full name of the user who was assigned to make the certification decision |
| Reviewer email | reviewItem.reviewerEmail | Email of the user who was assigned to make the certification decision |
| Reviewer user id | reviewItem.reviewerUserId | ID of the user who was assigned to make the certification decision |
| Original reviewer | reviewItem.originalReviewerFullName | Full name of the user or group who was originally assigned to make the certification decision |
| Original reviewer email | reviewItem.originalReviewerUserEmail | Email of the user who was originally assigned to make the certification decision |
| Original reviewer id | reviewItem.originalReviewerId | ID of the user or group who was originally assigned to make the certification decision |
| Reviewer reassigned | reviewItem.reviewerReassigned | Yes or No value indicates whether the reviewer was reassigned |
| Reviewer delegated | reviewItem.delegated | Yes or No value indicates whether the review item was delegated to and reviewed by a delegate |
| Reviewer status | reviewItem.reviewerStatus | Status of the reviewer on the review item |
| Business justification | reviewItem.businessJustification | Justification left by the reviewer with their decision |
| Campaign scheduled to start | campaign.scheduledStart | Date the campaign is scheduled to start |
| Campaign scheduled to end | campaign.scheduledEnd | Date when the campaign is scheduled to end |
| Level 1 reviewer | reviewItem.level1ReviewerFullName | Name of the Level 1 reviewer |
| Level 1 user ID | reviewItem.level1ReviewerUserId | User ID of the Level 1 reviewer |
| Level 1 reviewer email | reviewItem.level1ReviewerEmail | Email of the Level 1 reviewer |
| Level 1 original reviewer | reviewItem.level1originalReviewerFullName | Name of the Level 1 original reviewer (user or group) |
| Level 1 original reviewer id | reviewItem.level1originalReviewerId | ID of the Level 1 original reviewer (user or group) |
| Level 1 original reviewer email | reviewItem.level1originalReviewerEmail | Email of the Level 1 original reviewer |
| Level 1 reviewer status | reviewItem.level1ReviewerStatus | Status of the Level 1 reviewer on the review item |
| Level 1 business justification | reviewItem.level1ReviewerBusinessJustification | Justification left by the Level 1 reviewer with their decision |
| Level 2 reviewer | reviewItem.level2ReviewerFullName | Name of the Level 2 reviewer |
| Level 2 user id | reviewItem.level2ReviewerUserId | User ID of the Level 2 reviewer |
| Level 2 reviewer email | reviewItem.level2ReviewerEmail | Email of the Level 2 reviewer |
| Level 2 original reviewer | reviewItem.level2originalReviewerFullName | Name of the Level 2 original reviewer (user or group) |
| Level 2 original reviewer id | reviewItem.level2originalReviewerId | ID of the Level 2 original reviewer (user or group) |
| Level 2 original reviewer email | reviewItem.level2originalReviewerEmail | Email of the Level 2 original reviewer |
| Level 2 reviewer status | reviewItem.level2ReviewerStatus | Status of the Level 2 reviewer on the review item |
| Level 2 business justification | reviewItem.level2ReviewerBusinessJustification | Justification left by the Level 2 reviewer with their decision |
| Entitlement type | reviewItem.entitlementType | Indicates if it's an entitlement or an entitlement bundle under review |
| Entitlement value id | reviewItem.entitlementId | ID of the entitlement value that's under review |
| SOD rule conflicts | reviewItem.sodRuleConflict | Names of separation of duty rules that are violated by the entitlement under review |
| Assignment method | reviewItem.AssignmentMethod |
Values indicate the method that's used to assign access:
|
| Stage Version | campaign.stageVersion | The stage version of the campaign |