Filters and outputs for Identity Governance reports

Learn what filters and output are available for Identity Governance reports.

Staged campaign summary report

The following tables provide the available filters and outputs for the Staged campaign summary report.

Filters

Table 1. Staged campaign summary report filters
Field Value
Campaign id Enter the unique identifier for the campaign. You can find a campaign's ID from System Log events or from the URL for the campaign details page.
Campaign name Enter the name of the campaign to include or exclude.
Campaign scheduled to end Select a date if the operator is before or after.
Campaign scheduled to start Select a date if the operator is before or after.
Resource type Select the type of resource reviewed.
Stage Version Select the stage version of the campaign to filter results by.

Outputs

Table 2. Staged campaign summary report outputs
Column header (UI) Column header (in exported file) Column description
Campaign name campaign.name Name of the campaign
Campaign description campaign.description Description of the campaign
Campaign id campaign.id Unique identifier of the campaign. You can find this in the System Log or from the URL on the campaign's page.
Campaign created campaign.created Date the campaign was created
Campaign scheduled to start campaign.scheduledStart Date the campaign is scheduled to launch
Campaign scheduled to end campaign.scheduledEnd Date the campaign is scheduled to end
Duration (days) campaign.duration Days between the campaign's scheduled start date and scheduled end date
Reviewer type campaign.reviewerType

Values indicate the reviewer type:

  • Name of the user assigned as the reviewer

  • Name of the group assigned as the reviewer

  • Group Owner or Resource Owner
  • User's manager
  • Custom expression if Okta Expression Language expression was used to specify reviewers

  • Multilevel if part of a campaign with multilevel reviews

Resource type campaign.resourceType

Values indicate resource types included in the campaign scope:

  • Apps assigned to user
  • Groups assigned to user
  • Apps and Groups assigned to user
  • Collections assigned to user

  • Okta service account that a user can access
  • App service accounts that a user can access
  • Connections assigned to AI agent
Resource count campaign.resourceCount

Number of resources included in the campaign.

For resource campaigns, this field shows the number of resources scoped into the campaign.

For user campaigns, this field shows the number of resources (apps and groups) being certified in the campaign.

Identity scope campaign.userScope

Values indicate if the campaign targets all identities or specific ones, and if any were excluded:

  • All Users
  • All users except the number of users who were excluded
  • Specific users
  • Specific groups
  • Scoped by expression language
  • Users with no recent activity
  • Users with SOD conflicts
Number of identities campaign.userCount Number of distinct identities included in the campaign scope
Number of review items campaign.reviewItemCount Number of reviews included in the campaign
Action if approved campaign.approvedAction

Values indicate the remediation action defined by the campaign owner or admin in the campaign wizard for when a reviewer approves access:

  • Don't take any action
  • Remove from resource
Action if revoked campaign.revokedAction

Values indicate the remediation action defined by the campaign owner or admin in the campaign wizard for when a reviewer revokes access:

  • Don't take any action
  • Remove from resource
Action if unreviewed campaign.unreviewedAction

Values indicate the remediation action defined by the campaign owner or admin in the campaign wizard for when a reviewer doesn't make a decision before the campaign ends:

  • Don't take any action
  • Remove from resource
Transition policy campaign.levelTransitionPolicy

Level transition policy of the campaign that defines which review items move to the second level of review. This field is only defined for campaigns with multilevel reviews. Values include:

  • Only Approved Items
  • Approved and Revoked Items
Level 1 reviewer expression campaign.level1ReviewerExpression Reviewer expression of the campaign if Okta Expression Language (OEL) was used to define the Level 1 reviewer. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table.
Level 2 reviewer expression campaign.level2ReviewerExpression Reviewer expression of the campaign if Okta Expression Language (OEL) was used to define the Level 2 reviewer. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table.
Level 1 reviewer type campaign.reviewerTypeLevel1 Level 1 reviewer type of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table.
Level 2 reviewer type campaign.reviewerTypeLevel2 Level 2 reviewer type of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for the Reviewer type in this table.
Reviewer expression campaign.reviewerExpression Reviewer expression of the campaign if Okta Expression Language (OEL) was used to define the reviewer
Reviewer settings campaign.reviewerSettings

Values indicate the reviewer settings of the campaign:

  • Self Review Disabled
  • Justification Required
  • Bulk Decision Disabled
Level 1 reviewer settings campaign.level1ReviewerSettings Level 1 reviewer settings of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table.
Level 2 reviewer settings campaign.level2ReviewerSettings Level 2 reviewer settings of the campaign. This is populated only in campaigns with multilevel reviews. Refer to the description for Reviewer settings in this table.
Campaign Available campaign.campaignAvailable Yes or No value that indicates whether the campaign is available for review. Campaigns are archived one year after their last update.
Stage Version campaign.stageVersion The stage version of the campaign

Staged campaign details report

The following tables provide the available filters and outputs for the Staged campaign details report.

Filters

Table 3. Staged campaign details report filters
Field Value
Campaign id Enter the unique identifier for the campaign. You can find a campaign's ID from System Log events or from the URL for the campaign details page.
Campaign name Enter the name of the campaign to include or exclude.
Campaign scheduled to end Select a date if the operator is before or after.
Campaign scheduled to start Select a date if the operator is before or after.
Connected resource type Select the type of AI agent connected resource that was reviewed.
Identity Select one or more identities.
Resource Select one or more apps or groups. Or, use the Resource name filter instead if you want to find resources that aren't apps or groups, such as service accounts and AI agent connections.
Resource name Enter the name of the resource. Or, use this filter instead of the Resource filter if you want to find resources that aren't apps or groups, such as service accounts and AI agent connections.
Resource type Select the type of resource that's under review.
Reviewer Select one or more reviewers.
Reviewer delegated Select Yes to filter for review items approved or revoked by a delegate reviewer.

These results are available for this filter only if a delegate has been assigned for the user.

Reviewer email Enter the reviewer's email address.
Reviewer reassigned Select one or more options to indicate if the reviewer was reassigned or not.
Stage Version Select the stage version of the campaign to filter results by.
User email Enter the user's email address.
User Identity Enter the identity's name or username to include or exclude.

Outputs

Table 4. Staged campaign details report outputs
Column header (UI) Column header (in exported file) Column description
Campaign name campaign.name Name of the campaign
Campaign description campaign.description Description of the campaign
Campaign id campaign.id Unique identifier of the campaign. You can find this in the System Log or from the URL on the campaign's page.
Identity reviewItem.principalUserFullName Name of the user or AI agent under review
User email reviewItem.principalUserEmail Email of the user under review
Identity id reviewItem.principalUserId ID of the identity under review
Resource type reviewItem.resourceType

Values indicate the type of resource under review:

  • Group
  • Application
  • Collection

  • Okta service account
  • App service account
  • AI agent connection
Resource name reviewItem.resourceName Name of the resource under review
Resource global name reviewItem.resourceGlobalName Okta global name of the resource under review. For apps, this could be the official OIN name of the app or the app type. For example, OpenID Connect Client.
Resource id reviewItem.resourceId ID of the resource under review
App service account name reviewItem.applicationServiceAccountName Name of the application service account under review
Connected resource type reviewItem.connectedResourceType Type of connected resource under review
Connected resource details reviewItem.connectedResourceDetails Details of the connected resource that's under review
Entitlement reviewItem.entitlementName Name of the entitlement under review. This value is available only if the app being reviewed has entitlements, and entitlements are included in the resource scope for the campaign.
Reviewer reviewItem.reviewerFullName Full name of the user who was assigned to make the certification decision
Reviewer email reviewItem.reviewerEmail Email of the user who was assigned to make the certification decision
Reviewer user id reviewItem.reviewerUserId ID of the user who was assigned to make the certification decision
Original reviewer reviewItem.originalReviewerFullName Full name of the user or group who was originally assigned to make the certification decision
Original reviewer email reviewItem.originalReviewerUserEmail Email of the user who was originally assigned to make the certification decision
Original reviewer id reviewItem.originalReviewerId ID of the user or group who was originally assigned to make the certification decision
Reviewer reassigned reviewItem.reviewerReassigned Yes or No value indicates whether the reviewer was reassigned
Reviewer delegated reviewItem.delegated Yes or No value indicates whether the review item was delegated to and reviewed by a delegate
Reviewer status reviewItem.reviewerStatus Status of the reviewer on the review item
Business justification reviewItem.businessJustification Justification left by the reviewer with their decision
Campaign scheduled to start campaign.scheduledStart Date the campaign is scheduled to start
Campaign scheduled to end campaign.scheduledEnd Date when the campaign is scheduled to end
Level 1 reviewer reviewItem.level1ReviewerFullName Name of the Level 1 reviewer
Level 1 user ID reviewItem.level1ReviewerUserId User ID of the Level 1 reviewer
Level 1 reviewer email reviewItem.level1ReviewerEmail Email of the Level 1 reviewer
Level 1 original reviewer reviewItem.level1originalReviewerFullName Name of the Level 1 original reviewer (user or group)
Level 1 original reviewer id reviewItem.level1originalReviewerId ID of the Level 1 original reviewer (user or group)
Level 1 original reviewer email reviewItem.level1originalReviewerEmail Email of the Level 1 original reviewer
Level 1 reviewer status reviewItem.level1ReviewerStatus Status of the Level 1 reviewer on the review item
Level 1 business justification reviewItem.level1ReviewerBusinessJustification Justification left by the Level 1 reviewer with their decision
Level 2 reviewer reviewItem.level2ReviewerFullName Name of the Level 2 reviewer
Level 2 user id reviewItem.level2ReviewerUserId User ID of the Level 2 reviewer
Level 2 reviewer email reviewItem.level2ReviewerEmail Email of the Level 2 reviewer
Level 2 original reviewer reviewItem.level2originalReviewerFullName Name of the Level 2 original reviewer (user or group)
Level 2 original reviewer id reviewItem.level2originalReviewerId ID of the Level 2 original reviewer (user or group)
Level 2 original reviewer email reviewItem.level2originalReviewerEmail Email of the Level 2 original reviewer
Level 2 reviewer status reviewItem.level2ReviewerStatus Status of the Level 2 reviewer on the review item
Level 2 business justification reviewItem.level2ReviewerBusinessJustification Justification left by the Level 2 reviewer with their decision
Entitlement type reviewItem.entitlementType Indicates if it's an entitlement or an entitlement bundle under review
Entitlement value id reviewItem.entitlementId ID of the entitlement value that's under review
SOD rule conflicts reviewItem.sodRuleConflict Names of separation of duty rules that are violated by the entitlement under review
Assignment method reviewItem.AssignmentMethod Values indicate the method that's used to assign access:
  • Access request
  • Individual
  • Policy
  • None
Stage Version campaign.stageVersion The stage version of the campaign