Search reviews

Retrieve a list of reviews in Okta Identity Governance.

This card only supports non-recurring Campaign IDs. To use it with a recurring campaign, you must provide the specific Campaign ID for that individual instance.

Options

Field Definition Type Required

Result Set

Choose a method to filter search results:

  • First Matching Record: Returns the first record that matches.

  • First 200 Matching Records: Returns the first 200 matching records.

  • Stream Matching Records: Passes all matching records from your parent flow to a helper flow.

    Selecting this option adds a Streaming input section to the card where you can select a helper flow for streaming and add custom extensible fields.

Dropdown TRUE

Input

Field Definition Type Required

Search

Campaign ID

The unique identifier of the access certification campaign.

Text FALSE

Principal ID

The unique identifier of the principal (typically a user) whose access is being reviewed.

Text FALSE

Reviewer ID

The unique identifier of the user assigned to perform a specific review task.

Text FALSE

Resource ID

The unique identifier of the resource being reviewed.

Text FALSE

Decision

The reviewer's final choice on a review item.

  • Approve

  • Revoke

  • Unreviewed

Dropdown FALSE

Reviewer Type

The kind of reviewer for access certification.

  • Group

  • Resource Owner

  • User

Dropdown FALSE

Reviewer Level

The level of the reviewer for each review during access certification. This is applicable for multi-level campaigns only.

  • First

  • Second

Dropdown FALSE

Entitlement Value ID

The unique identifier of the entitlement value being reviewed (part of an entitlement assignment).

Text FALSE

Entitlement Bundle ID

The unique identifier of the entitlement bundle (set of entitlements) being reviewed.

Text FALSE

Streaming

Flow

Click Choose Flow to browse and select a helper flow where the search results will be streamed, then click Choose to confirm.

Optionally, click the empty field under Click or drop here to create and add custom extensible fields that pass data to the helper flow. These fields are added as key/value pairs under the State output object in the helper flow.

Flow

TRUE

Record Limit

Specify the number of records to stream.

  • When the Limit field is set to 0, the stream returns no records.

  • When the Limit field is set to greater than 0, the stream returns up to the maximum number specified.

  • When the Limit field is empty, null, or not selected, the stream returns all records.

  • The default value is 1000000 (1 million).

  • The valid range is from 0 to 1000000.

This field appears when you select Stream Records from the Result Set option.

Number FALSE

Output

Field Definition Type

Result

Raw Output

The raw object response for the reviews.

Object

ID

The unique identifier of the review.

Text

Campaign ID

The unique identifier of the access certification campaign.

Text

Resource ID

The unique identifier of the resource being reviewed.

Text

Decision

The reviewer's final choice on a review item.

  • Approve

  • Revoke

  • Unreviewed

Text

Remediation Status

The outcome of the system's action after a decision is made, such as whether the user's access was successfully revoked or an error occurred.

  • Error

  • Manual

  • None

  • Open

  • Success

Text

Reviewer Type

The kind of reviewer for access certification.

  • Group

  • Resource Owner

  • User

Text

Current Reviewer Level

The reviewer level of each review during access certification. Applicable for multi-level campaigns only.

  • First

  • Second

Text

Decided

The date and time when the decision was finalized (only set after the reviewer acts).

Text

Created

The date and time when the review was created.

Date & Time

Created By

The unique identifier of the Okta user who created the review.

Text

Last Updated

The date and time when the review was last updated.

Date & Time

Last Updated By

The unique identifier of the Okta user who last updated the review.

Text

Principal Profile

A limited set of properties from the principal's profile.

  • Email : The Okta user's email address.

  • ID: The Okta user's ID.

  • Status: The status of the principal's profile.

  • First Name: The Okta user's first name.

  • Last Name: The Okta user's last name.

  • Login: The name the Okta user uses to sign in.

Object

Links

Links that are available after reassigning reviews.

  • Reassign Review: A link that points to the API Endpoint used to reassign a review task to a different reviewer within the specified access certification campaign.

  • Self: A link that references the current review resource. This endpoint can be used to retrieve the full details and current state of the access review item, including its decision status, reviewer information, and related campaign and entitlement context.

Object

Entitlement Bundle

The entitlement bundle. This is only applicable if the resource is Application and Entitlement Management is enabled.

  • ID: The entitlement bundle id.

  • Name: The entitlement bundle name.

Object

Entitlement Value

The entitlement value. This is only applicable if the resource is Application and Entitlement Management is enabled.

  • ID: The entitlement bundle id.
  • Name: The entitlement bundle name.

Object

Reviewer Group Profile

The profile of the reviewer group. This is applicable only when the reviewer type is Group or Resource Owner.

  • Group ID: ID of an Okta group.

  • Group Type: The type of group. It's either Group or Resource Owner.

  • Name: The name of the Okta group.

Object

Reviewer Profile

The profile of the reviewer. This is applicable only when the reviewer type is Group or Resource Owner.

  • Email: The Okta user's email address.

  • ID: The Okta user's ID.

  • Status: The status of the principal's profile.

  • First Name: The Okta user's first name.

  • Last Name: The Okta user's last name.

  • Login: The name the Okta user uses to sign in.

Object

Risk Rule Conflicts

A list of risk rule conflicts caused by this entitlement value. Only applies to review items that have entitlement values.

  • Conflict Criteria: The specific criteria or rule that was violated.

  • ID: The unique identifier of the risk rule.

  • Type: The type of the rule.

List of Objects

Records Streamed

Number of records streamed in a streaming flow.

This field appears when you select Stream Matching Records from the Result Set option.

Number