Assuming that the policy violation owner has the necessary permissions, is this a valid option for the policy violation owner to use when acting on a policy violation of type ' Account Policy ' ?
Allow is a valid action when acting on a policy violation, assuming the policy violation owner has the required permissions. In IdentityIQ compliance workflows, not every violation is immediately remediated. Some violations are business-approved exceptions, temporary exceptions, or accepted risks. The Allow action is used to acknowledge that the violation may remain in place, often with justification, comments, expiration, or compensating-control context depending on configuration. This is different from remediation, where access is changed or removed, and different from mitigation, where a mitigating control is attached. In the Account Policy context, the violation may indicate that a user exceeds a permitted account condition. If the business determines the condition is acceptable, the owner may allow it rather than immediately remove or alter an account. This is a legitimate compliance decision, provided the user has permission to take that action. References/topics: IdentityIQ Engineer — policy violation lifecycle, Account Policy, allow/exception handling, mitigation, remediation, Compliance Manager.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit