During an Access Review campaign, clicking the violation icon displayed next to a user's access entry may reveal various violation types, such as User Violation, Role Violation, or Link Violation. This article clarifies what these categories represent and how the system determines them.
Violation types in Identity Governance are driven by the configuration of Business Policy Rules (BPRs) and Audit Cards. When configuring a campaign, you can choose to hide violations or display them based on these policies.
The specific category of violation (User, Role, or Link) is determined by the scope of the policy or audit card triggered:
The violation type is explicitly defined by the administrator during the creation of the Business Policy or Audit Card.
To manage these definitions, ensure that your BPRs and Audit Cards are accurately classified during the creation process to ensure that the campaign reporting reflects the correct violation category.
For detailed instructions on configuring these policies, refer to the documentation.
15.x documentation:
Creating a business policy