How the Pending Revoke category functions in the default reviewer interface style of the User Access Review in RSA Identity Governance & Lifecycle
Originally Published: 2020-03-17
Article Number
Applies To
RSA Version/Condition: 7.1.x, 7.2.x
Issue
Using the new interface style allows reviewers to review items based on categories as defined under the Reviews > Definitions > {Name of user access review} > Analysis & Guidance tab. The purpose of this RSA Knowledge Base Article is to explain how the Pending Revoke category functions as it behaves slightly differently from the other categories.
Note: The complete Pending Revoke description in the above screenshot is:
The system identifies review items that are already pending revocation. Any identified items are listed in the "Pending Revoke" category. Note: Reviewers cannot perform any action on items that are pending revocation. Regardless of whether the Pending Revoke category is displayed in the Analysis and Guidance panel, all entitlements that are pending revocation are displayed within a review as completed and locked.
Resolution
The Pending Revoke category shows review items that already have a change request associated with them to revoke that access and always displays as 0 since they are considered completed and do not need to be reviewed. These items may be viewed by choosing the Completed drop-down menu option under Showing.
If accessing a user access review created prior to 7.1.0 or if using the Legacy reviewer user interface in 7.1.0 and above, pending revoke items can be reviewed and maintained or revoked. This ability to maintain/revoke pending revoke items has been removed in the new interface because the functionality makes no sense. If you revoke an already revoked item, it has no effect, and if you maintain a revoked item, it also has no effect because the pending revoke change request still exists and is not cancelled. As a result, by maintaining a pending revoked item, the reviewer is misled into thinking the items will be maintained. As a result, the ability to review such items no longer exists starting in 7.1.0. If any pending revoke items need to be maintained, the existing change request(s) need to be cancelled. The ability to view these items in the new interface without performing any action on them allows you to determine if there are any such requests that need to be cancelled without performing actions that have no effect.
Related Articles
RSA Governance & Lifecycle Recipes: Chart - Review Results - Review Violations 10Number of Views Difference between a Delegate Reviewer and Alternate Manager in Access Certifications using Identity Governance & Lifecycle 39Number of Views How do supervisors view a report result that is specific to their subordinates in RSA Via Lifecycle and Governance 70Number of Views Cancelling a change made in a review redirects to a null page or a request could not be handled error in RSA Identity Gove… 30Number of Views Request Could not be Handled while generating server.keystore & client.keystore in RSA Governance & Lifecycle 238Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?