How the Pending Revoke category functions in the default reviewer interface style of the User Access Review in RSA Identity Governance & Lifecycle
Originally Published: 2020-03-17
Last Modified: 2023-10-06
Article Number
Applies To
RSA Version/Condition: 7.1.x, 7.2.x
Issue
Using the new interface style allows reviewers to review items based on categories as defined under the Reviews > Definitions > {Name of user access review} > Analysis & Guidance tab. The purpose of this RSA Knowledge Base Article is to explain how the Pending Revoke category functions as it behaves slightly differently from the other categories.
Note: The complete Pending Revoke description in the above screenshot is:
The system identifies review items that are already pending revocation. Any identified items are listed in the "Pending Revoke" category. Note: Reviewers cannot perform any action on items that are pending revocation. Regardless of whether the Pending Revoke category is displayed in the Analysis and Guidance panel, all entitlements that are pending revocation are displayed within a review as completed and locked.
Resolution
The Pending Revoke category shows review items that already have a change request associated with them to revoke that access and always displays as 0 since they are considered completed and do not need to be reviewed. These items may be viewed by choosing the Completed drop-down menu option under Showing.
If accessing a user access review created prior to 7.1.0 or if using the Legacy reviewer user interface in 7.1.0 and above, pending revoke items can be reviewed and maintained or revoked. This ability to maintain/revoke pending revoke items has been removed in the new interface because the functionality makes no sense. If you revoke an already revoked item, it has no effect, and if you maintain a revoked item, it also has no effect because the pending revoke change request still exists and is not cancelled. As a result, by maintaining a pending revoked item, the reviewer is misled into thinking the items will be maintained. As a result, the ability to review such items no longer exists starting in 7.1.0. If any pending revoke items need to be maintained, the existing change request(s) need to be cancelled. The ability to view these items in the new interface without performing any action on them allows you to determine if there are any such requests that need to be cancelled without performing actions that have no effect.
Related Articles
User Access Review incorrect value for Rows/Page in RSA Identity Governance & Lifecycle 20Number of Views How to interpret the RSA Identity Governance & Lifecycle User Access Review User Entitlement Coverage report. 41Number of Views Run history data is missing under the Custom Task workflow history tab in RSA Identity Governance & Lifecycle 37Number of Views Configuring a Restricted Agent to Control User Access 43Number of Views Access User Access Review not showing indirect entitlements associated with a role for RSA Identity Governance & Lifecycle… 97Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Governance & Lifecycle Generic Database Collector Guide RSA Authentication Manager 8.7 SP2 Administrator's Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager 8.9 Setup and Configuration Guide
Don't see what you're looking for?