20.2 Identifying Purgeable Data

The Data Purge utility removes the following types of data from the operations database when certain conditions are met.

Access Request

Can be purged only when the request is completed, which includes one of the following states:

  • Request was denied approval

  • Request was declined fulfillment

  • Request was fulfilled and verified

  • Request was fulfilled and verification failed

Analytical Facts

Can be purged only when retention time is specified and facts are older than the specified retention time

Business Role

Can be purged under all of the following conditions:

  • Business role approval state must be archive

  • Is not referenced from any review definitions or review items

  • Is not referenced from any change request items

Bulk data update definition

Can be purged if it has been deleted from the Identity Governance catalog.

Certification Policy

Can be purged under any of the following conditions:

  • Policy has been deleted

  • Policy is older than the retention time if specified

Collection

Can be purged under any of the following conditions:

  • Has associations that are not in a canceled, failed, completed, or terminated state

  • Is not in a current snapshot

Data source

Can be purged under any of the following conditions:

  • Is not a parent to another application

  • Is not scheduled for collection

  • Has been deleted from the Identity Governance catalog

  • Is not referenced by a role policy

    For example, a role policy references SPermission in the data source.

  • Is not referenced by a Separation of Duties policy

    For example, a Separation of Duties policy references SPermission in the data source.

Request approval policy

Can be purged under all of the following conditions:

  • Policy has been deleted

  • All requests associated with the policy have been previously purged

Request policy

Can be purged under all of the following conditions:

  • Policy has been deleted

  • All requests associated with the policy have been previously purged

Review definition

Can be purged under any of the following conditions:

  • Has been deleted from the Identity Governance catalog

  • Is not referenced by a review instance

Review instance

Can be purged under any of the following conditions:

  • Has been canceled or experienced an error (not running)

  • Is not referenced by a change item action that is not in a verified or error state

NOTE:Materialized view, if any, are also purged when review instances are purged.

Risk Score Status

Can be purged under all of the following conditions:

  • Is in the error, canceled, or completed state

  • If in completed state, there must be another completed risk score status of the same entity type that has a later start time

Snapshot

Can be purged under any of the following conditions:

  • Is not the current snapshot of the Identity Governance catalog

  • Is not a precursor to another snapshot

  • Is not referenced by a review instance

  • Is not referenced by a Separation of Duties violation

  • Is not referenced by a SPermission used in a Technical Role definition

Separation of Duties case

Can be purged under any of the following conditions:

  • Case is closed

  • Case action is closed

  • Is referenced by a change item action that is in a verified or error state

Separation of Duties policy

Can be purged under any of the following conditions:

  • Has been deleted from the Identity Governance catalog

  • Does not reference a Separation of Duties policy through a SoDConditionItem

  • Does not have a running detection

Technical Role

Can be purged only when all of the following conditions are met:

  • Has been deleted from the Identity Governance catalog

  • Is not referenced by a Review Instance through a ReviewItem

  • Is not referenced by a Separation of Duties policy through a SoDConditionItem

  • Is not referenced by a Review Definition

  • Does not have a running detection

Unregistered Facts

Can be purged when fact tables are available in schema even after custom facts are unregistered from fact catalog