In some scenarios, an administrator may start an attestation run unintentionally, or the run may generate more attestation cases than expected due to the attestation policy configuration.
After the attestation cases have been created and assigned to attestors, there may be a requirement to cancel the entire attestation run from Manager or the Web Portal.
However, there is no option to cancel the attestation run.
The Attestation Administration Guide describes canceling incomplete attestation runs from Manager under:
A fully generated attestation run with pending cases does not appear under these menu items because it is no longer considered incomplete.
This behavior is by design. The cancel option is only available for incomplete attestation runs.
In this context, incomplete means that the attestation run is still being constructed, or that an issue occurred while the attestation cases were being generated.
This is different from an attestation run that is in progress.
An in-progress attestation run may have pending cases, but if the cases were already generated successfully, the run is no longer considered incomplete. It is waiting for attester decisions.
Therefore, an attestation run with pending cases is not the same as an incomplete attestation run.
Incomplete refers to the case-generation phase. In progress refers to the attestation decision phase.
A fully generated attestation run with pending attestation cases cannot be canceled as a whole from Manager.
There is no out-of-the-box option to cancel a fully generated attestation run with pending cases from Manager or the Web Portal.
If the attestation run was started by a schedule, disable the schedule to prevent additional runs from being started.
Then review Job Queue Info and stop the related process step only if it is still generating attestation cases.
If the attestation cases have already been generated and are pending with attestors, allow the workflow to continue, ask the attestors to complete the decisions, or contact One Identity Support for further guidance.
How to check whether an attestation run is incomplete
The status can be checked in the AttestationRun table by reviewing the following column: CountChunksUnderConstruction
This can be reviewed in Object Browser by navigating to: AttestationRun. Then select the required attestation run and review CountChunksUnderConstruction.
This value shows whether the attestation run still has chunks under construction.
If the value is greater than 0, the attestation run is incomplete or still under construction.
If the value is 0, the construction phase has completed. If cases are still pending, this means the attestation run is in progress with pending decisions. It does not mean the run is incomplete.
An attestation run with pending cases is not the same as an incomplete attestation run. In this context, incomplete refers to the construction or case-generation phase, not to pending attester decisions.
Related articles:
Can attestation cases be recovered after deletion? Can attestation cases be recovered after deletion? (4372409)
Close Attestation Cases for Deactivated Employees: Close Attestation Cases for Deactivated Employees (4310849)
Delete attestation cases is not working: Delete attestation cases is not working (4381389)
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center