WardeDocs Administrators Connectors People using Warde warde.app

Administrator guide

Fulfilment and manual tasks

How approved access reaches the engine or a person, how manual tasks work, and how to deal with work that failed.

When a request is approved, Warde puts each line on its fulfilment queue. The queue sends it to the engine, or raises a ServiceNow catalog task for a person when the engine cannot do it. A request reads done only when the change is confirmed.

When a task is raised

Warde raises a catalog task instead of calling an engine when:

The task

FieldValue
Short descriptionGrant <access> to <person> or Remove <access> from <person>
DescriptionThe fulfilment instructions from the entitlement or collection, then the facts: person, account, access, request number
Assignment groupThe collection's support group, or the fallback group from Guided Setup step 8 if that group is missing, inactive or empty
TemplateThe entitlement's task template, else the collection's, else the instance default from Guided Setup step 8
Due dateFrom the collection's provisioning window, counted in business days on the Warde fulfilment hours schedule

Tasks are ordinary sc_task records under the requested item, so they follow your existing assignment rules, notifications and SLAs. The fulfiller role lets the people working them see the Warde records behind the task.

Closing a task

Do the work in the target system, then close the task.

Task stateWhat Warde does
Closed CompleteThe change is recorded as done. Warde records the access as granted or removed.
Closed Incomplete, Closed SkippedThe operation fails, and the access stays as it was

Warde checks open manual tasks every hour (x_66256_warde.queue.manual_poll_mins, default 60), so the request updates within the hour after the task closes. Warde does not tell the engine about manual work: the engine's next import reads the change.

Complete manually on a fulfilment operation records the change at once, for when the work was done some other way. The task stays open for you to close.

Watching the queue

The Admin Workspace's Operations lists and the Fulfilment operations dashboard show the queue:

ListWhat is in it
Failed or parkedWork that needs a person. Start here.
Awaiting manual fulfilmentOpen tasks, with how long they have been waiting
Waiting to retryEngine calls that failed and will be tried again
Past the retry deadlineEngine calls that ran out of retries
Queued or with the engineWork in flight

When an engine call fails

Warde retries a failed engine call with a growing delay, starting at x_66256_warde.queue.retry_base_secs (60 seconds) and giving up after x_66256_warde.queue.retry_window_mins (240 minutes). If the engine is out of service, its work is held and sent again when the engine recovers.

Work that still cannot be done is parked, and Warde raises a task for the Group for failed grants and removals from Guided Setup step 8. If that group is not set, the task goes to the collection's support group, then the fallback group.

On a failed or parked operation, an administrator can:

ActionWhat it does
Retry operationPuts it back on the queue for the next run
Retry nowSends it again at once
Cancel operationStops it. The request line shows it was cancelled.
Complete manuallyRecords the change as done, when it was done outside Warde

An operation nobody acts on is abandoned after x_66256_warde.queue.abandon_after_days (7 days, at most 30).

When an engine does not answer

If an engine accepts a grant but never confirms it, Warde looks for the request in the engine by Warde's own reference and adopts it rather than sending it twice. If it cannot find it, the work goes to a person after 30 minutes. Each connector guide describes what that engine does.

Promised dates

When Tell requesters when to expect access is on (Guided Setup step 8), the requester is told when to expect the access:

The business days are counted on the Warde fulfilment hours schedule, or a collection's own schedule. Set the schedule's time zone, or Warde counts the hours in UTC.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.