WardeDocs Administrators Connectors People using Warde warde.app

Administrator guide

Settings and scheduled jobs

Where Warde's settings live, the ones you are most likely to change, and the scheduled jobs that keep it running.

Most settings are set in Guided Setup, which explains each one in context. Every setting is also a system property, listed under Warde > Properties in categories, or in the Admin Workspace under Settings > Warde properties. Change a setting in Guided Setup where it offers one: some saves do more than write the property, such as audit retention, which also updates the table cleaner.

All Warde properties are named x_66256_warde.* and need the Warde administrator role to read or change.

Settings you are most likely to change

Approvals

PropertyDefaultWhat it does
default_approval_policynoneThe policy used when no entitlement, bundle or collection names one. With none, such requests stop for an administrator.
approval.exception_groupnoneApproves when a rule finds nobody and has no standby
approval.submitter_approvalrequirerequire asks a submitter who is also an approver; submission counts their submission as approval
approval.removal_approverholderWho approves a removal: holder, manager, rules or none
approval.removal_default_policynoneThe removal policy when none is named elsewhere
admin.groupnoneThe group that approves access bundle proposals

Fulfilment

PropertyDefaultWhat it does
fulfilment.fallback_groupnoneGets manual tasks for collections with no usable support group
fulfilment.exception_groupnoneGets failed and parked work
fulfilment.default_window_days2Business days promised for manual work
fulfilment.show_promisetrueTells requesters when to expect access
fulfilment.grant_task_template, fulfilment.removal_task_templatenoneDefault catalog task templates
queue.manual_poll_mins60How often Warde checks manual tasks for closure
queue.retry_base_secs60The first retry delay after a failed engine call
queue.retry_window_mins240How long Warde keeps retrying a failed engine call
queue.abandon_after_days7When an operation nobody acts on is abandoned, at most 30

Requests and My Access

PropertyDefaultWhat it does
request.act_for_scopeteamWho a requester can ask for: self, team (direct reports), org (everyone below them) or any. Administrators are not limited by it.
catalog.request_access, catalog.access_bundles, catalog.remove_access, catalog.remove_access_bundlestrueSwitches each catalog item on or off. Off hides the item without deactivating it.
catalog.single_accessfalseThe conversational item. Needs Now Assist and AI Search.
my_access.expiring_soon_days30How soon before its end date My Access marks access as expiring
my_access.max_rows500The most rows My Access shows in a panel
my_access.ticket_referencesc_req_itemWhether requests are quoted by RITM or REQ number

Reviews and expiry

PropertyDefaultWhat it does
uar.portal_suffixescThe portal reviews and email links open in
uar.removal_request_modedirectHow removals from reviews and My Access are made: direct, manual_only or always
uar.reminder_days_before3Days before the due date to remind reviewers. 0 means never.
uar.escalate_after_days3Days after the due date to escalate to the reviewer's manager. 0 means never.
uar.default_due_days14How long reviewers have when a definition sets no due period
removal.sweep_request_modemanual_onlyHow expired access is removed
expiry.notify_holder_days14Days before expiry to email the person. 0 turns it off.
expiry.notify_manager_days3Days before expiry to email the person and their manager

Separation of duties

See Separation of duties for sod.enforcement, sod.validation and the related settings.

Other

PropertyDefaultWhat it does
lifecycle.fulfilmentallWhat Warde does with a lifecycle call by default
audit.retention_days2557How long audit history is kept. Change it in Guided Setup step 11.
logging.verbositywarnThe log level: error, warn, info or debug
correlation.default_attribute, correlation.default_fieldThe default pair that binds engine accounts to users
alerting.sinknoneThe default engine alert: none, incident, em_event or both. See Health, alerts and logs.

Scheduled jobs

Warde runs twelve scheduled jobs. Guided Setup step 13 lists them and shows whether each is active. Leave them all active.

JobRunsWhat it does
Warde engine health checkHourlyChecks each engine with a real authenticated call and records its status
Warde engine alertingEvery 5 minutesRaises and clears engine alerts
Warde queue sweeperEvery 15 minutesRescues stalled fulfilment work, times out separation of duties checks, and releases removals waiting on a replacement
Warde ServiceNow accountsEvery 15 minutesKeeps the ServiceNow engine's accounts in step with the users who hold the requester role
Warde sync: catalogDaily at 02:00Imports collections, then entitlements, from each engine
Warde sync: accountsEvery 4 hoursImports accounts
Warde sync: assignmentsEvery 6 hoursImports who holds what. A full read runs at most weekly, on the days set in sync.assignment_sweep_days (Saturday and Sunday).
Warde sync: approval auditDaily at 04:00Finds SailPoint ISC items with an approval step of their own, and reads when the ISC token expires
Warde expiry removal sweeperDaily at 02:00Sends expiry emails, then removes expired access
Warde UAR sweeperDaily at 06:00Sends review reminders and escalations, and closes finished campaigns
Warde campaign schedulerDaily at 06:30Launches scheduled campaigns
Warde weekly licence reportDaily at 03:17, sending once a weekOn production instances only, sends Warde the number of people who hold a Warde role. See What leaves your instance.

Times are the instance's time zone.

What leaves your instance

Warde calls only the engines you connect, with the credentials you give it, plus one weekly report.

The licence report. Once a week, a production instance sends https://licensing.warde.app one signed message: the product name and the number of distinct active people who hold any Warde role. Service accounts, integration users, locked-out users and machine identities are not counted. No names, no access and no other data are sent. Instances that are not production (where glide.installation.production is not true) send nothing. The last report and its outcome are kept in x_66256_warde.licence.last_report, which Warde administrators can read. The connection it uses, Warde licensing, is installed with Warde. If a send fails, Warde logs one warning and tries again the next day.

Table cleaners

TableKept for
Audit events2,557 days (seven years) by default. Set in Guided Setup step 11.
Fulfilment operations90 days after they complete or are cancelled
Separation of duties probes1 day

Records Warde ships that you can change

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to hello@warde.app.

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.