# Authorize Identities for a specific Form

**URL:** <https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179>\
**Category:** SHF Discussion and Questions\
**Tags:** forms, workflows, identity-security-cloud\
**Created:** [August 5, 2026, 8:09am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179 "2026-08-05T08:09:52Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![AHKG022](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@AHKG022](https://developer.sailpoint.com/discuss/u/AHKG022)\
**Post date:** [August 5, 2026, 8:09am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/1 "2026-08-05T08:09:52Z")

</div>

Hi Guys,

We have created a form for special ad hoc resignations, and it is important to us that only certain identities can view and fill out this form. Is there a way to configure this?

The Form and Workflow have already been created.

Thanks in Advance

---

<div class="post-metadata">

**Author:** ![ROHPU](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rohpu/32/36109_2.png) [@ROHPU](https://developer.sailpoint.com/discuss/u/ROHPU)\
**Post date:** [August 5, 2026, 8:15am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/2 "2026-08-05T08:15:39Z")

</div>

Yes, this can be achieved using an Interactive Trigger. Instead of exposing the form to everyone, configure the trigger so that only the required identities (or a governance group) can launch and submit the form. This ensures only the intended users receive access to the form and can initiate the workflow

---

<div class="post-metadata">

**Author:** ![selvasanthosh](https://avatars.discourse-cdn.com/v4/letter/s/cab0a1/32.png) [@selvasanthosh](https://developer.sailpoint.com/discuss/u/selvasanthosh)\
**Post date:** [August 5, 2026, 8:23am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/3 "2026-08-05T08:23:18Z")

</div>

Hi @AHKG022,

Use an **Interactive Trigger** in your workflow and attach the workflow to a **Launcher**.

When you create a launcher, SailPoint creates an entitlement with the launcher’s name. You can provision this entitlement only to the users who need access to the form.

The form can then be launched directly from the **Launchpad**.

---

<div class="post-metadata">

**Author:** ![Pankaj\_IAM\_SailPoint](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pankaj_iam_sailpoint/32/38994_2.png) [@Pankaj\_IAM\_SailPoint](https://developer.sailpoint.com/discuss/u/Pankaj_IAM_SailPoint)\
**Post date:** [August 5, 2026, 8:23am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/4 "2026-08-05T08:23:49Z")

</div>

@AHKG022 Since your **Form and Workflow are already created** , the main thing you need to control is **who can launch or see the workflow/form**.

If you are exposing the workflow through a **QuickLink** , the easiest approach is to put the restriction on the QuickLink itself. You can configure the QuickLink so that it is available only to specific users, populations, roles, or users who meet certain conditions.

For example, if only the **HR team** should be able to submit a special ad-hoc resignation, create a population or use an appropriate capability/role to identify those HR users and restrict the QuickLink to them. Other users will then not see the option in the UI.

If your requirement is more complex—for example, HR can submit the form, but only for employees within their own department—then you should also add validation inside the workflow. This is important because hiding the QuickLink controls visibility, while workflow validation provides an additional authorization check before processing the request.

So, in simple terms:

**QuickLink restriction → controls who can see/open the form.**  
**Workflow validation → controls whether that person is actually allowed to perform the action.**

For sensitive actions like resignation/termination, I would recommend using **both** , rather than relying only on hiding the form.

---

<div class="post-metadata">

**Author:** ![AHKG022](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@AHKG022](https://developer.sailpoint.com/discuss/u/AHKG022)\
**Post date:** [August 5, 2026, 10:05am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/5 "2026-08-05T10:05:53Z")

</div>

Hi Pankaj,  
Thank you for your response. My question was specifically related to ISC. As far as I understand, QuickLinks are a feature that is available only in IdentityIQ. Could you please confirm if that is correct?

---

<div class="post-metadata">

**Author:** ![AHKG022](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@AHKG022](https://developer.sailpoint.com/discuss/u/AHKG022)\
**Post date:** [August 5, 2026, 10:06am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/6 "2026-08-05T10:06:31Z")

</div>

Hi Pucha,  
this helped! Thank you!

---

<div class="post-metadata">

**Author:** ![AHKG022](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@AHKG022](https://developer.sailpoint.com/discuss/u/AHKG022)\
**Post date:** [August 5, 2026, 10:07am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/7 "2026-08-05T10:07:13Z")

</div>

Hi Selvasanthosh,  
this helped! Thank you!

---

<div class="post-metadata">

**Author:** ![Pankaj\_IAM\_SailPoint](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pankaj_iam_sailpoint/32/38994_2.png) [@Pankaj\_IAM\_SailPoint](https://developer.sailpoint.com/discuss/u/Pankaj_IAM_SailPoint)\
**Post date:** [August 5, 2026, 10:46am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/8 "2026-08-05T10:46:17Z")

</div>

@AHKG022 Yes, Its for a IIQ only.

---

<div class="post-metadata">

**Author:** ![punna0001](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/punna0001/32/42011_2.png) [@punna0001](https://developer.sailpoint.com/discuss/u/punna0001)\
**Post date:** [August 6, 2026, 6:55am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/9 "2026-08-06T06:55:52Z")

</div>

Welcome to the SailPoint Developer community @AHKG022.

Access is not restricted directly through the Interactive Trigger.

When you create a Launcher, SailPoint automatically creates an entitlement for it. Assign that entitlement only to the users who should be able to view and submit the form from the Launchpad.

As @selvasanthosh correctly explained, the recommended approach in ISC is to control access through the Launcher entitlement.

---

<div class="post-metadata">

**Author:** ![StephenHolinaty](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/stephenholinaty/32/29996_2.png) [@StephenHolinaty](https://developer.sailpoint.com/discuss/u/StephenHolinaty)\
**Post date:** [August 6, 2026, 5:40pm UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/10 "2026-08-06T17:40:52Z")

</div>

If you want a decent presentation on the interactive workflows / forms / launchers, I did a presentation at Navigate2025 on this:

Found here: [Watch Navigate 2025 Sessions On Demand | SailPoint](https://www.sailpoint.com/navigate/on-demand?sessionTypes=breakout)  
under the title: **Real-world impact of workflows**

I go into the configuration and details in medium depth for this very “immediate termination” flow.

---

<div class="post-metadata">

**Author:** ![vikaspawar0303](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vikaspawar0303/32/34710_2.png) [@vikaspawar0303](https://developer.sailpoint.com/discuss/u/vikaspawar0303)\
**Post date:** [August 7, 2026, 1:14am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/11 "2026-08-07T01:14:37Z")

</div>

> [@AHKG022](#):
>
> We have created a form for special ad hoc resignations, and it is important to us that only certain identities can view and fill out this form. Is there a way to configure this?
> 
> The Form and Workflow have already been created.

Yes. The recommended approach is to control access to the **workflow** , not the form itself.

Options:

- **Workflow Trigger Permissions** : Restrict who can launch the workflow by assigning access only to specific governance groups, identity attributes, or administrative roles.
- **Form Visibility Logic** : Add conditional visibility/read-only rules within the form to hide or restrict fields based on the logged-in user’s attributes.
- **Separate Access Group** : Create a governance group (e.g., _Special Resignation Requesters_) and configure your process so only members of that group can access the workflow entry point.

If the form is a standalone Workflow Form, there is currently **no OOTB form-level ACL** that directly limits who can view the form URL. The common pattern is to **restrict workflow initiation to an authorized population** and validate the user’s eligibility at the start of the workflow, terminating the process if they are not authorized.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [October 6, 2026, 1:15am UTC](https://developer.sailpoint.com/discuss/t/authorize-identities-for-a-specific-form/218179/12 "2026-10-06T01:15:29Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
