Can there be a threshold check while assignment or removal of role?

Yeah, it’s far more liberating once you get outside of the confines of ISC. ISC itself is functionally rather rudimentary with its OOTB IGA use cases coverage. A lot of additional business logic has to be bolted on here and there.

Like you can’t even have ‘new’ custom email templates at the tenant level…you need to going to a step-level in workflow to define the email. There’s no OOTB access removal workflow (it’s community-built), no account deletion, no identity deletion, no per entitlement deletion OOTB. It doesn’t handle multi-account per source per identity very well either.

Also, with all the transforms built in JSON, just give us a graphical editor already. (e.g. below or similar to the workflow builder) Better yet, give us the AI and LLM to build transforms.

1 Like