# Custom SailPoint Roles

**URL:** <https://developer.sailpoint.com/discuss/t/custom-sailpoint-roles/22202>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud\
**Created:** [December 5, 2023, 7:50pm UTC](https://developer.sailpoint.com/discuss/t/custom-sailpoint-roles/22202 "2023-12-05T19:50:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![schen](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@schen](https://developer.sailpoint.com/discuss/u/schen)\
**Post date:** [December 5, 2023, 7:50pm UTC](https://developer.sailpoint.com/discuss/t/custom-sailpoint-roles/22202/1 "2023-12-05T19:50:37Z")

</div>

Is there an ability to create custom SailPoint permissions for users?  
 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/7/7e8c8a97e51ef348dd1fbdbb152226eb20af75fc.png)

The current built-in user permissions for SailPoint does not have a Read Only level of access and we would like the ability to customize these roles for first level resolution and auditing purposes.

For example we would like the helpdesk to be able to have read only rights to view entitlements listed within the persons identity under accounts. There is currently no way to modify the “Helpdesk Admin” role.

Another example is our auditors would like to validate information for roles and access profiles but “Role Admin” also grants write privileges.

These roles seem very limited on what they can do and we are stuck granting users multiple roles to serve one purpose e.g. “Helpdesk, Cert Admin, etc” The roles currently grant read AND write access to data and unable to restrict users from making changes.

Is there some way to create custom user permissions or customize the built-in user permissions within SailPoint?

---

<div class="post-metadata">

**Author:** ![adunker](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/adunker/32/2664_2.png) [@adunker](https://developer.sailpoint.com/discuss/u/adunker)\
**Post date:** [December 5, 2023, 7:54pm UTC](https://developer.sailpoint.com/discuss/t/custom-sailpoint-roles/22202/2 "2023-12-05T19:54:49Z")

</div>

Nothing at this time. A read-only capability is planned: [Idea: New Admin Role - Read-Only Admin | SailPoint Ideas Portal](https://ideas.sailpoint.com/ideas/GOV-I-737). You could generate PATs with more specific access - but this probably wouldn’t meet your requirements.

Additional items in this space are in various parts of the roadmap or discovery to hopefully improve these capabilities:

- [Segmentation of User Level Permissions based | SailPoint Ideas Portal](https://ideas.sailpoint.com/ideas/GOV-I-2241)

---

<div class="post-metadata">

**Author:** ![jrossicare](https://avatars.discourse-cdn.com/v4/letter/j/a698b9/32.png) [@jrossicare](https://developer.sailpoint.com/discuss/u/jrossicare)\
**Post date:** [December 5, 2023, 10:57pm UTC](https://developer.sailpoint.com/discuss/t/custom-sailpoint-roles/22202/3 "2023-12-05T22:57:04Z")

</div>

I am very much looking forward to SailPoint rolling out a read-only admin as well as finer grained admin access.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [February 3, 2024, 10:57pm UTC](https://developer.sailpoint.com/discuss/t/custom-sailpoint-roles/22202/4 "2024-02-03T22:57:21Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
