Enhancement: Custom User Levels now include SOD Permissions

Description

Background

Identity Security Cloud (ISC) shipped SOD violation management June 29, 2026.

Current Situation

The new feature enabled IAM teams to assign compliance teams to 4 new user levels removing the need to make compliance teams IAM org admins.

Problem

Customers need flexibility to assign SOD compliance permissions based on their needs.

Solution

Enable customers to utilize ISC custom user levels with the permissions from the in the box SOD user levels.

Who is affected?

SailPoint Identity Security customers who own Separation of Duties feature (suites) will have customer user levels for SoD available August 7.

Hey @Colin,

Is there an ETA when ALL other access rights can be assigned separately by customers to support least privilege.

In addition, identities with ORG_ADMIN capabilities can read and write objects, even for newly introduced object types.
Can you create a ORG_READ_ADMIN user level that, when we assign it to someone; they will automatically be able to read all objects that org_admins could read as well, including future object types (and only write them if allowed in other ways). So we shouldn’t have to update our stuff each time a new object type is introduced. (This last request is the most popular request as you can see in the idea portal)