Enhancement: Data Segmentation for Identities

Description

Data Segmentation provides a programmatic method for restricting access to data within core Identity Security Cloud objects, ensuring users can only see the data records they are authorized to access. This release expands Data Segmentation for Identities.

New Capabilities

For enterprise-level customers with complex organizational structures, the latest enhancement to Data Segmentation ensures administrators restrict Human Identity access at a more granular level for users - ensuring least privilege and diminishing privacy concerns.

Problem

  1. Customers often have information within their environment that they consider privileged or need to be visible on a need-to-know basis. However, when a user is granted any given piece of Identity Security Cloud access in the user interface, they are also granted access to all Identities globally across the platform.

  2. Customers often have a smaller, dedicated Identity Security Cloud Administration teams that would like to grant administrative functionality to distributed teams. For example, Conglomerate A would like to delegate administration for the Identities within it’s two companies: Company 1 and Company 2. However, they want to limit the Identity access that Identity Security Cloud administrators at Company 1 and 2 have to see each other’s configurations without limiting the access of Conglomerate A’s Identity Security Administrators.

Solution

To solve for these complex issues faced by Identity Security Cloud customers, SailPoint has extended Data Segmentation support to now include Human Identities, which provides a programmatic method for restricting Identities to those users who need to access them. This segmentation of data ensures users can only see the Human Identities they are authorized to see, and all others outside the segment will not be shown. Data Segmentation provides Org Administrators with multiple options for defining data segments that meet your business requirements.

With this latest enhancement, Data Segmentation provides administrators with restricting access to Roles, Entitlements, and now Identities across Identity Security Cloud.

Who’s Affected

  • Applies to: All Suites

  • Environments: Sandbox and Production

Important Dates

  • Sandbox Deployment begins Aug 11, 2026 and will be a phased delivery throughout the week.

  • Production Deployment will be released in a phased delivery from September 2nd - September 14th, 2026.

5 Likes

At long last - thank you! Very excited to see this.

3 Likes

Does this apply to the identity object opaquely, or can we restrict visibility into which attributes on the identity are viewable as well?

Hello, the identity itself will be restricted based on the segments. Identity attributes cannot be restricted via segmentation.

1 Like

Thank you! Thank you! Thank you!!

1 Like