Enhancement: Governance Group Custom User Levels

What’s New

We are excited to announce that Custom User Levels has now been extended to Governance Groups. This enhancement to Custom User Level now offers administrators to extend permissions to Governance Groups, to include Governance Group Membership Management, Governance Group Read Only, and Governance Group Management.

Who’s Affected

  • Applies to: Business and Business Plus
  • Environments: Sandbox and Production

Important Dates

  • May 18, 2026 – Available in Sandbox
  • May 25, 2026 – Available in Production
6 Likes

This is awesome and something some of our user groups had been asking for. I will just give another plug that I think SailPoint needs to re-evaluate what is considered “elevated” access and requires user’s to register an MFA device (even for users who only login via SSO). Currently anything that gives any access to the “admin” menu triggers that. In my opinion, read only access to things like entitlements, governance groups, etc. that are granted by Custom User Levels should not flag as elevated access and require users to register a throaway TOTP MFA device.

1 Like

Much awaited and definitely a much-needed enhancement. It would be great if this capability could also be extended to Applications in the future for more granular governance and delegation use cases.

1 Like

This is definitely a nice to have!

1 Like

That’s great news — this has been a long-awaited feature! :blush:

That’s a really great enhancement for Governance Group administration much awaited!

1 Like

Great news !! Much awaited One !

Great news.

Is there anything that needs to be done to see this in Custom User Level as it is not showing up in Sandbox Environment?

Same. Just opened a support ticket so we’ll see what they say there as well.

Thank you for opening a ticket @danielbock, I don’t see it in sandbox either. I see a Filter option for Governance Groups, but that’s all.

@JKistler do you know if there are plans to extend these Custom User Levels to provide a read-only view of sources and source configurations? This is one of the biggest elements standing in the way of creating a true read-only admin

Thank you all for posting about not seeing in Sandbox. I will work with the team to determine what the issue is.

Regarding Sources, we’re continuing to discuss with teams to enhance Custom User Levels and I will provide updates as we add additional functionality

Looks like the issue has been resolved and these new Custom User Levels should now be appearing in your Sandbox environments. I apologize for the delay.

This is really helpful.

They are visible now.

What about Production? It’s still not there in production.

We have been testing this feature as we find it quite useful. However, we found a couple of things we would like to highlight. We mostly wanted to see if this is an expected behavior.

  1. Anyone with any of these user levels can see all the governance group created. No only theirs. Nevertheless, they cannot edit the name, description or owner.

  2. This is mostly related to an error: Even if the identity has all three user levels, they come across this error message when trying to add a new member.

1 Like

@solidigmdcortes We are seeing the same behavior in our Sandbox while testing Governance Groups with Custom User Levels. When attempting to add a new member, we receive the same permission error shown in your screenshot, even though the identity has all the expected user levels assigned. Has SailPoint provided any update or resolution for this issue?

2 Likes

@ssowmya567 We opened a support ticket with SailPoint. As per their response, to solve it, you need to add ‘Identity Read Only’ permission to the custom user level. We tested and it worked. Be aware that with this new permission you will also grant users access to see every existing identity’s info.

1 Like

Thanks @solidigmdcortes , It’s working now!

2 Likes