# Entitiy structure for an application

**URL:** <https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, applications\
**Created:** [October 28, 2025, 6:15am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567 "2025-10-28T06:15:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![liza\_s](https://avatars.discourse-cdn.com/v4/letter/l/71c47a/32.png) [@liza\_s](https://developer.sailpoint.com/discuss/u/liza_s)\
**Post date:** [October 28, 2025, 6:15am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/1 "2025-10-28T06:15:19Z")

</div>

## Which IIQ version are you inquiring about?

_8.3_

## Share all details about your problem, including any error messages you may have received.

Hey everyone, I have a fundamental design question regarding the application entity structure in IIQ.

I want to connect my application to SailPoint IIQ.

I have three entities I would like to manage using IIQ (to aggregate them, provision, etc.).

The entities are users (accounts), groups, and roles.

What is the best practice for managing the connections between the entities? Should the account entity have a property named groups (holding a list of groups), or should I create a new entity named accountGroups, mapping account ID to group ID?

What’s the standard approach for this case? What structure will make provisioning and correlation the easiest?

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [October 28, 2025, 8:10am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/2 "2025-10-28T08:10:49Z")

</div>

Hi @liza_s,

First of all, if your application has a connector in IIQ(Salesforce,ServiceNow,etc.), use it.

In other case you can use JDBC, webservice or delimited file, depending how you want connect.

In every case, you must have the possibility to correlate groups and roles to accounts.

For example, in a JDBC connector, you can create 3 separate objects(account, groups and roles) and on account you must configure an attribute like groups and another like roles.

If you have some dubts on correlation between accounts and entitlements, you can check a standard connector schema like AD.

---

<div class="post-metadata">

**Author:** ![liza\_s](https://avatars.discourse-cdn.com/v4/letter/l/71c47a/32.png) [@liza\_s](https://developer.sailpoint.com/discuss/u/liza_s)\
**Post date:** [October 28, 2025, 9:50am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/3 "2025-10-28T09:50:35Z")

</div>

Hey @enistriminsait, thank you for your response.

I was planning to do what you suggested: create 3 separate objects(account, groups and roles) and on account configure an attribute like groups and another like roles).

I wonder how uncommon it is to configure the relationships as another entity.

In the case I’m wondering about, the account won’t have a groups attribute. I would have a separate entity named accountIdToGroupId, mapping between the two.

---

<div class="post-metadata">

**Author:** ![harsh\_gupta4](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/harsh_gupta4/32/28816_2.png) [@harsh\_gupta4](https://developer.sailpoint.com/discuss/u/harsh_gupta4)\
**Post date:** [October 28, 2025, 11:09am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/4 "2025-10-28T11:09:23Z")

</div>

Hi @liza_s , Can you please explain little bit about your target system , so we can help you with the Sailpoint connector and what steps and best practices you need to follow .

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [October 28, 2025, 12:20pm UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/5 "2025-10-28T12:20:25Z")

</div>

you can create an other object for accountIdToGroupId, but in every case you must mapping on account object an attribute to correlated on this object.

For example:

Account:

id,name,display,idaccountIdToGroupId

AccountIdToGroupId:

id,idAccount,idGroups

Groups:

id,name,displayname

---

<div class="post-metadata">

**Author:** ![paul\_hilchey](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/paul_hilchey/32/24080_2.png) [@paul\_hilchey](https://developer.sailpoint.com/discuss/u/paul_hilchey)\
**Post date:** [October 29, 2025, 5:20am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/6 "2025-10-29T05:20:52Z")

</div>

Hi @liza_s, it is more convenient if the group memberships are modelled as a multi-valued attribute on the account.

Even if your application internally has group membership as a list of accounts on the group object, you should present it to IIQ the other way.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [December 28, 2025, 5:21am UTC](https://developer.sailpoint.com/discuss/t/entitiy-structure-for-an-application/186567/7 "2025-12-28T05:21:49Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
