Hi Sailors,
I am currently working on onboarding an API-based application into IdentityIQ.
During account aggregation, I identified four break-glass accounts. Each account is assigned one of the following privilege levels:
- Admin
- Power
- Basic
- Custom
The Admin, Power, and Basic privilege levels are standard roles with predefined sets of permissions. However, the Custom privilege level allows administrators to individually select and customize permissions from a larger set of more than 100 underlying privileges.
From an IIQ access governance perspective, I see a potential challenge:
- IIQ currently aggregates only the high-level privilege (Admin, Power, Basic, Custom).
- The underlying permissions associated with the Custom privilege are not being aggregated or represented as entitlements in IIQ.
- As a result, two users assigned the Custom privilege could have completely different permission sets, while appearing identical during access reviews and certifications.
- This could make certifications inaccurate, as certifiers would only see “Custom” without visibility into the actual permissions granted.
My concern is that this creates a governance and audit gap, since the effective access is not fully represented in IIQ.
What would be the recommended approach to address this from an Identity Governance perspective?