# Group Correlation mechanism

**URL:** <https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, provisioning, workflows, apis, aggregation\
**Created:** [April 17, 2025, 4:23am UTC](https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489 "2025-04-17T04:23:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rishavghoshacc](https://avatars.discourse-cdn.com/v4/letter/r/dc4da7/32.png) [@rishavghoshacc](https://developer.sailpoint.com/discuss/u/rishavghoshacc)\
**Post date:** [April 17, 2025, 4:23am UTC](https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489/1 "2025-04-17T04:23:51Z")

</div>

Hi all,

Isn’t there a logic or mechanism in SailPoint that does the correlation for Group objects(like we have to manually write a logic to correlate accounts) while Account group aggregation?

I haven’t come across for this anywhere. So how does SailPoint know to correlate the data for the group coming in (if to correlate or to create a new entitlement)

Thanks in advance

---

<div class="post-metadata">

**Author:** ![officialamitguptaa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/officialamitguptaa/32/6624_2.png) [@officialamitguptaa](https://developer.sailpoint.com/discuss/u/officialamitguptaa)\
**Post date:** [April 17, 2025, 6:06am UTC](https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489/2 "2025-04-17T06:06:30Z")

</div>

@rishavghoshacc -

You’re absolutely right to raise this question — **group/entitlement correlation** in SailPoint IdentityIQ (IIQ) is **not as explicitly configurable as account correlation** , and it often leads to confusion. Let’s break this down clearly.

* * *

### Quick Summary:

While **account correlation** requires specific rules (`Correlation Rule`, `Identity Correlation Config`, `Identity Attribute Matching`, etc.), **entitlement (group) correlation** doesn’t follow the same pattern. But **yes, there _is_ a mechanism** that determines how SailPoint processes group objects — whether to **correlate** with existing entitlement definitions or **create new** ones.

* * *

### How Entitlement Correlation Works in SailPoint:

#### In IdentityIQ:

1. **During Aggregation** , when `group` objects are pulled in:

- IdentityIQ compares them against existing `Entitlement` definitions in the `Entitlement catalog`.
- The **key attribute** used for correlation is usually the **`Native Identity`** (i.e., the group name or ID in the source system).
- If an entitlement with the same `Native Identity` already exists in the catalog:
  - It is updated if needed (description, display name, etc.).

- If it doesn’t exist:
  - A new **entitlement entry** is created.

1. This behavior is driven by:

- The **schema configuration** of the `group` object in the application.
- The `group` schema must define a **unique attribute** (like `name`, `cn`, `sAMAccountName`) as the **identity attribute**.

* * *

### Important Notes:

- There is **no explicit correlation rule** for entitlements like there is for accounts.
- The **“correlation” is based on matching values** (usually on the `name`, `ID`, or similar field defined in schema).
- If you’re seeing duplicates being created during entitlement aggregation, it usually means:
  - The **identity attribute for the group schema** is misconfigured.
  - The **case sensitivity** or **whitespace** in names differs.
  - **Multi-valued** group membership attributes might not be parsed properly.

* * *

### Best Practices:

- In **IIQ** , always ensure that `group` schema has proper unique attribute and is defined correctly in the application’s schema.

Hope this helps.

---

<div class="post-metadata">

**Author:** ![rishavghoshacc](https://avatars.discourse-cdn.com/v4/letter/r/dc4da7/32.png) [@rishavghoshacc](https://developer.sailpoint.com/discuss/u/rishavghoshacc)\
**Post date:** [April 17, 2025, 6:24am UTC](https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489/3 "2025-04-17T06:24:45Z")

</div>

@officialamitguptaa I still have the question on why we need to correlate accounts explicitly and not Group objects

---

<div class="post-metadata">

**Author:** ![officialamitguptaa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/officialamitguptaa/32/6624_2.png) [@officialamitguptaa](https://developer.sailpoint.com/discuss/u/officialamitguptaa)\
**Post date:** [April 17, 2025, 6:54am UTC](https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489/4 "2025-04-17T06:54:26Z")

</div>

@rishavghoshacc -

Great follow-up — and it’s a subtle but important distinction in **how SailPoint handles correlation for accounts vs. groups (entitlements)**.

## **Why Do We Need Explicit Account Correlation But Not Group Correlation in SailPoint?**

### **1. Accounts require identity linkage** — groups do not.

- **Accounts** must be mapped to an **Identity object** (a person).
  - This linkage is **not obvious or guaranteed** just from the raw data.
  - Example: You may have 2 John Smiths — which account belongs to which identity?
  - Hence, **explicit correlation logic** is needed to determine the best match based on attributes like email, employee ID, etc.

That’s why we configure:

- **Correlation Config** : Matching rules on account attributes vs identity attributes.
- **Correlation Rules** : Custom logic using BeanShell to determine identity ownership.

* * *

### **2. Groups (Entitlements) are treated as metadata — not owned by identities**

- **Group objects** (like AD groups, DB roles, application privileges) are **not directly linked to identities**. They are:
  - Considered _attributes or properties_ of accounts
  - Managed in the **Entitlement Catalog**
  - Used to define access **within an account** , not between identity and account.

So, **SailPoint doesn’t need to “correlate” group objects to an identity** — it simply:

- Aggregates the **list of entitlements** assigned to accounts
- Builds an **Entitlement Catalog** of all known values
- When provisioning or certifying, matches entitlements **to role definitions** , **policies** , etc.

## To visualize this:

### **Account Correlation Flow:**

```auto
Aggregated Account → Match to Identity → Linked to Identity cube

```

### **Entitlement Handling Flow:**

```auto
Aggregated Account → Extract groups/roles → Populate Entitlement Catalog → Show in Identity's Access

```

So the entitlements ride along with accounts — **no correlation required** , just recognition and cataloging.

Hope this clarifies your query.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [June 16, 2025, 6:55am UTC](https://developer.sailpoint.com/discuss/t/group-correlation-mechanism/112489/5 "2025-06-16T06:55:01Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
