- Load the data via account/entitlement aggregation of SOT and target sources
- Validate all accounts are correlated to identities properly
- Validate entitlements that are part of roles are assigned to the accounts
- Have identities to role mapping sheet created for validation
- Use Submit Access Request (create-access-request | SailPoint Developer Community) API to raise access request via automated script or manually for identities that should be part of roles. Since all entitlements are already assigned to accounts, ISC will not provision anything on target system and only assign roles on the identities.
Thanks