New Capability: Custom User Levels

Hi @sreeram / @HussainshaSyed001 ,

Still we are unable to see in our stage/Prod tenants.

@vsekar7 , highly likely its being released in phases, we were not able to find this in our sandbox on the prescribed sandbox availability date ie. November 3rd.

1 Like

@jeremy_southerland
Thanks, good feature we’ve been waiting for this for a long time.

@jeremy_southerland

I would like to see the following in the custom user’s level
Search
Download access certification campaign reports
Access Request Read
Additionally
The CULs are not searchable in the search.
Make them entitlements and requestable in the request center.
Thanks

I tested this custom user level, promoting as entitlement

Added a custom user level to some users manually and performed aggregations for IdentityNow source

  1. Entitlement Aggregation – nothing
  2. Account Aggregation – Entitlement promoted, got custom user level ID alone, not any other properties like display name or description. I believe this is enough to get forwarded for access requests.

For custom user levels, it is a different API, guess they missed it to add in connector. I checked from scope perspective as well, there is no new scope created for custom user levels or maybe it will be created.

Cool feature but many permissions are missing so you still need the default user levels.

Also, these NEED to be entitlements so you can properly request them for audit purposes, just like the default user levers are.

Would be nice to have the default user levels listed in that feature so you can quickly check the identities that have the user level, even if you would be unable to change these user levels.

3 Likes

Thanks for this feedback ! Hope that SailPoint will add this feature in the connector quickly.

1 Like

This looks like a very helpful addition however we don’t see it available in our tenants. Do we know when its expected to be available?
Looking forward to using it soon. Thanks!

This is a great new feature and we have really been waiting for it to be available.

I have now created the first customized User level. But I can’t seem to find how I make it requestable through a role or as an entitlement.
How do users get the access?

I do not see governance group included. Will it be included at a later stage?

Love the idea, nut not sure if anyone else is seeing the issue where a custom UL is not able to be added to a role.

Hi @jeremy_southerland we get to know from SailPoint support that data segmentation and custom user level feature cannot work together. We were facing an issue with this feature and raised a support case for the same but get to know that issue was due to data segmentation feature was enable. could you help us to understand why the two feature are conflicting each other?

2 Likes

Governance groups are in the Loopback connector / Source type: Identity Security Cloud Governance, also user levels are in. Custom user levels are also aggregated, but not yet with a name (ID only). A manual rename fixes this for now.

1 Like

i agree it’s very frustrating not being able to sort many things alphabetically in ISC ( identity-level entitlements, etc) i’ve gone to SailPoint Ideas Portal and upvoted every search result for “alphabetical” :slight_smile:

Did you manage to make the custom roles requestable?

@jeremy_southerland do you know if there’s any plans to add in the ability to create a true read-only admin level? for example, there’s no ability to give people the ability to see all Sources and affiliated data without the ability to change the config

1 Like

Setup a Identity Security Cloud Governance source and your custom user levels can be made requestable.

Setup a Identity Security Cloud Governance source and your custom user levels can be made requestable.

That doesn’t work. We have one of those but only default UserLevels are visible. Not the new customized UserLevels.

I’ve experienced something similar, but found a workaround to get it to work.

  1. Add a user directly to the custom user level.
  2. Account Aggregate ISC Governance Source.
  3. Search the ID value of the custom user level (can go look at the one assigned to the user directly) in the entitlements and it should be present to make it requestable or add it to an access profile.

It does seem like a bug that it doesn’t appear after a group aggregation. It also only shows the ID value not the display name once aggregated from a user.

Hi @iamjenny ,

For the default user level, it will be available under the same name whereas for the custom user level, the source is not available. So if you search with the id of the custom user level, it will be available with name as ID under entitlement also from where you need to rename the entitlement. This is the same we have done for our tenant across environments.