Description
Customers can now delete human or machine accounts directly in Identity Security Cloud (ISC) — with configurable approval workflows and complete audit tracking. This removes the need for custom BeforeProvisioning rules, reduces deployment friction, and enables true end-to-end lifecycle management for human, machine, and uncorrelated accounts.
This update introduces source-level approval settings for account deletion requests via UI, API, and the workflow. Together, these capabilities provide a secure, governed, and transparent way to manage account deletions.
New Capabilities
- Source-level Account Deletion Approval Settings for:
- Human & Uncorrelated accounts
- Machine accounts
- Single and Multi-step approval configuration
- New Delete Account action available across supported Account UIs for applicable sources.
- Workflow enhancement: The Manage Account → Delete Account action now performs true account deletion on supported direct sources (previously limited to manual task generation for Flat File sources)
- Account deletion supported via API, enabling automation use cases
- Request tracking via My Requests → Account Requests
- Approval tracking via Approvals → Account Requests
- Full audit logging for:
- Approval configuration changes
- Delete Account success and failure events
- Email notifications for request submission, decision, cancellation, completion, and failure.
Problem
Customers need the ability to delete accounts — not just disable them — particularly when users are terminated or machine accounts must be decommissioned.
To help address this, we introduced account deletion via lifecycle management, . However, because this capability was only applicable to human identities in an inactive state, some customers still rely on code-based BeforeProvisioning rules to perform all necessary account deletions
Solution
ISC now provides a fully governed, trackable, and auditable account deletion capability across UI, Workflow, and API for any type of account - machine or human.
1. Configure Account Deletion Approval Settings
Admins can configure approval requirements for account deletions under:
- Source → Account Management → Approval Settings (Human & Uncorrelated Accounts)
- Source → Machine Accounts → Approval Settings (Default Machine Accounts)
Approval is set as required by default, and the source owner is pre-selected as the approver.
New ‘Approval Settings’ for human and machine accounts
2. Delete Accounts from the UI and API
Authorized users (Org Admin, Source Admin, and Account Owner) can initiate account deletion from supported Account pages.
- If approval is required → A delete request is created and routed for approval
- If approval is not required → A confirmation modal is shown before deletion
- A request to delete an account can be made via the API endpoint
- Approval logic applies when enabled via source configuration
‘Delete Account’ under the Actions menu
Submit the request when approval is required
3. Requester and Approver view
To support the growing volume and types of requests, the Request Center navigation and structure have been updated.
- The navigation bar now includes a Request Center dropdown with:
- New Request
- My Requests
Request Center new dropdown menu
- Account Delete requests can be:
- Tracked under Request Center → My Requests → Account Requests
Dedicated Account Requests page to track the account deletion requests
- Approved from Approvals → Account Requests
Account Requests page to approve/deny the account deletion requests
5. Workflow Support for True Deletion
The Manage Account → Delete Account action in Workflow now performs a true deletion on supported direct sources.
Previously, this only deleted accounts for Flat File sources. It now executes real delete operations where supported and respects source-level approval settings.
Note: When an account is deleted, any associated entitlements that are linked to the account are removed from the identity. If the identity still has a role assigned that includes entitlements on the source on which the account is being deleted, ISC will delete the account, but it will be recreated on the next identity refresh because of the active role assignment. To avoid this, we recommend removing any related Roles from the identity before deleting its accounts.
Who is affected?
All customers.
Action Required
Administrators should review the new Account Deletion Approval Settings at the source level and update the default values as needed to align with their organization’s governance policies. Approval is enabled by default for account delete requests.
Customers currently relying on custom BeforeProvisioning rules for account deletion should also evaluate whether those rules remain necessary.
Important Dates
- Sandbox: March 23rd
- Production: Week of March 30th







