New Capability
Next-Gen Access Request
Next-Gen Access Request introduces a simpler way to find access, choose recipients, and manage requests in Identity Security Cloud.
What this means for you: Your sandbox tenant receives the new experience automatically on September 28, 2026. Enabling it in production is your decision during a six-month opt-in window that runs October 12, 2026 through February 15, 2027, and on February 16, 2027 all remaining production tenants move automatically. Opting in is permanent — a production tenant cannot return to the legacy experience — so use the sandbox period to evaluate the change and prepare your users. See Action required below for what to do and when.
Aha! Ideas Portal
- GOV-I-2824 New Request Center: Simplify the search
- GOV-I-2918 Searching for users using attributes outside of display name
- GOV-I-3693 Search for a department or other identity attribute
- GOV-I-3918 User search filter when requesting for others
- GOV-I-905 Find people when multiple identities have the same name
- GOV-I-4786 AI assistance to simplify access requests
Description
Next-Gen Access Request replaces the current Request Center experience with streamlined access item and identity selection. Requesters can find access and the right recipients in fewer steps using enhanced search and filters. The experience also supports machine identity requests for customers with Machine Identity Security and includes the Access Request Agent for customers entitled to Harbor Pilot.
This is a Request Center experience change only. Existing access items, in-flight requests, and provisioning behavior stay the same.
Problem
Today, requesters choose separate paths when requesting access for themselves, for others, or for a team. Catalog search matches only an item name, identity selection relies on a single name-based dropdown, and results do not show enough access item or identity detail.
Solution
Find access more easily
Find Access searches across name, description, source, application, owner, privilege, and access model metadata. Requesters can filter results by roles, access profiles, entitlements, or applications, and move among the full catalog, Recommended, and selected items. Each card also shows an effective privilege label of HIGH, MEDIUM, or LOW.
Requesters can open an access item to review its description and metadata before adding it to a request.
Request access for others
Requests for others and for a team now enter through one flow. Search identities by name, email, or manager; filter on up to five public identity attributes configured by your administrator; toggle between All and My Team; and select multiple identities.
Request access for machine identities
Customers with Machine Identity Security can select machine identities from a dedicated experience and filter them by owner or type.
Use the Harbor Pilot Access Request Agent
For customers entitled to Harbor Pilot, the Access Request Agent can search in natural language, refine results, support interactive selection, submit requests—including required forms—cancel a request with a reason, and report request status. Approvals in the agent are not available yet.
Who is affected?
All Human Fabric and SailPoint Agentic Fabric customers using Identity Security Cloud will receive the new Request Center experience. Machine identity requests require the Machine Identity Security add-on. The Access Request Agent requires separate Harbor Pilot entitlement.
Action required
1. Prepare in sandbox — starting September 28, 2026
All eligible sandbox tenants receive Next-Gen Access Request automatically. No action is needed to enable it. During this period:
- Familiarize requesters and administrators with the new navigation
- Update training materials, runbooks, and internal documentation that show the previous layout
- Configure the public identity attributes used in recipient filters
- Plan the change management your organization needs before production
2. Decide when to opt in — October 12, 2026 through February 15, 2027
Enabling Next-Gen Access Request in production is your decision during this six-month window. Watch for the in-product opt-in prompt and notifications in your tenant. SailPoint is providing this window so administrators can choose the right timing for their users rather than absorbing the change on a fixed date.
Opting in is permanent. Once a production tenant opts in, it cannot be rolled back to the legacy experience. Evaluate the new experience in sandbox and complete your change management before you enable it in production.
3. Automatic move — February 16, 2027
All remaining production tenants move to Next-Gen Access Request. If you have not opted in by February 15, this happens for you.
Also note: all new access request functionality will be delivered only in Next-Gen Access Request going forward. The legacy experience will not receive new capabilities.
Important dates
| Milestone | Date |
|---|---|
| Early access availability | September 8, 2026 |
| Sandbox tenant availability | September 28, 2026 |
| Production opt-in period | October 12, 2026–February 15, 2027 |
| All production tenants moved | February 16, 2027 |
Resources
Product documentation will be available by sandbox availability on September 28, 2026.










