Segments not working as expected

I need help to set up a segment so that only a group of users can request for few entitlements in AD. I have created a test segment and assigned to single identity, and added 3 entitlements from AD. These entitlements are set as requestable too.

However, another user who is not part of the segment can see these entitlements in the request center. There is no other segment having these entitlements.

Based on what is described in this document, Managing Access Request Segments - SailPoint Identity Services only identities under the segment should see these entitlements in the request center

Hi @iamnithesh,

Does the other user has admin privileges ?

Hi @UjjwalJain Yes the second user is ORG_ADMIN

Is that the reason? I could not find anywhere in the document which says ORG_ADMINs are not affected by the segments (because they are Gods!!)