Setting Approvals on Editing Roles

Hi everyone,

We have a specific requirement regarding Roles. Our client has requested that an approval process be established for any changes to Roles. For instance, if someone wants to add or remove a specific Role, it should go through an approval process. Once all approvers have given their consent, the request should then be forwarded to the Role Owner or an individual with Role Admin permissions. I’m curious about how this can be implemented in SailPoint IdentityNow. Does anyone have any suggestions?

Thank you in advance!

Hi @sahincelik ,

ISC provides an approval process to define for Roles, Access Profile and Entitlements. You can manage the approval upto 3 levels or so. To setup the configuration you can edit the respective access items.

Please go through the provided link :- Managing Requests for Roles and Access Profiles - SailPoint Identity Services.

I hope it will help to manage the approval process for the access items as per your business requirement.

Thanks,
Prashant

Hi Sahin,

To the best of my knowledge, I dont believe this is possible in ISC.

The only way to restrict who is able to modify the roles is by carefully choosing who has access to the elavated Sailpoint permissions such as Admins and Role Admins as you say.

3 Likes

I cannot think of anyway to achieve this in ISC. Only way I can think of is to develop an external system that will communicate with ISC via APIs

1 Like

Hi @PrashantMishra, what you sent me is about configuring setting approvals for access/removal request for people. What I am looking for is adding approval process when adding/removing entitlements to Roles/Access Profiles.

Hi @sahincelik ,
Ahh I see.

Approval process for adding and removal of entitlements to access items are not achievable in ISC at the moment. But to restrict the exposure to assign/remove entitlements we can use the available permissions in ISC such as Admins, Role/Sub Role admins as per @Mccarney .

Thanks,
Prashant

Hi @sahincelik ,

I don’t get a way to do this in ISC. But after saving changes, we can go for a review using certifications (Role Composition).

Thanks!!

3 Likes

We actually advised to go with Role Compostion certification, however that was not accepted by our client.

1 Like

Then, the only way is to restrict who can able to modify roles like Admins, Role/Sub-Role admins.

Thanks!!

2 Likes