Skip to main content

IntelligenceService

HTTP API that returns the Intelligence (identity context) for SecOps enrichment use cases (SIEM/SOAR connectors, MCP, browser extension), and accepts asynchronous response actions for remediation. Identity reads are backed by Atlas internal-REST calls to MICE, Shelby List Accounts, SDS Search, IDA-outliers, and identity-history.

License-based segmentation​

  • `idn:response-and-remediation` (required): enforced on all `/intelligence/*` routes.
  • `IDA-outliers` (optional): governs the Human `outliers.rareAccess` slice only. When the tenant lacks this license, the `outliers` key is omitted.
  • `idg:base` (optional): governs the root-level `identityGraph` deep link on aggregate responses. When the tenant lacks this license, `identityGraph` is omitted.
  • `idn:machine-identity-security` (optional): governs the Human `nonHumanIdentityOwnership` slice. When the tenant lacks this license, `nonHumanIdentityOwnership` is omitted on the aggregate GET and the `/non-human-identity-ownership/{category}` child route returns 403 Forbidden.

Pagination​

The aggregated Human GET embeds the first page of each paged slice. Each upstream paged call sends `count=true` and reads `X-Total-Count`. Parent slices expose `totalCount` when `items` is non-empty and set `next` when `totalCount > offset + len(items)` (aggregate offset is always 0). Empty slices render as `items: []` with no `totalCount`. `privilegedAccess` is never paged and carries no `totalCount`. When licensed, `nonHumanIdentityOwnership` pages each `primaryOwned` / `secondaryOwned` bucket independently under `agents` and `applications`. Non-human identity aggregate `accounts` includes `totalCount` and `next`; continue with `GET .../accounts?isNHI=true` (bare array response).

Human child routes (`/accounts`, `/outliers/rare-access`, `/access-history/*`, `/non-human-identity-ownership/{category}`) follow the SailPoint V3 pattern: pass `count=true` to receive `X-Total-Count` (including `0` on empty pages). When `count` is omitted, upstream count work is skipped and the header is omitted.

Every method returns an Observable. All request paths are relative to the baseUrl you pass to provideSailPoint().

MethodHTTP requestDescription
create-response-action-v1POST /intelligence/v1/response-actionsCreate a response action
get-identity-intelligence-v1GET /intelligence/v1/identitiesGet identity by filter
get-intel-identity-access-item-history-v1GET /intelligence/v1/identities/{id}/access-history/access-itemsList identity access item history
get-intel-identity-accounts-v1GET /intelligence/v1/identities/{id}/accountsList identity accounts
get-intel-identity-certification-history-v1GET /intelligence/v1/identities/{id}/access-history/certificationsList identity certification history
get-intel-identity-non-human-identity-ownership-v1GET /intelligence/v1/identities/{id}/non-human-identity-ownership/{category}List owned NHI identities
get-intel-identity-rare-access-v1GET /intelligence/v1/identities/{id}/outliers/rare-accessList identity rare access
get-response-action-status-v1GET /intelligence/v1/response-actions/{id}/statusGet response action status

create-response-action-v1​

Create a response action Requires tenant license idn:response-and-remediation.

Creates a response action: the request is validated, a requestId (the correlation id) is minted, the action is recorded as SUBMITTED, and an event is published that triggers the correlated workflow(s).

Returns HTTP 202 with the requestId, an initial SUBMITTED status, and a statusUrl. Poll GET /intelligence/v1/response-actions/{requestId}/status for progress.

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is CreateResponseActionV1RequestParams.

NameTypeDescriptionNotes
responseactioncreaterequestResponseactioncreaterequest

Return type​

Observable<Responseactionaccepted>

HTTP request headers​

  • Content-Type: application/json
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';
import { Responseactioncreaterequest } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

createResponseActionV1(): void {
const responseactioncreaterequest: Responseactioncreaterequest = ; //
this.api.createResponseActionV1({ responseactioncreaterequest: responseactioncreaterequest }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-identity-intelligence-v1​

Get identity by filter Requires tenant license idn:response-and-remediation.

Caution: When Data Segmentation is enabled, generic API Management API keys are not tied to a user identity and may fail or return incomplete data. Use a personal access token or other user-scoped OAuth token. See API keys and Data Segmentation.

Resolves exactly one identity using a single SCIM-style filters expression. Returns an enriched Human or non-human identity (NHI) envelope. Single-clause filters only; unsupported fields or operators return HTTP 400.

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetIdentityIntelligenceV1RequestParams.

NameTypeDescriptionNotes
filtersstringFilter results using the standard syntax described in V3 API Standard Collection Parameters Filtering is supported for the following fields and operators: id: eq email: eq opaqueIdentifier: eq[default to undefined]

Return type​

Observable<Intelidentityenvelope>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getIdentityIntelligenceV1(): void {
const filters: string = ; // Filter results using the standard syntax described in [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters#filtering-results) Filtering is supported for the following fields and operators: **id**: *eq* **email**: *eq* **opaqueIdentifier**: *eq*
this.api.getIdentityIntelligenceV1({ filters: filters }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-intel-identity-access-item-history-v1​

List identity access item history Continuation endpoint for the parent response's accessHistory.accessItems.next link. Returns one page of access-item history events for the supplied limit and offset values. Pass count=true to receive X-Total-Count (including 0 on empty pages). Unsupported event types and per-record decode failures are dropped server-side. Requires tenant license idn:response-and-remediation.

Not applicable to non-human identities.

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetIntelIdentityAccessItemHistoryV1RequestParams.

NameTypeDescriptionNotes
idstringNon-empty identity id path segment for Intelligence sub-resources.[default to undefined]
limitnumberPage size. Defaults to 250; values above 250 are rejected with 400.[optional] [default to 250]
offsetnumberZero-based page offset. Defaults to 0.[optional] [default to 0]
countbooleanIf true it will populate the X-Total-Count response header with the number of results that would be returned if limit and offset were ignored. Since requesting a total count can have a performance impact, it is recommended not to send count=true if that value will not be used. See V3 API Standard Collection Parameters for more information.[optional] [default to false]

Return type​

Observable<Array<IntelAccessItemHistoryEvent>>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getIntelIdentityAccessItemHistoryV1(): void {
const id: string = ; // Non-empty identity id path segment for Intelligence sub-resources.
const limit: number = ; // Page size. Defaults to 250; values above 250 are rejected with 400. (optional)
const offset: number = ; // Zero-based page offset. Defaults to 0. (optional)
const count: boolean = ; // If *true* it will populate the *X-Total-Count* response header with the number of results that would be returned if *limit* and *offset* were ignored. Since requesting a total count can have a performance impact, it is recommended not to send **count&#x3D;true** if that value will not be used. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional)
this.api.getIntelIdentityAccessItemHistoryV1({ id: id }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-intel-identity-accounts-v1​

List identity accounts Continuation endpoint for accounts.next. Pass count=true for X-Total-Count.

  • Human (default): omit isNHI or set it to false. Slice object (items).
  • Non-human identity (NHI): set isNHI=true (required for NHI aggregate accounts.next links). Bare JSON array.

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetIntelIdentityAccountsV1RequestParams.

NameTypeDescriptionNotes
idstringNon-empty identity id path segment for Intelligence sub-resources.[default to undefined]
limitnumberPage size. Defaults to 250; values above 250 are rejected with 400.[optional] [default to 250]
offsetnumberZero-based page offset. Defaults to 0.[optional] [default to 0]
countbooleanIf true it will populate the X-Total-Count response header with the number of results that would be returned if limit and offset were ignored. Since requesting a total count can have a performance impact, it is recommended not to send count=true if that value will not be used. See V3 API Standard Collection Parameters for more information.[optional] [default to false]
isNHIbooleanNHI accounts when `true` (bare array). Human accounts when omitted or `false` (slice object).[optional] [default to false]

Return type​

Observable<GetIntelIdentityAccountsV1200Response>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getIntelIdentityAccountsV1(): void {
const id: string = ; // Non-empty identity id path segment for Intelligence sub-resources.
const limit: number = ; // Page size. Defaults to 250; values above 250 are rejected with 400. (optional)
const offset: number = ; // Zero-based page offset. Defaults to 0. (optional)
const count: boolean = ; // If *true* it will populate the *X-Total-Count* response header with the number of results that would be returned if *limit* and *offset* were ignored. Since requesting a total count can have a performance impact, it is recommended not to send **count&#x3D;true** if that value will not be used. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional)
const isNHI: boolean = ; // NHI accounts when &#x60;true&#x60; (bare array). Human accounts when omitted or &#x60;false&#x60; (slice object). (optional)
this.api.getIntelIdentityAccountsV1({ id: id }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-intel-identity-certification-history-v1​

List identity certification history Continuation endpoint for the parent response's accessHistory.certifications.next link. Returns one page of certification history events for the supplied limit and offset values. Pass count=true to receive X-Total-Count (including 0 on empty pages). Per-record decode failures are dropped server-side. Requires tenant license idn:response-and-remediation.

Not applicable to non-human identities.

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetIntelIdentityCertificationHistoryV1RequestParams.

NameTypeDescriptionNotes
idstringNon-empty identity id path segment for Intelligence sub-resources.[default to undefined]
limitnumberPage size. Defaults to 250; values above 250 are rejected with 400.[optional] [default to 250]
offsetnumberZero-based page offset. Defaults to 0.[optional] [default to 0]
countbooleanIf true it will populate the X-Total-Count response header with the number of results that would be returned if limit and offset were ignored. Since requesting a total count can have a performance impact, it is recommended not to send count=true if that value will not be used. See V3 API Standard Collection Parameters for more information.[optional] [default to false]

Return type​

Observable<Array<IntelCertificationHistoryEvent>>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getIntelIdentityCertificationHistoryV1(): void {
const id: string = ; // Non-empty identity id path segment for Intelligence sub-resources.
const limit: number = ; // Page size. Defaults to 250; values above 250 are rejected with 400. (optional)
const offset: number = ; // Zero-based page offset. Defaults to 0. (optional)
const count: boolean = ; // If *true* it will populate the *X-Total-Count* response header with the number of results that would be returned if *limit* and *offset* were ignored. Since requesting a total count can have a performance impact, it is recommended not to send **count&#x3D;true** if that value will not be used. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional)
this.api.getIntelIdentityCertificationHistoryV1({ id: id }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-intel-identity-non-human-identity-ownership-v1​

List owned NHI identities Continuation endpoint for a human parent's nonHumanIdentityOwnership.{category}.primaryOwned.next or nonHumanIdentityOwnership.{category}.secondaryOwned.next link. Returns a bare JSON array of owned non-human identity summary rows for the given category, optional ownershipRole, limit, and offset. Wire items match the aggregate ownership item shape ({ id, displayName, source? }).

When ownershipRole is omitted, the request defaults to primary. Pass count=true to receive X-Total-Count (including 0 on empty pages). The filters query parameter is not supported on this route (HTTP 400).

Requires tenant licenses idn:response-and-remediation and idn:machine-identity-security. Tenants without idn:machine-identity-security receive HTTP 403.

Not applicable to non-human identities (no ownership slice on the NHI envelope).

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetIntelIdentityNonHumanIdentityOwnershipV1RequestParams.

NameTypeDescriptionNotes
idstringNon-empty identity id path segment for Intelligence sub-resources.[default to undefined]
category`'agents''applications'`Non-human identity ownership category. Use `agents` for AI Agent subtypes and `applications` for Application subtypes.
ownershipRole`'primary''secondary'`Optional ownership role discriminator. When set to `primary` or `secondary`, returns one paged role bucket. When omitted, defaults to `primary`.
limitnumberPage size. Defaults to 250; values above 250 are rejected with 400.[optional] [default to 250]
offsetnumberZero-based page offset. Defaults to 0.[optional] [default to 0]
countbooleanIf true it will populate the X-Total-Count response header with the number of results that would be returned if limit and offset were ignored. Since requesting a total count can have a performance impact, it is recommended not to send count=true if that value will not be used. See V3 API Standard Collection Parameters for more information.[optional] [default to false]

Return type​

Observable<Array<Intelnonhumanidentityownershipitem>>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getIntelIdentityNonHumanIdentityOwnershipV1(): void {
const id: string = ; // Non-empty identity id path segment for Intelligence sub-resources.
const category: string = ; // Non-human identity ownership category. Use &#x60;agents&#x60; for AI Agent subtypes and &#x60;applications&#x60; for Application subtypes.
const ownershipRole: string = ; // Optional ownership role discriminator. When set to &#x60;primary&#x60; or &#x60;secondary&#x60;, returns one paged role bucket. When omitted, defaults to &#x60;primary&#x60;. (optional)
const limit: number = ; // Page size. Defaults to 250; values above 250 are rejected with 400. (optional)
const offset: number = ; // Zero-based page offset. Defaults to 0. (optional)
const count: boolean = ; // If *true* it will populate the *X-Total-Count* response header with the number of results that would be returned if *limit* and *offset* were ignored. Since requesting a total count can have a performance impact, it is recommended not to send **count&#x3D;true** if that value will not be used. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional)
this.api.getIntelIdentityNonHumanIdentityOwnershipV1({ id: id, category: category }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-intel-identity-rare-access-v1​

List identity rare access Continuation endpoint for the parent response's outliers.rareAccess.next link. Resolves the identity's first outlier, then returns one page of rare access items for the supplied limit and offset values. Pass count=true to receive X-Total-Count (including 0 on empty pages). An identity with no outlier returns an empty array with X-Total-Count: 0 when count=true. Requires tenant license idn:response-and-remediation and the IDA-outliers license.

Not applicable to non-human identities (no outliers slice on the NHI envelope).

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetIntelIdentityRareAccessV1RequestParams.

NameTypeDescriptionNotes
idstringNon-empty identity id path segment for Intelligence sub-resources.[default to undefined]
limitnumberPage size. Defaults to 250; values above 250 are rejected with 400.[optional] [default to 250]
offsetnumberZero-based page offset. Defaults to 0.[optional] [default to 0]
countbooleanIf true it will populate the X-Total-Count response header with the number of results that would be returned if limit and offset were ignored. Since requesting a total count can have a performance impact, it is recommended not to send count=true if that value will not be used. See V3 API Standard Collection Parameters for more information.[optional] [default to false]

Return type​

Observable<Array<IntelOutlierAccessItem>>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getIntelIdentityRareAccessV1(): void {
const id: string = ; // Non-empty identity id path segment for Intelligence sub-resources.
const limit: number = ; // Page size. Defaults to 250; values above 250 are rejected with 400. (optional)
const offset: number = ; // Zero-based page offset. Defaults to 0. (optional)
const count: boolean = ; // If *true* it will populate the *X-Total-Count* response header with the number of results that would be returned if *limit* and *offset* were ignored. Since requesting a total count can have a performance impact, it is recommended not to send **count&#x3D;true** if that value will not be used. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional)
this.api.getIntelIdentityRareAccessV1({ id: id }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]

get-response-action-status-v1​

Get response action status Requires tenant license idn:response-and-remediation.

Returns the current aggregate status of a previously submitted response action, identified by the requestId returned from POST /intelligence/v1/response-actions.

Supported actionType values: DISABLE_IDENTITY, DISABLE_ACCOUNT.

API Spec

Parameters​

The service takes one object that holds every parameter. Its type is GetResponseActionStatusV1RequestParams.

NameTypeDescriptionNotes
idstringThe requestId of the response action to look up.[default to undefined]

Return type​

Observable<Responseactionstatus>

HTTP request headers​

  • Content-Type: Not defined
  • Accept: application/json

Example​

import { Component, inject } from '@angular/core';
import { IntelligenceService } from '@sailpoint/angular-sdk/intelligence';

@Component({ selector: 'app-example', template: '' })
export class ExampleComponent {
private readonly api = inject(IntelligenceService);

getResponseActionStatusV1(): void {
const id: string = ; // The requestId of the response action to look up.
this.api.getResponseActionStatusV1({ id: id }).subscribe({
next: (result) => console.log(result),
error: (error) => console.error(error),
});
}
}

[Back to top]