Skip to main content

BusinessApplications

A Business Application groups machine identities (for example AI agents or applications) under a common owner and sanctioned status. Business Applications can be defined out-of-the-box, discovered from a source, or created by an administrator. Signatures on a Business Application drive automatic correlation of machine identities to it; sanctioned status is independent metadata that machine identities inherit once linked.

All URIs are relative to https://sailpoint.api.identitynow.com

MethodHTTP requestDescription
New-BusinessApplicationV1POST /business-applications/v1Create Business Application
Get-BusinessApplicationV1GET /business-applications/v1/{id}Get Business Application
Get-BusinessApplicationsV1GET /business-applications/v1List Business Applications
Update-BusinessApplicationV1PATCH /business-applications/v1/{id}Update Business Application

create-business-application-v1

Creates a custom Business Application. Requires the idn:business-application:create right, the Machine Identity Security product to be enabled, and the custom Business Application feature to be enabled for the tenant. The name must be unique within the tenant, and any provided signatures must not already be assigned to another Business Application.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
BodyBusinessApplicationBusinessApplicationTrue

Return type

BusinessApplication

Responses

CodeDescriptionData Type
200The created Business Application.BusinessApplication
400Client Error - Returned if the request body is invalid, for example a missing or blank `name`, an unrecognized signature `type`, or a duplicate `(type, name)` signature pair within the request.ErrorResponseDto
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.ListBusinessApplicationsV1401Response
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.ErrorResponseDto
409Conflict - Returned if the `name` is already in use by another Business Application in the tenant, or if a requested signature is already assigned to another Business Application.ErrorResponseDto
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.ListBusinessApplicationsV1429Response
500Internal Server Error - Returned if there is an unexpected error.ErrorResponseDto

HTTP request headers

  • Content-Type: application/json
  • Accept: application/json

Example

$BusinessApplication = @"{
"owner" : {
"name" : "William Wilson",
"id" : "2c91808568c529c60168cca6f90c1313",
"type" : "IDENTITY"
},
"vendor" : "Cursor",
"created" : "2026-01-15T13:45:12.312Z",
"origin" : "",
"name" : "Cursor",
"description" : "AI coding assistant used by the platform engineering team.",
"modified" : "2026-02-20T09:31:47.882Z",
"id" : "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"source" : {
"name" : "William Wilson",
"id" : "2c91808568c529c60168cca6f90c1313",
"type" : "IDENTITY"
},
"signatures" : [ {
"name" : "cursor",
"type" : "AI Agent"
}, {
"name" : "cursor",
"type" : "AI Agent"
} ],
"additionalOwners" : [ {
"name" : "William Wilson",
"id" : "2c91808568c529c60168cca6f90c1313",
"type" : "IDENTITY"
}, {
"name" : "William Wilson",
"id" : "2c91808568c529c60168cca6f90c1313",
"type" : "IDENTITY"
} ],
"sanctionedStatus" : ""
}"@

# Create Business Application

try {
$Result = ConvertFrom-JsonToBusinessApplication -Json $BusinessApplication
New-BusinessApplicationV1 -BusinessApplication $Result

# Below is a request that includes all optional parameters
# New-BusinessApplicationV1 -BusinessApplication $Result
} catch {
Write-Host $_.Exception.Response.StatusCode.value__ "Exception occurred when calling New-BusinessApplicationV1"
Write-Host $_.ErrorDetails
}

[Back to top]

get-business-application-v1

Returns a single Business Application by ID for the requesting tenant. Requires the idn:business-application:read right and the Machine Identity Security product to be enabled.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
PathIdStringTrueBusiness Application ID.

Return type

BusinessApplication

Responses

CodeDescriptionData Type
200A Business Application object.BusinessApplication
400Client Error - Returned if the request body is invalid.ErrorResponseDto
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.ListBusinessApplicationsV1401Response
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.ErrorResponseDto
404Not Found - Returned if no Business Application exists for the given ID.ErrorResponseDto
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.ListBusinessApplicationsV1429Response
500Internal Server Error - Returned if there is an unexpected error.ErrorResponseDto

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

$Id = "a1b2c3d4-e5f6-7890-abcd-ef1234567890" # String | Business Application ID.

# Get Business Application

try {
Get-BusinessApplicationV1 -Id $Id

# Below is a request that includes all optional parameters
# Get-BusinessApplicationV1 -Id $Id
} catch {
Write-Host $_.Exception.Response.StatusCode.value__ "Exception occurred when calling Get-BusinessApplicationV1"
Write-Host $_.ErrorDetails
}

[Back to top]

list-business-applications-v1

Returns the list of Business Applications defined for the requesting tenant. Requires the idn:business-application:read right and the Machine Identity Security product to be enabled for the tenant.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
QueryFiltersString(optional)Filter results using the standard syntax described in V3 API Standard Collection Parameters Filtering is supported for the following fields and operators: id: eq name: eq, co vendor: eq, co signatures.type: eq, co signatures.name: eq, co source.name: eq, co sanctionedStatus: eq
QuerySortersString(optional)Sort results using the standard syntax described in V3 API Standard Collection Parameters Sorting is supported for the following fields: id, name, sanctionedStatus
QueryCountBoolean(optional) (default to $false)If true it will populate the X-Total-Count response header with the number of results that would be returned if limit and offset were ignored. Since requesting a total count can have a performance impact, it is recommended not to send count=true if that value will not be used. See V3 API Standard Collection Parameters for more information.
QueryLimitInt32(optional) (default to 250)Max number of results to return. See V3 API Standard Collection Parameters for more information.
QueryOffsetInt32(optional) (default to 0)Offset into the full result set. Usually specified with limit to paginate through the results. See V3 API Standard Collection Parameters for more information.

Return type

BusinessApplication[]

Responses

CodeDescriptionData Type
200A list of Business Application objects.BusinessApplication[]
400Client Error - Returned if the request body is invalid.ErrorResponseDto
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.ListBusinessApplicationsV1401Response
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.ErrorResponseDto
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.ListBusinessApplicationsV1429Response
500Internal Server Error - Returned if there is an unexpected error.ErrorResponseDto

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

$Filters = 'sanctionedStatus eq "SANCTIONED"' # String | Filter results using the standard syntax described in [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters#filtering-results)  Filtering is supported for the following fields and operators:  **id**: *eq*  **name**: *eq, co*  **vendor**: *eq, co*  **signatures.type**: *eq, co*  **signatures.name**: *eq, co*  **source.name**: *eq, co*  **sanctionedStatus**: *eq* (optional)
$Sorters = "name" # String | Sort results using the standard syntax described in [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters#sorting-results) Sorting is supported for the following fields: **id, name, sanctionedStatus** (optional)
$Count = $true # Boolean | If *true* it will populate the *X-Total-Count* response header with the number of results that would be returned if *limit* and *offset* were ignored. Since requesting a total count can have a performance impact, it is recommended not to send **count=true** if that value will not be used. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional) (default to $false)
$Limit = 250 # Int32 | Max number of results to return. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional) (default to 250)
$Offset = 0 # Int32 | Offset into the full result set. Usually specified with *limit* to paginate through the results. See [V3 API Standard Collection Parameters](https://developer.sailpoint.com/idn/api/standard-collection-parameters) for more information. (optional) (default to 0)

# List Business Applications

try {
Get-BusinessApplicationsV1

# Below is a request that includes all optional parameters
# Get-BusinessApplicationsV1 -Filters $Filters -Sorters $Sorters -Count $Count -Limit $Limit -Offset $Offset
} catch {
Write-Host $_.Exception.Response.StatusCode.value__ "Exception occurred when calling Get-BusinessApplicationsV1"
Write-Host $_.ErrorDetails
}

[Back to top]

update-business-application-v1

Updates a Business Application using the JSON Patch standard. Requires the idn:business-application:update right and the Machine Identity Security product to be enabled. Patchable fields: name, description, owner, additionalOwners, sanctionedStatus, and signatures. Modifying signatures additionally requires the custom Business Application feature to be enabled.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
PathIdStringTrueBusiness Application ID.
BodyJsonPatchOperation[]JsonPatchOperationTrueA JSON array of patch operations per RFC 6902.

Return type

BusinessApplication

Responses

CodeDescriptionData Type
200The updated Business Application.BusinessApplication
400Client Error - Returned if the patch is malformed, targets a non-patchable field, clears the required `name`, or specifies an invalid signature.ErrorResponseDto
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.ListBusinessApplicationsV1401Response
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.ErrorResponseDto
404Not Found - Returned if no Business Application exists for the given ID.ErrorResponseDto
409Conflict - Returned if the new `name` is already in use by another Business Application in the tenant, or if a requested signature is already assigned to another Business Application.ErrorResponseDto
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.ListBusinessApplicationsV1429Response
500Internal Server Error - Returned if there is an unexpected error.ErrorResponseDto

HTTP request headers

  • Content-Type: application/json-patch+json, application/json
  • Accept: application/json

Example

$Id = "a1b2c3d4-e5f6-7890-abcd-ef1234567890" # String | Business Application ID.
$JsonPatchOperation = @"{
"op" : "replace",
"path" : "/description",
"value" : "New description"
}"@ # JsonPatchOperation[] | A JSON array of patch operations per RFC 6902. $JsonPatchOperation = @"{
"op" : "replace",
"path" : "/description",
"value" : "New description"
}"@ # JsonPatchOperation[] | A JSON array of patch operations per RFC 6902.


# Update Business Application

try {
$Result = ConvertFrom-JsonToJsonPatchOperation -Json $JsonPatchOperation
Update-BusinessApplicationV1 -Id $Id -JsonPatchOperation $Result

# Below is a request that includes all optional parameters
# Update-BusinessApplicationV1 -Id $Id -JsonPatchOperation $Result
} catch {
Write-Host $_.Exception.Response.StatusCode.value__ "Exception occurred when calling Update-BusinessApplicationV1"
Write-Host $_.ErrorDetails
}

[Back to top]