Managing Entitlements
Entitlements are the access rights an account has on a source. They're a key part of identity governance and an important way of quantifying access. They can be:
- Configured for direct access requests.
- Grouped with related entitlements in access profiles.
- Added directly to roles.
- Reviewed and managed in certifications.
Refer to Loading Entitlement Data for information on collecting entitlement data from sources.
You can work with all of your organization's entitlements in one place on the Entitlements page by going to Admin > Access Model > Entitlements.
You can also work with entitlements on sources.
Viewing Entitlements
Go to Admin > Access Model > Entitlements to see a list of the entitlements in your organization. The table columns include important information for each entitlement such as:
- Source
- Primary owner
- Additional owners
- Whether the entitlement is requestable
- Direct privilege level
- How many access profiles include the entitlement
- How many identities have the entitlement assigned to them
If your organization has licensed SailPoint Identity Graph, you can select the View in Identity Graph icon to display a visualization of the entitlement's relationships with other access objects.
Use the Search field to look for a specific entitlement or select the Filter icon
to refine the list of entitlements by specific attributes.
You can select an entitlement to view additional details about it, including:
- Cloud Access Details - If your site licenses a SailPoint cloud governance solution, you can view cloud access data related to entitlements on a source with cloud access. You can mark entitlements as Cloud Enabled by creating or editing cloud-enabled entitlement types.
-
Permissions - Permissions represent individual units of read/write/admin access to a system. If you have direct or indirect permissions on your supported sources, they can be aggregated. Direct permissions are aggregated as entitlements, and are displayed on the directPermissions attribute on an account. Indirect permissions appear in the attributes of an entitlement.
You can also view permissions per source. The Permissions column on an account's list of entitlements displays Yes or No to indicate whether the entitlement includes permissions.
Note
You cannot modify a permission within Identity Security Cloud.
-
Type - Some sources support multiple types of entitlements, each with a different attribute schema.
Notes
-
Not all sources support entitlement types or permissions. Refer to the source's connector documentation to find out whether it supports those attributes.
-
Newly created sources of supported types can aggregate entitlement types and permissions automatically. To configure an existing source to support this functionality, update the entitlement schema associated with the source using the Update Source Schema (Partial) API.
-
-
Direct Privilege Level - If the entitlement has a direct privilege level set, this field displays the level. A direct privilege level is assigned manually by an administrator or is assigned automatically using a Privilege Classification method. For more information, refer to Managing Privilege Classification. Possible values are: high, medium, or low. The entitlements list can be filtered by direct privilege level.
-
Direct Privilege Level Set By - If the entitlement has a direct privilege level set, this field displays the method by which the direct privilege level was set. For more information, refer to Managing Privilege Classification. Possible values are:
- Manual Override
- Applied custom criteria
- Applied recommendation
- Same level applied to all entitlements
Depending on the entitlement, the following information may also display on tabs:
-
Access Profiles - Lists the access profiles that include the entitlement.
-
Identities - Lists the identities that have the entitlement assigned and provides the ability to revoke the entitlement for an identity.
-
Roles - Lists the roles that include the entitlement.
- Parent and Child Entitlements - View the parent and child relationships each entitlement has. For more information, refer to Representing Nested Entitlements.
Notes
-
Entitlements generated by a Privileged Task Automation launcher process can take up to an hour to appear in the Entitlements list. Launcher-generated entitlements will have the internal IdentityNow source. Admins can edit and set the owners for these generated entitlements.
-
Entitlements from the internal IdentityNow source cannot be deleted or overwritten on import.
Working with Entitlements
You can manage, edit, and configure access requests for entitlements across sources from the Entitlements page by going to Admin > Access Model > Entitlements.
To work with entitlement recommendations for descriptions and privilege levels, select View Recommendations.
GenAI Entitlement Descriptions
SailPoint leverages GenAI to generate descriptions for your organization’s entitlements. Admins can select specific entitlements and generate descriptions for them.
You can customize GenAI entitlement description implementation for your organization in the following ways:
- Add GenAI context with key-value pairs.
- Configure GenAI description regeneration.
Note
Due to limitations in AWS regional support, GenAI entitlement descriptions are only available for customers in AWS regions where the AWS Bedrock LLM that SailPoint employs is supported.
The following regions are unavailable:
- FedRamp Gov Cloud: us-gov-west-1
- South America (São Paulo): sa-east-1
- Middle East (UAE): me-central-1
Generating Entitlement Descriptions
To generate descriptions:
-
Select entitlements and start description generation in one of the following ways:
- Multiple Entitlements - Select multiple checkboxes for multiple entitlements, and then select Actions > Generate descriptions.
- All Filtered Entitlements - Apply one or more filters, select the Results checkbox, select Select all, and then select Actions > Generate descriptions.
- One Individual Entitlement - Select Actions
> Generate descriptions for an individual entitlement.
-
Progress is displayed in the Generating Descriptions bar at the top of the GenAI Entitlement Descriptions page.
-
Once completed, newly generated entitlement descriptions are listed.
Viewing Generated Entitlement Descriptions
If there are GenAI entitlement descriptions to review and approve, a banner displays at the top of the Entitlements page. Select View Recommendations to view generated descriptions and their status.
To refine the list by source and status, select the Filter icon
. Use the predefined filter options under the search bar to further refine the list. The Entitlement Descriptions option filters the list for only suggested entitlement descriptions.
To display approver details for descriptions that are pending approval, select the description's Pending Approval status badge.
Reviewing and Approving GenAI Entitlement Descriptions
A generated entitlement description must be approved before it can be updated in the entitlement. On the Entitlement Recommendations page, select Approve to update the description. Use the checkboxes to select and approve several at once.
To make changes to the generated description:
-
Select Actions
> Edit. -
Make edits to the generated description.
-
Select Approve.
If the entitlement description should be approved by someone else in the organization, you can send it to another reviewer as follows:
-
Select Actions
> Send to Reviewer. -
Select an identity or governance group to review and approve the entitlement description.
-
Select Send.
The entitlement description approval appears in the reviewer's Approval page. They also receive an email and an in-app notification to let them know that they were assigned an entitlement description approval.
Privilege Level Recommendations
SailPoint AI Privilege Discovery leverages machine learning and delivers suggested direct privilege levels to help you quickly identify high-risk entitlement access. For more information about privilege classification and direct privilege levels, refer to Managing Privilege Classification.
Your organization’s entitlements are continuously monitored for high privilege levels, and suggestions are automatically presented by a banner on the Entitlements page or on the Entitlement Recommendations page.
You can review and approve suggested privilege levels or reassign to another decision-maker for approval.
Viewing Privilege Level Recommendations
If there are suggested privilege levels to review and approve, a banner displays at the top of the Entitlements page. Select View Recommendations to view suggested privilege levels and their status.
To refine the list by source and status, select the Filter icon
. Use the predefined filter options under the search bar to further refine the list. The Direct Privilege Levels option filters the list for only suggested privilege levels.
To display approver details for recommendations that are pending approval, select the suggested privilege level’s Pending Approval status badge.
Approving Suggested Privilege Levels
A suggested direct privilege level must be approved before it can be applied to the entitlement. On the Entitlement Recommendations page, select Approve for each suggested entitlement privilege level you want to apply. Use the checkboxes to approve suggested privilege levels for several entitlements at once, or send multiple to the same reviewer.
Assigned privilege level approvals are available on the user’s Privilege Classification tab on the Approvals page. Refer to Reviewing Privilege Classification for more information.
To make changes to an entitlement’s suggested privilege level before approval:
-
Select Actions
> Edit. -
Select a direct privilege level.
-
Select Approve.
If the direct privilege level should be approved by someone else in the organization, you can send it to another reviewer as follows:
-
Select Actions
> Send to Reviewer. -
Select an identity or governance group to review and approve the direct privilege level.
-
Select Send.
The privilege level approval appears in the reviewer's Approval page. They also receive an email and an in-app notification to let them know that they were assigned a privilege level approval.
Bulk Entitlement Updates
You can perform the following actions on multiple entitlements at once:
- Update entitlement primary owner
- Update requestable status
- Override direct privilege
- Remove direct privilege override
- Update metadata attributes
Entitlement updates that do not impact identities and their access can take up to 24 hours to appear in Search results because those updates are added to Search during a nightly synchronization job.
To update multiple entitlements:
-
Go to Admin > Access Model > Entitlements.
-
Select the checkboxes for the entitlements you want to update. Once you select more than one entitlement, the Actions button appears.
-
Select the Actions button.
-
From the dropdown list, select the update you want to make for the selected entitlements.
Refer to Updating a Metadata Attribute for Multiple Entitlements for details on the Update Metadata Attributes option.
-
Make your updates in the Update panel, and select Update.
Updating a Metadata Attribute for Multiple Entitlements
Metadata attributes are used to assign additional information to entitlements, so that entitlements with similar purposes can be easily associated with each other. There are additional steps to edit a metadata attribute on multiple entitlements.
To update a metadata attribute on entitlements in bulk:
-
Select the checkboxes for the entitlements you want to update or select the Results checkbox then Select all to update all entitlements.
-
Select Actions > Update Metadata Attributes.
-
In the Metadata Attribute field, choose the metadata attribute you want to update.
-
In the Operation field, choose the type of action you want to take on this metadata attribute for the selected entitlements.
-
If applicable, enter a value for the attribute in the Values field.
-
Select Update.
You can also update the metadata attributes on an individual entitlement.
Individual Entitlement Updates
You can perform the following actions on individual entitlements:
- Edit entitlement details
- Update entitlement status
- Override direct privilege
- Remove direct privilege override
- Add and update metadata attributes on an entitlement
- Revoke an entitlement from an identity
Entitlement updates that do not impact identities and their access can take up to 24 hours to appear in Search results because those updates are added to Search during a nightly synchronization job.
Editing Entitlement Details
To edit details for an entitlement:
-
Go to Admin > Access Model > Entitlements and find the entitlement you want to update.
Tip
To search for a specific entitlement, place the search term in
"". -
Select Actions
> Edit for the entitlement. -
In the Configuration panel, you can make the following edits:
-
Update the entitlement Display Name and Description.
Best Practice
Ensure the entitlement’s display name and description are easy to understand as the entitlement may appear in access requests and certifications. This will improve the accuracy, quality, and speed of requests and review decisions.
Note
Changes to the display name and description are not sent to the source.
-
Select the Primary Owner dropdown list to choose an identity to own this Entitlement. This identity can be configured as a reviewer for access requests or certifications.
Note
You can also assign an entitlement owner by submitting an API call with the Patch an entitlement endpoint.
-
(Optional) You can add Additional Owners by selecting Identities or Governance Group. You can add up to 10 identities or 1 governance group as additional owners. Additional owners can be configured as reviewers for access requests.
-
-
In the Access Request panel, set your access request configurations.
-
Select Save to save your changes.
Your changes will take effect immediately but may take a moment to display on the Entitlements page.
Updating Entitlement Status
To update the privileged or requestable status for an entitlement:
- Select Actions
for the entitlement you want to update. - Select the status update you want to make from the dropdown menu.
Your changes will take effect immediately but may take a moment to display on the Entitlements page.
Updating Metadata Attributes on Individual Entitlements
To add metadata attributes to an individual entitlement:
-
Go to Admin > Access Model > Entitlements.
-
Select the entitlement you want to edit.
-
Under Governance Metadata, select Edit.
-
Select Metadata Attributes.
-
Select Add Attributes.
-
Enter a value in the fields for any metadata attributes you want to configure for this entitlement.
-
Select Save.
The metadata attributes that were given values on this page are added to this entitlement.
To edit metadata attributes on an entitlement:
-
Go to the Metadata Attributes page on the entitlement you want to edit using the steps for adding a metadata attribute.
-
Select the checkboxes beside the metadata attributes you want to edit.
-
Select Actions > Update Metadata Attributes to update multiple attributes at once.
You can also select an entitlement's name or Actions
to edit an entitlement's metadata attribute values individually.Select Clear Attribute Value on the edit screen to remove all values for an attribute from the entitlement.
Revoking Entitlements
Admins and Access Revokers can submit requests to revoke an identity's entitlements.
- On the Admin > Access Model > Entitlements page, select the entitlement you want to revoke.
- On the Entitlement Details page, select the Identities tab.
- Locate the identity you want to remove the entitlement from and select View Assignments.
- On the Assignment page, you can select the option to Revoke Assignment. If a user has more than one assignment, verify the account target details first to make sure you revoke the access you intend to.
- In the Request Revocation dialog, enter comments.
- Select Revoke.
- A success message confirms that your revocation request was submitted.
Adding or Editing Access Start and End Dates
You can change the start and end dates for an access assignment.
- On the Admin > Identity Management > Identities page, select an identity.
- Select Access from the left navigation, then select an access item.
- Go to the Assignment page and select Add or Edit in the start or end date field.
-
In the Access Start Date and Time or Access End Date and Time field, select a date.
Note
The Access End Date and Time field is required for access items with a maximum duration. The last allowed access end date and time is calculated by adding the configured maximum duration to the current date, even when the current end date (before edits) is beyond the maximum duration. When an access start date is specified, any configured max duration requirement is applied for the access end date based on the selected start date and time instead of the moment of request.
When you change an access end date, the new date needs to be within the allowed duration.
-
If required, add comments.
- Select Save.
When you edit an access start date or an access end date to extend access time, the request goes through the Add Access approval process. If you edit an end date to remove access early, the request goes through the Remove Access approval process, which may be configured to not require approval. Refer to Configuring Access Requests for more information on the approval process. When requests to modify access start or end dates are shown to approvers, they are clearly labeled so approvers understand what they are being asked to review.
Viewing Entitlements with Critical Data
If your organization has SailPoint Data Access Security, you can view the classifications, policies, and data categories for the critical data that an entitlement grants access to.
- Go to Admin > Access Model > Entitlements.
- Find an entitlement with the critical data access flag
. - Select Actions
> View Details. - Select the Data Access tab to view the data’s classifications, policies, and categories.
For more information about critical data, refer to the Data Access Security documentation.
Working with Entitlements on Sources
Some information about entitlements can be modified on its source by going to Admin > Connections > Sources > Entitlement Management > Entitlements. Modifications include adding and removing direct privilege overrides, marking entitlements as requestable, and updating multiple attributes like display names and descriptions at once.
Adding and Removing Entitlement Direct Privilege Overrides on a Source
Direct privilege level overrides can be added or removed for an entitlement on its source. For instructions and more information, refer to Override Direct Privilege and Remove Direct Privilege Override.
Performing Bulk Entitlement Updates on a Source
Entitlement aggregation can read display names and descriptions from the source. If these are missing or insufficient, you can change those values through a manual bulk edit.
- Go to Admin > Connections > Sources.
- Select or edit the source you want to update.
- In the Entitlement Management section, select Entitlements.
- Select
to download a comma separated values (.csv) list of the entitlements. - Edit the file to fix any incorrect or incomplete entitlement data.
- Select
to upload your changes.
Notes
- Subsequent aggregations can replace blank display names or descriptions but will not overwrite existing values. This ensures your manual edits do not get overwritten.
- Entitlement descriptions can be up to 2000 characters. An error will occur if you attempt to upload a file containing descriptions that exceed that limit.
Representing Nested Entitlements
Hierarchical relationships between entitlements for source types are supported where it applies. To configure parent and child relationships between entitlements in a .csv file, use the hierarchyAttribute of the Update Source Schema API.
Ways to Revoke Entitlements
You can revoke entitlements in the following ways:
- Using the Entitlements page
- Creating certifications
- Configuring a lifecycle state to remove all access.
- Submitting an API call with the Submit Access Request endpoint.
Note
You can only submit revoke requests for one entitlement at a time through the Submit Access Request endpoint.
Deleting Entitlements
Entitlements can't be deleted directly in Identity Security Cloud. To remove an entitlement, delete it from the source itself and run an entitlement aggregation, unless the entitlement was created solely through account aggregation.
Account aggregations never delete entitlements from Identity Security Cloud, including source entitlements created solely through account aggregation. This is because an entitlement could still exist even if no accounts currently hold it.
Troubleshooting Entitlement Issues
The following list describes common entitlement issues and their solutions:
Entitlement names and descriptions are not aggregating from the source system
Perform an entitlement aggregation for your source to pull in the display names and descriptions for all entitlements.
This will only replace values that have not been updated manually in Identity Security Cloud. This is to protect and preserve any updates you make through the Entitlements page, the API, or by using the .csv download/upload option. Once a value has been updated manually, an aggregation will not replace it.
If the aggregation doesn't update the entitlement description, the following may have occurred:
-
The entitlement description may have been manually updated in Identity Security Cloud. You can check whether the description has been manually updated by using the Get an entitlement endpoint. The
manually_updated_fieldsproperty should be marked as false, meaning this property has not been manually updated since the first aggregation or on subsequent aggregations. You can override the value for this property through the Patch an entitlement endpoint. -
The description isn't mapped correctly in the source schema. To view your current mapping, submit an API call using Lists Schemas on Source. If the mapping is incorrect, you can submit an API call using the Update Source Schema (Partial) endpoint to alter the group schema’s description attribute.
Caution
This endpoint allows you to change your schema definitions, which can change the data SailPoint stores for the source’s accounts and entitlements.
The wrong attribute has been used as the entitlement's display name
Your entitlement schema defines which attribute is used as the display name. Use the Update Source Schema API to modify the display attribute designation.
If the entitlement schema for the source is editable in the user interface, you can also change it there:
- Go to Admin > Connections > Sources.
- Select or edit the source with the display name you want to change.
- In the Entitlement Management section, select Entitlement Types and Schemas.
- Select the entitlement type you want to edit.
- Change the attribute designated as the Entitlement Name to the desired display attribute.
- Run an entitlement aggregation.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.

