Blog

Action Required: Update Personal Access Tokens for NERM Scope by September 15, 2026

Author

  • mwoodberry

    SailPoint

Description

To improve API security, Non-Employee Risk Management will begin requiring an explicit Non-Employee Risk Management scope on Personal Access Tokens (PATs) starting September 15, 2026.

Today, administrator accounts can access Non-Employee Risk Management APIs with the default sp:scopes:default scope. After this change, Non-Employee Risk Management API access must be granted explicitly via the nerm:general:manage scope.

Required Action

Review your PATs and ensure the required nerm:general:manage scope is enabled. If the scope is enabled, no further action is needed.

To read the full announcement and learn more please visit the Developer Community.