Blog
Action Required: Update Personal Access Tokens for NERM Scope by September 15, 2026
Author
mwoodberry
SailPoint
Description
To improve API security, Non-Employee Risk Management will begin requiring an explicit Non-Employee Risk Management scope on Personal Access Tokens (PATs) starting September 15, 2026.
Today, administrator accounts can access Non-Employee Risk Management APIs with the default sp:scopes:default scope. After this change, Non-Employee Risk Management API access must be granted explicitly via the nerm:general:manage scope.
Required Action
Review your PATs and ensure the required nerm:general:manage scope is enabled. If the scope is enabled, no further action is needed.
To read the full announcement and learn more please visit the Developer Community.