Blog
Data Segmentation for Roles
Author
cameron_wilson
SailPoint
SailPoint® is excited to announce the launch of Data Segmentation for Roles in Identity Security Cloud!
The Problem
- Customers often have information within their environment that they consider privileged or need to be visible on a need-to-know basis. This stems from the basic security principle of least privilege (NIST Definition). However, when a user is granted any given piece of Identity Security Cloud (ISC) access in the user interface, they are also granted access to any given piece of information that user interface can access. Specific objects like Access Model Items, Identities, Sources, etc. which customers would like to restrict visibility for are currently visible globally.
- Customers often have smaller, dedicated ISC Administration teams that would like to grant administrative functionality to distributed teams. For example, Conglomerate A would like to delegate administration for the Identities, Sources, and Access Model Items within its two companies: Company 1 and Company 2. However, they want to limit the data access that Identity Security Cloud administrators at Company 1 and 2 have to see each other’s configurations without limiting the access of Conglomerate A’s ISC Administrators.
The Solution
This feature provides a programmatic method for restricting access to data within core Identity Security Cloud objects, ensuring users can only access the records they’re authorized to see. Data Segmentation enables organizations to lock down access at a more granular level, ensuring least privilege and reducing privacy concerns. This was initially available for Entitlement Administration and has now been expanded to Role Administration, and there will be additional object support introduced in future releases.
This feature integrates Roles into the Data Segmentation capability released last year from SailPoint that solves a challenge faced by many conglomerates and companies needing better record-level access controls to meet regulatory privacy, internal security, partner enablement, and least privilege enforcement.
For enterprise-level customers with complex organizational structures, Data Segmentation ensures they can lock down access to records at a more granular level for users - ensuring least privilege and diminishing privacy concerns.
For this General Availability release, Roles Administration will be the second use case with Data Segmentation support (Entitlement Administration was released in October 2024). Follow-up subsequent releases will add additional support.
Please Note:
- This release only covers Role Administration and Search functionality
- AI Features with their own data stores - like Outliers and Role Insights - will not have data segmentation applied in this release
Who is affected?
- Global ISC Administrators and users they want to sub-administrate roles
- Security & Privacy & Teams
- Data Segmentation is available for Identity Security Cloud Business Plus customers only