Blog

Get help describing your access with GenAI Descriptions for Entitlements

Author

  • alec

    SailPoint

Today we are proud to announce the release of an industry-first feature powered by a large-language model, GenAI Descriptions for Entitlements! This feature, available to customers in the Business Plus package, will transform how our customers interact with access.

Users face the persistent challenge that they are asked to grant or certify access on entitlements that they don't understand. Based on an analysis SailPoint conducted in 2023 over 60% of ISC entitlements had no descriptions. How can you be asked to certify access when most of what you see are cryptically named entitlements? This solves that pain point in a big way by making it much easier to populate those descriptions at scale.

The journey towards developing the feature started last year when a small team of talented Data Scientists, Software Engineers, and Product Managers explored the potential that large-language models seemed to unlock. Out of that effort, we identified several use cases we felt could be productized in a low-risk high-value generation scenario. Now our customers can try out this innovation for themselves.

One of the key pillars of our approach was to ensure that GenAI seamlessly integrates into existing workflows, enhancing the overall user experience. You'll find this feature in the Entitlements Admin page - select the entitlements for which you want to generate descriptions, and choose "Generate Descriptions" from the Action dropdown.

Descriptions are generated as the user watches the progress bar (times may vary based on number of entitlements and system throughput). From there the admin can approve or edit the descriptions, after which they are written to the entitlement in the ISC platform. Recognizing that admins need help evaluating how good the generated descriptions are, subject matter experts can be assigned as reviewers who can approve or edit.

We have designed this feature with data privacy in mind. We use AWS Bedrock to power our large-language model and under the hood these API requests are read-only, which means entitlement information sent in these requests are not used by AWS for training purposes. However, this doesn't mean that model quality doesn't improve over time. We have built out infrastructure that captures user feedback (such as approvals with no edits, but also if a description is edited before approval), measures model quality, and can fine-tune the results for you.

We generally see good results for well-known sources, such as Active Directory. But what about all those niche and custom sources? We are working to add a feature that will let customers build a knowledge base and help GenAI produce high-quality descriptions for those as well.

The release of GenAI Descriptions for Entitlements marks a significant milestone in how we enable our users to leverage the power of AI at scale. And this is just the beginning. We're starting with entitlements, but the vision is clear - to enable Identity Security through natural language. Imagine being able to paint the canvas of your entire access and governance model with just a few high-level guidelines!

We hope you enjoy using this new feature!

Please note that this feature is only available in AWS supported regions where the AWS Bedrock LLM is supported. This means that customers on GovCloud will not be seeing the feature.

For more information check out:

GenAI Descriptions for Entitlements Documentation

Getting Started with GenAI Descriptions for Entitlements