Blog

Introducing Dynamic Access Roles

Author

  • jerryaubel12

    SailPoint

We’re pleased to announce a new Identity Security Cloud Access Model feature that is making it easier than ever to govern, enforce, and maintain even the most complex security policies. Dynamic Access Roles offer an innovative approach to overcoming the rigid nature of traditional role-based access control models.

Complex, distributed enterprises can have many people performing very similar jobs requiring very similar access. But, because the context in which these jobs are being performed can vary, different roles must be created, maintained, and governed for each variation. This leads to an explosion of roles, where multiple roles are created to account for the dynamic needs of organizations.

Dynamic Access Roles extend standard Identity Security Cloud roles with dimensional access. This allows these roles to assign access selectively to role members based on the context of the assignment. Dynamic Access Roles use dimensions, dimension attributes, and dimension criteria to determine which access (entitlements or access profiles) to assign to each role member. Each dimension includes a dimension attribute criteria expression that is evaluated to determine if the dimensional access should be assigned.

By providing the ability to selectively assign access based on assignment context information, Dynamic Access Roles significantly reduces the total number of roles needed for enforcing least privilege and managing the identity lifecycle across your enterprise.

The initial release of Dynamic Access Roles for Identify Security Cloud in Q4 2024 will allow organizations to leverage dynamic access roles for automatic (birthright) access assignments. This will allow teams to implement Identity Lifecycle management use cases, such as joiners, movers, and leavers, with far fewer roles than were needed previously.

Dynamic Access Roles will be released to general availability at Navigate 2024.

For more information and documentation, visit the SailPoint documentation page.