Blog
New Capability: Custom User Levels
Author
jeremy_southerland
SailPoint
This capability is brought to you by Idea GOV-I-737
Description
- Least Privileged Model
- Custom User Levels enables organizations to create custom permission sets, allowing administrators define specific roles with the right level of access.
- Read Only View
- With Custom User Levels, organizations are now able to create read-only views for users who need access to identities, access, entitlements, VAs, and access policies.
New Capability
Custom user levels allows administrators to delegate administrative responsibilities while supporting least privileges by providing finer grained permissions to administrative functionalities within Identity Security Cloud. Initially, our permissions focus on access objects (entitlements, access profiles, access history, and roles), identities and the VA, but we have plans to expand custom permissions to other areas of the admin experience.
Problem
We’ve heard from customers that our existing user levels could be more adaptable. In some cases, admins found it tricky to align permissions with users’ specific needs. This update adds greater flexibility and precision, making it easier to assign just the right access within ISC.
Solution
What’s new and how it solves the problem.
Demo Link: Vidyard
Who is affected?
All business, business plus customers
Important Dates
Sandbox availability: November 3, 2025
Production rollout: Beginning November 10, 2025
Resources
Documentation: Custom User Levels - SailPoint Identity Services
To ask questions and learn more please visit the Developer Community.