Blog

New Capability: Data Segmentation!

Author

  • aaron_andrew

    SailPoint

Please Note: The Important Dates section has been updated with more specificity for when this feature will be available by region.

Description

SailPoint® is excited to announce the launch of Data Segmentation in Identity Security Cloud!

This feature provides a programmatic method for restricting access to data within core ISC objects, ensuring users can only access the records they’re authorized to see. Data Segmentation enables organizations to lock down access at a more granular level, ensuring least privilege and reducing privacy concerns. Initially available for Entitlement Administration, additional object support will be introduced in future releases.

New Capabilities

For enterprise-level customers with complex organizational structures, Data Segmentation ensures they can lock down access to records at a more granular level for users - ensuring least privilege and diminishing privacy concerns.

Problem

  1. Customers often have information within their environment that they consider privileged or need to be visible on a need-to-know basis. This stems from the basic security principal of least privilege (NIST Definition). However, when a user is granted any given piece of Identity Security Cloud (ISC) access in the user interface, they are also granted access to any given piece of information that user interface can access. Specific objects like Access Model Items, Identities, Sources, etc. which customers would like to restrict visibility for are currently visible globally.
  2. Customers often have a smaller, dedicated ISC Administration teams that would like to grant administrative functionality to distributed teams. For example, Conglomerate A would like to delegate administration for the Identities, Sources, and Access Model Items within it’s two companies: Company 1 and Company 2. However, they want to limit the data access that Identity Security Cloud administrators at Company 1 and 2 have to see each other’s configurations without limiting the access of Conglomerate A’s ISC Administrators.

Solution

For the initial General Availability release, Entitlement Administration will be the only use case support. Follow-up subsequent releases will add additional support.


Segmentation Definition

Entitlement Builder

Who is affected?

  • Global ISC Administrators
  • Privacy Officers & Teams
  • Data Segmentation is available for Identity Security Cloud Business Plus customers only

Important Dates

Delivery date of Data Segmentation will start Thursday, October 10th, 2024 for select tenants and will be slow rolled out by region.

Update:

Staging Dates:

  • Tenants not in useast1 week of 11/11
  • Tenants in useast1 week of 11/21

Production Dates:

  • Tenants not in eucentral or useast1 week of 12/2
  • Tenants in eucentral week of 12/9
  • Tenants in useast1 week of 12/16

If you’re unsure what region your tenant is in, this may be found in “Org Details” on the Administrative Dashboard. This feature is being targeted for Fedramp environments in Q1 2025.

To ask questions and learn more please visit the Developer Community.