Blog
Non-Employee Risk Management - Update to Delegation Behavior
Author
jeff_lakey
SailPoint
What was the problem with delegation that needed to be fixed?
Previously, the Delegation Permission available on User Roles only controlled whether the Delegate option was available to a user in the user interface.
If the delegation permission was disabled for a user while that user had active delegations, in certain circumstances they could still see the “plus sign” button (see below) under their user name and create new delegations via UI.
Please note: We believe this issue was already resolved for most customers some time ago. There may have been some edge cases were delegations could still be created per the above. This update will address those edge cases and ensure that delegations can only be created by users with the explicit permission to delegate.
What has changed?
The delegation feature has been updated to validate for permissions on the delegator user, and will prevent the creation of delegations in all cases if the delegator doesn't have the permissions enabled.
This will ensure that users who do not have permission to delegate will not be able to create delegations, whether by UI or API.
What are the relevant areas of the UI?
Please note that the UI for delegations will be unchanged. This change focuses on the underlying behavior.
Delegation permission (Admin → Lifecycle → User Roles → select or create Role:
Delegation setting (home page → side nav bar):
When will this change be enabled?
Dev/Sandbox tenants: rollout beginning Tuesday, July 29
Production Tenants: rollout beginning Monday, August 4