SaaS

SaaS Release Notes - October 10, 2025

Production release notes - October 10, 2025

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Identity Security Cloud - Identity Graph

SailPoint introduces Identity Graph, a feature within Identity Security Cloud, and part of the Observability and Insights product that provides users with:

  • An intuitive visualization of identities, roles, access profiles, and entitlements.
  • A unified view and understanding of the relationships between identity data objects.
  • The ability to manipulate and filter graph views to display granular data combinations and gain valuable insights for an identity's access.
  • The ability to build, save, and share graph snapshots, and export graph data to a CSV.

For more information, refer to the Identity Graph documentation.

Identity Security Cloud - Platform, Workflows

The Identity Security Cloud Atlas Platform's new Adaptive Approvals capability introduces a new Access Request Trigger and two new actions, Approval Policy and Generic Approval Policy, and three new Adaptive Approval templates in Workflows.

For more information, refer to Adaptive Approvals documentation.

Agent Identity Security - Agent Identity Security

SailPoint Agent Identity Security is now available as an add-on for Business and Business Plus customers. This new offering delivers comprehensive governance and security outcomes for AI agents. For more information about Agent Identity Security, refer to the product announcement and documentation.

SaaS Connectors - Salesforce SaaS

The SailPoint Salesforce SaaS connector now supports aggregation of Salesforce AgentForce Agents. For more information, refer to Configuring Agent Governance.

Identity Security Cloud - Platform, Workflows

The Identity Security Cloud Atlas Platform’s new Adaptive Approvals feature allows admins to dynamically assign approval flows for Access Items and non-Access Items using the flexibility of Workflows. This feature also introduces dynamic reviewers with the ability to Auto-Approve and Auto-Deny requests, as well as a new Quorum approval type for consensus approvals.

This feature includes the following:

  • The Workflows Access Request Submitted Trigger fires when a linked access item request is submitted.
  • 2 new Workflows approval policy actions that allow admins to create approval policies that include the ability to choose from Single, Multi-Step, and Quorum approval types, set a priority for the request, and configure customized notification schedules.
    • The Approval Policy Action enables admins to configure an approval policy for specific access requests. This action requires the Access Request Submitted Trigger.
    • The Generic Approval Policy Action enables admins to configure approval policies for any task-based items. The name and Description can be dynamically populated using variables.
  • An updated Access Request Configuration UI enables admins to select an Adaptive Approvals. workflow as a reviewer when configuring roles, access profiles, and entitlements for access requests.
  • An updated Access History UI shows Workflow-specific history updates.
  • An updated Approvals UI introduces a new Other tab to review Generic Approvals. Refer to Approvals Administration for more information.

For more information, refer to the Adaptive Approvals documentation.

Enhancements

ProductFeature enhancements

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

Added a sub-source permission check in the AWS test connection. Passing AWS test connection ensures SailPoint CIEM can discover member accounts.

Identity Security Cloud - Core Access Model

A new field, removeRoleIds, has been added to the refresh identity process to enhance visibility into role assignment changes. The new field lists role IDs whose correlation model state is disabled.

Identity Security Cloud - Identities, Provisioning and Task Manager

An audit event is now generated when a lifecycle state change fails. If provisioning did not occur before the failure, the identity’s lifecycle state is rolled back to its previous state and retried during the next refresh.

Identity Security Cloud - Core Access Model

We have improved alignment between detected role assignments and entitlement changes during identity refresh processes.

Identity Security Cloud - Access Requests, , Platform

Access Request Administration is being rebranded as Approval Management. In addition to viewing access requests, you can now manage approvals for entitlement descriptions and generic approval items, found under the Other tab. Refer to Approvals Administration.

Several new email templates are available to support approvals. Refer to Available Email Templates.

Identity Security Cloud - Core Access Model

Identity Security Cloud’s new Adaptive Approval capability lets you use custom workflows for role, access profile, and entitlement access request approval processes.

The following updates to access item configuration and administration support this capability:

  • Updated access request configuration offers the option of using a workflow for the access request approval process for a role, access profile, or entitlement, and choosing the specific workflow to use.
  • Updated role, access profile, and entitlement administration UIs let you specify either a standard or workflow-based approval and select the approval workflow from a dropdown list of options.

Fixes

ProductIssue IDFixes

Connectivity - Microsoft Entra ID

CONETN-5146

The Microsoft Entra ID connector now handles the ObjectNotFound exception during delta aggregation.

Identity Security Cloud - Core Access Model

IDNARC-5320

Fixed an issue during aggregation where the error message returned for the entitlement name exceeding 450 characters did not provide a reason for the error.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-5910

The Microsoft Entra SaaS connector now automatically retries network errors, such as 503 status codes or ECONNRESET errors, during aggregations.

Connectivity - JDBC

CONETN-5201

The JDBC connector can now successfully complete a test connection will null values.

SaaS Connectors - Snowflake SaaS

CONNAMDANG-6038

The Snowflake SaaS connector now properly revokes roles from users.

Connectivity - ServiceNow

CONETN-5198

The ServiceNow ServiceDesk Connector will wait for 30 seconds before retrying a request after receiving a 429 error code, if the 'Retry-After' header is not present in the response.

Connectivity - SAP SuccessFactors

CONNAMDANG-5515

The SAP SuccessFactors connector no longer has an Axis2 dependency.

SaaS Connectors - ServiceNow Identity Governance SaaS

CONSEALINK-7608

The ServiceNow Identity Governance SaaS connector now supports the dot walking feature through attribute sync in the create operation.