Administration · LessonBy Neelima, SailPoint Architect · Published · IdentityIQ 8.4 · all levels
Groups & workgroups
Using IdentityIQ groups and workgroups to assign capabilities, own objects and route work items.
Quick answer
Using IdentityIQ groups and workgroups to assign capabilities, own objects and route work items.
Key takeaways
- Groups filter/report; workgroups own objects and get work
- Workgroups can hold capabilities and scope
- Assign ownership to workgroups, not individuals
- Work items route to the whole team
Groups vs workgroups
IdentityIQ groups organise identities for filtering and reporting. Workgroups are special groups that can own objects and receive work items collectively.
Capabilities and scope
Workgroups can be granted capabilities and scopes, so a team shares administrative rights without assigning them to individuals.
Ownership
Assigning ownership of applications, roles or policies to a workgroup means work routes to the team, surviving staff changes.
Work item routing
Approvals and remediations sent to a workgroup appear for all members, and any member can action them.
Practice challenge
+0 XPStreak ×0
Question 1 of 1
What can a workgroup do that a plain group cannot?
Frequently asked questions
What does the term Groups & Workgroups refer to in SailPoint?
IdentityIQ groups organise identities for filtering and reporting. Workgroups are special groups that can own objects and receive work items collectively.
What is another point to note about Groups & Workgroups?
Workgroups can be granted capabilities and scopes, so a team shares administrative rights without assigning them to individuals.
What else is worth knowing about Groups & Workgroups?
Assigning ownership of applications, roles or policies to a workgroup means work routes to the team, surviving staff changes.
Want this with a live instructor and a lab tenant?