Administration · LessonReviewed by Neelima, SailPoint Architect · Updated · Published · IdentityIQ 8.4 · all levels
SailPoint Groups & workgroups
Using IdentityIQ groups and workgroups to assign capabilities, own objects and route work items.
Quick answer
Using IdentityIQ groups and workgroups to assign capabilities, own objects and route work items.
Key takeaways
- Groups filter/report; workgroups own objects and get work
- Workgroups can hold capabilities and scope
- Assign ownership to workgroups, not individuals
- Work items route to the whole team
Groups vs workgroups
IdentityIQ groups organise identities for filtering and reporting. Workgroups are special groups that can own objects and receive work items collectively.
Capabilities and scope
Workgroups can be granted capabilities and scopes, so a team shares administrative rights without assigning them to individuals.
Ownership
Assigning ownership of applications, roles or policies to a workgroup means work routes to the team, surviving staff changes.
Work item routing
Approvals and remediations sent to a workgroup appear for all members, and any member can action them.
Want this with a live instructor and a lab tenant?