Groups & workgroups
Quick answer
Using IdentityIQ groups and workgroups to assign capabilities, own objects and route work items.
Key takeaways
- Groups filter/report; workgroups own objects and get work
- Workgroups can hold capabilities and scope
- Assign ownership to workgroups, not individuals
- Work items route to the whole team
Groups vs workgroups
IdentityIQ groups organise identities for filtering and reporting. Workgroups are special groups that can own objects and receive work items collectively.
Capabilities and scope
Workgroups can be granted capabilities and scopes, so a team shares administrative rights without assigning them to individuals.
Ownership
Assigning ownership of applications, roles or policies to a workgroup means work routes to the team, surviving staff changes.
Work item routing
Approvals and remediations sent to a workgroup appear for all members, and any member can action them.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What can a workgroup do that a plain group cannot?
- A. Be filtered
- B. Own objects and receive work items
- C. Store attributes
- D. Run aggregation
Show answer
B. Own objects and receive work items
Workgroups can own objects and collectively receive work items.