Capture any privileged Entitlement with more than three users

I would like to somehow capture privileged Entitlements that have more than three assigned Identities. Those Entitlements and Identities would then either be returned in a report or end up in a Certification Campaign. Is there any way I can do this?

Hi  @pillar224  Another good challenge! I don’t have the answer yet, just some initial thoughts.

I don’t see how that’s possible with a UI OR API search query yet. A search of privileged entitlements (“privileged:true”) doesn’t seem to expose the count of identities with that entitlement, like we see in the UI Entitlements list.

It seems we would have to go through the identities index instead, and query those that have access to privileged entitlements and somehow do some kind of lopping and parsing of the data.

I was trying to work out something with a Search Query Aggregation, using the query “@access(privileged:true)” to work from, but I don’t now of a way to bucketize each privileged entitlement THEN filter or retrieve a count >=3. Maybe someone knows how to do this?

I appreciate your assistance as always Amy!

There is no direct way as the entitlement query does not returns the identities even thought it does in the UI.

Create a script:

  1. Get all identities which has a privileged entitlement : https://developer.sailpoint.com/docs/api/v2025/list-identity-access-items
  2. Loop through each of them and get the entitlements.
  3. Store the entitlement name and keep a track of its count.

Thank you  @cinilsunny . Do you think this can be accomplished in a Workflow? My scripting experience is lacking

Unfortunately, nope.

It can be easily done via java or other programs.