SaaS

SaaS Release Notes - June 19, 2026

Production release notes - June 19, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

SailPoint Accelerated Application Management

Shadow AI Remediation

SailPoint Accelerated Application Management and Shadow AI Remediation now log paste events across GenAI web applications. To protect privacy, only metadata is recorded and pasted content is never stored. Administrators can define keywords to detect potentially sensitive content, and activity logs can be used to identify paste events that matched those keywords. SAIR customers can also enable an end-user guidance playbook that educates employees on avoiding the sharing of sensitive information with GenAI web applications.

Connectivity - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Machine Identity Security

Machine Identity Security customers can now request, approve, and provision new machine accounts directly to connected sources through machine account creation. Administrators can configure account subtype-specific forms, multistep approval processes, and secure credential storage. For more information, refer to the product announcement.

Identity Security Cloud - Workflows

Workflows introduces the Define Comparison operator. With this operator, you can combine multiple comparison criteria and condition groups so workflows can evaluate more complex decision paths without spreading logic across many separate steps. The operator supports a guided Basic builder and an Advanced JSON view, making it easier to both configure and fine-tune conditions.

Refer to the Define Comparison operator documentation for more information.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Identity Graph

Export actions are now consolidated and shown as part of the main graph view within Identity Graph.

Identity Security Cloud - Workflows

The Workflows HTTP Request Action now uses Activity Output Trimming, which automatically reduces workflow payload sizes by keeping only the data your workflow references in later steps. This improves performance, reduces data transfer, and makes execution history easier to read, without requiring changes to existing workflows. This is only available if you select the GET Method and the JSON Request Content Type.

Refer to the HTTP Request Action documentation for more information.

Identity Security Cloud - API Documentation, User Levels

Resolved an issue where the Governance Group API’s idn:workgroup:write scope on the bulk-add and bulk-delete process was only granting read access. This scope now correctly grants write access, as the API documents indicate.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports PIM Groups azureADEligibleGroup and azureADActiveGroup as entitlement objects, including aggregation and adding or removing entitlements from accounts. For more information, refer to Azure PIM for Groups.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Provisioning and Task Manager

ISCARP-18569

Fixed an issue where, when a user submitted an access request for a manual access item, the requester’s comments did not display correctly on the generated manual task.

Identity Security Cloud - Access Requests

ISCNAPS-8084

Fixed an issue where the Access Revoke Approval Reassignment email template displayed incorrectly populated values in plain text, including $PreviousOwnerName and $NewOwnerName.

Connectivity - Microsoft Entra ID

CONETN-5407

The Microsoft Entra ID connector now supports the getObject method for both objectId and userPrincipalName when used in rules.