SaaS

SaaS Release Notes - August 14, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Identity Security Cloud

The Identity Security Cloud product name within the Solution Center has changed to SailPoint Identity Security.

SailPoint Agentic Fabric

SailPoint Agentic Fabric is now available in Identity Security Cloud through the Agentic Business and Agentic Business Plus suites. Discover AI agents and non-human identities (NHIs) across over 32 frameworks; govern them with a unified registry, ownership, lifecycle controls, and audit reporting. Capabilities are enabled based on your licensed suite and product flags.

Discover

  • Non-Human Identity Registry - single inventory of enterprise, endpoint, and browser agents with risk filtering and ownership management.
  • Guided onboarding - connect IdPs, AWS, endpoint sensors (SEAS), browser extension (SBAS), and SIEM sources; sanction business applications; review and activate.
  • Datasets and Resources - new data ingestion model to collect agents, credentials, MCP servers, tools, workflows, accounts, and AWS IAM roles at scale.
  • Endpoint and browser discovery - SEAS and SBAS surface agents and related assets that cloud connectors alone cannot reach.
  • Machine Account Discovery – Machine-learning-powered recommendations to identify hidden NHIs across supported sources.
  • Identity Graph - trace access lineage from users and agents through NHIs to sensitive data, embedded in enterprise agent detail views.
  • Business application sanctioning - define sanctioned/unsanctioned apps so matching agents inherit posture automatically.

Govern

For more information, refer to the product documentation and announcement.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports activating and deactivating Microsoft Copilot Studio agents through SailPoint Agentic Fabric. You can use this capability to govern Copilot Studio agent access by blocking or unblocking agents directly from Identity Security Cloud.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports aggregation of Microsoft 365 agent catalog packages. For more information, refer to Microsoft Agent 365 Catalog Management.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports aggregation of new Azure AI Foundry agents. For more information, refer to Azure AI Foundry Agents Attributes.

Agent Identity Security

Machine Identity Security

SailPoint Agentic Fabric

SailPoint Agentic Fabric and Machine Identity Security now supports AWS IAM roles as governable machine accounts, giving you visibility into role access, ownership, and usage across your AWS environment. This includes roles used by AI agents such as Amazon Bedrock and Amazon Bedrock AgentCore, enabling a least privileged model to be enforced for both traditional and agentic machine identities.

AWS IAM role governance is available to all SailPoint Agentic Fabric and Machine Identity Security customers. To use this capability, you must use the AWS SaaS connector, which may require an update. For more information, refer to Configuring the AWS SaaS Connector.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports the new Azure AI Foundry Agents module. The classic module is deprecated and becomes obsolete on August 26, 2026.

  • Aggregate new schema attributes that support the updated agent framework.
  • Switch to the new module within the Azure managed system, then reaggregate the source to review the updated schema attributes in the Microsoft Entra ID SaaS connector.

For more information, refer to Azure AI Foundry Agents Attributes.

Identity Security Cloud - Platform

Identity Security Cloud has added regional AWS SES support for emails. All domains will be automatically migrated to the correct region. Previously verified From email addresses will continue to send from the us-east-1 region until re-verified in the new region.

The email notification configuration UI will display the SES region associated with verified domains and From addresses for all tenants at release.

For more information, refer to Understanding SES Regions for Notification Emails and the product announcement.

Identity Security Cloud - Platform

Dark mode is now available, with full support across SailPoint Agentic Fabric and limited support across Identity Security Cloud. Turn on dark mode from the user menu.

If your organization has configured custom branding colors, they will continue to appear in light mode but will not be applied in dark mode.

Identity Security Cloud - Platform

A new instance badge in Identity Security Cloud replaces the top border of the navigation bar as an indication of which environment you are in – for example, sandbox or production. Enable instance badges and configure the badge color and the name of each instance on the Admin > System Settings > Product Branding page.

Agent Identity Security

SailPoint Agentic Fabric

AI Agent Lifecycle Management now supports activate and deactivate actions directly in SailPoint Agentic Fabric when the connected source supports those operations. Requests are tracked in My Requests > Agent Requests with approval and provisioning status. Approval settings can be configured at the global level under Admin > System Settings > Feature Settings > Approval Settings > Agent Requests settings.

SaaS Connectors - Cursor

The Cursor Enterprise SaaS connector is now available in the SailPoint platform. It manages Cursor members and groups for human governance and manages Cursor cloud agents in SailPoint Agentic Fabric.

For more information, refer to Integrating SailPoint with Cursor.

SaaS Connectors - N8N SaaS

The N8N SaaS connector is now available in the SailPoint platform. The connector supports:

  • Account and entitlement aggregation for N8N platform users and team projects.
  • Dataset aggregation for machine identities, including workflows, AI agents, tools, MCP clients, MCP servers, and stored credentials.

For more information, refer to Integrating SailPoint and N8N SaaS.

SaaS Connectors - Jenkins

The Jenkins connector is now available in Identity Security Cloud. It discovers and classifies non-human identities, including stored credentials, pipeline jobs, and managed controllers, through SailPoint Agentic Fabric.

For more information, refer to Integrating SailPoint with Jenkins.

SaaS Connectors - Argo CD SaaS

The Argo CD SaaS connector is now available for Identity Security Cloud. Using SailPoint Agentic Fabric, the connector discovers Argo CD local users and project JWT tokens, giving your organization visibility into non-human identities for governance and ownership assignment. For more information, refer to Integrating SailPoint with Argo CD.

SaaS Connectors - Wiz SaaS

SailPoint introduces a new Wiz connector that streamlines identity and access management. The connector aggregates Wiz users, roles, and projects through Wiz Platform APIs. It also discovers and imports machine identities, such as service accounts, and the cloud resource inventory associated with those identities. Through SailPoint Agentic Fabric, the connector delivers enhanced, pre-configured discovery capabilities that give organizations greater visibility into human and machine identities across their Wiz environment.

For more information, refer to Integrating SailPoint with Wiz.

Identity Security Cloud - Just-In-Time

SailPoint Privilege on Demand is now available, enabling Just-In-Time (JIT) activation for approved entitlements

Privilege on Demand helps organizations reduce standing "always-on" access while maintaining operational speed by allowing end users to activate access only when needed and for a bounded duration.

Privilege on Demand includes the following features:

  • On-Demand Activation - Users can activate approved entitlements for a set duration directly from Launchpad > Just-In-Time Access.
  • Time-bounded Access - Access is active only for the selected activation window.
  • Activation Window Control - Users can manually extend active windows within configured limits, or deactivate their access early.
  • Automatic Expiration - Access is automatically revoked as soon as the selected activation window ends.
  • Admin Controls - Admins can configure JIT behavior in System Settings > Feature Settings and define which entitlements are in scope for JIT.

For more information, refer to the Privilege on Demand and Configuring Just-In-Time Access documentation and the product announcement.

Enhancements

ProductFeature enhancements

Machine Identity Security

The List public machine identities API has been updated to return the subtype and primary owner contact details (id, name, and email) of machine identities when the tenant returns public machine identity data. Users can filter results by subtype and owner.id using the eq operator and sort results by subtype.

SaaS Connectors - Ceridian Dayforce HCM SaaS

The Ceridian Dayforce HCM SaaS connector now supports generic Dayforce base URLs for Production and Sandbox. You no longer need to configure version-specific hostnames.

For more information, refer to Connection Settings.

Agent Identity Security

Machine Identity Security

SailPoint Agentic Fabric

SailPoint Agentic Fabric introduces Multi Owner Correlation and Succession to aggregate and govern machine identities, including enterprise agents, across various sources. This feature automatically establishes accountable human ownership by mapping collected owner attributes to human identity or account attributes. Multi Owner Correlation and Succession supports one Primary Owner alongside multiple Additional Owners or governance groups, with automated succession pathways to preserve ownership continuity during personnel changes.

Multi Owner Correlation and Succession is available to all SailPoint Agentic Fabric, Machine Identity Security, and Agent Identity Security customers who manage machine identities and enterprise agents. To use this capability, configure the default mapping in your Datasets and Resources to align collected owner attributes with a human identity or account attribute. Primary Owners and Additional Owners can still be managed manually from the Machine Identities or Enterprise Agents list.

For more information, refer to Configuring Owner Correlation.

Agent Identity Security

Machine Identity Security

SailPoint Agentic Fabric

SailPoint Agentic Fabric introduces Datasets and Resources to simplify the governance of non-human identities, including agents. Datasets group multiple resources on a single aggregation schedule to replace Machine Identity Schemas and Aggregations with a more user-friendly experience with minimal to no setup required once the source is connected.

Datasets and Resources are now available to all SailPoint Agentic Suites and Machine Identity Security customers. To use this new functionality, you must use supported connectors including AWS, GCP, Azure, and others. Additionally, Datasets and Resources will be supported as part of the Web Services and JDBC connectors. Current customers who have already configured their supported connectors will be migrated to the new datasets and resources, with no action needed.

For more information, refer to Managing Datasets and Resources.

Agent Identity Security

Machine Identity Security

SailPoint Agentic Fabric

SailPoint Agentic Fabric introduces Multi Owner Correlation and Succession to aggregate and govern machine accounts across out-of-the-box datasets (for example AWS IAM Roles). This feature automatically establishes accountable human ownership by mapping collected owner attributes to human identity or account attributes. Multi Owner Correlation and Succession supports one Primary Owner alongside multiple Additional Owners or governance groups, with automated succession pathways to preserve ownership continuity during personnel changes.

Multi Owner Correlation and Succession is available to all SailPoint Agentic Fabric, Machine Identity Security, and Agent Identity Security customers who manage accounts for out-of-the-box datasets (with support for Multi Owner Correlation and Succession on all Machine Account Types available in the near future). To use this capability, configure the default mapping in your Datasets and Resources to align collected owner attributes with a human identity or account attribute. Primary Owners and Additional Owners can still be managed manually from the Machine Identities or Enterprise Agents list.

For more information, refer to Configuring Owner Correlation.

Connectivity - Oracle Database

The Oracle Database connector now supports mTLS authentication for secure connections. For more information, refer to Connection Settings using mTLS Authentication.

Connectivity - SAP HR/HCM

The SAP HR/HCM connector now masks Personally Identifiable Information (PII), including birthday details, in the Effective Dates attribute to enhance data privacy and security.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Provisioning and Task Manager

ISCRP-7437

Individual SDIM ticket provisioning results are now used to accurately update the IIQDisabled and IIQLocked status on accounts within Account Activity.

SaaS Connectors - SCIM 2.0 SaaS

CONETN-5505

The SCIM 2.0 SaaS connector now includes address sub-attributes, such as locality and country, during create and update account operations when relaxConfiguration is enabled.

Access Risk Management

ARM-33988

When adding a Mitigating Control to Rulebook Risk mapping via the Access Risk Management UI, the Mitigating Control field will now correctly filter results using the mitigating control code.

Machine Identity Security

ISCRP-7318

During machine account creation, the “Update” provisioning policy no longer runs after the “Create” provisioning policy.

Identity Security Cloud - Sources and Account Management

ISCRP-7668

Account correlation now honors the configured match mode (Starts With / Ends With / Contains) for single-valued identity attributes.

Identity Security Cloud - Provisioning and Task Manager

ISCRP-7525

When completed, the source attribute sync job now displays a PASSED event as well as the count of any account provisioning failures. These failures may be retried in the background and removed from the count if successful.

SaaS Connectors - Web Services SaaS

CONETN-5512

The Web Services SaaS connector now skips the getObject() call during update and add or remove entitlement operations when the source configuration parameters skipGetObjectAfterUpdateAccount and skipGetObjectAfterAddRemoveEntitlement are set to true.

Connectivity - Workday

CONETN-5461

Fixed an issue where the Workday connector did not sync null values for the WORK_TELEPHONE attribute during provisioning when the deletePhoneRecord flag was set to false.

Identity Security Cloud - Platform

PLTCONN-10872

Before entitlement aggregation initiation, the completed and completionStatus fields are now both checked for values. New entitlement aggregations are initiated only if both fields are populated correctly for the previous aggregations.

Identity Security Cloud - Access Requests

ISCARP-19122

Fixed an issue where an access request with a future start date and end date could fail to be revoked at the end date if a second request was submitted to grant that access immediately while keeping the same end date. The system removed both scheduled actions and those assignments could show as Revocation Pending instead of revoking automatically.

Now when a follow-up request grants access immediately and keeps the same end date, only the future start schedule is removed. The end-date revocation schedule is kept, so access still automatically revokes at the expected time.

Connectivity - REST WebServices Connector

CONETN-5468

The Web Services connector now handles failed API requests during retry operations by returning the actual error code instead of a null pointer exception.

Connectivity - Workday

CONETN-5467

Fixed an issue where the Workday connector repeatedly triggered attribute sync for the WORK_TELEPHONE attribute due to a format mismatch during provisioning. The connector now formats WORK_TELEPHONE values using E.164 format for consistent behavior. Enable the useE164PhoneNumber configuration flag to use this behavior.

Identity Security Cloud - Access Requests

ISCARP-19108

Fixed an issue where duplicate entitlement revocation requests were not being rejected when they were submitted without specifying an account. Now, a revoke with no nativeIdentity is treated as applying to any account, so new duplicate requests are correctly rejected when there is already a pending revoke request for the same entitlement on that identity.

Connectivity - NetSuite

SaaS Connectors - Oracle NetSuite SaaS

CONETN-5471

The Oracle NetSuite connector no longer ignores the configured pageSize value during aggregation.

SaaS Connectors - Workday SaaS

CONETN-5465

Fixed an issue where the Workday SaaS connector removed other email addresses when updating the primary work email address during provisioning.

Connectivity - SAP SuccessFactors

CONETN-5490

The SuccessFactors connector no longer incorrectly applies a termination date from a completed employment, such as a global assignment, to users with an active local employment during delta aggregation.

Connectivity - Microsoft Entra ID

CONETN-5439

The Microsoft Entra ID connector now fetches risky user details correctly without overwriting existing user data.

Connectivity - Microsoft Entra ID

CONETN-5482

The Microsoft Entra ID connector now supports a configurable spnCreateAccountTimelag setting with 10 seconds as default to prevent custom Service Principal account creation failures caused by Azure replication delays.

Connectivity - Oracle E-Business

CONETN-5437

The Oracle E-Business Suite connector now correctly aggregates MENU objects when the MENU_DETAILS schema attribute is included in the MENU schema.

Identity Security Cloud - Access Requests

ISCARP-18777

Fixed an issue where some access requests that were closed by system automation, for example when an approval timed out or hit platform expiration rules, could be shown as denied by a manager or governance group even though no human took action. Requests that expire or time out now say that the approval timed out so you can tell that the request was closed by the system. The action is no longer misattributed to a person or group.

Connectivity - SAP SuccessFactors

CONETN-5425

The SuccessFactors connector now handles the delta aggregation URL limit when the userID list exceeds the OData API’s maximum limit. To enable the fix, set the chunkDeltaUserOdataRequests source key to true.