SaaS

SaaS Release Notes - August 21, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's New

SaaS Connectors - GitHub SaaS

The GitHub SaaS connector now supports aggregating fine-grained tokens, personal access tokens, GitHub Copilot agents, GitHub Workflows, and GitHub environments as datasets. For more information, refer to Supported Resources.

SaaS Connectors - JDBC SaaS

The JDBC SaaS connector now supports the Dataset Resource model to aggregate non-human identity (NHI) entities, including Agent, MCP Server, and Tools, etc. The connector aggregates Agents as agent resources along with their capabilities and relationships between them. The connector also supports agent owner correlation for streamlined access governance. For more information refer to Dataset Management.

SaaS Connectors - Snowflake SaaS

The Snowflake SaaS connector now supports the Dataset resource model for Snowflake Cortex Agents in Identity Security Cloud. The connector aggregates Cortex Agents as agent resources along with their capabilities and relationships between them. These capabilities include Cortex Analyst, Cortex Search, generic functions/procedures, MCP servers, skills, web search, data-to-chart, and code execution. Existing sources continue to work through machine identity aggregation, while new sources support both machine identity and dataset resource aggregation. For more information, refer to Dataset Management.

SaaS Connectors - Databricks SaaS

The Databricks SaaS connector now supports the Dataset resource model for Databricks Mosaic AI Agents. The connector aggregates Mosaic AI agents as dedicated agent resources and allows you to activate and deactivate these agents. The connector also supports agent owner correlation for streamlined access governance. For more information, refer to Dataset Management.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors: Anypoint Exchange Castor EDC Doppler Givebutter IBM NS1 Connect Kommo Moneybird Runrun.it You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Identity Security Cloud - Shared Signals Framework

Events from Shared Signals Framework transmitters and receivers that are associated with an identity are now available in Search and in the identity’s Event History.

Identity Security Cloud - Access Requests, Forms

Admins can attach a form to roles, access profiles, and entitlements to gather additional information from users requesting access in the Request Center. If multiple access items use the same form, the requester completes it once. Submitted form data is made available to approvers, requesters, and requestees in My Requests, and Access Request Administrators in Approval Management. This capability requires the Forms product. For more information, refer to Forms and Configuring Access Requests.

Enhancements

ProductFeature enhancements

Connectivity - SAP SuccessFactors LMS

The SuccessFactors LMS connector now support OAuth 2.0 with SAML Bearer Assertion authentication when BizX integration is enabled with the SuccessFactors platform.

Connectivity - IQService

The IQService GMSAPasswordRetrievalHandler service now only executes over Transport Layer Security (TLS). If TLS is enabled in your environment, you must provide consent to run this service.

Connectivity - IQService

The IQService ScriptExecutor service now only executes if user consent has been provided. You must explicitly grant consent to run this service.

Agent Identity Security - Workflows

The Machine Identity Updated trigger now includes a changeSource field that identifies whether the change was made in the UI, from an API endpoint request, or aggregation. For more information, refer to the Machine Identity Updated documentation.

Identity Security Cloud - Platform

Updated the UI so that the application navigation bar is always visible on several Admin pages, including Sources, Discovery Connectors, Virtual Appliances, Credential Providers, Identities, Accounts, Roles, Access Profiles, Entitlements, Campaigns, Email Templates, and Forms.

Identity Security Cloud - Harbor Pilot

Harbor Pilot now protects against duplicate access requests. Before submitting, Harbor Pilot checks whether the user already has the access or a pending request for it, and skips submission when one is found.

Access Risk Management

Navigation between the new Online Reporting sheets is now easier. A new top navigation bar keeps all sheets within each report visible at all times and the right-most sheet in all reports provides application help. For more information, refer to Navigating the Online Report UI.

Fixes

ProductIssue IDFixes

Connectivity - Workday Accounts

CONETN-5410

Fixed an issue where the Workday Accounts connector restarted aggregation after a Page 1 must be requested first error during account aggregation. The connector now retries the page 1 request and resumes from the point of failure.

Connectivity - Microsoft Entra ID

CONETN-5516

The Microsoft Entra ID connector now skips the associated resources API call when aggregating system-assigned managed identities (SMIs), as SMIs do not support this operation.

Connectivity - Microsoft Entra ID

CONETN-5521

The Microsoft Entra ID connector now respects the CIEM license when aggregating cloud objects such as subscriptions and management groups.

Connectivity - Microsoft Entra ID

CONETN-5518

The Microsoft Entra ID connector no longer returns 400 or 403 errors when aggregating system-assigned managed identities.

SaaS Connectors - Zoom SaaS

CONETN-5530

The Zoom SaaS connector now creates accounts with the User License Type selected in the source configuration, instead of always using Basic. For more information, refer to Advanced Settings.

Connectivity - Okta

CONETN-5543

The Okta connector aggregation filter fields in the Admin UI now support up to 2028 characters instead of 256.

Connectivity - REST WebServices Connector

CONETN-5547

The Web Services connector now retries failed operations during server-side errors based on the value set in the maxRetries source configuration attribute.

Connectivity - Cloud Connector Gateway (CCG)

CONETN-5531

The Cloud Connector Gateway now retries credential provider source lookup requests to Identity Security Cloud. This prevents transient failures during credential provider name resolution from failing the entire credential fetch operation.

SaaS Connectors - SCIM 2.0 SaaS

CONETN-5520

The SCIM 2.0 SaaS connector now sends a PATCH remove operation with the specific attribute path instead of sending an empty PATCH request when an account attribute value changes to null.

Identity Security Cloud - SoD

ISCSOD-2894

Fixed a formatting issue with SOD Policy Reports to better align data in the downloadable csv report. Now the text is properly formatted and easier to read.

Identity Security Cloud - Provisioning and Task Manager

ISCRP-7878

Fixed an issue where access requests on multiple sources under a single ServiceDesk integration remained stuck in pending and queued states.

Identity Security Cloud - Configuration Hub

IDNPALM-9104

Fixed an issue where Configuration Hub deployments failed when importing access profiles that included entitlements from non-Identity Security Cloud sources (such as Active Directory or LDAP). The deployment returned a generic Unknown validation error. Deployments of access profiles that contain only non-Identity Security Cloud entitlements now succeed. Access profiles with Identity Security Cloud entitlements continue to be validated for interactive users.