SaaS
SaaS Release Notes - August 21, 2026
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What's New |
|---|---|
SaaS Connectors - GitHub SaaS | The GitHub SaaS connector now supports aggregating fine-grained tokens, personal access tokens, GitHub Copilot agents, GitHub Workflows, and GitHub environments as datasets. For more information, refer to Supported Resources. |
SaaS Connectors - JDBC SaaS | The JDBC SaaS connector now supports the Dataset Resource model to aggregate non-human identity (NHI) entities, including Agent, MCP Server, and Tools, etc. The connector aggregates Agents as agent resources along with their capabilities and relationships between them. The connector also supports agent owner correlation for streamlined access governance. For more information refer to Dataset Management. |
SaaS Connectors - Snowflake SaaS | The Snowflake SaaS connector now supports the Dataset resource model for Snowflake Cortex Agents in Identity Security Cloud. The connector aggregates Cortex Agents as agent resources along with their capabilities and relationships between them. These capabilities include Cortex Analyst, Cortex Search, generic functions/procedures, MCP servers, skills, web search, data-to-chart, and code execution. Existing sources continue to work through machine identity aggregation, while new sources support both machine identity and dataset resource aggregation. For more information, refer to Dataset Management. |
SaaS Connectors - Databricks SaaS | The Databricks SaaS connector now supports the Dataset resource model for Databricks Mosaic AI Agents. The connector aggregates Mosaic AI agents as dedicated agent resources and allows you to activate and deactivate these agents. The connector also supports agent owner correlation for streamlined access governance. For more information, refer to Dataset Management. |
SaaS Connectors - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: Anypoint Exchange Castor EDC Doppler Givebutter IBM NS1 Connect Kommo Moneybird Runrun.it You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Identity Security Cloud - Shared Signals Framework | Events from Shared Signals Framework transmitters and receivers that are associated with an identity are now available in Search and in the identity’s Event History. |
Identity Security Cloud - Access Requests, Forms | Admins can attach a form to roles, access profiles, and entitlements to gather additional information from users requesting access in the Request Center. If multiple access items use the same form, the requester completes it once. Submitted form data is made available to approvers, requesters, and requestees in My Requests, and Access Request Administrators in Approval Management. This capability requires the Forms product. For more information, refer to Forms and Configuring Access Requests. |
Enhancements
| Product | Feature enhancements |
|---|---|
Connectivity - SAP SuccessFactors LMS | The SuccessFactors LMS connector now support OAuth 2.0 with SAML Bearer Assertion authentication when BizX integration is enabled with the SuccessFactors platform. |
Connectivity - IQService | The IQService |
Connectivity - IQService | The IQService |
Agent Identity Security - Workflows | The Machine Identity Updated trigger now includes a changeSource field that identifies whether the change was made in the UI, from an API endpoint request, or aggregation. For more information, refer to the Machine Identity Updated documentation. |
Identity Security Cloud - Platform | Updated the UI so that the application navigation bar is always visible on several Admin pages, including Sources, Discovery Connectors, Virtual Appliances, Credential Providers, Identities, Accounts, Roles, Access Profiles, Entitlements, Campaigns, Email Templates, and Forms. |
Identity Security Cloud - Harbor Pilot | Harbor Pilot now protects against duplicate access requests. Before submitting, Harbor Pilot checks whether the user already has the access or a pending request for it, and skips submission when one is found. |
Access Risk Management | Navigation between the new Online Reporting sheets is now easier. A new top navigation bar keeps all sheets within each report visible at all times and the right-most sheet in all reports provides application help. For more information, refer to Navigating the Online Report UI. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Connectivity - Workday Accounts | CONETN-5410 | Fixed an issue where the Workday Accounts connector restarted aggregation after a |
Connectivity - Microsoft Entra ID | CONETN-5516 | The Microsoft Entra ID connector now skips the associated resources API call when aggregating system-assigned managed identities (SMIs), as SMIs do not support this operation. |
Connectivity - Microsoft Entra ID | CONETN-5521 | The Microsoft Entra ID connector now respects the CIEM license when aggregating cloud objects such as subscriptions and management groups. |
Connectivity - Microsoft Entra ID | CONETN-5518 | The Microsoft Entra ID connector no longer returns 400 or 403 errors when aggregating system-assigned managed identities. |
SaaS Connectors - Zoom SaaS | CONETN-5530 | The Zoom SaaS connector now creates accounts with the User License Type selected in the source configuration, instead of always using Basic. For more information, refer to Advanced Settings. |
Connectivity - Okta | CONETN-5543 | The Okta connector aggregation filter fields in the Admin UI now support up to 2028 characters instead of 256. |
Connectivity - REST WebServices Connector | CONETN-5547 | The Web Services connector now retries failed operations during server-side errors based on the value set in the maxRetries source configuration attribute. |
Connectivity - Cloud Connector Gateway (CCG) | CONETN-5531 | The Cloud Connector Gateway now retries credential provider source lookup requests to Identity Security Cloud. This prevents transient failures during credential provider name resolution from failing the entire credential fetch operation. |
SaaS Connectors - SCIM 2.0 SaaS | CONETN-5520 | The SCIM 2.0 SaaS connector now sends a PATCH remove operation with the specific attribute path instead of sending an empty PATCH request when an account attribute value changes to null. |
Identity Security Cloud - SoD | ISCSOD-2894 | Fixed a formatting issue with SOD Policy Reports to better align data in the downloadable csv report. Now the text is properly formatted and easier to read. |
Identity Security Cloud - Provisioning and Task Manager | ISCRP-7878 | Fixed an issue where access requests on multiple sources under a single ServiceDesk integration remained stuck in pending and queued states. |
Identity Security Cloud - Configuration Hub | IDNPALM-9104 | Fixed an issue where Configuration Hub deployments failed when importing access profiles that included entitlements from non-Identity Security Cloud sources (such as Active Directory or LDAP). The deployment returned a generic Unknown validation error. Deployments of access profiles that contain only non-Identity Security Cloud entitlements now succeed. Access profiles with Identity Security Cloud entitlements continue to be validated for interactive users. |