SaaS

SaaS Release Notes - July 10, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Data Access Security

The Databricks connector for Data Access Security is available to customers. The new connector supports crawling structured data from Databricks, analyzing object-level permissions, and ingesting Data Classification labels from Databricks.

SaaS Connectors - Salesforce SaaS

The Salesforce SaaS connector now supports Salesforce External Client Application (ECA), which can be installed from the Salesforce Marketplace to securely connect and manage your Salesforce environment.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Connectivity - SalesForce

The Salesforce connector now supports Salesforce External Client Application (ECA), which can be installed from the Salesforce Marketplace to securely connect and manage your Salesforce environment.

Identity Security Cloud - Core Access Model

SailPoint introduces AI Privilege Discovery to help you quickly identify high-risk entitlements and support continuous monitoring! Privilege level recommendations are automatically presented for you to review and approve or assign to expert decision-makers.

Enhancements

ProductFeature enhancements

Identity Security Cloud - SoD

Separation of Duties (SoD) has a new UI to create policies and view violations. Additionally, suites customers may apply controls with expiration duration to violations. Refer to Managing Policies.

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

SailPoint CIEM can now display native AWS tags, Azure tags, and GCP labels when searching and viewing the effective access of cloud resources. Refer to Viewing Cloud Resource Tags for more information.

Identity Security Cloud - Provisioning and Task Manager

When multiple entitlements are provisioned to a single account attribute, the Provisioning Complete trigger is now serialized as a valid JSON array string with one entry per attribute.

Identity Security Cloud - Harbor Pilot

Harbor Pilot now supports future-dated and temporary access requests. You can use natural language to specify access start times and automatic deprovisioning dates when requesting access for yourself or others. Harbor Pilot follows configured governance rules, including maximum allowed provisioning durations, to support least privilege access.

Non-Employee Risk Management

You can now configure the date format for core date attributes. This improves synchronization in regions that use a format other than the default mm/dd/yyyy format. For more information, refer to Selecting the Date Format for Core Attributes.

Identity Security Cloud - MySailPoint

Updated the UI so that the application navigation bar is always visible on the User preferences > Work Reassignment > Work Reassignment History page, the My Access > Roles and Entitlements page, and the My Team > Roles and Entitlements page.

Connectivity - Oracle EPM Cloud

SaaS Connectors - Oracle EPM Cloud - AR SaaS, Oracle EPM Cloud - FCCS SaaS, Oracle EPM Cloud - NR SaaS, Oracle EPM Cloud - Planning SaaS

The Oracle EPM Cloud connector now supports REST API aggregation for application roles and groups. This enables efficient data collection from Oracle EPM Cloud sources.

Connectivity - SAP Direct

The SAP Direct connector now provides out-of-the-box (OOTB) support for user groups that are not assigned to any users as well as groups as entitlements. This includes native support for the user group attribute during account aggregation and provisioning.

Machine Identity Security

Machine Account Discovery now supports machine account detection for the following sources:

  • Google Workspace (SaaS)
  • Linux (Direct)
  • OpenLDAP (Direct)
  • Workday Accounts (Direct)
  • Workday Accounts (SaaS)

Machine account recommendations for Active Directory and Microsoft Entra ID have also been improved. For more information, refer to the product announcement.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Audit Events & Reporting, Provisioning and Task Manager

ISCRP-6835

Fixed an issue where account names were mapped incorrectly in Account Provisioning audit events. identityDisplayName, accountDisplayName, and accountNativeIdentity attributes are now listed and mapped correctly in the Additional Event Attributes section.

SaaS Connectors - Salesforce SaaS

CONETN-5462

The Salesforce SaaS connector now successfully populates the isFrozen attribute during optimized and unoptimized full aggregations.

Connectivity - Microsoft Entra ID

CONETN-5453

The Microsoft Entra ID connector now retrieves complete appRoleAssignments for users without truncating results.

Connectivity - Oracle ERP Cloud

CONETN-5440

The Oracle ERP Cloud connector now executes a get account operation after enabling or disabling an account.

Connectivity - Workday

CONETN-5429

The Workday connector now correctly displays worker status as TERMINATED when a worker is terminated, then rehired, and then have their rehire rescinded.

Identity Security Cloud - Sources and Account Management

PLTCONN-10452

Source-health behavior now separates “no accounts present” from true connectivity recovery to prevent false positive recovery emails for NO_ACCOUNTS.

Connectivity - SAP SuccessFactors

CONETN-5424

The SailPoint SuccessFactors connector now determines the effective employment record by using the latest end_date when multiple terminated employments exist. This behavior is enabled by configuring the calculateEffectiveEmpByEndDate source-level flag.

Connectivity - Oracle ERP Cloud

CONETN-5375

Fixed an issue in the Oracle ERP Cloud connector where the Status attribute was not updated correctly after enable or disable operations during single account aggregation. The account status now reflects changes accurately.