SaaS

SaaS Release Notes - July 31, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Identity Security Cloud - Settings

Admins can now view all Personal Access Tokens for their entire organization, and edit their expiration dates in the new Personal Access Tokens page under Admin > Security Settings. For more information, refer to Managing Personal Access Tokens as an Org Administrator.

Enhancements

ProductFeature enhancements

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

SailPoint Cloud Infrastructure Entitlement Management now ingests and displays the effective access and access paths for human identities for the GCP AI Platform (Vertex/Gemini AI Agents) and Microsoft Cognitive Services (Foundry Agents) and the associated cloud resource types. This feature allows you to remove unneeded access and modify privileges as needed for these cloud resources.

Identity Security Cloud - Platform

SailPoint has enhanced access model metadata custom attributes:

  • Custom metadata attributes can now be configured to allow ad hoc values up to 100 characters.
  • Attribute and value limits have been expanded to support up to 250 custom metadata attributes per access object type and 5,000 values per custom attribute.

Identity Security Cloud - Access Requests

On the Admin > Approval Management page, admins can now filter access requests by Current Owner, Requested For, and Requested By, even when those identities are inactive (for example, users who have left the organization). This makes it easier to find and manage pending requests that reference former employees.

Identity Security Cloud - Provisioning and Task Manager

Identity Security Cloud now queues an attribute promotion request for an identity when the calculation of its nextProcessingDate attribute results in the past.

Identity Security Cloud - Identity Graph

Users can now view inherited access from within the data table.

Identity Security Cloud - Identity Graph

Bulk actions can now be performed from within the data table.

Non-Employee Risk Management

SailPoint Non-Employee Risk Management user and profile sources now support OAuth credentials as an authentication method.

Connectivity - Coupa

SaaS Connectors - Coupa SaaS

The Coupa connector now supports Coupa licenses as entitlements.

Identity Security Cloud - Workflows

The Get Workflow Executions API Authorization has been updated for Personal Access Tokens. Personal Access Tokens should now reference sp:workflow-execution:read instead of sp:workflow:read.

The following GET endpoints are impacted:

  • /workflows/{id}/executions
  • /workflow-executions/{id}
  • /workflow-executions/{id}/history
  • /workflow-executions/{id}/history-v2

Fixes

ProductIssue IDFixes

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

CAM-32330 TRIAGE-17243 CAM-32330 SAASDOCS-12453

Fixed an issue where effective access processing and Identity Center account entitlement aggregation failed for resources with no cloud resource tags.

Identity Security Cloud - Provisioning and Task Manager

ISCRP-7294

Remove All Access no longer removes protected access profiles (cloudProtected=true) from identity role detection's during a life-cycle state change on identities with multiple accounts on the same source.

Other access continues to be removed as before (manual roles, non-protected access profiles, direct entitlements), while birthright roles, life-cycle state required access, and assignment-linked detection's remain unchanged.

Connectivity - SAP SuccessFactors

CONETN-5503

The SuccessFactors connector no longer skips future-dated information for additional attributes configured via SFAPI path in multiple employment rehire scenarios where an employee is rehired as a contingent worker.

Connectivity - Microsoft Entra ID

SaaS Connectors - Microsoft Entra SaaS

CONETN-5458

The Microsoft Entra ID and Entra SaaS connectors now add a configurable delay between requests when adding or removing assigned plans during bulk provisioning, preventing 409 errors. The delay is controlled by the sleepBetweenAssignedPlans attribute, with a default of 3 seconds. For more information, refer to the respective connector guides:

Identity Security Cloud - Sources and Account Management

ISCARP-18934

When deleting sources simultaneously, the source threads no longer overwrite each other. Each source thread now deletes its own single source row from the database.

Connectivity - Workday

CONETN-5418

Fixed an issue where the Workday connector marked workers as rescinded instead of corrected during single account aggregation when their hire date was corrected to fall outside the Effective Date Offset.

Connectivity - Microsoft Entra ID

CONETN-5363

The Microsoft Entra ID connector now correctly retries failed requests when provisioning appRoleAssignments.