SaaS

SaaS Release Notes - September 11, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat’s new

SaaS Connectors - Octopus Deploy SaaS

The Octopus Deploy SaaS connector is now available for Identity Security Cloud. The connector aggregates users as accounts, teams and user roles as entitlements, and service accounts, API keys, and stored credentials as non-human identities. For more information, refer to Integrating SailPoint with Octopus Deploy.

SaaS Connectors - Buildkite SaaS

The Buildkite SaaS connector is now available for Identity Security Cloud. The connector aggregates organization members as accounts, organization roles and teams as entitlements, and agent tokens, secrets, and registry tokens as non-human identities. For more information, refer to Integrating SailPoint with Buildkite.

Connectivity - JDBC

The JDBC connector now supports the Dataset Resource model to aggregate non-human identity (NHI) entities, including Agent, MCP Server, and Tools, etc. The connector aggregates dataset resources such as Agent along with their capabilities and relationships between them. The connector also supports agent owner correlation for streamlined access governance. For more information refer to Dataset Management.

Connectivity - REST WebServices Connector

The WebServices connector now supports the Dataset Resource aggregation model to aggregate non-human identity (NHI) entities, including Agent, MCP Server, and Tools, etc. The connector aggregates dataset resources such as Agent along with their capabilities and relationships between them. The connector also supports agent owner correlation for streamlined access governance. For more information refer to Dataset Management.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Enhancements

ProductFeature enhancements

SaaS Connectors - Azure DevOps SaaS

The Azure DevOps SaaS connector now supports OAuth 2.0 authentication using client credentials and JSON Web Token (JWT) certificate, giving customers additional secure authentication options alongside personal access token (PAT) authentication.

SaaS Connectors - Slack SaaS

The Slack SaaS connector can now aggregate Slack bots as machine accounts. To enable this on a source, select Enable Slack Machine Accounts and enter a Bot User OAuth Token.

For more information, refer to Machine Identity Governance Settings.

SaaS Connectors - Web Services SaaS

The Web Services SaaS connector now creates new sources without the default group entitlement object. Existing sources continue to function without changes. If your integration requires group-based access, create the group entitlement object in the Entitlement Type menu and configure the associated endpoints.

Identity Security Cloud - SoD

In addition to entitlements, users can now include roles and access profiles in separation of duties (SoD) policy criteria.

Identity Security Cloud - Workflows

The Workflows HTTP Request Action now supports Activity Output Trimming for POST requests, which automatically reduces workflow payload sizes by keeping only the data your workflow references in later steps. For POST, trimming is applied only when the action output is used as an input to a loop. This improves performance, reduces data transfer, and makes execution history easier to read, without requiring changes to existing workflows.

Identity Security Cloud - Virtual Appliance

The virtual appliance can now export metrics to the Datadog OpenTelemetry endpoint.

Identity Security Cloud - User Levels, Workflows

Custom User Levels now support read-only access to Workflows through two new permissions: Workflows Read Only, for viewing workflow configurations, and Workflows Audit Read Only, for viewing configurations plus execution history.

Refer to Workflow Permissions for more information.

Fixes

ProductIssue IDFixes

Connectivity - Workday

CONETN-5498

Fixed an issue where the Workday connector preferred a future termination over a future hire during single account aggregation when a worker had multiple future actions within the effective date offset, even when preferFutureTerminatedRecord was set to true.

SaaS Connectors - SCIM 2.0 SaaS

CONETN-5523

The SCIM 2.0 SaaS connector now generates a path with a flat value array for multivalued SCIM attributes.

Connectivity - SAP Concur

CONETN-5500

Fixed an issue where the SAP Concur connector failed to deprovision roles that included EXP_EMPLOYEE_ADMIN::Global when they were removed with other roles in the same request.

SaaS Connectors - ISC Cloud Governance Connector

CONETN-5627

The Identity Security Cloud Governance connector no longer crashes when a reassignment API call returns HTTP 403 during account disable with owner reassignment. The connector now logs a permission error for the failed reassignment and continues disabling the account.

Identity Security Cloud - Search

IDNARC-6456

Fixed an issue where an audit event wasn’t being generated when enabling or disabling reauthentication for an entitlement.

Identity Security Cloud - Access Requests

ISCARP-19349

The Create Access Request API no longer returns a prior request’s access request ID in existingRequests when a new request is submitted for the same identity but a different entitlement within the recent-request cache window.

Machine Identity Security

IDNARC-7633

Fixed an issue where Identity Security Cloud indicated that a machine account owner was deleted successfully when the system prevents identities assigned machine accounts from being deleted. Users now receive a warning message when they attempt to delete a machine account owner.