Access recommendations from AI Services in IdentityIQ 8.2
- Overview
- Video: AI Services recommendations for end users
- Configuring AI Services recommendations
- How recommendations work in access requests
- Reporting on recommendations and decisions
Overview
For self-service requests for roles, IdentityIQ can now receive recommendations from SailPoint's AI Services. AI Services uses peer group analysis, based on information such as the user's manager, department, location, and colleagues, to make recommendations about which roles this user should have. The user is presented with a single, data-driven list of role recommendations; this can help reduce confusion on the user's part about what roles to request, and save valuable time and effort in the role request process. The recommendations and the final decision are captured in reports, supplying important information about access decisions for auditors.
Video: AI Services recommendations for end users
This brief video gives an overview and demo of how the recommendations feature of AI Services works in IdentityIQ:
Configuring AI Services recommendations
IdentityIQ needs a configured connection to SailPoint's AI Services. This requires an IdentityNow tenant. See Getting Started with SailPoint AI Services for more information.
The IdentityIQ AI Services documentation has details on configuring this feature.
How recommendations work in access requests
With AI Services recommendations, when a user clicks Manage My Access from the home page, he or she is prompted to review any roles that are recommended:
When the user clicks Yes, show my recommendations, a list of recommended roles is shown. The user can click the "thumbs up" icon to see why this role was recommended.
Clicking Yes, show my recommendations also changes the user's options for searching for access. The Search Access field gives the user the choice between searching for recommended access only, or searching by keyword among all access:
Reporting on recommendations and decisions
AI Services recommendation information is included in the following IdentityIQ reports.
- Access Review Decision Report (note that the Roles table for this report intentionally does not contain the recommendation columns)
- Access Request Status Report
- Advanced Access Review Live Report
- Application Owner Access Review Live Report
- Certification Activity by Application Report
- Access Review Live Report (for Managers)
- Role Membership Access Review Live Report
- Targeted Access Review Live Report
- Work Item Archive Report
These reports include columns for Recommended Decision, Recommendation Timestamp, Recommendation Reasons, Auto Decision Generated, and Auto Decision Accepted.