The statement is explicitly incorrect. Identity Security Cloud allows users to hold multiple User Levels in many circumstances, and permissions from compatible User Levels are cumulative. However, SailPoint defines several combinations that cannot be assigned simultaneously because their delegated administrative scopes conflict.
One of the specifically prohibited combinations is Role Admin and Source Sub-Admin . SailPoint's User Level documentation lists this pair among the User Levels that cannot coexist on the same user. Other prohibited combinations include Role Sub-Admin with Source Admin, Role Sub-Admin with Role Admin, and Source Sub-Admin with Source Admin.
The distinction is important. A Role Admin has broad role-management privileges, whereas a Source Sub-Admin receives scoped administrative capabilities based on Governance Group associations with particular sources. Combining certain global and scoped administrative models could create inconsistent authorization behavior, so SailPoint prevents those assignments.
Administrators should therefore consult the User Level compatibility matrix before granting multiple elevated permissions rather than assuming that every User Level can be stacked.
Study Guide Reference: Platform — User Level Permissions, User Level Compatibility, Role Admin and Source Sub-Admin.
===============
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit