Yes. In SailPoint IdentityIQ, marking an application account schema attribute as managed identifies that attribute as governance-relevant access data. This is commonly applied to attributes that contain entitlement-like values, such as groups, roles, permissions, or application access assignments. When the attribute is managed, IdentityIQ can create and maintain managed attribute records for the values discovered during aggregation, allowing those values to be represented in the entitlement catalog with business metadata such as display name, description, owner, requestability, and classification.
This managed designation supports governance processes, including certifications. In an access review, reviewers need to evaluate meaningful access items rather than raw account data. Managed entitlement values can therefore be surfaced as reviewable access so managers, application owners, or entitlement owners can approve, revoke, or otherwise act on them during certification campaigns.
This does not mean the attribute itself is simply editable in IdentityIQ; editability is controlled separately through provisioning policies, forms, workflows, and connector support. The managed flag is primarily about governing the attribute’s values as access.
Reference topics: Applications — schema attribute properties; Access Modeling — entitlement catalog; Governance — certification review items.
Submit