Yes. In SailPoint IdentityIQ, an entitlement represents an access right, permission, privilege, group membership, role membership, or similar access-granting value on an application. Entitlements are discovered from application account data during aggregation and are commonly modeled in IdentityIQ through schema attributes marked as entitlement attributes. Once aggregated, these values may appear in the entitlement catalog as managed attributes, where they can be reviewed, requested, certified, governed by policies, and associated with roles.
The definition “an access right on an application” is accurate because entitlements describe what an identity’s account is allowed to do or access within a connected system. Examples include Active Directory group membership, database roles, application permissions, cloud groups, or other system-specific access values. IdentityIQ uses entitlements as core governance objects for certifications, access requests, policy checks, role modeling, and provisioning.
This definition is intentionally broad because different target systems represent access differently. IdentityIQ normalizes those application-specific access values into entitlement concepts for identity governance.
Reference topics: Access Modeling, entitlement catalog, managed attributes, application schema, entitlement aggregation, certifications, access requests, and provisioning.
‘
Submit