Yes. Configuring a role to contain a set of entitlements is fundamental to IdentityIQ role modeling. IdentityIQ defines a role as a collection of access that enables an identity to perform a business or technical function. For IT-oriented roles in particular, entitlement profiles define the access that is provisioned when the role is assigned. An entitlement can represent a specific value of an account attribute, such as membership in an Active Directory group, or a permission on a target application.
The Role Editor includes an Entitlements section in which engineers can create profiles and associate multiple entitlements with the role. SailPoint documentation specifically states that a profile is a set of entitlements on an application and that the engineer can specify as many entitlements as required for a role. This allows complex access requirements to be packaged into a governed reusable role rather than individually assigning each entitlement to every identity.
Therefore, the proposed solution is valid.
References/topics: IdentityIQ Engineer — Role Editor, IT Roles, entitlement profiles, role provisioning, role-based access model.
=======
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit