• Votes

    2

    Allow an access request approver to modify the access request

    Access request approvers may have a better understanding of what access the person should have and thus may need to modify the request. They may need to approve some of ...

  • Votes

    2

    Request access for non human accounts (not tied to a human identity)

    When requesting access for a service account, which is not for a specific person's use, the account would not be for a specific person's identity. There should be a ...

  • Planned

    5

    Reviews - Escalation tree

    Desire the ability for an escalation to go from one manager and then on to the next manager, etc. So if your timeout values are for two weeks and your review time is for ...

  • Votes

    1

    Importing of delegates

    All delegates must be created manually. I don't see a way to export delegates or import. It would be great to have a way to import and export delegates in mass. As part ...

  • Planned

    4

    Limit view of change reviewer

    When a reviewer selects to change the reviewer, they can see all users in the catalog, from what I can gather. Requesting the ability to have a filter to allow only ...

  • Votes

    3

    central admin page for all configuration

    SSPR like configuration for OSP / Identity Application SSPR, and Identity Governance. Where a bootstrap admin can access the configuration until it is ready to be ...

  • Votes

    2

    update notification email template requires restart

    It would be ideal for any testing or updating the email template(s) to be able to update the template without doing a restart of the tomcat service. In troubleshooting a ...

  • Votes

    5

    Default ES scripts for matching identitities

    case sensitivity, spaces, unicode, etc. If matching on CN and sAMAccountName it would be great if case sensitivity wasn't an issue. Actually, it would be great if it ...

  • Votes

    3

    Explicit handling of nested groups

    For at least one of our configurations, we'd like the ability to review groups along side with user in the list of review items. That is, if a group has other groups ...

  • Votes

    1

    Reassignment of approver based on permission relationship

    When reassigning an access review of an item, currently only user based reassignment is supported. It would be nice if I have for example an AD Group permission being ...

  • Votes

    3

    Require application owner review of application permission changes ...

    Business role permission changes should be coordinated with application owners, both to ensure that the business role owner is using the correct application permission ...

  • Planned

    10

    Fulfillment notification to end user and others

    As a user I want to be notified when a requested permission is actually fulfilled by the system. There are use cases in which a service desk or manager requests ...

  • Votes

    4

    Collection / publication triggered by scheduled review

    As a (review) adminstrator I want to be able to collect and publish an application source before and after a review. It is recommended to collect/publish before and after ...

  • Votes

    9

    Connector certificates in trust store

    Currently the certificates of applications need to be manually imported via the GUI. For our current customer we have multiple sort of "virtual" applications in AD and ...

  • Votes

    8

    Ability to automatically assign additional (conditional) permissions

    A lot of applications have a structure like this: - Application account - Certain permission right - Certain default permissions that every user needs when they have a ...

  • Votes

    9

    Check on permissions in other technical roles on revoke of technical ...

    Currently IGA does not check other technical role contents on revoke. When you have two technical roles with (partly) overlapping permissions (which can happen with some ...

  • Votes

    2

    Configupdate - add sanity checks for URL:s

    It would be nice if configupdate would do a sanity check on the URL:s entered so that they are well-formed, syntactically correct and maybe even throw in a DNS name check ...

  • Votes

    2

    ServiceNow Fulfillment with OAuth2.0 support (Rest version)

    The ServiceNow Fulfillment is currently designed to utilize SOAP endpoints. The available ServiceNow Fulfillment templates offer the possibility to configure Basic ...

  • Votes

    2

    Add additional email tokens to Identity Governance notifications

    For example, we see an advantage to being able to have a request notification have information like the user who the request is for, what application(s) the request is ...

  • Votes

    1

    Name/recipient data is not in Ascending order and Application name and ...

    In IG portal while going to Approvals in My Approvals tab. 1. Name/recipient data is not in Ascending order. If the data is in Ascending order it would be easy for ...