• Votes

    4

    Group Review Items by Comment

    A customer misses the option to look at commented review items first. This can happen in a 2 phase review or after the reviewer has changed. It would help to be able to ...

  • Votes

    9

    IG: Deprovisioning of granted Permissions by Business Role ...

    IG 3.0 seems not to provide a mechanism that causes deprovisioning of a granted permission that is deleted from a Business Role. There must be a way to achieve this. ...

  • Votes

    8

    Have a native linux and windows local account collector

    Have a native linux and windows collector to get local accounts to identify and review orphans accounts on these systems. This is a very common and important requirement.

  • Votes

    2

    Have a SAP collector that gets object authorization and transactions ...

    Collect object authorization and transactions that users are assigned on SAP system. That makes possible to have SoD at that level of access in SAP systems. This is a ...

  • Votes

    1

    Software appliance installation option

    Have a software appliance option to install IG. That would make easier the deployment of it in projects, POCs, demos, and mainly for maintenance of the patches/updates in ...

  • Planned

    4

    Reviewer can visualize more detailed info about the IT and Business ...

    Today, in version 3.0, the reviewer cannot visualize some detailed information of the Role being reviewed. For instance, if a Technical role is being reviewed, it would ...

  • Votes

    1

    Be able to create a dashboard listing users by risk level and ...

    Be able to create a dashboard to identify and separate users by risk and also per department or job title (or any other identity attribute). This view can help the ...

  • Votes

    1

    Have a dashboard that demonstrates the number of violations per ...

    Have a dashboard that demonstrates the number of violations per department/job title so executive level users can visualize which group of users brings more risk to the ...

  • Votes

    4

    Create a SoD policy which has as a condition identity attribute data

    Create other types of SoD policies or just access policies that consider the mix of permissions and identity attribute date. For instance, an user who is a contractor ...

  • Votes

    5

    Track approvals by the requester user

    The requester user should be able to see who is next approver and also, if the approval process is more than 1 level, if the request was already approved by the 1st level ...

  • Votes

    4

    Make available a field that filters the application permissions listed ...

    In 3.0, when an application is selected for requests, all permissions are listed but if that list of permissions are too large, it would be difficult for the user to find ...

  • Votes

    10

    Upload button on web page to copy a file content to the IG server

    Today, access to host (operating system) is very restricted and limited so it would be great to have a button on web page of application/identity csv collector that the ...

  • Planned

    6

    Role Composition Periodic Access Review

    Have a role composition (not membership) such as which permissions are part of a IT role that is reviewed periodically by someone (e.g. role owner, app owner). The idea ...

  • Votes

    4

    Import and Export SoD policies from/to a csv file

    It is very common to have a SoD policies in a csv file before the customer acquires a solution to keep them so it would be great if it would be possible to import SoD ...

  • Votes

    1

    Can we use external (password, email, etc.) risk scoring as part of ...

    Hi guys, Can we please use a repository (e.g. https://haveibeenpwned.com/Passwords ) to score and measure the risk of the credential landscape over time? Thanks!

  • Votes

    3

    Ability to record delegated (onBehalfOf) permissions and certify them

    Many systems (such as exchange) have delegated permissions. Using MS Exchange as the example the ability to review mailbox and calendar delegate access/permissions is ...

  • Planned

    1

    Technical Role - Allow selection of Entitlements & Bound Permissions

    IG 301 - During Technical Role creation the Permission selection list does not display Entitlements and their Bound Permissions. These permissions were collected by the ...

  • Planned

    10

    Triggered Reviews

    Provide the capability to generate triggered Reviews for Joiner, Mover, Leaver, or Other use cases. Example Use Cases : A Review should be automatically generated due ...

  • Votes

    2

    Data Dictionary of attributes listing values & purpose

    The application needs a Data Dictionary providing a list of the attributes for User / Account / Group / Permission / Business Roles and their values & purpose within the ...

  • Planned

    2

    Capability Matrix per Authorization Assignment

    Provide a Capability Matrix (of IG left navigation Menu selections & privileges) per Authorization Assignment. (Global Administrator, Access Request Administrator, etc) ...