Role Mining
Analyzing existing access to discover sensible roles, reducing role explosion and cleaning up entitlements. A common step in rolling out or fixing RBAC.
Role mining is most useful as a cleanup exercise rather than a design method: the clusters it finds describe access as it happened to accumulate, including the mistakes. Treat the output as a starting proposal that business owners edit, and pair it with usage data so roles are built from entitlements people actually exercise rather than from everything they were ever granted.
See also: RBAC, what is IGA, entitlement, access certification
Related on Start with Identity
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- GlossaryABAC
Attribute-Based Access Control. Access decisions are made by evaluating attributes of the subject, resource, action, and environment against policy. Flexible bu
- GlossaryIAM
Identity and Access Management. Workforce identity for employees, contractors, and partners. Covers authentication, authorization, lifecycle, and audit. Distinc
- BlogServiceNow closes its Veza acquisition at about 1.2 billion dollars
Announced in December 2025 and closed on 2 March 2026, substantially in cash. Veza, valued at 808 million dollars in its Series D, now supplies the permission g
- CVESailPoint IdentityIQ role-editing authorization flaw
IdentityIQ failed to authorize role edits on all versions at disclosure (April 2026). Anyone who could reach the role-editing surface could change roles they sh