Yes. IdentityIQ ' s authorization model uses granular SPRights and higher-level Capabilities to control access to product functions. SPRights govern access to menus, tools, tabs, pages, and individual operations. Capabilities group one or more of those rights into logical sets that can be assigned according to job responsibilities.
A capability can be assigned directly to an Identity through the identity ' s User Rights configuration. Capabilities may also be inherited indirectly through workgroup membership. Therefore, the capabilities available to a logged-in identity are one of the mechanisms IdentityIQ uses to determine which product features that user can see and what administrative or operational actions the user can perform.
Capabilities should not be confused with Scopes . Scopes constrain the objects or portions of the environment to which a user has visibility or control, whereas capabilities determine the functions/features the user is authorized to use. The two mechanisms can operate together.
SailPoint documentation explicitly states that identities can have capabilities assigned directly and that capabilities determine which IdentityIQ features users can access.
References/topics: IdentityIQ Engineer — SPRights, Capabilities, User Rights, authorization, workgroup-inherited rights, scopes.
=======