Last Updated date: October 6, 2026
Automate access, reduce risk, and stay audit-ready
Access accumulates quickly in enterprise environments. Users receive permissions based on their responsibilities, teams, and projects, but these permissions are not always organized into reusable roles. Over time, this can lead to excessive direct entitlement assignments that are difficult to manage and govern.
Role mining addresses this by analyzing existing access patterns and identifying opportunities to create structured IT Roles. Instead of designing every role from scratch, organizations can discover roles from the access users already have.
Identity Confluence supports three ways to provision access: Business Roles, IT Roles, and Direct Entitlements, providing a flexible and structured approach to access management.
The challenge is not only managing access, but also identifying whether existing permissions can be grouped into meaningful and repeatable roles.
For example, multiple users may have the same application permissions without an IT Role representing that access. Without role mining, these permissions continue to be assigned individually, creating unnecessary direct entitlements and making access harder to standardize.
Role mining reverses this approach. Instead of defining a role first and assigning permissions to it, organizations start with existing access and identify patterns that can be converted into IT Roles.
Role Discovery analyzes existing access to identify potential IT Roles that have not yet been formally defined.
The workflow is accessible through:
Role Mining → Application → Quick Links → Role Discovering
Before running the discovery, administrators can define parameters that determine which access patterns should be considered.
Defines the minimum number of users who must share an access pattern for it to qualify as a potential role. This helps prevent highly specific access combinations from becoming unnecessary roles.
Defines the maximum number of users that can be associated with a discovered role. Together, these parameters help focus discovery on relevant access patterns.
Once the parameters are configured, select Start Role Discovery. Identity Confluence analyzes existing access and presents potential IT Roles along with the permissions associated with each pattern.
Suppose 100 users have direct Jenkins access across four configurations:
Role Discovery identifies these four common access patterns and suggests four IT Roles, one for each configuration, instead of continuing to manage them as individual direct entitlements.
Existing access → Discover pattern → Review permissions → Create IT Role → Govern access
Discovery identifies potential roles, but each role still needs to be reviewed before it becomes part of the access model.
The Review Queue provides an Entitlements Review for IT Roles, allowing administrators to validate the permissions associated with each discovered role and ensure that they accurately represent the required access.
Role mining is particularly useful when organizations have accumulated significant access data but lack a well-defined role structure. It helps teams:
Role mining helps organizations move from scattered permissions to a structured and governed access model. With Identity Confluence, teams can analyze existing access, discover reusable IT Roles, review their entitlements, and reduce reliance on individual Direct Entitlements.
