Yes. Account Groups are commonly used to represent entitlement-bearing group or application objects from a target system. SailPoint documentation uses the terms account group and application object closely, and many applications model access through membership in groups. During aggregation, an account may contain an entitlement attribute such as groups, memberOf, roles, or another group-membership attribute.
When the application also defines a group schema, IdentityIQ can aggregate the group objects themselves. The account schema ' s entitlement attribute is linked to the group schema by setting its type to the applicable native object type—commonly group. IdentityIQ can then associate the entitlement values found on accounts with the corresponding group objects.
These group values can become ManagedAttribute objects and appear in the Entitlement Catalog, where IdentityIQ can attach governance information such as owner, description, requestability, and certification metadata. This allows the target-system group to function as a governed entitlement.
Therefore, representing a particular group-based entitlement associated with accounts on a target system is an appropriate Account Group use case.
References/topics: IdentityIQ Engineer — Account Groups, Application Objects, group schemas, ManagedAttribute, Entitlement Catalog, account entitlements.
=======