Yes. IdentityIQ roles can be configured to include permissions as part of the access represented by the role. A role is fundamentally a logical collection of access that can include application entitlements and permission-based profile definitions. SailPoint describes roles as collections of permissions that group underlying system access into meaningful business or technical units.
Within a role profile, IdentityIQ supports Attribute Permissions in addition to attribute rules. Permissions define rights against targets on an application. An engineer can select rights such as create, read, update, delete, or execute and associate those rights with the appropriate target. These permission definitions become part of the role profile and therefore form part of the access granted through the role.
This should not be confused with IdentityIQ administrative SPRight objects. Application-level permissions contained in a role profile are governed access on target systems, whereas SPRights control functionality inside IdentityIQ itself. IdentityIQ roles can also grant capabilities and scopes when that feature is enabled.
Therefore, configuring a role to contain a set of permissions is a valid role configuration.
References/topics: IdentityIQ Engineer — Role Modeling, role profiles, attribute permissions, entitlements, targets and rights.
=======