---
title: Access Modeling
description: Overview of Access Modeling, which uses role mining to discover candidate roles in your PingOne Identity Governance environment
component: pingoneaic
page_id: pingoneaic:identity-governance:administration/access-modeling-preface
canonical_url: https://docs.pingidentity.com/pingoneaic/identity-governance/administration/access-modeling-preface.html
llms_txt: https://docs.pingidentity.com/pingoneaic/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-09-28
keywords: ["access modeling", "role mining", "candidate roles", "confidence scoring", "configure access modeling", "run a role mining job", "review and publish roles", "PingOne Identity Governance", "IGA"]
section_ids:
  how_access_modeling_works: How Access Modeling works
---

# Access Modeling

Access Modeling, also known as role mining, analyzes existing access patterns to help optimize user-to-entitlement assignments. Identity Governance uses machine learning and analytics to propose candidate roles for review and publication by role owners.

|   |                                                                                                                                                                                                                                                                                                                                                                                                               |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | PingOne Identity Governance add-on capabilityAccess Modeling is an additional add-on capability for PingOne Identity Governance. Contact your Ping Identity representative if you want to add the Access Modeling (Role Mining) add-on SKU to your PingOne Advanced Identity Cloud Identity Governance subscription. Learn more in [Add-on capabilities](../../product-information/add-on-capabilities.html). |

## How Access Modeling works

The Access Modeling workflow involves the following participants:

1. An administrator [configures Access Modeling](iga-access-modeling-admin.html), activates governance lifecycle management (the machine learning model that powers role mining), sets confidence thresholds, and creates the `access-modeling-administrator` group.

2. The administrator assigns one or more end users to the `access-modeling-administrator` group.

3. An authorized end user (a member of the `access-modeling-administrator` group) [runs a role mining job](../end-user/iga-access-modeling-end-user.html#run-a-role-mining-job). Identity Governance analyzes the latest access data and generates candidate roles.

4. A role owner and an approver [review and publish roles](../end-user/iga-access-modeling-end-user.html#create-drafts-and-publish-roles). The role owner refines a candidate into a draft, and an approver publishes the draft as an active role in Identity Governance.
