Glossary
Plain-language definitions of the SailPoint and identity governance terms you will meet, A to Z.
This glossary defines the SailPoint and IGA terms that trip people up: Identity Cube, Link, entitlement, Managed Attribute, Bundle, aggregation, provisioning, correlation, certification, SoD and more, each in one clear sentence with a link to the full module.
- One-sentence definitions of key terms
- Covers objects, lifecycle and governance vocabulary
- Links each term to its full module
- A fast reference while reading other lessons
- Great for interview and exam recall
The vocabulary of SailPoint and identity governance, in plain language. These are the terms that trip people up most; keep this open while you work through the other modules, and follow the links in each lesson for the full explanation.
Core terms A to Z
| Term | Meaning |
|---|---|
| Identity Cube | The single correlated record for a person; the identity object in IdentityIQ. |
| Identity | A person or service represented in SailPoint, linking all their accounts and access. |
| Account (Link) | One credential on one application, correlated to an identity as a Link. |
| Entitlement | A single permission on an application, e.g. a group membership or privilege. |
| Managed Attribute | An entitlement enriched for governance with an owner, description and classification. |
| Role (Bundle) | A business-meaningful bundle of entitlements; stored internally as a Bundle object. |
| Aggregation | Reading accounts and entitlements from a source into the warehouse. |
| Provisioning | Writing approved access changes out to target systems. |
| Correlation | Attaching an aggregated account to the correct identity. |
| Certification | A campaign in which reviewers attest whether access is still appropriate. |
| Separation of duties (SoD) | A policy preventing toxic combinations of access in one person. |
| Least privilege | Granting only the access a role genuinely needs, and nothing more. |
| Authoritative source | The system of record (usually HR) that defines who exists and their attributes. |
| Lifecycle event | Automation that adjusts access on joiner, mover and leaver transitions. |
| Policy | Rules that detect risky or non-compliant access, most importantly SoD. |
| Workflow | A configurable multi-step process (approvals, provisioning) in IdentityIQ. |
| Task | A scheduled or manual background job such as aggregation or refresh. |
| Rule | BeanShell logic run at a defined hook to customise behaviour. |
| Identity refresh | A task that recomputes cubes, attributes, roles and policy. |
| Virtual Appliance | A lightweight component connecting Identity Security Cloud to on-premise systems. |
The pairs people confuse most
- Identity vs account, a person versus one login they own.
- Aggregation vs provisioning, reading data in versus writing changes out.
- Authentication vs authorization, proving who you are versus what you may do.
- Assigned vs detected role, granted deliberately versus inferred from held entitlements.
- Role vs Bundle, the same object; Bundle is the internal name.
How to use this glossary
Definitions here are deliberately one line each. When a term matters to what you are doing, follow it to its full lesson, most of these terms have a dedicated concept or object page in this course that explains the why and the how in depth.
Common pitfalls
- Treating a one-line definition as complete, follow the links for depth.
- Confusing the paired terms above, they are the usual source of mistakes.
- Assuming IdentityIQ and Identity Security Cloud use identical terminology, some names differ (Application vs Source).