Skip to content
IT Canvass
Getting started · Lesson

The Identity Cube

Quick answer

An Identity Cube is IdentityIQ's single record for a person. It links together every account they hold across connected systems, plus their attributes, roles and entitlements, into one governable object. Correlation is the process that attaches an incoming account to the correct cube.

Key takeaways

  • One cube per person, the unit of governance
  • Aggregates all of a person's accounts (Links) in one view
  • Holds identity attributes mapped from an authoritative source
  • Correlation attaches accounts to the right cube
  • Roles and entitlements on the cube drive access decisions

The Identity Cube is IdentityIQ’s name for the identity object, the single, correlated, person-centric record that ties together everything known about one person: all their accounts, all their entitlements and roles, and a set of governed attributes. It is the object every other capability revolves around, so understanding it is understanding SailPoint.

Why "cube"

The term evokes a consolidated, multi-dimensional view of a person: their identity attributes on one axis, their accounts across systems on another, and their entitlements and roles on a third. Instead of scattered logins on dozens of systems, the cube gives you one authoritative picture of everything a person can access.

What the cube contains

  • Links, one per correlated account on each application.
  • Identity attributes, name, department, title, manager, status, plus extended attributes.
  • Roles, assigned (granted deliberately) and detected (inferred from held entitlements).
  • Policy state, any current violations such as SoD conflicts.

How the cube is built

Identity aggregation reads the authoritative source and creates a cube per worker. Account aggregation of target systems, followed by correlation, attaches Links to the right cube. Identity refresh then applies attribute mappings, evaluates roles and runs policy. The result is a live, accurate picture that governance acts on.

Why it makes governance possible

You cannot answer "does this person still need finance access?" from a list of AD accounts, but you can from a cube that shows the person, their role, and every entitlement they hold. Certifications review a cube, provisioning changes a cube’s accounts, policy evaluates a cube’s combined access. The person-centric model is the foundation everything else stands on.

Keeping cubes healthy

Cube quality depends on reliable correlation (so no orphan accounts), clean attribute mapping from the authoritative source, and a regular refresh after aggregation. Weakness in any of these produces wrong governance decisions, so cube hygiene is a core operational discipline.

Common pitfalls

  • Weak correlation leaving accounts unattached to any cube.
  • Mapping attributes from non-authoritative sources, causing conflicts.
  • Skipping the refresh after aggregation, so cubes look current but roles and policy are stale.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. An Identity Cube represents?

    • A. An orphan account. Uncorrelated accounts are orphans and a governance risk.
    • B. One person. The cube is the single correlated record for a person.
    • C. Correlation. Correlation matches account attributes to identity attributes.
    Show answer

    B. One person. The cube is the single correlated record for a person.

    One person. The cube is the single correlated record for a person.

  2. Attaching an aggregated account to the right cube is called?

    • A. An orphan account. Uncorrelated accounts are orphans and a governance risk.
    • B. Correlation. Correlation matches account attributes to identity attributes.
    • C. One person. The cube is the single correlated record for a person.
    Show answer

    B. Correlation. Correlation matches account attributes to identity attributes.

    Correlation. Correlation matches account attributes to identity attributes.

  3. An account that matches no identity is?

    • A. One person. The cube is the single correlated record for a person.
    • B. Correlation. Correlation matches account attributes to identity attributes.
    • C. An orphan account. Uncorrelated accounts are orphans and a governance risk.
    Show answer

    C. An orphan account. Uncorrelated accounts are orphans and a governance risk.

    An orphan account. Uncorrelated accounts are orphans and a governance risk.

Frequently asked questions

What does the term The SailPoint Identity Cube refer to in SailPoint?

The Identity Cube is IdentityIQ’s name for the identity object, the single, correlated, person-centric record that ties together everything known about one person: all their accounts, all their entitlements and roles, and a set of governed attributes.

What is the role of aggregation in The SailPoint Identity Cube?

Account aggregation of target systems, followed by correlation, attaches Links to the right cube.

What is the practical takeaway on The SailPoint Identity Cube?

The term evokes a consolidated, multi-dimensional view of a person: their identity attributes on one axis, their accounts across systems on another, and their entitlements and roles on a third.

What tends to go wrong with The SailPoint Identity Cube?

Weak correlation leaving accounts unattached to any cube. Mapping attributes from non-authoritative sources, causing conflicts. Skipping the refresh after aggregation, so cubes look current but roles and policy are stale.
CallWhatsAppEnquire