IT CanvassTalk to an advisor
Objects · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Application

The Application object: a connected target system SailPoint governs.

Quick answer

An Application (Source) object represents a connected system, its connector config, schema, and the accounts it holds.

Key takeaways
  • What the Application object represents
  • Key attributes and relationships
  • How it is created and maintained
  • Where it appears in governance

The Application object (called a Source in Identity Security Cloud) represents a connected system that SailPoint governs. It holds the connector type, connection settings, account and group schemas, and the correlation configuration for that one system. Aggregation and provisioning both act through the Application object.

What it contains

  • Connector configuration: type, host/URL, credentials and options.
  • Schemas: the account schema (and group/entitlement schema) describing the attributes read from the target.
  • Correlation config: how the target’s accounts map to identities.
  • Provisioning settings: whether and how changes are written back.

Authoritative versus target applications

An application can be an authoritative source (usually HR), which supplies identities and their attributes, or a target, which supplies accounts to govern. Some are both. Designating authoritative sources correctly is critical, they drive identity creation and the attributes everything else depends on.

How accounts become part of an identity

When you aggregate an application, its accounts are read into the warehouse as Links and correlated to identities. From that point the application’s access appears on the relevant cubes and can be governed like any other.

Onboarding an application

Bringing an application under governance means creating the Application object, configuring its connector, mapping its schema, defining correlation, aggregating, and verifying. An application not onboarded is invisible to every control, so coverage, how many of your systems are actually governed, is a key programme metric.

Common pitfalls

  • Mis-mapped schema breaking correlation or provisioning.
  • Wrong authoritative designation, letting a target overwrite identity data.
  • Low coverage, sensitive systems left un-onboarded and ungoverned.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What is an Application object?

Frequently asked questions

What does the term Application object refer to in SailPoint?
The Application object (called a Source in Identity Security Cloud) represents a connected system that SailPoint governs. It holds the connector type, connection settings, account and group schemas, and the correlation configuration for that one system.
What is the role of aggregation in Application object?
When you aggregate an application, its accounts are read into the warehouse as Links and correlated to identities.
What is another point to note about Application object?
An application can be an authoritative source (usually HR), which supplies identities and their attributes, or a target, which supplies accounts to govern.
What tends to go wrong with Application object?
Mis-mapped schema breaking correlation or provisioning. Wrong authoritative designation, letting a target overwrite identity data. Low coverage, sensitive systems left un-onboarded and ungoverned.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support