Application
Quick answer
An Application (Source) object represents a connected system, its connector config, schema, and the accounts it holds.
Key takeaways
- What the Application object represents
- Key attributes and relationships
- How it is created and maintained
- Where it appears in governance
The Application object (called a Source in Identity Security Cloud) represents a connected system that SailPoint governs. It holds the connector type, connection settings, account and group schemas, and the correlation configuration for that one system. Aggregation and provisioning both act through the Application object.
What it contains
- Connector configuration: type, host/URL, credentials and options.
- Schemas: the account schema (and group/entitlement schema) describing the attributes read from the target.
- Correlation config: how the target’s accounts map to identities.
- Provisioning settings: whether and how changes are written back.
Authoritative versus target applications
An application can be an authoritative source (usually HR), which supplies identities and their attributes, or a target, which supplies accounts to govern. Some are both. Designating authoritative sources correctly is critical, they drive identity creation and the attributes everything else depends on.
How accounts become part of an identity
When you aggregate an application, its accounts are read into the warehouse as Links and correlated to identities. From that point the application’s access appears on the relevant cubes and can be governed like any other.
Onboarding an application
Bringing an application under governance means creating the Application object, configuring its connector, mapping its schema, defining correlation, aggregating, and verifying. An application not onboarded is invisible to every control, so coverage, how many of your systems are actually governed, is a key programme metric.
Common pitfalls
- Mis-mapped schema breaking correlation or provisioning.
- Wrong authoritative designation, letting a target overwrite identity data.
- Low coverage, sensitive systems left un-onboarded and ungoverned.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What is an Application object?
- A. A connected target system, with its connector config, schema and accounts.
- B. Links on the correlated identities.
- C. Connector type, connection settings, schemas and correlation configuration.
Show answer
A. A connected target system, with its connector config, schema and accounts.
A connected target system, with its connector config, schema and accounts.
What does it hold?
- A. Links on the correlated identities.
- B. A connected target system, with its connector config, schema and accounts.
- C. Connector type, connection settings, schemas and correlation configuration.
Show answer
C. Connector type, connection settings, schemas and correlation configuration.
Connector type, connection settings, schemas and correlation configuration.
What do aggregated accounts become?
- A. Links on the correlated identities.
- B. A connected target system, with its connector config, schema and accounts.
- C. Connector type, connection settings, schemas and correlation configuration.
Show answer
A. Links on the correlated identities.
Links on the correlated identities.