Application
The Application object: a connected target system SailPoint governs.
An Application (Source) object represents a connected system, its connector config, schema, and the accounts it holds.
- What the Application object represents
- Key attributes and relationships
- How it is created and maintained
- Where it appears in governance
The Application object (called a Source in Identity Security Cloud) represents a connected system that SailPoint governs. It holds the connector type, connection settings, account and group schemas, and the correlation configuration for that one system. Aggregation and provisioning both act through the Application object.
What it contains
- Connector configuration: type, host/URL, credentials and options.
- Schemas: the account schema (and group/entitlement schema) describing the attributes read from the target.
- Correlation config: how the target’s accounts map to identities.
- Provisioning settings: whether and how changes are written back.
How accounts become part of an identity
When you aggregate an application, its accounts are read into the warehouse as Links and correlated to identities. From that point the application’s access appears on the relevant cubes and can be governed like any other.
Onboarding an application
Bringing an application under governance means creating the Application object, configuring its connector, mapping its schema, defining correlation, aggregating, and verifying. An application not onboarded is invisible to every control, so coverage, how many of your systems are actually governed, is a key programme metric.
Common pitfalls
- Mis-mapped schema breaking correlation or provisioning.
- Wrong authoritative designation, letting a target overwrite identity data.
- Low coverage, sensitive systems left un-onboarded and ungoverned.