Skip to content
IT Canvass
Objects · Lesson

Application

Quick answer

An Application (Source) object represents a connected system, its connector config, schema, and the accounts it holds.

Key takeaways

  • What the Application object represents
  • Key attributes and relationships
  • How it is created and maintained
  • Where it appears in governance

The Application object (called a Source in Identity Security Cloud) represents a connected system that SailPoint governs. It holds the connector type, connection settings, account and group schemas, and the correlation configuration for that one system. Aggregation and provisioning both act through the Application object.

What it contains

  • Connector configuration: type, host/URL, credentials and options.
  • Schemas: the account schema (and group/entitlement schema) describing the attributes read from the target.
  • Correlation config: how the target’s accounts map to identities.
  • Provisioning settings: whether and how changes are written back.

Authoritative versus target applications

An application can be an authoritative source (usually HR), which supplies identities and their attributes, or a target, which supplies accounts to govern. Some are both. Designating authoritative sources correctly is critical, they drive identity creation and the attributes everything else depends on.

How accounts become part of an identity

When you aggregate an application, its accounts are read into the warehouse as Links and correlated to identities. From that point the application’s access appears on the relevant cubes and can be governed like any other.

Onboarding an application

Bringing an application under governance means creating the Application object, configuring its connector, mapping its schema, defining correlation, aggregating, and verifying. An application not onboarded is invisible to every control, so coverage, how many of your systems are actually governed, is a key programme metric.

Common pitfalls

  • Mis-mapped schema breaking correlation or provisioning.
  • Wrong authoritative designation, letting a target overwrite identity data.
  • Low coverage, sensitive systems left un-onboarded and ungoverned.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. What is an Application object?

    • A. A connected target system, with its connector config, schema and accounts.
    • B. Links on the correlated identities.
    • C. Connector type, connection settings, schemas and correlation configuration.
    Show answer

    A. A connected target system, with its connector config, schema and accounts.

    A connected target system, with its connector config, schema and accounts.

  2. What does it hold?

    • A. Links on the correlated identities.
    • B. A connected target system, with its connector config, schema and accounts.
    • C. Connector type, connection settings, schemas and correlation configuration.
    Show answer

    C. Connector type, connection settings, schemas and correlation configuration.

    Connector type, connection settings, schemas and correlation configuration.

  3. What do aggregated accounts become?

    • A. Links on the correlated identities.
    • B. A connected target system, with its connector config, schema and accounts.
    • C. Connector type, connection settings, schemas and correlation configuration.
    Show answer

    A. Links on the correlated identities.

    Links on the correlated identities.

Frequently asked questions

What does the term Application object refer to in SailPoint?

The Application object (called a Source in Identity Security Cloud) represents a connected system that SailPoint governs. It holds the connector type, connection settings, account and group schemas, and the correlation configuration for that one system.

What is the role of aggregation in Application object?

When you aggregate an application, its accounts are read into the warehouse as Links and correlated to identities.

What is another point to note about Application object?

An application can be an authoritative source (usually HR), which supplies identities and their attributes, or a target, which supplies accounts to govern.

What tends to go wrong with Application object?

Mis-mapped schema breaking correlation or provisioning. Wrong authoritative designation, letting a target overwrite identity data. Low coverage, sensitive systems left un-onboarded and ungoverned.
CallWhatsAppEnquire