What is SailPoint?
SailPoint is the identity governance platform that controls who has access to what across the enterprise, and proves it.
SailPoint is an identity security and governance platform. It connects to every system that holds accounts, builds one correlated record per person, and governs their access across the joiner, mover and leaver lifecycle through requests, certifications and policy. IdentityIQ is the on-premises product; Identity Security Cloud is the SaaS version.
- Governs who has access to what, and why
- Two products: IdentityIQ (on-prem) and Identity Security Cloud (SaaS)
- Centres on the Identity Cube, one object per person
- Automates joiner, mover and leaver access
- Certifications and SoD policy keep access compliant
SailPoint is the market-leading identity governance and administration (IGA) platform. It answers, continuously and with evidence, who has access to what across an enterprise, whether that access is appropriate, and it automates granting, reviewing and removing access as people join, move and leave. In short, SailPoint is the control plane for enterprise access.
What problem SailPoint solves
Large organisations run hundreds of systems, each with its own accounts and permissions. Access accumulates faster than it is removed, audits demand proof that it is controlled, and manual management does not scale. SailPoint centralises all of this: it builds a person-centric view of access, applies policy and review over it, and enforces decisions back into the target systems automatically.
The two products
- IdentityIQ, the established, self-managed product: a Java web application on an app server backed by a database, highly customisable via rules and workflows.
- Identity Security Cloud (formerly IdentityNow), the SaaS platform: SailPoint runs the infrastructure, you configure governance, with a Virtual Appliance for connectivity to on-premise systems.
What SailPoint does day to day
- Aggregates accounts and entitlements from every connected system.
- Builds a person-centric identity for each worker (the Identity Cube in IdentityIQ).
- Models access as business-meaningful roles.
- Automates joiner/mover/leaver so access follows the lifecycle.
- Runs certifications so access is periodically reviewed.
- Enforces separation-of-duties and least privilege.
- Provisions and deprovisions access in target systems.
What SailPoint is not
SailPoint governs authorization, what people may access, and generally is not your login/MFA engine; that is your identity provider. It complements, not replaces, directories and SSO: the IdP proves who you are, SailPoint governs what you are allowed to do.
Why organisations adopt it
Three forces: compliance (provable, reviewed access for SOX, HIPAA, GDPR, ISO 27001), security (least privilege and prompt deprovisioning to shrink breach impact), and operational efficiency (automating access at scale). Where those three pressures meet, an IGA platform becomes essential rather than optional.
Common pitfalls
- Expecting SailPoint to handle login/MFA, that is the identity provider’s job.
- Buying the tool without a programme, process, ownership and clean data matter more than the software.
- Automating grants but not removals, so access still sprawls.
Practice challenge
Frequently asked questions
SailPoint's core purpose is to govern?
The on-premises SailPoint product is?
One correlated record per person is the?
Want this taught live, with job support?
SailPoint Training is delivered live by working practitioners, with certification prep and placement support.
See SailPoint Training →