IAM / SailPoint

SailPoint Human Fabric / Identity Security Cloud

SailPoint Identity Security Cloud is an identity governance platform for discovering, governing, and protecting human access. It focuses on lifecycle, access certifications, and separation of duties rather than login user experience, with modules that extend toward cloud entitlements and non-employee identities.

Identity governanceResearch reviewed

What you are evaluating

Current public naming also uses Human Fabric and describes its relationship to Identity Security Cloud. Existing customer editions and migration requirements still need contract-specific verification. This profile is identity governance, not workforce single sign-on.

A useful evaluation context

An enterprise can evaluate governance when business applications contain entitlements whose ownership or continuing need is unclear.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Lifecycle, certifications, and separation-of-duties rules review whether standing access to applications and entitlements is still justified.
  • Discovery and governance modules examine entitlement sprawl; verify just-in-time access patterns against the selected connectors.
  • Cloud infrastructure entitlement and non-employee modules exist as adjacent coverage; confirm which edition your tenant actually includes.

Where it fits in the work

  1. Connect a synthetic human-resources source and two lab applications, then import entitlements rather than only usernames.
  2. Run a certification campaign on a small synthetic population and record who approved, who revoked, and what the connector actually changed.
  3. Test a joiner and a mover against written separation-of-duties rules, including one entitlement the connector cannot yet manage.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In a SailPoint lab tenant, import a synthetic employee with an extra finance entitlement, launch a certification, revoke the extra entitlement, and re-read the application.

Evidence to look for

The certification record shows the revoke decision, and the connected lab application no longer lists that entitlement for the synthetic user.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which current offering and edition does the proposal specify, and are any actual migration requirements documented?
  2. For each in-scope application, does the connector both read entitlements and revoke them, or only list accounts?
  3. How are just-in-time or zero standing privilege claims demonstrated on a real connector rather than a brochure?

Names you may encounter: IdentityNow. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.