The purpose of this article is to provide a review of SailPoint.
What is Identity and Access Management?
Identity and Access Management is the ability to manage identities and the access those identities have to corporate resources such as applications, files, and databases as well as IT resources like privileged accounts that manage firewalls and network infrastructure, virtualized environments, and IT management applications. Identity and Access Management is a cyber security and operations function that is delivered by using specific tools to manage identities and their access.
What and Who is SailPoint?
SailPoint is an Austin-Texas based software firm that delivers enterprise Identity and Access Management solutions. SailPoint is one of those solutions under the Identity and Access Management umbrella. It specifically provides the functions of managing digital identities and their access rights for applications, files and folders, databases, and IT resources. SailPoint is focused on enterprise-based customers and provides an open platform. SailPoint helps organizations apply the principle of least privilege by being the management platform that ensures people only have access to the things they need to do in order to perform their job duties.
The Core Components of SailPoint
- Identity and Life Cycle: The purpose of the Identity and Life Cycle function is to maintain (i.e. do maintenance) identities during their existence at the enterprise. This solves to challenge of manual based processes for change management as it relates to the identity. This function helps to automate creation, role change, archival, and eventual deletion of an identity. This is managed by SailPoint’s Identity Warehouse which is the identity store, virtual directory, and central warehouse that connects all identities. Each unique identity can be reviewed, which shows us a page detailing the entitlements they have within specific applications.
- Access Management: The purpose of the Access Management function is to provide the right level of access to the right people at the right time (meaning during their tenure in their specific role). This function is the repository of entitlements granted to permissions being held on end applications. SailPoint can assign codes (called “TCodes”) to specific rights within applications.
- Access Requests: The purpose of this function is to enable self-help; giving the end user the opportunity to request access through a user friendly interface. SailPoint provides a shopping cart-like experience for managing access requests. An administrator, or manager has the ability to log into the system, search for users for whom they would like to grant access, and then search for the entitlements they wish to apply within specific applications for that specific user or user group. Once selected, the administrator or manager needs to submit for review. The submit and review process page shows any policy violations that might have occurred based on conflicting entitlements across applications.
- Workflow: The purpose of this function is to provide automation and streamlined workflow such as on-boarding/off-boarding and role changes. An example of a workflow would be when a person receives a promotion and a notification and request is automatically generated for the new Manager, the old Manager, and HR to grant new access rights and revoke old access rights. SailPoint provides a user-friendly interface for HR and Managers who review access levels of employees. HR personnel and Managers are given a review page where they review reports of important alerts and open tasks they need to take action upon. In this page, they have the ability to review submissions from the Access Request function and revoke or approve access.
- Policy Management: The purpose of this function is to create policies around separation of duties and detect policy violations. For example, an employee in HR should not have the ability to record, approve, and review salary and payroll and the access to the applications that perform these functions should be restricted to the respective, specific people.
- Access Review: SailPoint’s IdentityCube gives a 360-degree view of access and compliance information for the review of management and leadership personnel to ensure that company policies are being enforced.
- Policy Administration & Provisioning: SailPoint has the ability to automatically create the necessaries accounts and access to applications based on user role and fill in needed information based on a users identity details. An example of this can be found within the scenario of on-boarding a new help desk person. Upon creating the identity in SailPoint, the administrator can define the user’s username, password, and role. Based on the user’s role and pre-defined rules for that role, SailPoint can automatically provision that user with the access to applications they need in order to do their job (i.e. Active Directory, ServiceNOW, etc.). When that user changes roles, their access will also automatically be provisioned according to their new role.
Conclusion
One of the main benefits of SailPoint is its native integration with other enterprise third party applications, like Workday, SAP, Oracle, Salesforce, Microsoft, Box, Dropbox, ServiceNOW, and many others. This is important because rules within those applications are pre-populated making searching for entitlements within those applications easy. This is a powerful component for access requests, because it streamlines the ability for non-technical decision makers to make changes based on making changes in layman’s terms (example: searching for the ability within an application such as “create sales order”).