Access Governance is a rapidly growing segment within IAM/IAG, centered on access request management, role management, access recertification, and segregation of duties (SoD) enforcement, increasingly enhanced by “Access Intelligence” for analytics-driven risk identification and entitlement analysis. Its purpose is to mitigate access-related risks such as information theft, fraudulent changes, and the subversion of IT systems to enable illegal activity. The broad range of recent incidents across industries underscores the business impact of access failures, including operational disruption, strategic loss (e.g., blueprints), financial fraud in ERP systems, reputational damage from privacy breaches, and exposure of confidential documents.
A complete approach must extend beyond standard users to privileged access (administrators, technical users, system-level accounts, and shared accounts). While privileged users can be governed similarly to standard users, true risk mitigation also requires privilege management capabilities like runtime elevation controls and shared password management—an integration most vendors still lack.
SailPoint, founded in 2005, is positioned as a pioneer with IdentityIQ 7.0, which unifies access governance and identity provisioning in one product. Since 2010, SailPoint strengthened provisioning through acquisition of the former BMC Control-SA team/assets and by expanding connector breadth and depth (including SAP). IdentityIQ supports standalone governance or deployment as a full IAM/IAG stack, and it can integrate with third-party provisioning systems, service request management tools, mobile device management tools, and cloud environments.
Architecturally, IdentityIQ is web-based (J2EE and database backend) with business-oriented, configurable interfaces. Its top layer includes Compliance Manager, Lifecycle Manager, and Identity Intelligence; the Governance Platform provides shared models and services; and the bottom layer delivers provisioning via SailPoint or external engines. Key capabilities include certification campaigns, policy enforcement with preventive checks and remediation, role mining/modeling, risk scoring, workflow automation, APIs (SCIM 2.0), expanded connectors, and integration with SecurityIQ, balanced by limited multi-tenancy.
See All Locations
See All Locations