Documentation

SailPoint IdentityNow

Connect SailPoint IdentityNow (ISC) to Compass for governance analysis.

The SailPoint connector integrates with SailPoint Identity Security Cloud (formerly IdentityNow) to pull governance, certification, and access management metrics.

Prerequisites

  • A SailPoint ISC tenant
  • An API client with appropriate permissions

Setup

1. Create an API Client

  1. Sign in to your SailPoint Admin Console
  2. Go to Global Settings > API Management
  3. Click Create New
  4. Name it "Compass IAM Discovery"
  5. Grant the following scopes:
    • idn:accounts:read
    • idn:certifications:read
    • idn:roles:read
    • idn:entitlements:read
    • idn:access-profiles:read
    • idn:identity-profiles:read
  6. Copy the Client ID and Client Secret

2. Add to Compass

  1. Go to Settings > Connectors in Compass
  2. Click Add Connector > SailPoint IdentityNow
  3. Enter:
    • Tenant URL — Your SailPoint tenant URL (e.g., yourcompany.api.identitynow.com)
    • Client ID — The API client ID
    • Client Secret — The API client secret
  4. Click Test Connection
  5. Save

Metrics Collected

CategoryMetrics
IdentitiesTotal count, correlated vs uncorrelated, identity profiles
Access CertificationsCompletion rates, overdue certifications, revocation rates
RolesRole count, role composition, role membership distribution
EntitlementsTotal entitlements, orphaned entitlements, high-risk entitlements
Access RequestsRequest volume, approval times, auto-approval rates
Segregation of DutiesSoD policy violations, conflicting access, risk scores

Troubleshooting

Authentication failures

SailPoint API tokens expire after a configurable period. If authentication fails, verify your Client ID and Secret are still valid in the SailPoint Admin Console.

Missing certification data

Certification metrics require active certification campaigns. If no campaigns are running or recently completed, these metrics will show as unavailable.