Product
Identity Gets Smart

Mark McClain, CEO & Founder opens up to InformationWeek about identity governance. Watch the video »
Identity Governance Buyer's Guide
Contains tools to help you identify your priorities, conduct side-by-side product analysis and find a solution that suits your needs. Download the Guide »
Stay Connected
Subscribe to our quarterly newsletter.
Subscribe »
Get the latest news and views with SailPoint's podcast series, "The Identity Intelligence Insider"
Listen » | Subscribe »
Subscribe
SailPoint's Identity Intelligence Insider is a monthly podcast series on hot topics in identity risk management.
Listen »
CONTACT US
Hours
8:00AM - 6:00PM CST
Monday through Friday excluding holidays
Email
support@sailpoint.com
Phone
(888) 4SAILPT
(888) 472-4578
"By using roles to request, approve and certify user access privileges, BNSF will be able to simplify its user administration and compliance processes. SailPoint IdentityIQ will allow us to enforce and verify role-based access across our critical enterprise applications using a streamlined, automated approach."
Bart Boudreaux, Director, Technology Services, BNSF Railway
"SailPoint helps us define the connection between user access, financial control and intellectual property protection. Their risk-aware approach focuses on the relative risks associated with user access within our business."
Russ Finney, Vice President of U.S. Information Systems operations for Tokyo Electron, U.S. Holdings
"Businesses that are concerned with compliance mandates and ensuring the security and integrity of their IT systems cannot afford 12 to 18 month deployments. With IdentityIQ, organizations can gain immediate payback from automating key governance processes to better address business risk."
Kevin Cunningham, Co-Founder and President, SailPoint
|
Role Assignment
Role assignments within IdentityIQ can be managed using configurable assignment rules, or by leveraging the Access Request Manager capability within IdentityIQ to directly assign users to roles as needed. To automate the assignment of business roles to users, IdentityIQ Role Manager provides seamless integration with provisioning systems. The solution maps business roles to the appropriate set of IT entitlements, and then issues the request for provisioning systems to assign the entitlements to users.
Overview
Assign Users to Roles in a Policy-Controlled Environment
By leveraging the integration between IdentityIQ and provisioning solutions, organizations benefit from improved consistency of granting user entitlements to critical IT resources and streamline their overall compliance and identity governance efforts. This approach enables organizations to build compliance into the provisioning process by applying centralized business policy to new user role assignments and changes.
Capabilities
- Flexible Role Assignment – IdentityIQ role assignments can be rule-based or they can be directly assigned to users with IdentityIQ's Access Request Manager.
- Provisioning Integration – Role Manager translates business roles into detailed entitlement level changes and communicates them to provisioning systems, help desk solutions, and other change management systems.
- SoD Policy Checking – Before assigning a new role, IdentityIQ performs separation-of-duty (SoD) policy checks to prevent the introduction of violations into the production environment. Policy checks for new user role assignments and changes build compliance directly into the provisioning process.
- Change Auditing – For closed-loop audit control, IdentityIQ verifies that any role or entitlement changes sent to provisioning are implemented within an appropriate time frame.
Features
- Flexible Role Assignment – Allows role assignments to be rule-based or directly assigned by the Access Request Manager
- Provisioning Integration – Integrates seamlessly with user provisioning systems for role assignment using open industry-standards
- SoD Policy Checking – Proactively checks SoD policies before making user role assignments to ensure compliant provisioning
- Closed-Loop Change Auditing – Verifies that any role or entitlement changes sent to provisioning are implemented in a timely manner
Resources
- SailPoint IdentityIQ Product Overview – A high-level introduction to SailPoint IdentityIQ, an innovative identity governance solution that delivers risk-aware compliance management, adaptive role management, access request management and identity intelligence.
- IdentityIQ Role Manager Data Sheet – Offers a complete view into the benefits, key capabilities and features supported by the role management component of SailPoint IdentityIQ including role creation, role lifecycle management and role assignment.
- Viewpoints: Role Management and Risk – This educational paper reviews how effective role management can provide the business context necessary for non-technical personnel to oversee and verify user access policy. It reviews three ways that role management helps organizations to manage information security risk and ultimately corporate risk.
- Best Practices: Practical Role Management – This paper identifies common pitfalls on the road to role management and which best practices can pave the way to solving real business problems.
- Role of Roles in Compliance Podcast – Jackie Gilbert, VP of Marketing and Founder, interviews Darran Rolls, CTO for SailPoint, on the subject of role-based access control (RBAC), and its relevance to identity management and compliance projects. Darran tackles the controversial topic concerning the difference in roles for provisioning and roles for compliance and where they can, ultimately, come together.
- Why Enterprises Need More Roles – SailPoint speaks with Forrester Research Senior Analyst, Andras Cser, to discuss the growing importance of enterprise role management. Cser, a leading expert on identity management, explains why role management is becoming increasingly strategic to organizations as business users become more involved in identity governance, particularly during the recent economic turmoil. He also provides recommendations for companies considering an enterprise role management project.
Demo
Register to See IdentityIQ in Action
Please complete the questions below and someone
will contact you soon to schedule an IdentityIQ demo.
*Please note, fields
marked with an asterisk (*)
are required.
* If your browser is
set to accept cookies, you will be recognized on
subsequent visits and immediately granted access
to the SailPoint Resource Center.
|
|