Knowledge Article
Program staffing considerations
Author
ryan_cutter
SailPoint
Staffing the right mix of roles is critical for a successful identity security program. This goes beyond hiring a few IT specialists; it means assembling a cross-functional team that includes executive sponsor(s), program managers, technical experts, and stakeholder representatives from various departments (e.g., HR, Compliance, Finance).
In this article, we’ll look at common roles, their responsibilities, and typical time commitments. We’ll also examine why engaging a certified implementation partner or SailPoint professional services can help your program succeed more quickly and sustainably.
Key objectives / takeaways
- Identify the key roles typically required in an identity security program.
- Understand general role responsibilities and time commitments.
- Recognize the value of engaging certified implementation partners or SailPoint professional services.

Roles and responsibilities
Below is a breakdown of common roles, typical time commitments, and the core responsibilities each role plays in the success of your identity security program. These roles may come from various departments, such as IT, Security, HR, or GRC, and can include employees with titles ranging from analyst to senior manager.
Adjust staffing as needed to match the size, complexity, and specific business needs of your program, keeping in mind the value of expert assistance from a certified implementation partner or SailPoint professional services team.
Program Manager
Helps coordinate and run the program while managing the wider influence of the program.
- During Implementation: 10-20 hours per month
- Post Implementation: 1-2 hours per month
Project Manager
Ensures adherence to scheduled delivery. Should be tech savvy enough to understand program requirements.
- During Implementation: 10-20 hours per month
- Post Implementation: 1-2 hours per month
Technical/Security Architecture Lead
Collaborates on overall solution design and oversight on implementation deliverables.
- During Implementation: 10-14 hours per month
- Post Implementation: 0-1 hours per month
Identity Security Cloud Administrator
Owns day to day operations of the application, addresses any automated alerts sent from Identity Security Cloud. Main point of contact for SailPoint Support.
- During Implementation: 16-20 hours per month
- Post Implementation: 8-14 hours per month
Identity Security Cloud Engineer
Owns maintenance and ongoing development of cloud-based identity security solutions, including design, configuration, application onboarding, and the writing and implementation of transforms, workflows, and rules.
- During Implementation: 0-1 hours per month
- Post Implementation: 8-14 hours per month
Business/Systems Analyst
Communicates overall business processes needing to be factored into solution such as resource onboarding, role based access, out of band provisioning, and certification compliance.
- During Implementation: 8-12 hours per month
- Post Implementation: 0-1 hours per month
Source Owner(s)
Acts as a point of contact to provide or validate source specific details associated with connectivity, account and access management.
- During Implementation: 2-4 hours per month
- Post Implementation: 1-2 hours per month
Tester
Creates test cases based on requirements, stages data for test cases, and executes System Integration Testing and User Acceptance Testing.
- During Implementation: 20-30 hours per month
- Post Implementation: 0-1 hours per month
Risk/Compliance Officer
Works closely with the Identity Security Cloud Administrator during certification campaigns to kick off proper campaigns and review campaign reports to satisfy compliance needs
- During Implementation: 2-6 hours per month
- Post Implementation: 2-6 hours per month
Support Helpdesk
Administrates account-level issues associated with enabling, disabling, and unlocking. Views activity and interacts with identity data but they cannot make changes to sources, apps, and many other features within Identity Security Cloud.
- During Implementation: 6-10 hours per month
- Post Implementation: 8-10 hours per month
Virtual Appliance Engineer
Installs/Configures Virtual Appliance image, troubleshooting connectivity or other connector related issues. UNIX platform background is strongly recommended.
- During Implementation: 2-3 hours per month
- Post Implementation: 0-1 hours per month
Network Engineer
Provides guidance on internal network structure for components in scope, typically during implementation.
- During Implementation: 2-3 hours per month
- Post Implementation: 0-1 hours per month
Additional considerations
- Budgeting: Account for not only upfront costs (licensing, partner fees) but also ongoing operational expenses such as staff training and certifications when managing program budgets.
- Cross-functional alignment: Encourage collaboration between IT, Security, HR, and other departments, ideally through a steering committee, that manage user data or access requests. This fosters a more holistic identity program.
- Continuous training: SaaS identity security solutions evolve quickly. Regularly update staff on role-based training, product updates and release notes, security threats, and compliance changes through ongoing training and certifications.
- Resource flexibility: Some roles may be combined or scaled up/down depending on your program’s maturity and complexity. Ensure you periodically revisit staffing levels.
- Automation opportunities: Look to automate repetitive tasks (e.g., routine provisioning) so high-value staff can focus on architecture, strategy, and governance.
- Clear escalation paths: Define how issues or risks surface to the executive sponsor and steering committee. Prompt action often prevents larger setbacks.
- Leverage community and networking: Engaging with the SailPoint community, attending user groups, or participating in webinars can provide additional insights and best practices from peers.
Engaging a certified implementation partner or SailPoint professional services
When launching or scaling an identity security program, organizations often benefit from the expertise of certified partners or SailPoint professional services. These teams bring invaluable experience with:
- Accelerating deployment times through proven implementation methodologies.
- Providing specialized technical and strategic insights for complex identity governance challenges.
- Offering training and knowledge transfer to your internal staff, reducing long-term dependence on external resources.
In a nutshell
Building an effective identity security program requires the right people in the right roles, collaborating under a well-defined governance structure. By clarifying responsibilities, engaging cross-functional teams, and leveraging specialized expertise—either in-house or through certified partners—you’ll set the stage for smooth implementations and long-term program success.
Consider the following next steps:
- Evaluate your current team to identify role gaps. Recruit or train staff to cover those essential skill areas.
- Develop clear RACI matrices to ensure accountability and prevent duplicative efforts.
- Engage with a SailPoint-certified implementation partner or professional services to fast-track deployments or handle complex integrations.
- Attend SailPoint's annual Navigate Conference, other events and webinars, and join SailPoint user groups to exchange insights on staffing models, partner experiences, and ongoing identity security best practices.