Knowledge Article

The Identity Workstream

Author

  • ryan_cutter

    SailPoint

Establishing a robust identity workstream is key to ensuring that all individuals and entities within an organization have appropriate access while mitigating risks. A successful identity workstream begins with accurately modeling various types of identities and their associated attributes.

This article outlines a step-by-step approach for developing a comprehensive identity workstream, covering human, machine, and external identities using SailPoint’s Identity Security Cloud.

Personalized Insights and Reporting hero.png

Introduction to the Identity Workstream

The Identity Workstream is the foundation of SailPoint's identity governance framework. It involves:

  • Modeling diverse identities: Understanding and representing different identity types, including employees, contractors, machine identities, and business-to-business relationships.
  • Attribute management: Defining and managing attributes that describe identities, such as roles, permissions, and access levels.
  • Ensuring appropriate access: Aligning permissions with organizational policies to ensure individuals have the access they need—and nothing more.

By focusing on these elements, organizations can build a robust identity governance program that enhances security, compliance, and operational efficiency.

Step 1: Begin with employee onboarding

The starting point of the identity workstream is onboarding employees—the most critical and well-known identities within an organization. Employees are typically defined and sourced from one or more Human Resources (HR) systems.

Best practices:

  • Integrate HR systems: Connect SailPoint with your HR platforms to automate the creation, modification, and termination of employee identities.
  • Automate provisioning: Use SailPoint's capabilities to automatically assign appropriate access permissions based on roles and responsibilities.
  • Maintain data accuracy: Ensure that employee data is accurate and up-to-date to prevent access discrepancies.

Step 2: Incorporate contractor management

After establishing employee identity management, focus on incorporating contractors, who are typically high-value targets for identity governance. Contractors may enter the organization through the same HR sources as employees or via other systems like timekeeping platforms. SailPoint’s Non-Employee Lifecycle Management (NELM) solution provides tools to effectively define and manage contractor identities.

Best practices:

  • Centralize contractor identities: Use NELM to maintain a single source of truth for all contractor information.
  • Tailor access controls: Assign permissions that reflect the specific roles and durations of contractor engagements.
  • Implement delegated administration: Allow designated personnel to manage contractor identities within a controlled framework.

Step 3: Expand to machine identities

With human identities managed, it's time to focus on machine identities using SailPoint’s Machine Identity Management (MIM) solution. Machine identities include devices, bots, service accounts, workloads, and more.

Best practices:

  • Discover and classify machines: Utilize SailPoint to identify all machine identities within your environment.
  • Apply governance framework: Extend identity governance policies to machine identities to manage them securely.
  • Reduce risk exposure: Recognize that machine identities often have high privileges and ensure they are appropriately controlled.

Step 4: Integrate business-to-business relationships

To further mature your identity workstream, include identities associated with business-to-business (B2B) relationships. This encompasses third parties like vendors, suppliers, outsourcers, freelancers, and more.

Best practices:

  • Leverage NELM for third parties: Manage non-employee identities within a delegated administration framework using NELM.
  • Define access agreements: Establish clear terms outlining access levels and durations for third-party entities.
  • Continuous monitoring: Regularly review and audit third-party access to ensure compliance and security.

Step 5: Implement delegated administration

As your identity ecosystem grows, delegated administration becomes essential. This approach allows certain administrative responsibilities to be distributed to appropriate stakeholders while maintaining overall governance.

Best practices:

  • Define administrative roles: Clearly specify who has the authority to manage different identity types and access rights.
  • Use SailPoint tools: Utilize SailPoint's features to support secure and efficient delegated administration.
  • Maintain oversight: Ensure all delegated activities are tracked and auditable to prevent unauthorized changes.

In a nutshell

Optimizing the Identity Workstream involves a strategic approach to managing all types of identities within your organization:

  • Start with employees: Automate and secure employee onboarding and access provisioning.
  • Add contractors: Effectively manage contractor identities using specialized solutions.
  • Include machine identities: Govern machine and service accounts with the same rigor as human identities.
  • Incorporate B2B relationships: Extend governance to third-party identities to mitigate external risks.
  • Implement delegated administration: Distribute administrative tasks while maintaining control and oversight.

Final recommendations:

Regularly assess and update your identity workstream strategies to adapt to changing business environments and emerging security threats. Engage with SailPoint's support and professional services for expert assistance in optimizing your identity governance solutions.



Related Content