Knowledge Article
The importance of a steering committee in an identity security program
Author
ryan_cutter
SailPoint
An identity security program can involve complex processes, diverse teams, and evolving requirements. One of the most effective ways to keep these efforts aligned and on track is to establish a steering committee. By bringing together key stakeholders on a regular basis, the committee ensures that projects stay focused on broader business objectives, fosters continuous improvement, and drives strategic decision-making. This article explores why steering committees matter and provides recommendations for creating, managing, and maximizing their impact.
Key objectives / takeaways
- Understand how a steering committee supports alignment between identity security initiatives and overall business goals.
- Learn best practices for creating, managing, and engaging steering committee members.
- Discover how regular committee involvement drives continuous improvement and accountability.

Why a steering committee matters
Ensuring alignment with business objectives
An identity security program typically spans multiple functions—IT, HR, Legal, Compliance, and more. Without a central body to review progress and prioritize initiatives, efforts can become fragmented. A steering committee:
- Sets clear direction: Guides the program’s goals in alignment with the program's roadmap, ensuring they support broader strategic objectives (e.g., compliance mandates, expansion plans, mergers and acquisitions).
- Brings cross-functional insight: Aggregates perspectives from various departments to evaluate the impact of decisions on different parts of the organization.
- Facilitates timely adjustments: Allows leaders to quickly pivot or reallocate resources if business priorities shift.
Driving accountability and transparency
A well-structured steering committee clarifies roles, responsibilities, and timelines, creating a culture of accountability:
- Regular reporting: The program manager and functional leads present status updates, risks, and key metrics, ensuring stakeholders remain informed.
- Escalation path: Issues that surpass the authority of individual teams can be quickly escalated for committee review and resolution.
- Documentation and follow-through: Action items identified during meetings are tracked via program records, with progress reviewed at subsequent sessions.
Fostering continuous improvement
Because identity security programs evolve in response to regulatory changes, new technologies, and shifting business landscapes, the committee ensures that teams stay proactive:
- Periodic performance reviews: Evaluate successes and challenges to refine processes, governance structures, and technology usage.
- Sharing best practices: Committee members bring diverse experiences, enabling them to exchange insights and solutions that benefit the entire organization.
- Long-term sustainability: Ongoing engagement and strategic planning lay the groundwork for future improvements and expansions (e.g., integrating new applications, automating additional tasks).
Best practices for creating and managing a steering committee
Define the committee’s purpose and scope
Before assembling a steering committee, outline its primary objectives and expected outcomes. Clarify whether the committee will oversee the entire identity program or focus on specific projects. This helps attract the right mix of participants and sets the stage for meaningful engagement:
- Charter development: Draft a concise program charter detailing objectives, roles, and decision-making authority.
- Goal alignment: Ensure the committee’s scope is clearly linked to organizational strategies and business priorities.
Select diverse, influential members
Your steering committee should include representatives from across the organization who have both the expertise and authority to make meaningful contributions:
- Executive sponsor: A senior leader who champions the identity program at the executive level and secures necessary resources.
- Cross-functional leads: Individuals from IT, HR, Finance, Security, Legal, and other impacted departments or business units.
- Program manager: The operational lead who provides regular updates, tracks action items, and prepares meeting agendas.
Establish a structured meeting cadence
Consistent engagement keeps the committee aligned and responsive to changes. Determine a schedule that suits the pace and complexity of your identity program:
- Frequency: Monthly or quarterly meetings often strike a balance between keeping stakeholders informed and respecting busy executive calendars.
- Agenda setting: Distribute agendas in advance, highlighting key topics such as program milestones, risk management, budget considerations, and upcoming regulatory changes.
- Action item follow-up: Dedicate a portion of each meeting to review previous action items, ensuring accountability and visibility.
Track relevant metrics and milestones
Steering committee discussions should be grounded in data. By monitoring clear metrics, members can make informed decisions about resource allocation and strategic direction:
- Key performance indicators (KPIs): Examples include time-to-provision, certification completion rates, audit findings, and policy violations.
- Technology adoption: Measure how effectively SailPoint solutions are being utilized or where manual processes still exist.
- Risk indicators: Track potential compliance gaps, open incidents, or other areas where swift intervention may be needed.
Foster continuous improvement and collaboration
A steering committee is most valuable when it drives ongoing optimization and alignment:
- Encourage open dialogue: Create a culture where members feel comfortable sharing challenges, raising concerns, and debating ideas.
- Review and refine: Periodically revisit the program charter, membership, and meeting structure to ensure continued relevance.
- Engage with SailPoint Customer Success: Leverage resources such as roadmap webinars and program strategy guides to inform committee discussions and keep your program on the cutting edge.
Example scenario: steering committee in action
A global healthcare organization implementing SailPoint Identity Security Cloud formed a steering committee composed of executives from IT, HR, and Compliance, along with business unit leaders. Meeting monthly, the committee reviews KPIs like time-to-provision, policy violations, and upcoming regulatory changes (e.g., regional data protection laws). This regular engagement enables them to:
- Streamline processes: Quickly address role-management bottlenecks before they impact hiring timelines.
- Adjust budgets: Allocate additional funds for training when the committee identifies skill gaps in certain regions.
- Improve collaboration: Encourage ongoing dialogue between HR and IT, leading to faster resolution of access-related issues.
Thanks to the steering committee’s cross-functional oversight, the organization saw a 30% reduction in audit findings and a noticeable improvement in user satisfaction with account provisioning.
In a nutshell
A steering committee is vital for guiding identity security initiatives toward strategic success. By bringing the right people to the table and maintaining consistent engagement, your program benefits from cross-functional alignment, informed decision-making, and a strong foundation for ongoing improvements.
If you’re ready to strengthen or establish your steering committee:
- Define the committee’s purpose and select cross-functional stakeholders who can drive progress.
- Set a regular meeting cadence, track meaningful metrics, and foster open dialogue.
- Attend SailPoint's annual Navigate Conference, other events and webinars, and join SailPoint user groups to stay informed on best practices and new features that can enhance your program.