
Project Planning: This initial phase involves defining the project scope, gathering detailed requirements, and establishing timelines. Stakeholders from various departments, including IT, HR, and compliance, are often involved to ensure all needs are addressed.
Infrastructure Setup: During this phase, the necessary systems and environments are provisioned. This may include setting up servers, configuring databases, and establishing network connections. For cloud-based deployments, this might involve setting up the appropriate cloud resources.
Core Configuration: This phase focuses on setting up the foundational components of the SailPoint platform. It includes configuring basic settings, establishing identity vaults, and setting up initial governance models.
Application Onboarding: This critical phase involves integrating target applications and data sources with SailPoint. It includes configuring connectors, mapping attributes, and establishing synchronization processes for each application.
Customization: In this phase, business-specific rules, workflows, and processes are implemented. This might include creating custom approval workflows, setting up specific access policies, or developing custom reports.
Testing: Comprehensive testing is conducted, including system testing to ensure all components work correctly, and user acceptance testing to verify that the solution meets business requirements.
Training: This phase involves educating administrators on how to manage and maintain the system, as well as training end-users on how to use SailPoint for access requests, certifications, and other self-service functions.
Workflow Customization: SailPoint provides no-code workflow automation tools, enabling businesses to create custom processes without extensive coding. This allows for the creation of complex approval chains, automated provisioning processes, and custom lifecycle management workflows.
Rule Configuration: Custom rules can be implemented for access controls, provisioning, and compliance checks. These rules can be based on various attributes such as job role, department, location, or any custom attribute defined in the system.
Connector Development: While SailPoint offers a wide range of pre-built connectors for common applications, custom connectors can be developed for unique or proprietary applications. This ensures that SailPoint can integrate with virtually any system in an organization's IT ecosystem.
Reporting and Analytics: Custom reports and dashboards can be created to meet specific business intelligence needs. This allows organizations to track key metrics, monitor compliance, and generate audit reports tailored to their requirements.
User Interface: The interface can be tailored to match organizational branding and user experience requirements. This includes customizing the look and feel of the user portal, modifying navigation structures, and creating custom forms for access requests or certifications.
Role-Based Access Control (RBAC): Custom roles and access policies can be defined to align with organizational structures. This allows for granular control over who can perform specific actions within the SailPoint system.
Integration Capabilities: SailPoint can be integrated with various third-party tools and systems to extend functionality. This might include integrating with SIEM tools for enhanced security monitoring, or with HR systems for improved lifecycle management.
Implementation Services: Professional services for deployment and customization can be a significant cost. These services are often provided by SailPoint's professional services team or certified partners. The cost is typically based on project scope and complexity and can range from tens of thousands to millions of dollars for large, complex implementations.
Training: Costs for administrator and end-user training programs are an important consideration. SailPoint offers various training options, including online courses, classroom training, and custom on-site training. Prices can vary widely based on the type and extent of training required.
Infrastructure: Expenses related to hosting, whether on-premises or cloud-based, need to be factored in. For on-premises deployments, this might include server hardware, storage, and networking equipment. For cloud deployments, ongoing cloud infrastructure costs should be considered.
Maintenance and Support: Annual fees for software updates, patches, and technical support are typically a percentage of the initial license cost, often ranging from 15% to 25% annually.
Additional Modules: Costs for optional features or modules beyond the core platform, such as advanced AI capabilities or specific compliance modules, can add to the overall expense.
Scaling Costs: As organizations grow, there may be fees associated with adding users, integrating additional applications, or expanding usage of the platform.
Consulting Services: Some organizations may require ongoing strategic guidance and optimization services, which can be provided by SailPoint or its partners for an additional fee.
Identity University: SailPoint provides a full day of free, in-person technical training called "Identity University: Skilled Sessions" at their Navigate conference. This includes hands-on labs, tenant access, and Q&A sessions with SailPoint Certified Engineers.
Online Training Courses: SailPoint offers various online courses with in-depth knowledge and hands-on exercises designed to promote effective learning. These courses cover different aspects of SailPoint's products and are suitable for users with varying levels of expertise.
Certification Programs: SailPoint provides certification programs to validate users' expertise in their products. These certifications are recognized in the industry and can be valuable for career advancement.
Documentation and Resources: SailPoint offers extensive online documentation, including user guides and API documentation. These resources are regularly updated and provide detailed information on product features and best practices.
Customer Support: SailPoint provides dedicated customer support, professional services, and online documentation to assist with implementing IdentityIQ. This ensures that customers have access to expert help when needed.
Encryption: Data is encrypted both in transit and at rest. SailPoint uses "Zero Knowledge Encryption" for credentials, encrypting them at the user's device before transmission. This ensures that sensitive information remains secure throughout its lifecycle.
Strong Authentication: IdentityNow supports strong authentication options, including two-factor authentication and integration with third-party authentication solutions. This adds an extra layer of security to prevent unauthorized access.
Network Security: SailPoint implements industry-leading technologies including firewalls, intrusion prevention systems, monitoring, network segmentation, VPN, and wireless security. These measures help protect against various network-based threats.
Cloud Security: SailPoint's cloud approach supports secure design, build, and evolution of enterprise cloud architectures, aligned with industry benchmarks and best practices. This ensures that cloud-based deployments meet stringent security standards.
Threat Detection and Response: SailPoint uses industry-standard measures to detect and remediate malware, viruses, ransomware, and other malicious programs. This proactive approach helps mitigate potential security risks.
Continuous Development: SailPoint is constantly developing, with each release bringing new features and functionalities. This ensures that the product remains up-to-date with evolving industry needs.
Sandbox Testing: SailPoint releases updates to a sandbox environment before rolling them out to production. For example, the MySailPoint feature was released to sandbox on October 24 before being rolled out to production in batches from October 30 to November. This approach allows customers to test new features in a safe environment.
Customer Data Control: Customers can download their data from the SaaS Services at any time during the subscription term. This ensures that customers always have access to their own data.
Data Retention: SailPoint retains customer data in the SaaS Services only for the duration of the subscription term. This policy respects customer privacy and data ownership rights.
Data Deletion: Within 30 days of termination or expiration of the SaaS Services, SailPoint will delete all customer data unless prohibited by law. This ensures that customer data is not retained unnecessarily after the service period.
Limited Data Collection: SailPoint discourages customers from loading sensitive personal data into their products, including special categories of personal data as referenced in Art. 9 GDPR. This policy helps minimize potential privacy risks.