Integrating SailPoint and Amazon Web Services SaaS
Revised Date: 11 September 2026
The SailPoint Amazon Web Services (AWS) SaaS connector enables organizations to extend existing identity lifecycle and compliance management capabilities within SailPoint to mission-critical AWS IaaS environments to provide a central point of visibility, administration, and governance across the entire enterprise. This includes policy discovery and access history across all organization accounts, provisioning AWS entities and objects, access review and certification, and federated access support.
This guide is designed to give specific information about the requirements and field definitions needed to get a working instance of Amazon Web Services (AWS) SaaS.
Important
If you want to enable additional cloud governance features (for example,visualization of effective access) for your AWS Cloud Infrastructure, you must have a CIEM license. Contact your SailPoint Customer Success Manager to request access and for more information.
For more information on the additional features supported with cloud governance, refer to the table in the Supported Features section.
Onboard AWS with SailPoint Agentic Fabric (SAF)
SailPoint Agentic Fabric (SAF) provides an automated, guided onboarding experience to connect your AWS environment to Identity Security Cloud (ISC). SAF automatically creates, deploys, and configures the AWS SaaS source in ISC, reducing the manual setup steps. After onboarding, the source is ready for aggregation and governance.
For detailed onboarding instructions, prerequisites, and supported deployment models, refer to Configuring the AWS SaaS Connector.
Important
To enable advanced governance capabilities for AWS resources and AI agents, an active SailPoint Agentic Fabric Advanced Governance license is required. Contact your SailPoint Customer Success Manager to request access and for more information.
Note
To view the latest features, enhancements, and fixes for all SaaS connectors, refer to the SaaS Release Notes page.