Skip to content

Connectivity Browser Extension Overview

Many business applications lack the modern interfaces required to connect with central security systems. Without a direct connection, org admins must manage user accounts manually. The SailPoint Connectivity Browser Extension solves this integration challenge. By recording an admins manual setup steps, the extension allows Identity Security Cloud to automatically replicate those actions whenever an account needs to be created, updated, or removed.

Operations are recorded individually rather than as a single continuous script. Each lifecycle action functions as an independent, modular workflow.

  • Authentication (sign-in) - Captures session establishment, login credentials, and initial landing page navigation.
  • Account creation (provisioning) - Records the creation of a new user profile, required field inputs, and confirmation actions.
  • Account read (aggregation) - Records locating and reading user account details to verify status and entitlements.
  • Account updates and deprovisioning - Records modifying permissions, disabling accounts, or removing user access.

Prerequisites

To ensure a seamless installation process, verify that your system meets the following requirements:

  • Google Chrome is installed, version 130 or newer.
  • The Chrome browser extension is installed. Your IT team might push it to you automatically, or you may add it yourself.
  • You have access to the source you are configuring in Identity Security Cloud.
  • You have a service account on the managed system with permission to do the task. Use this rather than your own login, because SailPoint will sign in as this user later.
  • The managed system is reachable over HTTPS.
  • Sign-in must not require manual intervention. MFA, CAPTCHA, and SSO approval are not supported during replay.

Configuring the Extension

Register the extension to give it access to the site.

  1. Select the extension icon in the Chrome toolbar to open the window.

  2. In Managed Application URL, enter the system you are going to record in.

  3. If your tenant uses a custom address, enter the Vanity URL.

  4. Select Save.

  5. Select Yes to give the extension access to that site.

Each saved address shows a tag with its status:

  • Allowed - Ready to use.
  • Waiting for site access - Saved, but Chrome has not granted access yet. Select Save again and accept the prompt.
  • Set by policy - Your IT team added this. You cannot remove it.

Starting a Recording

Always start in Identity Security Cloud. Initiate every recording session directly from the source page in Identity Security Cloud. Identity Security Cloud must tell the extension which operation you are performing, such as Create Account or Aggregate Accounts. The extension cannot launch or guess this independently.

Identity Security Cloud automatically opens your managed system in a new tab and prepares the recorder. If the extension panel displays a "Waiting for ISC" message, return to your Identity Security Cloud tab and restart the recording process. Keep the originating Identity Security Cloud tab open until you have fully submitted your recording. Closing the tab will break the session link. Complete your recording in one continuous session. The active recording link expires after 15 minutes of inactivity.

Using the Recorder Panel

The floating recording panel overlays your managed system to provide real-time session tracking. At a glance, you can monitor the active operation, current recording status, elapsed duration, and the total count of captured actions. You can drag to reposition the panel, resize it, or collapse it.

Recording Sign-In

Record the sign-in process.

  1. Select Start Recording.

  2. Sign in as the service account.

  3. Select Stop and Finish.

  4. Select Submit.

  5. If the panel warns you afterwards that the page has an unusual layout, run Test Connection in Identity Security Cloud.

    If that fails, record the sign-in again.

Recording Account and Entitlement Changes

Record account create/update or add/remove entitlement.

  1. Select Start Recording and perform the task from start to finish.

  2. Use Pause and Resume as needed.

  3. Select Stop and Finish when the task is completed.

  4. If you're asked which field you searched in to find the account, choose the field from the list and select Confirm.

  5. Select Review Attributes to open the mapping screen.

  6. Select Submit to send the recording.

    You can also select Delete to start over.

Recording a Single Account Read

Record a Get Object operation for one account.

  1. Select Start Recording, search for a single account, and open it.

  2. With that account's details on screen, select Scan Account.

  3. Select Stop and Finish.

  4. Select Review Attributes.

Recording Aggregation

Record an account or group aggregation.

  1. Select Start Recording and go to the page that lists the accounts or groups.

  2. With the list on the screen, select Capture Data.

  3. Select Finish.

  4. Select Review Attributes.

Confirming Captured Attributes

The Confirm captured attributes window lists everything the extension read from the page, next to the matching Identity Security Cloud attribute. Most rows are matched for you and marked Auto-matched.

Check the listed attributes and set which captured field is the Account ID and which is the Account Name. For groups, set the entitlement ID and entitlement name.

Per row you can:

  • Choose a different Identity Security Cloud attribute to correlate with.
  • Select + Add as new to keep it as a new attribute.
  • Select Write only to send it during provisioning but not read it back.
  • Select Delete to drop it.

Caution

A deleted attribute is not available during replay. If a field you need is missing from the list, add it to the account schema in Identity Security Cloud first, then record again.

Submitting the Recording

Send the recording to Identity Security Cloud.

  1. Select Submit. The status changes to Submitting, and on success you see Sent to Identity Security Cloud. Finish setting up the source there.

    Note

    Submit once. A recording can only be delivered one time. To change it, record again.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.