Skip to content

SailPoint SecOps Identity Intelligence

SailPoint SecOps Identity Intelligence provides security teams with the identity context that is often missing during triage. Instead of reviewing a single directory account, analysts can see the identity behind an alert, the accounts correlated to that identity, and the access that determines operational impact.

Security platforms request identity intelligence through the Intelligence API. The API resolves one identity from a filter such as email, identity ID, or a non-human native identifier, then returns an identity envelope for enrichment.

Refer to Get identity by filter in the Developer Community for more information.

SecOps Identity Intelligence organizes context around the following themes:

  • Privilege impact - What power the identity has now, including entitlements classified as high, medium, or low privilege.

  • Access impact - Which accounts, sources, and sensitive access the identity can reach.

  • Lateral movement potential - Whether unusual or rare access could help an attacker move beyond the original alert.

  • Operational blast radius - What else is affected if the identity or a related account is contained.

Human Identities

For a human identity, SecOps Identity Intelligence can include:

  • Core identity details such as display name, email, login alias, and identity status.

  • Correlated accounts, including disabled and locked state.

  • Privileged access items and privilege level.

  • Rare access outliers, when the tenant has Access Insights.

  • Access history, including grants, removals, account status changes, and certification events.

  • Non-human identities the person owns when the tenant has SailPoint Agentic Fabric.

  • A link to Identity Graph when the tenant has Identity Graph.

Non-Human Identities

For a non-human identity, such as an AI agent or application, SecOps Identity Intelligence can include:

  • Core identity details such as display name, subtype, native identity, and source.

  • Primary and secondary owners.

  • Correlated machine accounts.

  • Derived signals such as orphaned ownership, authorized human identities, and a blast radius summary.

  • A link to Identity Graph when the tenant has Identity Graph.

Tip

Non-human identities can be looked up by identity ID or by an opaque identifier from the connected system, such as an ARN, distinguished name, or account name.

Understanding Response Actions

Response actions enable security teams to contain a human identity-related threat from their SIEM or SOAR platform without changing access directly in the native source. Actions are submitted to Identity Security Cloud and routed through workflow templates. This keeps containment inside identity governance, reduces native change detection from out-of-band source updates, and records audit events for identity and security teams.

Supported response actions for human identities are:

  • Disable Identity - Disables the identity in Identity Security Cloud, which prevents access across correlated accounts.

  • Disable Account - Disables a specific account correlated to the identity on the native source through Identity Security Cloud.

Response actions are submitted through the response actions API. Each request must include a source context, such as CrowdStrike, Microsoft Sentinel, Splunk, or a custom integration. After submission, the action moves through Submitted, In Progress, and Completed or Failed.

Workflow templates used by response actions can include approvals and notifications so identity teams retain control of containment.

Using Workflows

Build a workflow to define how events are handled.

SailPoint offers a pre-built workflow template to assist in getting started with Response and Remediation. This template serves as a starting point and must be configured to meet your needs.

Intel Response Actions Trigger

The Intel Response Actions trigger initiates when a response action, to disable an identity or to disable an account, is requested for a human identity from an XDR, SIEM, or SOAR solution.

SecOps Identity Intelligence Response Action Template

The SecOps Identity Intelligence Response Action template is triggered when a response action, to disable an identity or to disable an account, is requested for a human identity from an XDR, SIEM, or SOAR solution. Based on the request, the selected account or accounts, or all accounts for the selected identity, will be disabled by the workflow.

Integrating SIEM and SOAR Platforms

SecOps Identity Intelligence and response actions are designed to be consumed in the security tools analysts already use. Integrations call the Intelligence API to enrich an alert, then submit a response action when containment is required.

Integrating with CrowdStrike Foundry

The SailPoint Identity Security Intelligence CrowdStrike Foundry app enriches CrowdStrike detections with identity context from Identity Security Cloud.

After the app is installed and configured, analysts can:

  • View identity details in the Identity Security Intelligence panel on a CrowdStrike detection.

  • Search identities by email or identity ID.

  • Initiate Disable Identity and Disable Account response actions from the detection side panel.

  • Review workflow execution history for audit and tracking.

  • Troubleshoot function invocations from the Function Execution Logs page.

Refer to Integrating with CrowdStrike Foundry for SecOps Identity Intelligence for more information.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.