Skip to content

Configuring Sources

Identity Security Cloud collects information about your users' system accounts and their associated access so they can be governed.

You will use sources to load user data from applications, databases, or directory management systems into Identity Security Cloud. SailPoint provides connectors to collect user accounts and access rights from those systems and associate them with the source definition.

A source can be added through a direct connection using a connector or a flat file feed using a .csv file:

  • A direct connection is a method of communicating directly between a source server and Identity Security Cloud. You'll use connectors to provide connection information specific to the source.
  • A flat file feed is a .csv file that contains the relevant information about the accounts you want to add.

Note

By default, new sources are read-only. Deep governance capabilities like provisioning must be manually enabled in the source's Base Configuration. This cannot be undone.

When you have completed your connection, you can aggregate, or load data, from your connected systems.

Configuring a Source

You must provide basic details and authentication information to connect to your source systems. You can do this through the Standard Setup, or depending on the source type, you might be able to configure the source by providing minimal configurations through Express Setup or Using the Connectivity Agent.

Note

Sources with the Quick Compliance badge use read-only connections and support account and entitlement aggregation only. They can be set up using Express Setup or Standard Setup but cannot be used for provisioning.

Configuring a Source Using Standard Setup

  1. Go to Admin > Connections > Sources.

  2. Select Create New.

    Tip

    The top navigation bar includes a shortcut to this page. Select the Add icon, then Source.

  3. Search for a source type and select Configure or Actions > Standard Setup.

  4. Enter a unique name and description for the source to help admins differentiate it from others.

  5. Select a source owner who will be responsible for the system.
  6. Choose whether you will be connecting directly to the source system or using a file-based representation of its data.
  7. For direct connect, select a virtual appliance cluster with connectivity to the source.
  8. (Optional) Select a governance group to grant its members source or role sub-admin level oversight of the source and its access.
  9. If this source represents a primary system containing your organization's personnel records, select the Authoritative Source checkbox.

    • You must create identity profiles for the authoritative source to create identities from the source data. Ensure the correlation logic for this source will match the source accounts to the correct identities.
  10. Select Continue to go to the source configuration page.

  11. For sources that support deep governance, select Enable Provisioning in the Base Configuration page to enable provisioning actions. This cannot be undone.

The remaining source configuration details depend on the source type and connection type.

If you choose a flat file connection type for a source type, you will import a .csv file with your source data. If there is not a predefined connector for the source, you can use the Delimited File and Generic source types.

After you complete and save your source configuration, you can manually aggregate account information as needed or schedule account aggregations from direct connect sources on a regular basis.

Configuring a Source Using Express Setup

If a source type supports Express Setup, you can quickly create a read-only connection to your target system by providing minimal configurations and authentication.

Note

Express setup supports Credential Providers. If a Credential Provider is already enabled in your org, use it to ensure consistency and security.

  1. Go to Admin > Connections > Sources.

  2. Select Create New.

    Tip

    The top navigation bar includes a shortcut to this page. Select the Add icon , then Source.

  3. Search for a source type and select Actions > Express Setup.

  4. Review the directions and select Start Express Setup.

  5. Review the pre-populated source name, source owner, and description. You can opt to use credential providers if one is already enabled in your org.
  6. Provide the required authentication like the Base URL and API Token.
  7. Select Finish.
  8. You will be prompted to start an aggregation to load data from the source system or exit the setup.

Tip

If you want to provide additional configurations after using Express Setup, you can edit the source after creation.

Configuring a Source Using a Connectivity Agent

Note

The connectivity agent is currently available for the following connectors:

  • Web Services SaaS (supports connections to REST API-based applications)

The connectivity agent can recommend contextual configurations to simplify complex setup processes. At any point during the connectivity agent-assisted setup, you can switch to the standard setup method. Once you switch to the standard setup method, you can't return to the agent-assisted setup.

Important

The connectivity agent assistant relies on generative AI technology to assist with the source setup process. AI can make mistakes, and as a result, its recommended configurations may not be entirely accurate or complete. Be sure to verify the recommendations it generates to ensure accuracy.

To configure a source with the help of a connectivity agent:

  1. Go to Admin > Connections > Sources.

  2. Select Create New.

    Tip

    The top navigation bar includes a shortcut to this page. Select the Add icon , then Source.

  3. Search for source type and select Configure.

  4. Enter a unique name and description for the source to help admins differentiate it from others.

  5. Select a source owner who will be responsible for the system.

  6. (Optional) Select a governance group to grant its members source or role sub-admin level oversight of the source and its access.

  7. If this source represents a primary system containing your organization's personnel records, select the Authoritative Source checkbox.

    • You must create identity profiles for the authoritative source to create identities from the source data. Ensure the correlation logic for this source will match the source accounts to the correct identities.
  8. Select Continue to go to the Choose Your Path page.

  9. Select Get Started in the Connectivity Agent tile.

  10. Select Enable and Continue to verify that you agree to SailPoint's AI Terms and to begin.

    The connectivity agent-assisted setup begins and guides you through a number of tabs, including Source Setup, Connection, Provisioning (Optional), and Review. Additional tabs may appear depending on the connector type, such as HTTP Operations for REST API-based connectors. The Connectivity Agent chat window on the right of the screen provides instructions and recommendations for each tab.

  11. On the Source Setup tab, enter the target system name - the official name of the system you're connecting to (for example, Box Enterprise, Google Workspace, or LastPass). This determines the API endpoints and authentication methods used during setup.

  12. Select the target system the connectivity agent recommends, then select Save and Continue.

    Tip

    Select Learn More to view why the connectivity agent recommended a target system. To generate new recommendations, edit the target system name and select Refresh. If the agent is unable to find the details about the named system, you can switch to the standard setup method.

  13. Select an Account Object the connectivity agent presented to represent the user accounts in Identity Security Cloud, then select Save and Continue.

    Tip

    Select Learn More next to a recommended account object to view a description of the object, its confidence level, and links to the supporting API documentation the connectivity agent used to generate the recommendation.

  14. On the Connection tab, select your authentication type and provide the required authentication information for that authentication type, such as Base URL, Client ID, and Client Secret. The connectivity agent does not have access to this information and cannot provide it for you.

  15. Select Test Connection to verify your connection information. Once the test connection is successful, select Save and Continue.

    Note

    Some connectors, such as the Web Services SaaS connector, include an HTTP Operations tab where you can review the operations the connectivity agent configured for your source. You can preview the account schema and sample accounts, and repeat this for roles or other endpoints you selected during setup.

  16. (Optional) On the Provisioning tab, configure provisioning for the source. If you enable provisioning, the connectivity agent presents recommendations to help you configure it.

  17. On the Review tab, review your source, connection, and HTTP operation settings, then select Finish.

  18. In the Load Data from Source window, select Aggregate to load account and entitlement data for your connected source now, or select Cancel to aggregate it later.

The remaining source configuration details depend on the source type.

Switching to the Standard Setup Method

While configuring a new source with a connectivity agent's assistance, you can switch to the standard setup process to configure the source manually. After you have completed the test connection, any configurations you entered are retained when you switch during the agent-assisted process. If you go back a page on your browser or move to the standard setup prior to testing the connection, the changes are not retained.

Important

Once you switch to the standard setup method, you can't return to the agent-assisted setup.

  1. During any step of the agent-assisted setup process, in the top-right corner, select the settings cog icon icon.

  2. Select Switch to Standard Setup.

  3. Select Continue.

Enabling Provisioning on a Read-Only Source

Some sources can support both read-only and deep governance configurations. If you've configured a supported source to perform read-only actions, you can convert it into a deep governance source capable of changing users' access to systems and data in your enterprise.

  1. Go to Admin > Connections > Sources.
  2. Select the source you configured as read only.
  3. In Base Configuration, select Enable Provisioning.

    Caution

    Converting a read-only source to deep governance cannot be undone.

You can now configure the source to perform provisioning actions.

Note

Sources with the Quick Compliance badge support read-only operations and cannot be used for provisioning.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.