Knowledge Article
Identity Security Program Milestones
Author
ryan_cutter
SailPoint
HORIZON 1
Fragmented identity experience across organization
Organizations in Horizon 1 are at the initial stage of their identity security journey. They typically have fragmented and siloed identity management processes, often with no centralized IAM function. Identity governance is rudimentary, and there is little to no automation. Compliance is achieved manually, and responses to security incidents are largely ad hoc and reactive.
To advance to Horizon 2:
- Establish a centralized IAM function.
- Begin consolidating identity management processes.
- Introduce basic automation and governance tools.

Executive sponsor
Obtain executive support and resources, and ensure alignment with organizational goals.

Program charter
Define the scope, objectives, stakeholders, and governance structure of your identity security program.

Steering committee
Guide the direction and prioritize efforts of the identity security program, involving key stakeholders.

Program roadmap
Outline your plan and milestones for your program.

Identity foundation
Onboard your authoritative sources and data.

Advanced analytics
Verify your data is correct, accurate, and expected.
HORIZON 2
Started on identity management but mostly manual
Organizations in Horizon 2 rely heavily on manual identity management processes, with low adoption of identity tools and reactive, tactical responses to external pressures such as compliance or security breaches. The centralized IAM function is basic, mainly focused on fulfilling service tickets, with limited organizational buy-in.
To advance to Horizon 3:
- Increase identity security tool adoption.
- Begin introducing more strategic automation of manual identity processes.

Access insights
Capture access history and identify risky outliers

Targeted certifications
Perform targeted access reviews of business-critical access.

Lifecycle management
Manage the lifecycle of identities, from onboarding to offboarding.

Access requests
Automate and streamline the process for users to request and gain access.

Policy modeling
Define and enforce policies that govern identity and access management.

Password management
Enable secure and efficient password handling, including resets and changes.
HORIZON 3
Digitalized at-scale identity management
Organizations in Horizon 3 have a more mature identity management approach, with moderate adoption of IAM tools and automated processes. The centralized IAM function is evolving, with a focus on improving efficiency and reducing risk. Compliance and security measures are more proactive, but there is still room for improvement in terms of organizational buy-in and strategic alignment.
To advance to Horizon 4+:
- Fully integrate IAM with broader business processes.
- Expand automation and governance capabilities to additional identity types and infrastructure.

Dedicated identity team
Establish a team solely focused on managing and securing digital identities within the organization.

Access modeling
Develop and manage access roles and policies to ensure appropriate access levels.

Cloud infrastructure entitlement management
Govern and manage access across multi-cloud infrastructures.

Access risk management
Streamline GRC controls across SAP.