Knowledge Article

Lifecycle Management Milestone

Author

  • ryan_cutter

    SailPoint

Implementing lifecycle management with SailPoint's identity security solutions requires a strategic approach to ensure alignment with business needs, stakeholder engagement, and operational efficiency. This page outlines SailPoint's guidelines for achieving the Lifecycle Management Milestone, offering practical advice, identifying common pitfalls, and providing valuable resources. Whether you're defining lifecycle events, configuring account and access management, or establishing certification processes, these guidelines will help you achieve a secure and efficient identity lifecycle management system.

 

1

Establish phased scope, objectives, and measures

Resources:

Identity Security Cloud

IdentityIQ

Advice:

Collaborate with business stakeholders to define and prioritize initial lifecycle states and events based on key drivers.

  • Prioritze joiners to boost operational efficiency and productivity.
  • Prioritize movers to maintain continuous compliance by adjusting access during role changes.
  • Prioritize leavers to prevent post-departure access and meet data retention obligations.

Break requirements into phased increments by business impact, measure the current state against each phase’s requirements, and set clear post-implementation objectives for the future state.

Pitfalls:

  • Broad implementation scoping increases complexity and delivery time, delaying value realization.
  • Defining requirements without stakeholder input may lead to incomplete or inaccurate solutions, and potential security or governance issues.
  • Lack of clear requirements may result in missed expectations or increased timelines due to rework.
  • Not understanding improvement objectives may miss opportunities for optimal solution design.
  • Failing to measure the current state may prevent effective comparison to the future state, reducing the ability to quantify and validate value realization.

 

2

Develop a solution design, test plan, and run book

Resources:

Note: This guideline should be applied to most (if not all) other implementation milestones.

Advice:

Work with architects and team resources to develop a solution design tied to requirements and a test plan for solution components. Ensure traceability from requirements to the solution and the tests confirming its efficacy. Obtain approval for both the solution design and test plan. Consider creating a traceability matrix to track and socialize the connection between requirements, solution designs, and test plans.

Establish a run book that will be updated throughout the implementation and deployment lifecycle, containing operational knowledge formatted into executable steps. Test the run book to confirm its accuracy and efficacy.

Pitfalls:

  • Lack of a solution design that traces back to requirements may lead to incomplete implementation and unmet stakeholder expectations.
  • Failing to secure stakeholder approval of a solution design may result in unmet requirements and increased likelihood of rework.
  • Not developing a test plan may result in a subpar or non-functional solution.
  • Failing to secure stakeholder approval of a test plan may result in inadequate test coverage.
  • Test plans developed solely by implementors may be biased and ineffective.
  • Not establishing and maintaining a run book may lead to lost valuable knowledge and inefficient or error-prone operations.

 

3

Configure Account Management Logic

Resources:

Identity Security Cloud

IdentityIQ

Advice:

Configure account states (e.g., enabled, disabled) according to identified identity lifecycle states for each in-scope identity population.

Pitfalls:

  • Improper account state management throughout an identity's lifecycle may result in usage issues and/or security risks.

 

4

Configure Identity States

Resources:

Identity Security Cloud

Note: Identity States is a must for Identity Security Cloud customers (that own the “Provisioning” module) and should be applied to all Lifecycle States in each Identity Profile. For customers, that do not own the “Provisioning” module in Identity Security Cloud, please refer to the Identity Security Cloud License Administration link above.

Advice:

Assigning specific identity states to lifecycle states (e.g., Active, Inactive short-term, Inactive long-term) streamlines identity management by improving processing efficiency, enabling cleaner UI filtering, ensuring the right lifecycle actions occur, and providing clearer license visibility.

Pitfalls:

  • If the identity state is left unconfigured (null), SailPoint defaults it to “Active,” which can cause unnecessary identity processing, weaker enforcement of lifecycle actions, misleading UI selections (e.g., terminated identities still appearing), and potential licensing compliance issues.

 

5

Configure Access Management Logic

Resources:

Identity Security Cloud

IdentityIQ

Advice:

Leverage roles and their assignment criteria to provide proper access at each stage of the identity lifecycle for in-scope populations.

Pitfalls:

  • Using disparate product features for access management may increase administrative and operational burden and reduce access triaging efficiency.

 

6

Consider Configuring Attribute Synchronization

Resources:

Identity Security Cloud

IdentityIQ

Advice:

Configure synchronization of relevant identity attributes to key sources, especially where they impact access or identification in downstream systems.

Pitfalls:

  • Synchronizing too many attributes, especially those unrelated to access or identification, may be inefficient or unnecessary.

 

7

Consider Configuring Certification Events

Resources:

Identity Security Cloud

IdentityIQ

  • Rapid Setup Mover Overview
  • Rapid Setup Mover Configuration
  • Certification Event
  • Lifecycle Events
  • Triggering Workflows

Advice:

Configure certifications triggered by identity lifecycle events necessitating significant access changes (e.g., mover). If a manager change is part of the lifecycle event, assign the certification to the new manager to ensure proper access decisions. Retain previously appropriate access under time-bound conditions during major access change events and request access separately with an expiration date.

Pitfalls:

  • Failing to certify major access changes may result in over-provisioned access, posing security risks.
  • Relying on self-certification during major access changes may lead to inappropriate access decisions.
  • Relying on the previous manager for certifications during major access changes may result in uninformed access decisions.

 

8

Execute Test Plan and Resolve Issues

Resources:

Advice:

Establish proper environments and conditions necessary to effectively execute the approved test plan. Resolve issues following implementation best practices and perform regression tests before retesting the issue resolution and proceeding.

Pitfalls:

  • Inadequate testing may result in production issues and/or security risks.
  • Failing to regression test issue resolutions may result in unnoticed and unaddressed repercussive issues.

 

9

Deploy and Monitor Solution

Resources:

Identity Security Cloud

IdentityIQ

Note: This guideline should be applied to most (if not all) other implementation milestones.

Advice:

Follow deployment best practices to migrate the solution to production and execute relevant run book steps. Perform final sanity tests and monitor the platform and target systems for potential issues.

Pitfalls:

  • Failing to follow deployment best practices may lead to unintended consequences in a live production environment.