Knowledge Article
SailPoint E-Fix Policy
Author
lyndsay_lantz
SailPoint
SailPoint provides frequent patch releases for IdentityIQ, and service pack releases for IdentityIQ File Access Manager to address issues that customers may experience in a timely manner. These patch releases primarily focus on fixes only, as opposed to new product features, to ensure transparent upgrades and ongoing system stability.
Every patch release undergoes a full and comprehensive QA cycle prior to availability. The latest patch release can be found on Compass under the Downloads section. All Compass users are, by default, signed up to receive notifications when a new patch release is available.
SailPoint recognizes there are situations in which a temporary fix is required to quickly address a critical production issue until a patch release is available to permanently address the issue. In these rare situations, SailPoint will provide an e-fix. Issues blocking a customer’s internal pre-production milestones or scheduled "Go Live" date fall outside the standard e-fix criteria. These situations are handled on a case-by-case basis between Engineering and the Customer Success Manager or Engagement Manager overseeing the customer’s implementation, in which an e-fix request may be considered.
E-fixes are minimally tested solutions, and their purpose is to bridge the gap until a more extensively tested patch release is available, so as to ensure the stability and performance of the customer's environment. It is expected that a customer or partner receiving an e-fix reports back any issues with the e-fix via the associated support case, for which a follow-up e-fix may be required. An e-fix is fully supported in a customer’s environment until the targeted patch release is made generally available. At that time, it is expected the customer incorporates the patch into their environment and removes the e-fix as soon as possible. It is recommended that no more than 3 e-fixes be deployed in a production environment at any given time. An e-fix cannot be shared.
The criteria listed below must be met for an ETN to be considered for an e-fix. The goal is to limit using e-fixes to only the most dire circumstances. An e-fix should not be an option until all other paths have been exhausted, and requires approval by SailPoint Engineering.
- Issue must be Severity 1, e.g., production system/application down, severe data loss or corruption, etc. More detail on Severity 1 criteria can be found in the SailPoint Customer Support Guide on Compass.
- Issue must have been reported against a version of IdentityIQ or IdentityIQ File Access Manager that’s in Full Support (no e-fix will be provided for versions in Limited or Dropped Support)
- Issue must have been reproduced by Support, and an ETN opened on behalf of the customer
- Issue must be considered by Engineering to be a defect. Generally, these are the conditions of a defect:
- Loss or corruption of data
- Inability to load or access data as normal
- Regression of functionality from a previous version
- Security issues (e.g., improper access to data, cross-site scripting vulnerabilities, etc.)
- No enhancements will be considered for e-fixes
- Issue must not have a viable workaround, or workaround would take significantly more time (and introduce more risk) than generating an e-fix
- If the issue has been resolved in a patch or service pack that is applicable to the customer’s current release, it will not be considered for an e-fix. In such a case, the customer should apply the latest patch or service pack.
- Specific to IdentityIQ File Access Manager - if the issue has been resolved in a later release, it will not be considered for an e-fix. In such a case, the customer should upgrade to the latest release.
E-fixes are only supported in the customer’s environment until the next patch is made generally available. At which point, the customer is required to remove the e-fix and apply the patch.
This policy doesn’t pertain to security e-fixes, which are generally available to all IdentityIQ customers and partners. Refer to the IdentityIQ Security Vulnerability Matrix for more information on available security e-fixes recommended for specific versions and patch levels of IdentityIQ and ancillary components.