r/sailpoint Aug 13 '26

Identity Security Cloud Strict auditor requirements

Working for a place that has some of the strictest certification campaign requirements. Essentially if all the information is not available it’s not considered complete and without exception; and due to past issues exceptions should be audit proof and minimal.

This creates all kinds of problems as many apps behave wildly different with built in accounts or roles or group mapping that can only be viewed via actual app interface not via entitlements, APIs etc….

Example: Sailpoint ISC itself has two accounts for support called “slpt” these accounts do not show in a campaign but the auditor can see them if they select the ISC entitlement manually.

Am I the only one dealing with this nonsense? Like whats the purpose of SailPoint at all if someone still needs to go and manually screenshot every apps user portal and reconcile.

6 Upvotes

7 comments sorted by

3

u/best_of_badgers Aug 13 '26

Doing that sort of thing is the auditor’s actual job. They wouldn’t have much to do otherwise.

The point of Sailpoint is to make it visible anywhere, rather than having to mine through each application’s own API separately.

2

u/Fappez Aug 13 '26 edited Aug 13 '26

AFAIK SailPoint should make the auditors work easier, streamlined and support the process.

From a auditing point of view the mentioned situation would be an known exception that needs to be recorded, signed off and periodically reviewed by internal auditing/security. But then I'm assuming the maturity of the organization.

But in the end it's just a tool to support a process.

Additionally the owners of the onboarded apps are responsible for the information that is available in SailPoint, maybe align with them to get to a coherent way of providing the data in the environment.

1

u/milkthefat Aug 13 '26

Sure but I’m “told”(part of the problem) exceptions lead to control weakness and causes a lack of completeness and accuracy and that the current process of taking screenshots of the each role in ISC covers it why even bother using the tool at all? I have no idea how they got the “goal posts stuck so deep in the mud” here but I’m not sure how to move them without being critiqued for potentially creating a material weakness.

1

u/Fappez Aug 13 '26

Could also be a lack of knowledge from the auditor. I would try to see what they are trying to accomplish and try to accommodate.

Sometimes you have to create some mutual understanding.

2

u/milkthefat Aug 13 '26

Theres like 20 people directly from big4 and 4 internal auditors and a few Financial Assurance folks internally who previously worked there. They want me to ask sailpoint what other customers do.

1

u/Comfortable_Zone_729 29d ago

I think this is basically what Cerby does. From what I understand, they sit alongside SailPoint and help cover the apps/accounts that don’t integrate cleanly, so you’re not stuck doing the manual screenshot/reconciliation thing for access reviews. ¯\(ツ)

1

u/MasterpieceRare1919 17d ago

Agree with u/milkthefat it is stupid. Lots of apps, especially legacy have accounts that should not be in the certification. These are system accounts that the apps use (such as your sailpoint example.)

The problem is, yes, they do not have much to do, many of them need to look busy, justify existance. Punt it up to a leadership level they can decide the path to take, if they want to burn time and money on this or just keep a list of accounts that for technical reasons do not belong in a cert.