Security & Identity · Integration

SailPoint

Add SailPoint to your product for your customers, and give your AI agents governed access to it.

SailPoint sits a layer above the login. The identity provider decides whether somebody can sign in; SailPoint decides what they should be entitled to and proves it afterwards. An embedded SailPoint integration reads identities and the accounts and entitlements aggregated from each connected source, works with access profiles and roles, raises and tracks access requests, and reads the certification campaigns where a manager confirms or revokes what their people hold. Two things shape the build. There are two deployments, the SaaS platform with a tenant specific API host and the on premise IdentityIQ, so the endpoint is part of what a customer configures. And the blast radius here is large, so scopes are kept to the actions you actually enable and every call is recorded, which is what makes an automated access change reviewable later. fastn holds the per-tenant credentials and follows the API.

Start freeBook a demo

In your product

Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.

Let each customer connect their own SailPoint tenant and grant only the scopes the features you shipped need.

Read identities, accounts and entitlements so your product can show what somebody genuinely holds across their connected sources.

Raise an access request from your product and follow it through approval, so entitlement changes go through governance rather than around it.

Read certification campaign results so your product can act on what a reviewer revoked, with the change traceable.

For your AI agents

Governed, audited access for the agents you build, through the MCP server.

An agent lists which identities hold a sensitive entitlement and which of those came in through a role rather than a direct grant.

An agent raises an access request on a user's behalf within governed permissions, with the request attributed to the tenant that authorised it.

An agent explains how someone obtained an entitlement by reading the access profile and source it came from.

Example prompt

Who holds this entitlement in our SailPoint tenant, and which of those grants has never been certified?

Set up SailPoint in 4 steps

  1. 01Enable the SailPoint connector in your fastn dashboard.
  2. 02Have each customer supply their own tenant API host and credentials, since the SaaS platform and IdentityIQ are reached differently.
  3. 03Map the identity, account, entitlement and access profile fields your product uses, and enable only the request and review actions you need.
  4. 04Call it from your product and expose the same connection to your agents through the MCP gateway.

Why teams use the SailPoint integration

What you get by embedding it with fastn instead of building it yourself.

  • Ship a SailPoint integration without building it. Your customers connect their own SailPoint account inside your product and work their users, groups and roles there, with no per-customer code on your side.
  • Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a SailPoint update is not your on-call problem.
  • One integration serves your product and your agents. The same governed SailPoint connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.

Used by these teams

Security & IT

Compare with

OktaLumosAuth0

Often used alongside

Tools the same teams tend to run next to SailPoint, across other categories.

ServiceNowDatadogPagerDutyAWS CloudWatch

SailPoint integration FAQ

How do I add a SailPoint integration to my product?

Enable the SailPoint connector in your fastn dashboard, then let each customer authenticate their own SailPoint account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no SailPoint client code in your app and no per-customer branch in your codebase. Setup is 4 steps.

Do my customers each connect their own SailPoint account?

Yes. Every connection is scoped to the individual customer, so each authorises their own SailPoint account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.

Can AI agents use this SailPoint integration?

Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent lists which identities hold a sensitive entitlement and which of those came in through a role rather than a direct grant.

Who maintains the SailPoint integration?

fastn does. When SailPoint changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.

What permissions does the SailPoint integration need?

Only the scopes required for the actions you enable. Each customer grants access to their own SailPoint tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.

Can access changes be automated safely?

Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.

What can I build with the SailPoint integration?

A common starting point: let each customer connect their own SailPoint tenant and grant only the scopes the features you shipped need. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.

How much does the SailPoint integration cost?

It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding SailPoint does not change your per-connector cost. You can start free with 3 connected accounts.

Add SailPoint to your product

Start free with 3 connected accounts. No sales call required, and no per-customer integration code.

Start freeRead the docs
← All integrations