Identity governance for a global miner
SailPoint Identity Security Cloud automating identity lifecycle and access governance across the enterprise for one of the world's leading mining organisations.
The brief
One of the world's leading mining organisations was managing identity and access at enterprise scale with heavy manual effort. Provisioning was slow, visibility into who could access what was limited, and audit and compliance pressure was constant across a sprawling application estate.
They needed to automate identity lifecycle management and put real access governance in place — onboarding applications into SailPoint Identity Security Cloud and replacing manual joiner-mover-leaver work with governed automation.
- Automate the full identity lifecycle across enterprise applications.
- Govern access centrally with clear visibility into who has what.
- Cut the manual effort in provisioning and de-provisioning.
- Be audit-ready, with certification evidence on demand.
- Enforce role-based access at enterprise scale.
- Keep the platform optimised with ongoing production support.
Our approach
Our consultants implemented and enhanced SailPoint Identity Security Cloud (ISC), onboarding enterprise applications and automating the joiner-mover-leaver lifecycle so access follows the person, accurately, from day one to exit.
We layered role-based access and recurring certification campaigns on top, integrating with Active Directory and Microsoft Entra ID, and stayed on to optimise the platform in production.
What we delivered
Application onboarding & integration
Enterprise applications connected into ISC via REST, JDBC and directory integrations.
Identity lifecycle automation
Joiner-mover-leaver events drive access automatically and accurately.
Access governance
Centralised visibility and policy over who has access to what.
Role-based access management
Access granted by role, reducing risk and manual decisions.
Certification campaigns
Periodic access reviews produce audit-ready evidence.
Production support & optimisation
Ongoing support keeps the platform healthy and tuned.
How we built it
We began by mapping the application and directory landscape, then onboarded systems into ISC through the right connectors — Active Directory, Microsoft Entra ID, REST and JDBC — so identity data was clean and authoritative before automation went live.
Joiner-mover-leaver automation and certification campaigns were rolled out in phases, with PowerShell and API integration where needed, followed by hypercare and ongoing production optimisation.
How it works
Onboard
Applications and sources are integrated into ISC.
Provision
Joiner-mover-leaver events drive access automatically.
Govern
Role-based policy controls who gets what.
Certify
Certification campaigns review and attest access.
Support
Production support keeps it optimised.
The governance win is automation with evidence: ISC turns joiner-mover-leaver events into accurate, policy-driven access, while certification campaigns generate the audit trail compliance teams need on demand. Role-based access removes manual, error-prone decisions.
Tight integration with Active Directory and Microsoft Entra ID keeps identity authoritative across the estate, so access reflects reality rather than drifting over time.
The impact
Joiner-mover-leaver processes were automated end to end.
Compliance and audit readiness improved markedly.
Manual provisioning effort fell sharply.
Visibility into user access across the enterprise improved.
Technology stack
Securing identity with SailPoint?
Whether you're implementing ISC, running IdentityIQ, or planning a migration, tell us where you are. Our certified engineers will come back within one business day with a point of view.