Identity security · SailPoint

SailPoint IdentityIQ vs Identity Security Cloud: how to choose

IdentityIQ and Identity Security Cloud both govern who has access to what, but they are built differently. One is software you run and can customise deeply; the other is SailPoint's SaaS platform, built to be configured rather than coded. This guide sets out the differences that decide the choice.

Yashvant SikarvarFounder & CEO7 min read

In short

SailPoint IdentityIQ (IIQ) is identity governance software you host, upgrade and customise yourself, often with BeanShell rules, custom workflows and plugins. Identity Security Cloud (ISC) is SailPoint's SaaS platform, configured through identity profiles, transforms and workflows, with code as a last resort. ISC suits teams that want less to run; IIQ suits estates that depend on deep custom logic. Moving between them is a redesign, not a copy.

The differences that matter

Both platforms cover the core of identity governance: aggregating accounts from sources, joiner-mover-leaver automation, roles, Segregation of Duties policies, access requests and certification campaigns. Where they differ is who runs the platform and how you change its behaviour.

IdentityIQ and Identity Security Cloud compared
IdentityIQIdentity Security Cloud
How it is deliveredSoftware you host, patch and upgradeSaaS run and updated by SailPoint
How you change behaviourJava and BeanShell rules, custom workflows, tasks and pluginsIdentity profiles, transforms and ISC workflows; rules only where nothing else works
Custom code reviewYour team decides what is deployedCloud-executed rules are reviewed by SailPoint before deployment
Reaching on-premise systemsDirectly from your IdentityIQ serversThrough a SailPoint virtual appliance in your network
Common connectorsActive Directory, JDBC, Web Services, SCIM 2.0, RESTActive Directory, Microsoft Entra ID, JDBC, Web Services, SCIM 2.0, REST
Who carries upgrade effortYour team, as upgrade projectsSailPoint, as part of the service
Product names: in August 2026 SailPoint introduced Human Fabric, which it describes as the evolution of Identity Security Cloud. The comparison applies whichever name you use.

When IdentityIQ still fits

  • Your governance depends on custom logic that has no configuration equivalent yet, and the business is not ready to simplify it.
  • Policy or contracts require the identity platform to run inside your own infrastructure.
  • You have a stable, well-run IIQ estate and a capable team to keep upgrading it, and no pressing reason to change platforms this year.

Staying on IdentityIQ is a reasonable decision in these cases, but it is still worth knowing what your estate contains. An inventory of rules, workflows and connectors pays for itself whichever way you decide later.

When Identity Security Cloud fits

  • You are starting an identity governance programme and have no IdentityIQ estate to carry.
  • Your team spends more time keeping IdentityIQ running and upgraded than improving governance.
  • Most of your applications can be reached through standard connectors (directories, HR systems, JDBC, SCIM or REST APIs).
  • You want to adopt SailPoint's newer capabilities as they ship rather than through upgrade projects.

What changes if you move from IdentityIQ to ISC

A move is a redesign of how the platform is customised, not a lift-and-shift. These are the points that shape the plan:

  • IdentityIQ rules, workflows and tasks are not portable. SailPoint's developer-community guidance is that each one is re-expressed as ISC configuration, a transform, an ISC workflow or a reviewed rule, or retired.
  • Identity and role models, SoD policies, access requests, certifications and email templates map more closely and can often be moved in bulk with SailPoint's tooling, though their logic still needs review.
  • Accounts and entitlements are re-aggregated from the sources in ISC. IdentityIQ audit history does not move, so decide how it will be archived for your retention period.
  • Both platforms can run side by side. Moving sources in waves, and reconciling identities, accounts and entitlements before each cut-over, keeps joiner-mover-leaver and certifications working throughout.
  • In June 2026 SailPoint announced Agentic Acceleration, AI-assisted tooling for converting IdentityIQ configurations. It speeds up conversion; deciding what should move, testing against real HR data and reconciling access still has to be done.

Questions to answer before you decide

  1. How many BeanShell rules, custom workflows and plugins are in production, and which are still used?
  2. Which applications rely on custom connector code rather than a standard connector?
  3. Is there a hosting or data-residency requirement that rules out SaaS?
  4. What did your last two IdentityIQ upgrades cost in time and effort?
  5. How long must IdentityIQ audit history be kept, and where?
  6. Which certification campaigns and SoD reports must keep running without a gap during any change?

Our experience on both platforms

MappOptimist engineers have implemented IdentityIQ 8.x for a healthcare provider and a bank in the UAE, and Identity Security Cloud for a global miner in the UK and a Fortune 500 distributor and a cybersecurity firm in the US. These are implementations, not migrations; they are the depth on each side that a migration draws on.

Frequently asked questions

Is IdentityIQ being replaced by Identity Security Cloud?

SailPoint's SaaS platform is where its new capabilities are announced, including Human Fabric in August 2026, which SailPoint describes as the evolution of Identity Security Cloud. Check SailPoint's current support policy for your IdentityIQ version when you plan; this guide does not state support dates.

Can we customise Identity Security Cloud as much as IdentityIQ?

Not in the same way. ISC is designed to be configured: identity profiles, transforms and ISC workflows cover most needs, and rules are a last resort. Cloud-executed rules are reviewed by SailPoint before deployment, and connector-executed rules run on the virtual appliance. Deep Java customisations and IdentityIQ plugins have to be redesigned or retired.

How long does an IdentityIQ to ISC migration take?

It depends on what the IdentityIQ estate contains: the number of applications, custom rules, workflows and connectors. That is why we start with an inventory and give estimates after it, rather than before.

Can we run IdentityIQ and ISC at the same time?

Yes. A phased migration runs both platforms side by side. Authoritative sources move first, then applications in waves, and each wave is reconciled before provisioning and certifications switch to ISC.

Can MappOptimist engineers work on both platforms?

Yes. Our published SailPoint work covers three Identity Security Cloud and two IdentityIQ implementations. You can bring in individual SailPoint engineers, a dedicated team, or white-label delivery if you are a consultancy running the programme.

Sources

  • SailPoint developer documentation (developer.sailpoint.com): cloud-executed and connector-executed rules.
  • SailPoint developer community: IdentityIQ to Identity Security Cloud migration guidance.
  • SailPoint announcements: Agentic Acceleration (June 2026) and SailPoint Human Fabric (4 August 2026).
  • MappOptimist SailPoint case studies: three Identity Security Cloud and two IdentityIQ implementations.

Related

Discuss your SailPoint programme

Staying on IdentityIQ, moving to ISC, or still deciding: tell us about your estate and we will tell you what we would look at first.