SailPoint implementation and identity governance engineering
We implement, extend and support SailPoint IdentityIQ and Identity Security Cloud: authoritative sources, joiner-mover-leaver automation, RBAC, Segregation of Duties and certification campaigns that stand up to audit. Enterprises hire us directly; consultancies use us as their SailPoint engineering bench.
MappOptimist is a SailPoint implementation partner for enterprises and IT consultancies. We deploy and extend SailPoint IdentityIQ and Identity Security Cloud: HR and directory integration, joiner-mover-leaver automation, connector development, RBAC, Segregation of Duties and access certifications. Our engineers are based in India and deliver remotely to clients worldwide, as a project team, dedicated SailPoint engineers or white-label capacity.
Problems we solve
Provisioning still runs on tickets
Every joiner, mover and leaver needs someone to create, change or remove accounts by hand. Access lags on day one, lingers after exit, and the effort grows with headcount instead of shrinking.
Nobody can say who has access to what
Entitlements are scattered across Active Directory, Entra ID and dozens of applications with no single view. Over-entitlement builds up quietly until an auditor or an incident finds it.
Audits and certifications are a spreadsheet exercise
Reviewers rubber-stamp access lists exported by hand, SoD conflicts are found after the fact, and producing evidence for regulators takes weeks of manual work.
An IdentityIQ estate full of custom code
Years of BeanShell rules, custom workflows and JDBC connectors make IdentityIQ upgrades risky and a move to Identity Security Cloud hard to scope. You need people who can read what is actually there.
Your SailPoint bench is too thin
Consultancies and system integrators win SailPoint work and then struggle to staff it. Experienced IdentityIQ and ISC engineers are hard to hire quickly and expensive to keep idle between projects.
What we build
SailPoint Identity Security Cloud implementation
Tenant configuration, identity profiles, source onboarding and provisioning through REST, SCIM 2.0, JDBC, Web Services and directory connectors. Workday or Oracle HRMS as the authoritative source, Active Directory and Microsoft Entra ID as core targets, with PowerShell for directory automation where needed.
SailPoint IdentityIQ consultants
IdentityIQ 8.x deployment, enhancement and support: application onboarding via JDBC, Oracle Database and web services, custom BeanShell rules and workflows, lifecycle events, provisioning policies and governance reporting. We work inside existing IIQ estates as readily as on new builds.
Joiner-mover-leaver automation
We model the real lifecycle from HR data first, then automate it: birthright access on hire, role changes that remove old entitlements on a move, and timely revocation on exit. Access follows the person, and the team handles exceptions instead of every request.
RBAC, Segregation of Duties and certifications
Role models built from actual entitlement data, SoD policies that block conflicting access at request time, governed access request and approval flows, and recurring certification campaigns (manager, entitlement owner, targeted) that produce audit-ready evidence on demand.
IdentityIQ to Identity Security Cloud migration
We inventory your IIQ applications, BeanShell rules, workflows and custom connectors, then map each one to its ISC equivalent: standard connectors, transforms, cloud rules, workflows or an external service. Sources, roles and certification campaigns move in waves, with both platforms reconciled until cut-over.
SailPoint connector development and support
Onboarding applications with no out-of-the-box connector through JDBC, Web Services, SCIM 2.0 or REST, plus production support after go-live: aggregation failures, provisioning errors, correlation issues and platform tuning as your application estate changes.
How an engagement runs
Map identity where it actually lives
We start with the directory and application landscape: authoritative sources, account and entitlement data quality, correlation rules and the real joiner-mover-leaver process. Nothing is automated until the data underneath it is understood.
Integrate sources and clean the data
HR systems such as Workday or Oracle HRMS, Active Directory and Entra ID are connected first, and identity data is reconciled so every account correlates to a real person before provisioning is switched on.
Automate lifecycle and governance
We build JML workflows, onboard applications, then layer RBAC, SoD policies, access requests and certification campaigns on the clean foundation, testing each release in non-production before it reaches users.
Go live and support in production
Production support follows every implementation: issue resolution, new application onboarding, campaign runs and platform changes, so governance keeps holding as the organisation changes.
Ways to work with us
SailPoint implementation project
A managed team runs a defined scope such as an ISC rollout, an IIQ enhancement or an IIQ to ISC migration, against outcomes you agree up front. We handle delivery management; you own decisions and sign-off.
Dedicated SailPoint engineers
Individual IdentityIQ or ISC engineers, or a dedicated team with a lead, working inside your IAM team, tools and ceremonies on a monthly rolling basis. You interview and approve everyone before they start.
White-label delivery for consultancies
For IT consultancies and system integrators, our SailPoint engineers deliver under your brand and your client relationship, as overflow capacity or a full delivery pod. You stay the face to the client.
Need individual engineers rather than a project? See roles and monthly pricing for IT staff augmentation.
Technology we work with
Case studies
Identity governance for a global miner
SailPoint Identity Security Cloud automating identity lifecycle and access governance across the enterprise for one of the world's leading mining organisations.
Read the case study →SailPoint ISC · DistributionAccess governance for a Fortune 500 distributor
SailPoint Identity Security Cloud streamlining access management and strengthening identity governance controls for a Fortune 500 distribution organisation.
Read the case study →SailPoint ISC · CybersecurityIdentity governance for a global security firm
SailPoint Identity Security Cloud securing user access and automating identity management for a global cybersecurity organisation.
Read the case study →SailPoint IIQ · HealthcareCentralised identity governance in healthcare
SailPoint IdentityIQ establishing centralised identity governance and automating user access management for a major UAE healthcare organisation.
Read the case study →SailPoint IIQ · Banking & FinanceCompliance-grade IAM for a bank
SailPoint IdentityIQ delivering identity governance, regulatory compliance and access management for a leading banking institution.
Read the case study →Frequently asked questions
Do you work on SailPoint IdentityIQ, Identity Security Cloud, or both?
Both. Our published case studies cover three Identity Security Cloud engagements (a global miner in the UK, a Fortune 500 distributor and a cybersecurity firm in the US) and two IdentityIQ engagements (a healthcare provider and a bank, both in the UAE). The work spans source integration, JML automation, RBAC, SoD, certification campaigns and production support.
How do you approach an IdentityIQ to Identity Security Cloud migration?
We begin with an inventory of the IIQ estate: applications and connectors, BeanShell rules, custom workflows, roles, SoD policies and certification definitions. Each item is mapped to an ISC equivalent or flagged for redesign, since IIQ customisations do not transfer directly. Sources and roles then move in waves, with aggregation and access reconciled between both platforms before each cut-over.
Can you build a connector for an application SailPoint does not support out of the box?
Usually, yes. Most applications can be onboarded through JDBC against the application database, SCIM 2.0, REST or the Web Services connector, which we have used across our ISC and IdentityIQ engagements. We assess the application's API or data model first, then agree what aggregation and provisioning operations are realistic before building.
Can we hire SailPoint developers to join our existing IAM team?
Yes. You can bring in individual SailPoint engineers or a dedicated team with a lead, working in your tools, ticketing and standups on a monthly rolling basis. You interview and approve each engineer before they start, and we match working hours to your team wherever possible.
We are a consultancy. Can you deliver SailPoint work under our brand?
Yes. White-label delivery is designed for IT consultancies and system integrators that win SailPoint projects but need extra engineering capacity. Our engineers work under your delivery lead and client relationship, either filling specific roles on your project or running a scoped workstream such as connector development, certification setup or production support.
How is a SailPoint engagement priced?
Staff augmentation is billed per engineer on a monthly rolling basis, and scoped projects are quoted against agreed outcomes. Our 2026 rate card lists an Identity & Access Management (IAM) Consultant at $46/hr (2-3 years), $54/hr (4-6 years) and $62/hr (6+ years). Rates are indicative and confirmed per engagement scope, duration and resource availability.
Do you hold a SailPoint partner status or certification?
We do not claim a SailPoint partner tier on this site. What we show instead is delivery evidence: five published SailPoint case studies across mining, distribution, cybersecurity, healthcare and banking, with the platforms, integrations and governance controls used in each. We are happy to walk through that work in detail on a call.
Related services
Discuss your SailPoint programme
ISC rollout, IdentityIQ enhancement, an IIQ to ISC migration or engineers for a project you have already won: tell us where you are and we will come back within one business day with a clear point of view.