Identity security · SailPoint

SailPoint implementation and identity governance engineering

We implement, extend and support SailPoint IdentityIQ and Identity Security Cloud: authoritative sources, joiner-mover-leaver automation, RBAC, Segregation of Duties and certification campaigns that stand up to audit. Enterprises hire us directly; consultancies use us as their SailPoint engineering bench.

IIQ + ISC
Both SailPoint platforms
5
Published SailPoint case studies
UK · US · UAE
Regions delivered
In short

MappOptimist is a SailPoint implementation partner for enterprises and IT consultancies. We deploy and extend SailPoint IdentityIQ and Identity Security Cloud: HR and directory integration, joiner-mover-leaver automation, connector development, RBAC, Segregation of Duties and access certifications. Our engineers are based in India and deliver remotely to clients worldwide, as a project team, dedicated SailPoint engineers or white-label capacity.

01

Problems we solve

Provisioning still runs on tickets

Every joiner, mover and leaver needs someone to create, change or remove accounts by hand. Access lags on day one, lingers after exit, and the effort grows with headcount instead of shrinking.

Nobody can say who has access to what

Entitlements are scattered across Active Directory, Entra ID and dozens of applications with no single view. Over-entitlement builds up quietly until an auditor or an incident finds it.

Audits and certifications are a spreadsheet exercise

Reviewers rubber-stamp access lists exported by hand, SoD conflicts are found after the fact, and producing evidence for regulators takes weeks of manual work.

An IdentityIQ estate full of custom code

Years of BeanShell rules, custom workflows and JDBC connectors make IdentityIQ upgrades risky and a move to Identity Security Cloud hard to scope. You need people who can read what is actually there.

Your SailPoint bench is too thin

Consultancies and system integrators win SailPoint work and then struggle to staff it. Experienced IdentityIQ and ISC engineers are hard to hire quickly and expensive to keep idle between projects.

02

What we build

SailPoint Identity Security Cloud implementation

Tenant configuration, identity profiles, source onboarding and provisioning through REST, SCIM 2.0, JDBC, Web Services and directory connectors. Workday or Oracle HRMS as the authoritative source, Active Directory and Microsoft Entra ID as core targets, with PowerShell for directory automation where needed.

SailPoint IdentityIQ consultants

IdentityIQ 8.x deployment, enhancement and support: application onboarding via JDBC, Oracle Database and web services, custom BeanShell rules and workflows, lifecycle events, provisioning policies and governance reporting. We work inside existing IIQ estates as readily as on new builds.

Joiner-mover-leaver automation

We model the real lifecycle from HR data first, then automate it: birthright access on hire, role changes that remove old entitlements on a move, and timely revocation on exit. Access follows the person, and the team handles exceptions instead of every request.

RBAC, Segregation of Duties and certifications

Role models built from actual entitlement data, SoD policies that block conflicting access at request time, governed access request and approval flows, and recurring certification campaigns (manager, entitlement owner, targeted) that produce audit-ready evidence on demand.

IdentityIQ to Identity Security Cloud migration

We inventory your IIQ applications, BeanShell rules, workflows and custom connectors, then map each one to its ISC equivalent: standard connectors, transforms, cloud rules, workflows or an external service. Sources, roles and certification campaigns move in waves, with both platforms reconciled until cut-over.

SailPoint connector development and support

Onboarding applications with no out-of-the-box connector through JDBC, Web Services, SCIM 2.0 or REST, plus production support after go-live: aggregation failures, provisioning errors, correlation issues and platform tuning as your application estate changes.

03

How an engagement runs

1

Map identity where it actually lives

We start with the directory and application landscape: authoritative sources, account and entitlement data quality, correlation rules and the real joiner-mover-leaver process. Nothing is automated until the data underneath it is understood.

2

Integrate sources and clean the data

HR systems such as Workday or Oracle HRMS, Active Directory and Entra ID are connected first, and identity data is reconciled so every account correlates to a real person before provisioning is switched on.

3

Automate lifecycle and governance

We build JML workflows, onboard applications, then layer RBAC, SoD policies, access requests and certification campaigns on the clean foundation, testing each release in non-production before it reaches users.

4

Go live and support in production

Production support follows every implementation: issue resolution, new application onboarding, campaign runs and platform changes, so governance keeps holding as the organisation changes.

04

Ways to work with us

SailPoint implementation project

A managed team runs a defined scope such as an ISC rollout, an IIQ enhancement or an IIQ to ISC migration, against outcomes you agree up front. We handle delivery management; you own decisions and sign-off.

Dedicated SailPoint engineers

Individual IdentityIQ or ISC engineers, or a dedicated team with a lead, working inside your IAM team, tools and ceremonies on a monthly rolling basis. You interview and approve everyone before they start.

White-label delivery for consultancies

For IT consultancies and system integrators, our SailPoint engineers deliver under your brand and your client relationship, as overflow capacity or a full delivery pod. You stay the face to the client.

Need individual engineers rather than a project? See roles and monthly pricing for IT staff augmentation.

05

Technology we work with

SailPoint platforms
SailPoint Identity Security CloudSailPoint IdentityIQ 8.xAccess certificationsRole-based access controlSegregation of DutiesGovernance reporting
Identity sources and targets
Active DirectoryMicrosoft Entra IDWorkdayOracle HRMSEnterprise applications
Connectors and integration
SCIM 2.0REST APIsJDBCWeb Services connectorDirectory connectors
Customisation and data
BeanShellPowerShellOracle DatabaseSQL Server
07

Frequently asked questions

Do you work on SailPoint IdentityIQ, Identity Security Cloud, or both?

Both. Our published case studies cover three Identity Security Cloud engagements (a global miner in the UK, a Fortune 500 distributor and a cybersecurity firm in the US) and two IdentityIQ engagements (a healthcare provider and a bank, both in the UAE). The work spans source integration, JML automation, RBAC, SoD, certification campaigns and production support.

How do you approach an IdentityIQ to Identity Security Cloud migration?

We begin with an inventory of the IIQ estate: applications and connectors, BeanShell rules, custom workflows, roles, SoD policies and certification definitions. Each item is mapped to an ISC equivalent or flagged for redesign, since IIQ customisations do not transfer directly. Sources and roles then move in waves, with aggregation and access reconciled between both platforms before each cut-over.

Can you build a connector for an application SailPoint does not support out of the box?

Usually, yes. Most applications can be onboarded through JDBC against the application database, SCIM 2.0, REST or the Web Services connector, which we have used across our ISC and IdentityIQ engagements. We assess the application's API or data model first, then agree what aggregation and provisioning operations are realistic before building.

Can we hire SailPoint developers to join our existing IAM team?

Yes. You can bring in individual SailPoint engineers or a dedicated team with a lead, working in your tools, ticketing and standups on a monthly rolling basis. You interview and approve each engineer before they start, and we match working hours to your team wherever possible.

We are a consultancy. Can you deliver SailPoint work under our brand?

Yes. White-label delivery is designed for IT consultancies and system integrators that win SailPoint projects but need extra engineering capacity. Our engineers work under your delivery lead and client relationship, either filling specific roles on your project or running a scoped workstream such as connector development, certification setup or production support.

How is a SailPoint engagement priced?

Staff augmentation is billed per engineer on a monthly rolling basis, and scoped projects are quoted against agreed outcomes. Our 2026 rate card lists an Identity & Access Management (IAM) Consultant at $46/hr (2-3 years), $54/hr (4-6 years) and $62/hr (6+ years). Rates are indicative and confirmed per engagement scope, duration and resource availability.

Do you hold a SailPoint partner status or certification?

We do not claim a SailPoint partner tier on this site. What we show instead is delivery evidence: five published SailPoint case studies across mining, distribution, cybersecurity, healthcare and banking, with the platforms, integrations and governance controls used in each. We are happy to walk through that work in detail on a call.

Discuss your SailPoint programme

ISC rollout, IdentityIQ enhancement, an IIQ to ISC migration or engineers for a project you have already won: tell us where you are and we will come back within one business day with a clear point of view.