A broad catalog of pre-built connectors, plus AI self-discovery connectors for REST and database targets that onboard in minutes rather than days. We do not compare role names — we resolve inheritance down to the atomic permission in each system, then map those to a common model.
Featured platforms
These six have a page each because their access models differ most — and because cross-application rules usually span them. They are a subset of the catalog, not the extent of it.
Resolve composite and single roles down to the authorization object, field and value — then evaluate them against entitlements held in Oracle, Workday or the directory.
Flatten nested duty-role inheritance to the privilege level, and evaluate data security by business unit alongside functional access.
Model EBS the way EBS works: responsibility, menu and form function, with operating-unit scope evaluated inside the rule rather than filtered afterwards.
Extend an existing SailPoint deployment with continuous reasoning: risk-scored findings, cross-application SoD and evidence, without replacing the platform you already run.
Resolve nested group membership and directory role assignments, and bring them into the same rule set that evaluates your ERP entitlements.
Track which identities can effectively use a vaulted credential, so privileged access is reasoned about alongside the entitlements it unlocks.
Self-discovering connectors
Most connector work is schema archaeology: reading documentation, mapping attributes by hand, then rebuilding it when the target changes. For REST and database targets the connector does that itself — turning an onboarding that took days into one that takes minutes.
The catalog
ERP, HR, directory, cloud, ticketing and the identity platforms you may already run — onboarded through a guided flow rather than a services engagement.
Connector catalog
Select the system, add its details, configure the integration, map the schema, and finish — with connector types spanning ERP, HR, directory, cloud, ticketing and the IGA platforms you may already run.

Schema mapping
Every connector declares how its source attributes map onto the identity model, with inbound and outbound transformation, hooks and a provisioning threshold configured per target system.

If it speaks REST or sits on a database, the self-discovery connector handles it — and anything else is a conversation about the extract model, not a rebuild.