KeyForge AI
Integrations · SailPoint

Access governance for SailPoint IdentityIQ & Identity Security Cloud

Extend an existing SailPoint deployment with continuous reasoning: risk-scored findings, cross-application SoD and evidence, without replacing the platform you already run.

The access model

How SailPoint grants access

Rules evaluate the effective permission after inheritance is resolved — then normalise it, so the same rule can reach into another platform.

Access is granted by

Role and entitlement model

The object an administrator assigns in SailPoint.
Resolved to

Application entitlement

The atomic permission we evaluate rules against, after nesting and inheritance are flattened.
Data dimension

As modelled

Evaluated alongside functional access, so scope is part of the rule rather than a filter applied afterwards.

In practice

What this catches

01

Risk and SoD posture written back onto certification line items

02

Cross-application rules spanning applications SailPoint governs separately

03

Micro-certifications between scheduled campaigns

The conflicts that matter most rarely sit inside one system. Pair SailPoint with the directory, a payments gateway or a second ERP and the combination becomes visible — which is the point of a cross-application rule.

Also supported

Pairs with

See it against your SailPoint estate.

Book a technical demo, or start with a read-only risk assessment.