Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Sailpoint IAM ServiceCatalog integration

SushmaDahal
Giga Contributor

Hello, we are ServiceNow customers ( Healthcare) implementing Sailpoint as our IAM solutions to integrate Service Catalog and maintaining access request and approval through ServiceNow while managing the governance and identity through Sailpoint ISC. Looking to chat with organizations who have successfully completed the integration. Specifically interested to learn:

1. Out of box integration or custom integration

2. Roll out strategy

3. Change management for end users impacted with the request flow

4. Lessons learned

2 REPLIES 2

KatariinaE
Tera Contributor

Since you’re already using ServiceNow, it may also be worth considering IAM natively on the ServiceNow platform instead of integrating a separate IAM solution.
At Appmore, we’ve built an IAM Application directly on ServiceNow, covering identity lifecycle management, access requests, approvals, governance and provisioning.
You can take a look at the approach here: https://appmore.com/servicenow-identity-and-access-management/

Josh Pirozzi
Kilo Sage

 

Hi @SushmaDahal,

 

We've implemented the integration for our org (also healthcare), although successfully would be the piece in question. This is primarily associated to the implementation partner we worked with and the lack of experience or clarity provided on what the 'best practices' are for connecting SailPoint to ServiceNow Catalog. 

 

We implemented using the OOB integration, but from there we created an 'Access Request' that mimicked an Access Request Catalog Item we already had in place. This is where guidance was lacking from the implementation team on if this would function or not. Our 'Access Request' methodology provides our staff with the ability to select one or more CI's from a List Collector, and we used this as our template for the 'SailPoint Access Request'. This caused an issue, according the implementation partner where, they needed the CI SysID's for any/all birthright access(es) that would pass through from SailPoint to ServiceNow. So, we would need to figure out how to keep the table data in sync with SailPoint. 

 

For the entire project, we initially slated connecting SailPoint with:

  • ERP Platform: Source of truth for Employee Records
  • AD/Entra
  • ServiceNow
  • Several clinical platforms, including our EMR

From the start to when we went live, we scaled back to:

  • AD/Entra
  • ServiceNow - but removed the account sync as we discovered issues and had to switch gears to having a direct connection between Workday and ServiceNow. 
    • Side Note: We were also migrating to Workday for our org.
  • ERP Platform
  •  

 

Change management: In our initial deployment, we called out each individual connector and their implementation was broken down by, as the implementation partner defined, as their Roll-out (IE: Read-only, manual and then automated go-live).

 

Lessons Learned:

  • Don't take on too much for the initial launch / work iteratively. 
    • Focusing on just deploying integrations with AD/Entra and also ServiceNow is a lot and would have been a big win.
  • Role mining / Development
    • As a huge piece of SailPoint is Birthright access granting and logging, I wish we focused more energies there as it would have been felt on a larger scale by the wider audience as opposed to what we have for launch, which is Workday > SailPoint > AD.