> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleria.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SailPoint

> Connect your SailPoint tenant to Oleria to continuously discover user and role access across your identity governance platform.

SailPoint is an identity governance platform that many teams use as their identity provider (IdP). Connect your SailPoint tenant to Oleria to bring user and role access into your identity and access graph, without a dedicated SailPoint-specific integration.

## What Oleria discovers

* User accounts and profile attributes synced from SailPoint's directory.
* Roles assigned to each user.
* Identity posture signals, such as administrative role assignment.

Oleria uses this data for dormant account detection and access reviews, refreshed on SailPoint's standard sync schedule.

## Prerequisites

* Admin access in SailPoint IdentityNow with permission to create an OAuth2 client credential.
* Admin access on the Oleria platform to add a new integration.

<Note>
  The exact location of these settings can change over time. If the steps below don't match what you see, refer to SailPoint's own API documentation.
</Note>

## Get your SCIM credentials from SailPoint

<Steps>
  <Step title="Create an OAuth2 client credential in SailPoint IdentityNow">
    Sign in to SailPoint IdentityNow as an admin, go to **Admin** → **API Management**, and create an OAuth2 client credential.
  </Step>

  <Step title="Copy your SCIM Base URL and Authentication token">
    Copy both values before you leave the page - you'll paste them into Oleria in the next section:

    * **SCIM Base URL** - the HTTPS API endpoint for your SailPoint tenant.
    * **Authentication token** - the credential you generated.

    <Note>
      Copy the credential now. Many applications display it only once. Store it securely and rotate it per your organization's security policy.
    </Note>
  </Step>
</Steps>

## Connect SailPoint to Oleria

<Steps>
  <Step title="Open the integration">
    Go to your Oleria workspace, select **Integrations**, then select the **SailPoint** tile.
  </Step>

  <Step title="Complete the connection form">
    Select **Continue** and fill in the connection form:

    | Field                | Notes                                                                                    |
    | :------------------- | :--------------------------------------------------------------------------------------- |
    | Instance name        | Optional. Short, recognizable label for this connection (for example, `sailpoint-prod`). |
    | SCIM Base URL        | Required. The HTTPS API endpoint copied from SailPoint.                                  |
    | Authentication token | Required. The credential issued by SailPoint.                                            |
  </Step>

  <Step title="Save the integration">
    Select **Connect** to validate the credentials and save the integration.
  </Step>
</Steps>

## Verify the integration

Confirm the new instance appears in your Oleria workspace under **Connected Integrations** with a status of **Healthy**. Oleria syncs users and roles from SailPoint on the standard SCIM provisioning schedule once the initial sync completes.

<Note>
  If SailPoint rotates your credential, update the Authentication token in Oleria by editing the integration.
</Note>

## Governance actions

Oleria can also invoke lifecycle actions in SailPoint when the credential you provide has write access:

* Enable or disable a user account
* Create a new user

<Note>
  Many teams start with a read-only credential for visibility, then grant write access once they're ready to automate remediation in SailPoint.
</Note>

## Contact us

For questions about this integration, contact us at [support@oleria.com](mailto:support@oleria.com).
