# Community Blog

**URL:** https://developer.sailpoint.com/discuss/c/content/community-blog/125.md

[Latest](https://developer.sailpoint.com/discuss/latest.md) · [Categories](https://developer.sailpoint.com/discuss/categories.md) · [Tags](https://developer.sailpoint.com/discuss/tags.md)

---

## [About This Category](https://developer.sailpoint.com/discuss/t/about-this-category/190822)

<div class="topic-metadata">

**Author:** [@DNAndrist](https://developer.sailpoint.com/discuss/u/DNAndrist)\
**Replies:** 0\
**Last updated:** [December 17, 2025, 7:09pm UTC](https://developer.sailpoint.com/discuss/t/about-this-category/190822 "2025-12-17T19:09:26Z")

</div>

The Developer Community Blog is a place for community members to write and share blog posts about the interesting, fun, and unique ways in which they’re implementing SailPoint in their organizations. How it Works Before…

---

## [Taking Control of Aggregation Schedules with Workflows and PAG](https://developer.sailpoint.com/discuss/t/taking-control-of-aggregation-schedules-with-workflows-and-pag/224321)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 0\
**Last updated:** [September 29, 2026, 8:55pm UTC](https://developer.sailpoint.com/discuss/t/taking-control-of-aggregation-schedules-with-workflows-and-pag/224321 "2026-09-29T20:55:16Z")

</div>

Introduction Why: Managing, backing up, and manipulating aggregation schedules at scale in SailPoint Identity Security Cloud (ISC) can be a common operational headache. Native functionality does not provide a single-…

---

## [Mastering Timezone & Daylight Savings Management in ISC Transforms](https://developer.sailpoint.com/discuss/t/mastering-timezone-daylight-savings-management-in-isc-transforms/222118)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 2\
**Last updated:** [September 10, 2026, 2:42am UTC](https://developer.sailpoint.com/discuss/t/mastering-timezone-daylight-savings-management-in-isc-transforms/222118 "2026-09-10T02:42:44Z")

</div>

Introduction Why: If you manage time-dependent logic in SailPoint Identity Security Cloud (ISC), you likely know the pain of Daylight Saving Time. When you use a transform that calculates an offset based on hours, th…

---

## [Delegating Role Management in ISC Using Interactive Forms and Workflows](https://developer.sailpoint.com/discuss/t/delegating-role-management-in-isc-using-interactive-forms-and-workflows/220655)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 0\
**Last updated:** [August 25, 2026, 5:46pm UTC](https://developer.sailpoint.com/discuss/t/delegating-role-management-in-isc-using-interactive-forms-and-workflows/220655 "2026-08-25T17:46:13Z")

</div>

Introduction Why: Empowering role owners to manage their own roles reduces the administrative burden on the core IAM team. By delegating this responsibility, business owners can maintain their roles efficiently and s…

---

## [Targeted Role Refreshes: Building a Paginated Workflow Solution in ISC](https://developer.sailpoint.com/discuss/t/targeted-role-refreshes-building-a-paginated-workflow-solution-in-isc/220562)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 1\
**Last updated:** [September 9, 2026, 10:33am UTC](https://developer.sailpoint.com/discuss/t/targeted-role-refreshes-building-a-paginated-workflow-solution-in-isc/220562 "2026-09-09T10:33:37Z")

</div>

Introduction Why: Sometimes you just need to refresh a single role in SailPoint Identity Security Cloud without triggering an “Apply Changes” for the entire tenant. Problem: Currently, the UI does not offer a simple …

---

## [CCG Not Installed After Virtual Appliance Pairing: Deployment Behavior and Resolution](https://developer.sailpoint.com/discuss/t/ccg-not-installed-after-virtual-appliance-pairing-deployment-behavior-and-resolution/220052)

<div class="topic-metadata">

**Author:** [@Siddharth60](https://developer.sailpoint.com/discuss/u/Siddharth60)\
**Replies:** 2\
**Last updated:** [August 21, 2026, 7:22am UTC](https://developer.sailpoint.com/discuss/t/ccg-not-installed-after-virtual-appliance-pairing-deployment-behavior-and-resolution/220052 "2026-08-21T07:22:36Z")

</div>

Introduction The Cloud Connector Gateway (CCG) is the component responsible for processing source communication requests routed through the SailPoint Virtual Appliance (VA). If CCG is unavailable, source operations su…

---

## [Integrating BeyondTrust Password Safe as a Credential Provider in SailPoint Identity Security Cloud](https://developer.sailpoint.com/discuss/t/integrating-beyondtrust-password-safe-as-a-credential-provider-in-sailpoint-identity-security-cloud/219547)

<div class="topic-metadata">

**Author:** [@mpotti](https://developer.sailpoint.com/discuss/u/mpotti)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 8:36pm UTC](https://developer.sailpoint.com/discuss/t/integrating-beyondtrust-password-safe-as-a-credential-provider-in-sailpoint-identity-security-cloud/219547 "2026-08-18T20:36:18Z")

</div>

Overview This article outlines how to integrate BeyondTrust Password Safe as a Credential Provider in SailPoint Identity Security Cloud (ISC) to support secure credential usage within source configurations and wor…

---

## [Building Email Notifications for Work Items in SailPoint Identity Security Cloud](https://developer.sailpoint.com/discuss/t/building-email-notifications-for-work-items-in-sailpoint-identity-security-cloud/218733)

<div class="topic-metadata">

**Author:** [@Pratyush27](https://developer.sailpoint.com/discuss/u/Pratyush27)\
**Replies:** 0\
**Last updated:** [August 12, 2026, 1:57am UTC](https://developer.sailpoint.com/discuss/t/building-email-notifications-for-work-items-in-sailpoint-identity-security-cloud/218733 "2026-08-12T01:57:42Z")

</div>

If you run a role composition campaign in ISC and let a reviewer revoke something, a remediation work item lands in someone’s Task Manager at sign-off. Now ask that person when they found out about it. Usually the an…

---

## [Bypassing Access Item Index Delays in SailPoint Identity Security Cloud](https://developer.sailpoint.com/discuss/t/bypassing-access-item-index-delays-in-sailpoint-identity-security-cloud/218153)

<div class="topic-metadata">

**Author:** [@Pratyush27](https://developer.sailpoint.com/discuss/u/Pratyush27)\
**Replies:** 0\
**Last updated:** [August 5, 2026, 2:37am UTC](https://developer.sailpoint.com/discuss/t/bypassing-access-item-index-delays-in-sailpoint-identity-security-cloud/218153 "2026-08-05T02:37:58Z")

</div>

If you’ve just created a requestable role in ISC and tried to test it immediately, you’ve probably noticed something annoying. It doesn’t show up in the Request Center. Wait a bit. Still nothing. Eventually it will a…

---

## [Building Custom Paginated Reports Natively in ISC Workflows](https://developer.sailpoint.com/discuss/t/building-custom-paginated-reports-natively-in-isc-workflows/217827)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 0\
**Last updated:** [August 1, 2026, 3:11am UTC](https://developer.sailpoint.com/discuss/t/building-custom-paginated-reports-natively-in-isc-workflows/217827 "2026-08-01T03:11:21Z")

</div>

The Problem: The 250 Item Limit The Requirement: Organizations often need custom reports, such as a comprehensive list of all disabled accounts that still retain active access entitlements across all sources. The Gov…

---

## [Implementing Dynamic Retry Workflows in Identity Security Cloud](https://developer.sailpoint.com/discuss/t/implementing-dynamic-retry-workflows-in-identity-security-cloud/217267)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 2\
**Last updated:** [July 29, 2026, 12:43pm UTC](https://developer.sailpoint.com/discuss/t/implementing-dynamic-retry-workflows-in-identity-security-cloud/217267 "2026-07-29T12:43:19Z")

</div>

Introduction Why: In Identity Security Cloud (ISC), we often interact with APIs or external scripts that might occasionally fail or require a bit of extra time. Launching a certification campaign and waiting for it t…

---

## [Tackling Nested AD Group Certifications in SailPoint ISC Using Role Composition](https://developer.sailpoint.com/discuss/t/tackling-nested-ad-group-certifications-in-sailpoint-isc-using-role-composition/217009)

<div class="topic-metadata">

**Author:** [@ajmerasunny1](https://developer.sailpoint.com/discuss/u/ajmerasunny1)\
**Replies:** 2\
**Last updated:** [July 24, 2026, 7:24pm UTC](https://developer.sailpoint.com/discuss/t/tackling-nested-ad-group-certifications-in-sailpoint-isc-using-role-composition/217009 "2026-07-24T19:24:42Z")

</div>

The Problem: Nested Groups Are a Certification Blind Spot Reviewing nested Active Directory groups and their memberships is one of the most common and challenging problems organizations face during access certificati…

---

## [Designing Beyond Default: The Ultimate Guide to SailPoint Form UI Customization](https://developer.sailpoint.com/discuss/t/designing-beyond-default-the-ultimate-guide-to-sailpoint-form-ui-customization/216502)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 10\
**Last updated:** [August 12, 2026, 1:55pm UTC](https://developer.sailpoint.com/discuss/t/designing-beyond-default-the-ultimate-guide-to-sailpoint-form-ui-customization/216502 "2026-08-12T13:55:19Z")

</div>

Form Adoption vs. Form Function As IAM professionals, we spend weeks designing robust joiner mover leaver processes, automated workflows, and complex approvals. When it’s time to roll them out to the business, we depl…

---

## [Inactive Account Day Threshold Handling Using Transforms](https://developer.sailpoint.com/discuss/t/inactive-account-day-threshold-handling-using-transforms/216210)

<div class="topic-metadata">

**Author:** [@jsosa](https://developer.sailpoint.com/discuss/u/jsosa)\
**Replies:** 0\
**Last updated:** [July 11, 2026, 2:39am UTC](https://developer.sailpoint.com/discuss/t/inactive-account-day-threshold-handling-using-transforms/216210 "2026-07-11T02:39:00Z")

</div>

Background A common request from our clients is to monitor some last-login attribute — the field that records the date and time a user last signed in, such as lastSignInDateTime on an Entra ID account or lastLogonTime…

---

## [Self-Service Certification Escalation: A Custom Workflows & Interactive Forms Solution](https://developer.sailpoint.com/discuss/t/self-service-certification-escalation-a-custom-workflows-interactive-forms-solution/215955)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 2\
**Last updated:** [July 15, 2026, 10:53am UTC](https://developer.sailpoint.com/discuss/t/self-service-certification-escalation-a-custom-workflows-interactive-forms-solution/215955 "2026-07-15T10:53:18Z")

</div>

The Problem: The End-of-Quarter Certification Crunch The Late-Reviewer Dilemma: At the end of a quarterly or semi-annual access certification cycle, compliance administrators often face a common problem: a handful of…

---

## [Automating First-Day Access and Password-less Registration with SailPoint ISC and Microsoft TAP](https://developer.sailpoint.com/discuss/t/automating-first-day-access-and-password-less-registration-with-sailpoint-isc-and-microsoft-tap/215828)

<div class="topic-metadata">

**Author:** [@smukhija](https://developer.sailpoint.com/discuss/u/smukhija)\
**Replies:** 12\
**Last updated:** [September 3, 2026, 2:21pm UTC](https://developer.sailpoint.com/discuss/t/automating-first-day-access-and-password-less-registration-with-sailpoint-isc-and-microsoft-tap/215828 "2026-09-03T14:21:46Z")

</div>

A practical implementation guide for automating Microsoft Temporary Access Pass generation using SailPoint ISC Workflows and Microsoft Graph APIs. Overview First-day access remains a challenge for many organizations.…

---

## [Building a Custom Identity Timeline Report in ISC: Form, Workflow, and PTA Solution](https://developer.sailpoint.com/discuss/t/building-a-custom-identity-timeline-report-in-isc-form-workflow-and-pta-solution/215299)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 4\
**Last updated:** [July 2, 2026, 12:22pm UTC](https://developer.sailpoint.com/discuss/t/building-a-custom-identity-timeline-report-in-isc-form-workflow-and-pta-solution/215299 "2026-07-02T12:22:08Z")

</div>

Introduction Why: During audits, governance reviews, or troubleshooting security events, administrators frequently need a single, chronological timeline of everything that has occurred for a specific identity in Iden…

---

## [Restricting Access Profile Visibility to Multiple Departments Using Transforms and Segments in SailPoint ISC](https://developer.sailpoint.com/discuss/t/restricting-access-profile-visibility-to-multiple-departments-using-transforms-and-segments-in-sailpoint-isc/214538)

<div class="topic-metadata">

**Author:** [@ssowmya567](https://developer.sailpoint.com/discuss/u/ssowmya567)\
**Replies:** 2\
**Last updated:** [June 30, 2026, 3:34pm UTC](https://developer.sailpoint.com/discuss/t/restricting-access-profile-visibility-to-multiple-departments-using-transforms-and-segments-in-sailpoint-isc/214538 "2026-06-30T15:34:51Z")

</div>

Introduction In many organizations, Access Profiles should not be visible to all users in the Request Center. For example: HR Access Profiles should be visible only to HR users Finance Access Profiles should be…

---

## [Implementing Recursive Governance: How to Govern SailPoint ISC PATs Using a Web Services Connector](https://developer.sailpoint.com/discuss/t/implementing-recursive-governance-how-to-govern-sailpoint-isc-pats-using-a-web-services-connector/212420)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 3\
**Last updated:** [June 16, 2026, 2:55am UTC](https://developer.sailpoint.com/discuss/t/implementing-recursive-governance-how-to-govern-sailpoint-isc-pats-using-a-web-services-connector/212420 "2026-06-16T02:55:36Z")

</div>

The Problem: “Invisible” Access The Rise of PATs: Personal Access Tokens (PATs) are very common in SailPoint ISC implementations due to almost all ISC API endpoints requiring a PAT to execute the call. The Governance…

---

## [Delaying Birthright Role Assignment to Prevent Duplicate AD Accounts](https://developer.sailpoint.com/discuss/t/delaying-birthright-role-assignment-to-prevent-duplicate-ad-accounts/212011)

<div class="topic-metadata">

**Author:** [@moises\_proof](https://developer.sailpoint.com/discuss/u/moises_proof)\
**Replies:** 2\
**Last updated:** [June 9, 2026, 11:38pm UTC](https://developer.sailpoint.com/discuss/t/delaying-birthright-role-assignment-to-prevent-duplicate-ad-accounts/212011 "2026-06-09T23:38:31Z")

</div>

Overview In some SailPoint ISC environments, a user may already have an existing Active Directory account before the identity is created in ISC. When a birthright role is assigned immediately after identity creation,…

---

## [Bringing IIQ Maintenance Mode to ISC: Custom Workflow & Forms Solution](https://developer.sailpoint.com/discuss/t/bringing-iiq-maintenance-mode-to-isc-custom-workflow-forms-solution/210795)

<div class="topic-metadata">

**Author:** [@trettkowski](https://developer.sailpoint.com/discuss/u/trettkowski)\
**Replies:** 3\
**Last updated:** [May 29, 2026, 6:12pm UTC](https://developer.sailpoint.com/discuss/t/bringing-iiq-maintenance-mode-to-isc-custom-workflow-forms-solution/210795 "2026-05-29T18:12:25Z")

</div>

Introduction Why: During a recent IIQ to ISC migration, a key requirement was to replicate IIQ’s Maintenance Mode functionality. Currently, ISC does not offer an OOTB equivalent, and there is no immediate roadmap fo…

---

## [Cloud Attribute Generator Rule - Flow Diagram](https://developer.sailpoint.com/discuss/t/cloud-attribute-generator-rule-flow-diagram/210071)

<div class="topic-metadata">

**Author:** [@ts\_fpatterson](https://developer.sailpoint.com/discuss/u/ts_fpatterson)\
**Replies:** 0\
**Last updated:** [May 20, 2026, 10:54pm UTC](https://developer.sailpoint.com/discuss/t/cloud-attribute-generator-rule-flow-diagram/210071 "2026-05-20T22:54:25Z")

</div>

Understanding Uniqueness, Data Flow, and Real-Time Limitations in SailPoint Identity Security Cloud Introduction When provisioning new accounts in SailPoint Identity Security Cloud (ISC), the platform does not query …

---

## [Creating an Account Without Granting Real Access Using a Non-Persistent Entitlement](https://developer.sailpoint.com/discuss/t/creating-an-account-without-granting-real-access-using-a-non-persistent-entitlement/205354)

<div class="topic-metadata">

**Author:** [@moises\_proof](https://developer.sailpoint.com/discuss/u/moises_proof)\
**Replies:** 11\
**Last updated:** [June 26, 2026, 3:17pm UTC](https://developer.sailpoint.com/discuss/t/creating-an-account-without-granting-real-access-using-a-non-persistent-entitlement/205354 "2026-06-26T15:17:00Z")

</div>

High-Level Understanding Use case In some scenarios, the requirement is to create the account only, without granting any real access in the target system. We don’t want to add a real dummy group on the target system. …

---

## [Source Maintenance Mode — An out-of-the-box operational capability ISC still needs and how to build a safe version today](https://developer.sailpoint.com/discuss/t/source-maintenance-mode-an-out-of-the-box-operational-capability-isc-still-needs-and-how-to-build-a-safe-version-today/192701)

<div class="topic-metadata">

**Author:** [@amrdodani](https://developer.sailpoint.com/discuss/u/amrdodani)\
**Replies:** 1\
**Last updated:** [January 13, 2026, 12:47am UTC](https://developer.sailpoint.com/discuss/t/source-maintenance-mode-an-out-of-the-box-operational-capability-isc-still-needs-and-how-to-build-a-safe-version-today/192701 "2026-01-13T00:47:44Z")

</div>

Every mature IGA program eventually hits the same operational pothole: A business-critical source goes into a planned upgrade window (hours… sometimes days). During that window, aggregations fail, provisioning fails, ti…

---

## [Provisioning of users in two different databases using a single JDBC connector application in IIQ](https://developer.sailpoint.com/discuss/t/provisioning-of-users-in-two-different-databases-using-a-single-jdbc-connector-application-in-iiq/191456)

<div class="topic-metadata">

**Author:** [@bhanuprakashkuruva](https://developer.sailpoint.com/discuss/u/bhanuprakashkuruva)\
**Replies:** 2\
**Last updated:** [June 16, 2026, 6:47am UTC](https://developer.sailpoint.com/discuss/t/provisioning-of-users-in-two-different-databases-using-a-single-jdbc-connector-application-in-iiq/191456 "2026-06-16T06:47:27Z")

</div>

Introduction This guide is for implementing a custom solution for one of the use cases, like provisioning of accounts from a single JDBC application to more than one database at a time. This solution has some workarounds…

---

## [Automating Bulk Access Profile Creation in SailPoint Identity Security Cloud using the VS Code ISC Extension](https://developer.sailpoint.com/discuss/t/automating-bulk-access-profile-creation-in-sailpoint-identity-security-cloud-using-the-vs-code-isc-extension/185560)

<div class="topic-metadata">

**Author:** [@ssowmya567](https://developer.sailpoint.com/discuss/u/ssowmya567)\
**Replies:** 26\
**Last updated:** [September 8, 2026, 6:03pm UTC](https://developer.sailpoint.com/discuss/t/automating-bulk-access-profile-creation-in-sailpoint-identity-security-cloud-using-the-vs-code-isc-extension/185560 "2026-09-08T18:03:30Z")

</div>

Manually creating Access Profiles in large SailPoint Identity Security Cloud (ISC) environments can be time-consuming and prone to errors. When managing dozens or even hundreds of applications, adding profiles one by…

---

## [Access Profiles Composition Certification Campaigns by Owner](https://developer.sailpoint.com/discuss/t/access-profiles-composition-certification-campaigns-by-owner/151946)

<div class="topic-metadata">

**Author:** [@Bassem\_Mohamed](https://developer.sailpoint.com/discuss/u/Bassem_Mohamed)\
**Replies:** 3\
**Last updated:** [January 8, 2026, 1:07am UTC](https://developer.sailpoint.com/discuss/t/access-profiles-composition-certification-campaigns-by-owner/151946 "2026-01-08T01:07:34Z")

</div>

This solution was the result of a collaborative effort with @mostafa\_helmy, whose valuable insights and contributions played a key role in shaping the solution. What are Access Profiles? Access Profiles are predefined…

---

## [IdentityIQ workItem reminders and escalation explained](https://developer.sailpoint.com/discuss/t/identityiq-workitem-reminders-and-escalation-explained/148386)

<div class="topic-metadata">

**Author:** [@aleksander\_jachowicz](https://developer.sailpoint.com/discuss/u/aleksander_jachowicz)\
**Replies:** 6\
**Last updated:** [February 4, 2026, 5:59pm UTC](https://developer.sailpoint.com/discuss/t/identityiq-workitem-reminders-and-escalation-explained/148386 "2026-02-04T17:59:08Z")

</div>

In IdentityIQ, work items can sit idle in a user’s inbox. To prevent these from going stale, IIQ provides mechanisms for reminders and escalations—so your approvals don’t go unnoticed or unresolved. Despite this being…

---

## [Using Custom SaaS Connectors on IdentityIQ](https://developer.sailpoint.com/discuss/t/using-custom-saas-connectors-on-identityiq/143023)

<div class="topic-metadata">

**Author:** [@fernando\_delosrios](https://developer.sailpoint.com/discuss/u/fernando_delosrios)\
**Replies:** 0\
**Last updated:** [June 9, 2025, 5:49pm UTC](https://developer.sailpoint.com/discuss/t/using-custom-saas-connectors-on-identityiq/143023 "2025-06-09T17:49:02Z")

</div>

Ever since the release of the SaaS Connectivity Framework, I’ve been using it to solve countless use cases that previously had little to no solution—at least not without a dedicated external system. My experience has …

---

## [Automating SailPoint SaaS Connector Deployments with GitLab CI/CD](https://developer.sailpoint.com/discuss/t/automating-sailpoint-saas-connector-deployments-with-gitlab-ci-cd/128400)

<div class="topic-metadata">

**Author:** [@adunker](https://developer.sailpoint.com/discuss/u/adunker)\
**Replies:** 2\
**Last updated:** [May 15, 2025, 2:32pm UTC](https://developer.sailpoint.com/discuss/t/automating-sailpoint-saas-connector-deployments-with-gitlab-ci-cd/128400 "2025-05-15T14:32:00Z")

</div>

Automating SailPoint SaaS Connector Deployments with GitLab CI/CD Continuous Integration and Continuous Deployment (CI/CD) practices are essential for modern software development, and SailPoint SaaS connector deve…

[Next page](https://developer.sailpoint.com/discuss/c/content/community-blog/125.md?page=1)
