Introducing ISC ODT (Identity Security Cloud Object Deployment Tool)

Hello everyone,

I’m excited to share ISC ODT (Identity Security Cloud Object Deployment Tool), an open-source utility designed to help teams manage and promote SailPoint Identity Security Cloud (ISC) configuration across environments. I’ve built this in collaboration with Justin Sewell (@jsewell).

After working on numerous ISC implementations, one recurring challenge has been managing configuration changes between sandbox, test, and production tenants. While ISC provides powerful APIs, deploying and promoting configuration objects at scale can become time-consuming and error-prone.

ISC ODT was created to help address that challenge by providing a repeatable and automated approach to exporting, tokenizing, versioning, and deploying ISC configuration objects.

This is basically a successor of IIQ’s SSB and was started back in 2024 which I presented at DevDays (NodeJS utility to help export, tokenize, and deploy IDN configuration objects via SPConfig APIs).

Key Features

  • Export ISC configuration objects from a source tenant
  • Deploy configuration objects into target tenants
  • Maintain single configuration objects that can be deployed to any environment via tokenization
  • Support CI/CD pipelines
  • Track configuration changes through source control
  • Handle object relationships and deployment dependencies
  • Support promotion across development, test, and production environments

Common Use Cases

  • Migrating configuration between ISC tenants
  • Managing ISC configuration as code
  • Supporting enterprise CI/CD pipelines
  • Standardizing deployments across multiple environments
  • Reducing manual deployment effort and configuration drift

Project Repository

GitHub Repository:

Documentation, examples, installation instructions, and supported object types can all be found in the repository.

Community Feedback Welcome

This project is being shared with the community in hopes that it can help other practitioners facing similar deployment and promotion challenges.

Feedback, bug reports, feature requests, and contributions are all welcome. If you’ve encountered deployment scenarios that aren’t currently supported, I’d be interested in hearing about them.

Thanks to everyone in the SailPoint Developer Community who continuously shares knowledge, tooling, and ideas that help move the ecosystem forward.

Looking forward to hearing your thoughts and feedback. I am not a software developer by any means, so don’t be too harsh :blush:

13 Likes

Thanks for sharing this @patrickboston and @jsewell Deploying through Config Hub while keeping Git as a separate piece has been one of the more frustrating parts of ISC work. What you promote through Config Hub does not map cleanly to what you version in Git, so you end up managing two different notions of the same artifact. Object mappings are their own bottleneck too, managed separately per deployment, and limited tenant connections make the whole thing harder to scale. A tool that brings this together in one repeatable flow addresses a real gap. Well done :clap: .

Would love to see this expand to cover more object types via direct API calls, things like credential providers and user levels. Would make it even more powerful.

2 Likes

@patrickboston this is awesome! I can’t wait to try this. As a long time IIQ engineer who shifted to ISC a few years ago, the SSB / tokenization was one thing I sorely missed from IIQ. I really appreciate yours and @jsewell hard work putting this together!

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.