Problem
SailPoint Non-Employee Risk Management (NERM), previously known as SecZetta, is critical for mitigating the security threat vectors and risks associated with non-compliant non-employee lifecycle management. While SailPoint Identity Security Cloud (ISC) provides an out-of-the-box (OOTB) NERM connector for identity lifecycle management and governance, using it introduces significant limitations depending on your data architecture.
Diagnosis
The viability of the OOTB NERM connector depends entirely on how your organization structures its non-employee data:
- Linear Architecture: If your setup uses a basic non-employee data architecture where there is a strict 1:1 relationship between 1 person and 1 assignment, the OOTB connector functions as expected and reduces delivery time.
- Complex Architecture: If your architecture allows 1 person profile to have multiple concurrent assignments, the OOTB connector cannot scale to provide proper account data representation or support an end-to-end integration.
- Writeback Limitations: The OOTB NERM connector does not support writing data back to the target application, which is an essential requirement for most customers.
Solution
To accommodate complex configurations where 1 person profile has multiple assignments attached, and to support the writeback of data from SailPoint ISC to NERM, you must implement a custom Web Service connector approach instead of the OOTB option.
A sample JSON outline for a custom Web Service-based NERM source configuration is structured as follows:
NERM.json (37.4 KB)
Conclusion
Choosing the right integration method for SailPoint NERM depends entirely on your data architecture complexity and writeback requirements. While linear architectures with a 1:1 relationship can successfully leverage the quick deployment of the OOTB connector, complex multi-assignment profiles require the scalability of a custom Web Service connector. Regardless of the connector approach chosen to ingest this data, when an identity is discovered across multiple authoritative sources, SailPoint ISC relies on Identity Profiles to determine which source takes precedence.