SailPoint: IdentityIQ, Identity Security Cloud, and which one fits
SailPoint is the enterprise standard for identity governance, and the first real decision is which of its two platforms you are actually buying. IdentityIQ is the long-established product you run yourself. Identity Security Cloud, formerly IdentityNow, is the SaaS platform. They are not the same product with different hosting, and choosing the wrong one is expensive to unwind at month eight.
Custom JavaBeanShell rulesCompiled connector JARUI-configured transformsCloud-approved rulesWebhooksIdentityIQ and Identity Security Cloud, compared
The real difference is not hosting. It is whether you can run your own code inside the platform. IdentityIQ runs in your environment, so the runtime is yours. You can write custom Java, extend the database schema to store objects SailPoint never anticipated, and embed a bespoke web portal directly into the platform's own navigation. Identity Security Cloud is shared, multi-tenant SaaS, and it structurally prohibits arbitrary code execution: both the interface and the backend data model are locked down. That single architectural fact decides most of the rest.
| IdentityIQ | Identity Security Cloud | |
|---|---|---|
| Where it runs | Your infrastructure. You own the runtime. | SailPoint's cloud, multi-tenant. |
| Custom code | Custom Java and BeanShell run natively inside the platform. | No arbitrary code execution. Logic is shaped through UI-configured transforms, cloud-approved rules and webhooks. |
| A bespoke approval form for legacy mainframe access | Built and run natively inside the platform. | Built as a separate external application — hosted, patched and secured by you — talking to ISC over APIs. |
| Connectors | Run on your application server. You can inject Java or BeanShell into the connector lifecycle and manipulate data in real time. | Decoupled. They run in SailPoint's cloud or through a locked-down virtual appliance acting as a proxy. |
| Custom connectors | Write one from scratch in Java, compile it, drop the JAR into the classpath. | Build one in TypeScript through the SaaS connectivity framework and deploy it into SailPoint's cloud. Compiled Java connectors are structurally prohibited. |
| Upgrades | A major version upgrade typically runs three to six months, most of it regression testing and merging custom code. | Handled by SailPoint. |
| Exclusive capability | Bespoke compiled connectors for proprietary, legacy or air-gapped systems. | Activity connectors feeding the usage and risk analytics modules. |
The line that decides it: if you choose ISC and still need heavily bespoke logic, you are not avoiding the build. You are moving it outside the platform and taking on the cost of hosting, patching and securing those external services forever. For organizations with deeply entrenched legacy processes, that ongoing operational cost is often exactly why they stay on IIQ.
What an IdentityIQ upgrade actually costs
This is the hidden running cost of IdentityIQ, and almost nobody writes about it honestly. A major version upgrade typically takes three to six months. Minor patches can be weeks. The time goes almost entirely on regression testing and merging custom code, and three things break more or less reliably.
- Custom UI plugins and JavaScript. Anything touching the frontend — modified SailPoint bundle files, custom dashboards — breaks when the underlying UI framework changes.
- Custom Java and BeanShell rules. Bespoke workflow scripts fail wherever they call a SailPoint API method that has since been deprecated.
- IQService version mismatches. Upgrade the IdentityIQ servers but leave the IQService agent on the Windows servers at the old version, and Active Directory provisioning stops dead.
The pattern is simple: the more IdentityIQ was treated as a custom development platform, the more painful every upgrade becomes. That is the real argument for restraint during the build, and it is the number that belongs in a business case before anyone writes custom Java.
Should you move from IdentityIQ to Identity Security Cloud?
Move if you want to stop paying for server maintenance and six-month upgrade cycles, and you are ready to trade bespoke custom code for standard configuration.
Stay if you need an air-gapped network, have strict data residency requirements, or depend heavily on custom Java and UI plugins. There is no lift and shift for custom code; it cannot be moved into ISC. If you cannot afford to re-architect the legacy business processes that code supports, the migration is not a migration. It is a rebuild, and it should be budgeted as one.
What SailPoint governs
Whichever platform, the job is the same: lifecycle provisioning from HR data so joiners, movers and leavers get the right access on the right day; access requests with approval routed to the person who actually owns the decision; certification campaigns that finish; role modeling that describes how the organization really works; and separation-of-duties policy enforced before an auditor finds the conflict. The vocabulary differs from other platforms in places — SailPoint's "identity cube" and "entitlement" model trip people up in scoping conversations — and we translate.
What a SailPoint implementation involves. The full answer is on the IGA implementation page. The SailPoint-specific part is that IdentityIQ needs more upfront architectural design and more hand-written rules than a wizard-driven platform, which is why a traditional IIQ phase one often runs four to eight months. Connector work through the IAM integration practice is where most of the technical hours go; agreeing what a role means is where most of the calendar goes, and that is the same on every platform.
Where SailPoint fits against Saviynt. SailPoint handles bespoke, non-standard approval workflows and unusual legacy systems better, even though the initial build takes longer. Saviynt is faster to a standard phase one and hits a flexibility ceiling earlier. The honest question is not which platform is better; it is whether your first phase is standard or strange. The fuller comparison is in how SailPoint and Saviynt compare.
Certified delivery
SailPoint Certified IdentityIQ Engineer, SailPoint Certified IdentityNow Engineer, IdentityNow Security Engineer and IdentityNow Cloud Engineer, held by named engineers. We implement SailPoint; we are not a SailPoint partner, and we say so plainly. Day-two operations are available as managed IAM services, and campaign design draws on what makes access reviews hold up.
Common questions about SailPoint
Not the hosting. IdentityIQ lets you run your own Java, extend the schema and embed custom interfaces inside the platform. Identity Security Cloud is multi-tenant SaaS and prohibits arbitrary code — customization happens through configured transforms, approved rules and external services you host yourself. Everything else follows from that.
No. There is no lift and shift for custom Java, BeanShell or UI plugins. Anything bespoke either becomes standard configuration or becomes an external application you build and run outside the platform. That is the most important question on this page, and the answer decides whether a migration is a migration or a rebuild.
Three to six months for a major version, mostly regression testing and merging custom code. Custom UI plugins, deprecated API calls in BeanShell rules, and IQService version mismatches are the three reliable breakages.
If you want out of server maintenance and upgrade cycles and can trade custom code for standard configuration, yes. If you need air-gapped or data-resident deployment, or depend on custom Java and UI plugins, no — not without re-architecting the processes that code supports.
Phase one on IdentityIQ often runs four to eight months. Application onboarding runs another six to twelve after that, and program maturity takes two to three years. The full shape is on the IGA implementation page.
No. We implement SailPoint and hold delivery certifications on both platforms, but we make no partnership claim. That is deliberate, and we would rather say so than let you assume.
Yes. We start with what is live — which lifecycles run, which connectors work, and how much custom code exists — then decide with you whether to repair, re-architect or, on IdentityIQ, whether the custom code makes an ISC move realistic at all.
IdentityIQ or Identity Security Cloud?
A free consultation covers your estate, how much custom logic you actually need, and which platform that points to. You get the findings in writing.