Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

SailPoint Identity Verification for Third-Party Access

Sailpoint
06/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


power of SailPoint's Atlas platform to innovate and deliver exceptional identity solutions for our customers. Today I'm joined by Hardik Modi, Senior Director, Identity Management at IDM Works. I am also excited to share that IDM Works is one of our top delivery admiral partners in America and around the world. One of the biggest challenges enterprises face today is onboarding third party identities, contractors, vendors, field workers, even contingent labor who are not part of an organization's HR system. To address this scenario, SailPoint has created the Non-Employee Risk Management Platform, sometimes referred to as NIRM, to grant critical third party access. But in a world of increasing digital fraud, how can we reliably verify a third party identity before granting access to sensitive applications? Identity verification isn't just a technical problem, it's a business critical trust issue. That's where our SailPoint delivery admiral partner, IDM Works, comes in. I'm thrilled to have Hardik from IDM Works with us today. So Hardik, let's go ahead and jump in. Thanks so much for joining us. I know you're in the trenches with clients every day and your time is precious, so I really appreciate it. Do you mind kicking us off by sharing more about the IDM Works Verify solution that you guys have developed to secure the end-to-end third party onboarding process? Thanks Neil for having me. So a big challenge we consistently hear from our customers is, how do I verify my non-employee populations? Whether you are contractors, partners, or vendors. Through our partnership with both SailPoint and ID Data Web, IDM Works has built a plug and play identity proofing solution, we call it IDM Works Verify, on top of the SailPoint at last platform that we deploy as a managed service offering. With this offering, customer gain is secure, scalable, and frictionless way to verify non-employees before granting an access, which is a very, very key thing. Our proofing solution takes the approach of validation of those third party user who they claim to be, once they are onboarded within the SailPoint's NUM platform. And once a user is onboarded, SailPoint sends them an account claiming invitations. And during this process, we are leveraging ID Data Web to perform those real time identity verifications, document checks that identifies and triggers the fraud signals when appropriate. We embed this entire verification flowing to the SailPoint's at last platform. So customers get a seamless identity life cycle experience from onboarding to proofing to governance, and then eventually deprovisioning that access. This approach enforces a verify first, grant access second strategy, making those entire identity proofing a governance control rather than an afterthought. All right, Hardik. So let's dive into that last phrase. I like that one. Verify first, grant access second. So it sounds simple, but can you tell me a little bit more about the implementation design on that one? Absolutely. So we developed IDM Works Verify solution as a seamless, fully managed services built onto the SailPoint at last platform. This solution combines the three key components. Number one, we leverage ID Data Web's data sources for that identity proofing to verify identities prior to that activation. Second, ID Works delivers those implementation as well as configuration of those ID Data Web integrated within the NUM workflows, ensuring that identity proofing is seamless, inserted into the life cycle processes, delegated administrator flows, and all the other high risk identity life cycle events. And then the last one would be our MSP team, our managed services team, that provides the continuous monitoring as well as tuning of those proofing process, adjust those risk thresholds to balance the security posture with end user experience to ensure that solution continues to run smoothly. And this offering also includes the compliance audit, I guess that's a key one for any type of high risk third party users. For our customers, it means they get trust and speed at the same time. It's a very fast, frictionless, and automated experience for the end user. But at the same time, it's backed by a robust enterprise grade verification process. So Hardik, I want to step back for a second. So we see this use case out in the field a lot. We hear about it, but we don't hear about that many clients coming back to us saying, this is what we need to do right now. This is the first thing, right? So where did you guys get the idea to build this? Did you partner with one of our clients? What did that look like? Just to kind of step out of kind of where we were heading, I just want to go back to the beginning for a second and kind of how you actually created the idea. Absolutely. So we started this one with one of our healthcare customers. Because again, when we look into this healthcare, they are having a number of those non-employee populations, right? Maybe the visiting physicians or maybe researchers, medical providers, the nurses, right, who are going from one facility to another facility. Those user-based needs access to those sensitive patient information on day one. They needed to have that absolute certainty that every person who has been granted those access is a legitimate user. So this is pretty much that idea of verification that came up and there is a compliance need. So we started with them, essentially we implemented our IDM Works Verify solution in conjunction with the SailPoint Atlas platform and every incoming provider's identity is pretty much automatically verified against that identity ID database, trusted data sources. During that NUM onboarding, as well as that entire process, proofed using the BioGov ID and mobile match templates. This pretty much entire approach provided the three outcomes. First by using IDM Works Verify offering, the customer got a lot more confidence in the access decisions that are being made. Those decisions were happening into the real time based on the verified results. And the nice part was that team did not need a lot of training to start using it effectively because that is one of the challenges that we see. That okay, what does that organizational change management looks like, how I can train, but the solution is essentially more like a plug and play. Second would be this entire approach made it possible to automatically onboard Active Directory, Epic and any other healthcare applications, which pretty much helped create that, I would say that very smooth day one experience for those end users. And again, with our experience, that is always a very big deal into these healthcare environments because they are essentially working for life and death situations. And any type of these access delays can quickly become that operational issues. And then the last one we had would be this solution helped our customer meet that HIPAA requirements by putting in place a process that was reputable, governed and audit ready. So if I look at from that 360 degree view, I guess this was not only about the automation, but it was also about giving them a leaner comfort structure they could stand behind. And all of those pretty much resulted into the customer confidence to operate securely at the scale. Man, Hardiff, that's a pretty powerful outcome, especially in such a critical industry. So really highlights the value behind the solution that you and the team have built. Obviously building a truly seamless solution like this often means overcoming implementation hurdles. So what specific features of the SailPoint Atlas platform were key to making this technology possible? Yep. So that entire Atlas platform, I guess that was a fundamental in allowing us to build a SailPoint native solution instead of going into this some external capability. And the extensibility that Atlas platform allows us, I guess that essentially force us to innovate. We used workflows within the platform to orchestrate that entire processes. When a new identity request access within the ISC platform, the workflow gets triggered and that workflow makes a real time call to the ID data web APIs to perform that identity check. And then based upon whether it's a pass or fail, the workflow decides what should be that next step, either proceeding with the creating the account and granting the birthright access or maybe flagging the identity for the review if it's failed. So without the flexibility of workflows and our ability to call third party APIs, building this kind of integrated frictionless or even event driven solution would have been far more difficult, if not impossible. Our offering takes an advantage of several Atlas native capabilities, ISC APIs, as well as those event triggers for those real time status updates from ID data web, custom UI tiles that we have built directly within that Atlas platform. Identity data web's API is integrated as our identity verification engine to verify against the BioGov ID mobile match. And then of course, the NumData model extension to store those verification attributes as well as that overall risk scoring. And then of course, we have used access request as well as lifecycle workflows or events. Those are pretty much tied to the proofing results. I got to tell you, Hardik, I love that. It's truly a fantastic example of using the Atlas platform to extend identity security to solve unique business challenges. And specifically for this case, obviously in the healthcare space, but as we know, there's so many other use cases, so many other industries where this is important. All right. It sounds like kind of the combination of IDM works expertise in the SailPoint Atlas framework is where that magic actually happens. So what's next for identity proofing? I would tell you that myself and my entire team is very excited about our IDM works verify offering. And I think it provides that easy button for both any of our new customers who is just starting their SailPoint journey or any of our existing customer who is pretty much having that NUM inbuilt within their ecosystem. We are continuously looking for ways to enhance the solution with more data sources or even more additional risk signals and see this one as in a foundational component of a true zero trust model. This offering is pretty much available today as in a managed services from IDM works. So we are very excited. Hardik, I got to tell you, this has been incredibly insightful. It's a perfect showcase of how our partners are building on top of SailPoint's Atlas framework and Atlas platform to deliver real business value. Thank you so much for sharing this offering with us today and all of your amazing insights into ID proofing. If you want to learn more about ID proofing from IDM works, please go visit their website, reach out to Hardik on LinkedIn. They are truly one of our greatest partners. They are in the trenches with all things identity around the globe. So no matter what your identity challenges are, they're a great resource to reach out to if you're looking for some additional assistance. With that said, have a great day, everybody.

TL;DR

  • IDM Works developed a plug-and-play identity proofing solution that integrates ID Data Web verification into SailPoint's NIRM platform, enabling enterprises to verify third-party identities before granting access rather than after.
  • The solution was initially deployed with a healthcare customer to verify visiting physicians and medical providers, delivering HIPAA-compliant processes, automated day-one access to critical applications, and increased confidence in access decisions.
  • Built natively on SailPoint's Atlas platform, the solution uses workflows and APIs to perform real-time identity verification checks during onboarding, automatically provisioning or flagging accounts based on verification results.
  • IDM Works delivers the solution as a fully managed service offering that includes implementation, configuration, continuous monitoring, risk threshold tuning, and compliance auditing.
  • The verify-first approach transforms identity proofing from an afterthought into a governance control, supporting zero trust models and addressing the growing challenge of securing non-employee populations.

IDM Works Verify: Securing Non-Employee Onboarding

This Built on SailPoint partner showcase features IDM Works' innovative identity proofing solution designed to address a critical enterprise security challenge: verifying third-party identities before granting system access. The IDM Works Verify solution integrates identity verification directly into SailPoint's Non-Employee Risk Management (NIRM) platform, creating a seamless verify-first, grant-access-second workflow. By leveraging ID Data Web's data sources and biometric verification capabilities, the solution performs real-time identity checks during the onboarding process, validating contractors, vendors, and contingent workers against trusted databases before provisioning accounts. This approach transforms identity verification from an afterthought into a governance control, ensuring that only legitimate users gain access to sensitive applications and data.

Healthcare Implementation and Business Outcomes

The solution was initially developed in partnership with a healthcare customer facing the challenge of onboarding visiting physicians, researchers, and medical providers who needed immediate access to sensitive patient information. The implementation delivered three significant outcomes: increased confidence in access decisions through real-time verified results, automated provisioning to Active Directory and Epic healthcare applications for seamless day-one access, and HIPAA compliance through repeatable, governed, and audit-ready processes. The plug-and-play nature of the solution minimized organizational change management requirements, while the automated workflows eliminated access delays that could impact critical healthcare operations.

Technical Architecture on SailPoint Atlas

IDM Works built the solution as a SailPoint-native capability using the extensibility of the Atlas platform rather than implementing external systems. The architecture leverages Atlas workflows to orchestrate the verification process, making real-time API calls to ID Data Web when identity requests are submitted. Based on pass/fail results, workflows automatically determine next steps—either proceeding with account creation and birthright access provisioning or flagging identities for manual review. The solution utilizes ISC APIs, event triggers for real-time status updates, custom UI tiles within the Atlas platform, NIRM data model extensions to store verification attributes and risk scores, and lifecycle workflows tied to proofing results. This native integration approach creates a frictionless, event-driven solution that would have been significantly more difficult to achieve through external bolt-on capabilities.

Chapters

0:00 - Introduction to Built on SailPoint Series
1:33 - IDM Works Verify Solution Overview
3:43 - Verify First, Grant Access Second Design
5:35 - Healthcare Customer Use Case
9:29 - SailPoint Atlas Platform Integration
12:17 - Future of Identity Proofing
13:19 - Closing and Resources

Key Quotes

1:57 "A big challenge we consistently hear from our customers is, how do I verify my non-employee populations? Whether you are contractors, partners, or vendors."
3:29 "This approach enforces a verify first, grant access second strategy, making those entire identity proofing a governance control rather than an afterthought."
5:17 "For our customers, it means they get trust and speed at the same time. It's a very fast, frictionless, and automated experience for the end user. But at the same time, it's backed by a robust enterprise grade verification process."
8:32 "With our experience, that is always a very big deal into these healthcare environments because they are essentially working for life and death situations. And any type of these access delays can quickly become that operational issues."
10:10 "The extensibility that Atlas platform allows us, I guess that essentially force us to innovate."
13:11 "We are continuously looking for ways to enhance the solution with more data sources or even more additional risk signals and see this one as in a foundational component of a true zero trust model."

FAQ

How does IDM Works Verify integrate with existing SailPoint NIRM deployments?

The solution is built natively on the SailPoint Atlas platform using workflows, APIs, and NIRM data model extensions. When a non-employee identity requests access, Atlas workflows automatically trigger real-time verification checks through ID Data Web APIs. Based on pass/fail results, the workflow either proceeds with account creation and birthright access provisioning or flags the identity for manual review. This native integration approach creates a seamless experience without requiring external systems or complex middleware.

What types of verification does the solution perform during onboarding?

The solution leverages ID Data Web's trusted data sources to perform real-time identity verification, document checks, and biometric validation using BioGov ID and mobile match templates. It validates that third-party users are who they claim to be by checking against authoritative databases and identifying fraud signals. Verification attributes and risk scores are stored in extended NIRM data model fields for governance and audit purposes.


Categories:
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Zero Trust
  • Compliance & Governance
  • Technical Deep Dive
  • Customer Story
  • Identity Verification
  • Third-Party Access Management
  • Non-Employee Risk Management
  • SailPoint Atlas Platform
  • Healthcare Identity Security
  • Zero Trust Architecture
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SailPoint Identity Verification for Third-Party Access

              Upcoming Webinar Calendar

              • 06/24/2026
                11:00 AM
                06/24/2026
                Accelerating Insights on AI Innovation and Trends
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-innovation-and-trends/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Implementing AgenticTrust for Transformative Engagement
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-implementing-agentictrust-for-transformative-engagement/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/15/2026
                12:00 PM
                07/15/2026
                Discover How Cyera Is Transforming Agent Security Approaches
                https://www.truthinit.com/index.php/channel/2036/discover-how-cyera-is-transforming-agent-security-approaches/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                24

                Accelerating Insights on AI Innovation and Trends

                06/24/202611:00 AM ET
                • Jun
                  25

                  Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                  06/25/202601:00 PM ET
                  • Jun
                    30

                    Mastering Active Directory Certificate Services for Long-Term Success

                    06/30/202601:00 PM ET
                    • Jul
                      01

                      Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                      07/01/202604:00 AM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version