Transcript
IAM over at Sideris. Sideris has been a SailPoint Delivery Admiral partner for four years in a row and currently holds the prestigious status in both the Americas and EMEA regions. Before we jump into the details, I want to take a second to provide some context and background to the use case we will be discussing today. As a SailPoint partner, Sideris has been engaged in one of our large healthcare clients this year focused on an identity transformation journey. They recently deployed a successful ISC, or Identity Security Cloud, go-live for the customer's identity program. Anything you would add here, G.K. and Suramya? Now thank you for the introduction, Neil, and Suramya was the lead for the implementation of the journey. I'm going to let him speak to that, but all I can say, the CISO is absolutely elated with the deployment. Him and his team has been trying to go live with SailPoint for quite some time. We were engaged probably six months ago and we have been able to deploy that, so it's a brilliant story of true partnership, true technology success. And then Suramya, anything you want to add on top of that? Yeah, truly a remarkable partnership where I think both the teams came together and then delivered it. To give you a little bit of background, this was the first phase of a long IGA journey. We went live with the multiple authoritative sources, as well as some code applications for provisioning, which included AD and Cerner. As G.K. said, they've been trying to do this for more than two to three years with different partner and different teams, so it's been a remarkable journey. So G.K., can you talk about some of the unique challenges in this specific customer's identity transformation journey, specifically around the time when Sideris joined the program? Sure, Neil. I'll give you two cents and then I want Suramya to talk about that as well. In terms of the challenges, the processes are complex. You can imagine healthcare industry, a lot of complexities, technology-wise, people-wise, process-wise, and we were able to solve several of these problems by true partnership, as I mentioned before. And then I want Suramya to talk about the specifics on exactly what he encountered and how did we resolve that in conjunction with working with the team? Yeah, one of the major, if it's a starting point, was there was a very low confidence about the entire IGA program because they had been trying to do this for two and a half to three years and they replaced their entire internal team as well as the external partner. So overall, from the stakeholders' point of view, the board's point of view, the project, even the product's point of view, the confidence was really low. The team, when we came in, they had no real recollection or they had no understanding of how their roadmap is or how they would actually go live and be successful. And I think when we came in, we sat with them, understood the requirements, what exactly we could go live in this phase, what was feasible, and also helped them to envision the roadmap because as from our experiences, we said, okay, if you start small and do things in phases, that will make you more successful. And the other side was the communication from our side, both the sides was extremely great. And at the end of that, if you could come to the go live, both the teams would look like just one single team. So it wasn't Sideris and the client team, it was just one IM team delivering it. And I think that sort of made a lot of difference. So Suramya, obviously there's always challenges in every single deployment. Do you mind deep diving a little bit into some of the technical challenges you guys ran into and how you overcame them? Yeah. So one of the major problem, because this is a healthcare customer, one of the major problem was the SIRNER birthright provisioning, where SIRNER usually only has one position. So if you're working as a nurse or a provider, you can only do one position at a time. But as you know, in healthcare industry, they wear multiple hats. So providers usually have four or five positions they can switch in and out in between. So another issue with SIRNER provisioning was, you don't want them to flip it back to the previous position because they may switch it to the new position. So that thing was a challenge when we started. The other thing was, there was a lot of data issues in the lower environment. And then no active directory, or I would say there was an active directory environment. But again, in terms of data, it was sort of almost non-existent. It was in healthcare. So again, multiple HR systems, a lot of challenges there. And so the way we solved them first was, I think we wrote some rules and workflows in Service Cloud to solve the SIRNER provisioning problem so that it only changes when for a mover or a conversion scenario, but it doesn't change for anything else. And then for multiple HR solutions, we connected them, had some common attributes where we could identify which is who is who so that there's no duplicate accounts creation. And then for lack of data in the lower environments, we helped the team see that, okay, the reason, the rationale behind how more production-like data in lower environments will help them. And that helped a lot during the testing portions. Well, I think, I don't know that I've ever run into a project that didn't have some level of data problems, that's for sure. So always nice to understand how folks get through that. So if we dive into the data problem for a second, was that just your architects coming in and taking a look and figuring out how to work through it? Or was there a more programmatic process you had to go through for that? So one was actually looking into the problems and I think that came out of on-surface when we started doing some of the unit testing, where the data in the lower environment, everything worked really well. But as you look at some of the data from production, some of the processes which we thought were working would not work. So that came out in surface during unit testing that helped us see the client that let us look at the data, what exactly are we missing on the HR side where the attributes which were missing, where actually they were completely different from production and lower environment that caused a lot of duplication of accounts. I think that again helped the customer. So it was more of, I think, unfortunately, more of a manual effort in this where you actually go and look at a deep dive, but then once you do it, once you understand where the problem is, then it doesn't take that long to fix the problem. Well, sounds like you had a good testing regimen at least. So you caught it in time, which is fantastic news. Well, thanks. Let's dive into the next question. You know, it's always amazing to me, you know, the longer we're in this business, the more times we see, you know, in identity programs, when you get lost, it's hard. It's hard to figure out how to come back and figure out how to restart that program. And you know, kind of the salient point that you made there around that partnership between the client and the team, it just makes all the difference when you're trying to restart a program and get them across the line. So I love the fact that you guys went in there with that mindset and helped shift things around. So, GK, when we start to think about some of the challenges that you guys ran into, how did you leverage the Atlas platform to get through those? Neil, for me, I always compare the Atlas and ISC as the iOS ecosystem where someone builds a base operating system, and then you open up to the world, and then people come and start building apps which are useful for everyone. I think that's how I envision Atlas is going to be in the next two to three years. And that's exactly what the client offered as well. So the client was migrating from a legacy IG solution to ISC. And one of the things that they wanted to do was compare accesses between different people. If Neil Kay, for example, has 10 roles on Cerner on the old IG or legacy IG platform, and when we are provisioning that to ISC, do we see the same comparison or not? So one of the team members from the client actually built a utility that leveraged Atlas and ISC's API on one part of the screen, and the other part of the screen leverages the APIs from the old legacy technology. I can just do a quick comparison. Imagine doing that when someone say that, oh, I did not get the access I had on the old platform. Well, there you have. That's the missing part. Go and add that as a role on Atlas or ISC. Happy days. So that was amazing. GK, I love that. And it's always interesting to see how our clients and partners are leveraging, you know, either the APIs out of Atlas or just Atlas in general to make their lives easier. So talk about a fantastic migration tool. I hope you guys have worked out an IP deal so that you can leverage that on your future healthcare projects, because I have a feeling that's going to be needed. One project after another. That's going to be actually a plugin on the Atlas platform available for free. So yeah, I love it. That is fantastic. Where can you find that plugin, GK? Soon. Soon. All right. I'm in. So once it gets released, let me know. We'll go ahead and bring you guys back on and do another podcast just on that. All right. Well, let's dive into the next question. So when we were talking earlier, you guys mentioned kind of the phase two that you're heading towards with a focus on at least one aspect being application onboarding. As we know, the long pole and the identity tent can often be application onboarding. How fast can we onboard? And certainly the move to ISC has allowed us to move faster with application onboarding than ever before. We're seeing ISC clients onboard hundreds of apps per month, thousands of apps in less than a year to two years, truly just amazing numbers. But it sounds like you guys have created a pretty incredible, I'll call it, innovation to help with application onboarding and help your clients move through that journey even faster. GK, maybe we start with you. As you guys are approaching phase two, what does that look like from an application onboarding standpoint? How does your tool ultimately help this particular healthcare customer move faster so they can play catch up and hopefully get to a more secure environment within the next couple of months? That's a great question, Neil. So it all started with planning and prioritization with the customer. Well, what do you want to see in Atlas and ISC? What will drive the most value in terms of ROI, user experience, and risk reduction? And along with that, as you rightly mentioned, we have an internal tool. We call it the Siderisk Identity Portal or SIP or CIP. We have an internal IAM R&D or research and development department where this is being run by a gentleman who has been in the R&D for, I would say, 20 years or so. So he understands IAM coming from legacy technologies and see what the challenges that we see in all the customers. The idea of this portal is to fast track application onboarding. I know that ISC also offers a lot of AI-driven approach to faster application onboarding and we are here to complement that offering from Atlas and make sure that the customers can leverage both that platform. So it all comes down to one final solution where everyone is a happy bunch of people, I suppose. So let me deep dive into some questions here because I always love when our partners create kind of application onboarding tools. Is there a piece that allows business application owners to come and interface with the tool or is it more back office? No, no, absolutely. The idea is to create a UI simple enough for non-technical people to input as much information as they can on the portal so that we can get some basic building blocks. And then at the click of a button, a basic structure of the application can be created into the Atlas and ISC platform. And that's the integration we absolutely love that ISC and Atlas gives us the flexibility to call the extended APIs for us to leverage and customize to our heart's content. So yeah, to your point, it's open to business people and technical folks can also use it. That's fantastic. So if we're following the rabbit hole here, sounds like business user, does it then pop into your team to then onboard the application? And is there an offshore component from a cost savings perspective in there, anything like that? Oh yeah, absolutely. So the idea is you open the tool for business people to add some context, and then the technical team can fine tune it, add on some more details to ensure that the requirements and the use cases are finalized. It looks what it was originally designed to do. And then we have a global delivery team, Neil, as you mentioned. My team is spread across India, UK, US, and Canada. And the idea is to ensure cost saving for the customer. We can use the offshore resources by, mind you, all certified architects and consultants in SailPoint. So we ensure that we have the quality of the people as well, and the customer doesn't need to shell out a lot of dollars to get the value from the product. I love hearing that. So speaking of dollars, have you guys done any metrics around how much faster you can onboard applications leveraging the tool? Great question. So we have some stats on it. In an ideal world, you would want to onboard applications as fast as you can without doing the basic rebuilding over and over again. That doesn't make sense. It's not like you encounter unique application all the time. Based on that, that was the thought process behind creating this portal. And then, roughly speaking, Neil, I would say that we are looking at around 25% to 30% of reduction in effort in terms of onboarding a single application. Now, that may not sound a lot per application, but when you do economies of scale and you have hundreds and thousands of applications to onboard across several customers, that does add up. So it's a great cost saving. I can't wait to see how the CIP tool and the new AI functionality, when you combine those metrics together, where we wind up in the next year. Might be fun for a follow up in 12 months just to see what that looks like. I would love that. Yes. Well, again, thank you guys. It's been a great conversation. If you want to learn more about CIP or any of the great tools or processes that the Sideris team has created to bring our clients further into their identity journey, feel free to reach out to GK and team, fantastic partners, and obviously one of our delivery admirals. So guys, thank you again for sharing your experiences. I hope the identity security community can leverage these collective insights and experiences. And of course, have a great day to those watching. Stay tuned for more from our Built on SailPoint series. Have a wonderful day.