1Security + SailPoint

SailPoint decides who should have access. 1Security shows what access actually does.

SailPoint Identity Security Cloud governs identities and their access across every system you connect - entitlements shaped into roles, lifecycle states that provision and deprovision on their own, campaigns that keep certifying. What it hands the reviewer is the entitlement. Inside Microsoft 365, every one of those entitlements has an interior - sharing links, inheritance, three years of actual usage. That interior is where 1Security begins.

  • 70%
    of breaches exploit excessive permissions
  • 98%
    of granted permissions are never needed
  • 12h → 10 min
    a blast-radius investigation, before and after

Credit where due

What SailPoint does brilliantly.

One platform to manage and govern identities and their access - across every source you connect.

  • Governance across every source

    Connectors aggregate account data from the systems you run into one governed model - entitlements, access profiles and roles - so least privilege is decided in one place, for everything at once.

  • A lifecycle that runs itself

    Lifecycle states drive provisioning as people join, move and leave; access requests route through approvals; separation-of-duties policies catch conflicting access before it lands - with violations handled, not just flagged.

  • Certification with intelligence

    Manager and source-owner campaigns put every access decision back in front of a human on schedule - and Identity Outliers and Access Intelligence point the reviewer at the identities that deserve the closest look.

The other half

An entitlement engine, by design.

SailPoint’s model is the entitlement: aggregated from a source, shaped into roles and access profiles, requested, approved, certified. That abstraction is the whole point - it is what lets one platform govern hundreds of systems with one set of decisions.

Inside Microsoft 365, standing access has a second life below the entitlement. Sharing links, item-level grants, nested groups and inheritance decide what a mailbox or a site membership really opens - and how that access is exercised day to day is a story the entitlement itself doesn’t tell. What did this account actually reach? Was the permission ever used, from which device, from where? Those are questions about one workload’s interior, resolved item by item.

That interior was never SailPoint’s design brief. It is 1Security’s entire product.

The complement

What 1Security adds under the entitlement.

1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.

  1. 01

    The reach behind every entitlement

    Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The line item a reviewer certifies becomes a map of what it actually opens.

  2. 02

    Usage evidence for every decision

    Three years of activity history without a SIEM contract, and a behavior baseline for every identity. Revoke-or-keep stops being a memory test - anomaly episodes, with an alert line you position yourself, show how the access behaves.

  3. 03

    Findings that carry to their fix

    Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.

Joint architecture

Breadth above, depth below.

SailPoint governs the entitlement layer across every source you connect - lifecycle, requests, certifications, separation of duties. 1Security connects to your Microsoft 365 tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the item layer: every identity, every permission, three years of activity. The role says what an identity should hold; the graph says what it can reach and what it did. First findings land the same day.

DORA, jointly

One regulation, two halves of least privilege.

DORA - Regulation (EU) 2022/2554 - requires financial entities to limit access to ICT assets to what legitimate, approved functions actually need, under Article 9(4)(c) - and to keep proving that the limits hold.

SailPoint covers the decision side: access granted through roles and approvals, re-checked in certification campaigns, conflicting combinations blocked by separation-of-duties policy. 1Security covers the evidence side: the permission graph shows what each entitlement really opens inside Microsoft 365 and which of those permissions were ever used - then trims the excess through reviewed, reversible automations.

When the supervisor asks whether access is limited to what’s required, the answer is a report, not a project.

SailPoint decides. 1Security shows the evidence.

Keep SailPoint governing every source - and put the permission graph under the one that matters most.

Or keep asking reviewers to certify what they can’t see.