
Signal the future: Real-time security with the Shared Signals Framework
Source: YouTube · SailPoint · published Jul 1, 2026 · 31:16
The Shared Signal Framework (SSF) enables real-time, standardized communication of security events across enterprise identity systems, allowing components to cooperate proactively rather than operate in isolation 0:22 3:46.
Key Takeaways:
• Identity systems have traditionally operated in silos; SSF connects them so context—like compromised credentials or device non-compliance—is shared instantly across the architecture 0:50 1:13.
• SSF uses transmitters to broadcast security events and receivers to take action, utilizing an async publish-subscribe model with Security Event Tokens (SETs) over push or pull streams 5:01 7:13.
• SailPoint's SSF receiver supports CAPE event types including device compliance changes, risk level changes, session revocations, token claims changes, and credential changes 11:25.
• Received events can trigger automated workflows, such as disabling high-risk accounts, launching access reviews, or forcing reauthentication based on the correlated risk level 19:33.
• SailPoint can also act as a transmitter, sending session revoked events to downstream vendor systems when an identity's lifecycle state changes (e.g., termination) 20:34.
By adopting SSF, organizations can achieve zero standing privileges and unified, real-time identity security across diverse IT ecosystems 4:31.
Sources:
- 0:22 Introduction to SSF and real-time security
- 0:50 The problem of isolated identity systems
- 5:01 SSF terminologies: transmitters, receivers, and streams
- 11:25 Supported CAPE event types in SailPoint
- 19:33 Workflow automation based on received events
- 20:34 SailPoint as a transmitter for lifecycle state changes
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello everyone, welcome and thank you for joining Cellpoint Developer Days 2026. I'm DH, senior product manager at Cellpoint. I'm going to speak on signal the future realtime security with a ser signals framework. Today I'm going to cover the identity and security context. Why the identity context is important. The shared signal framework, fundamentals of it, some terminologies, cape event types, the various event types that is supported in shared signal frameworks receiver of cell point, the SSF configuration, then we'll have a quick tip dive demo and key takeaways. I'm going to share that with you. So for far too long identity has operated in isolation. Vendors often attempt to claim that they are the only providers of information and control for an organization. Just buy our product and…