
Automating conditional access with an identity governance bot
Source: YouTube · SailPoint · published Jul 1, 2026 · 27:44
SailPoint support engineer Thomas Carter presents a method for automating conditional access approvals using identity governance bots, eliminating manual data checks to reduce approver fatigue and streamline access requests 0:14.
Key Takeaways:
• The automated process works behind the scenes: a user requests access, a workflow fires to check for required attributes (like training or location), and the bot automatically approves or denies the request 1:21.
• This approach is ideal for access that falls between birthright and high-level privileged access, such as roles requiring standard training completions or specific location attributes 2:08.
• Setup involves three main steps: creating non-human bot identities with API tokens, formatting role descriptions with standardized nomenclature to define requirements, and building a four-part workflow to parameterize, compare, and decide 3:49.
• The workflow executes rapidly, processing up to 250 pending requests per run by comparing parsed user attributes or entitlements (via API search) against the role's required criteria before routing to human approvers if fully qualified 15:02.
• The system provides clear audit trails and detailed denial emails to requesters, and can be enhanced using custom metadata (requiring an additional purchase) to mask the configuration from end users 23:23.
By shifting the burden of qualification checks from human reviewers to automated bots, organizations can significantly increase productivity and reduce human error in identity governance.
Sources:
- 0:14 Introduction and project scope
- 1:21 Diagram of the 3-step automated process
- 2:08 Primary use cases and approval fatigue
- 3:49 Three key setup parts: bot creation, formatting, workflow
- 15:02 Workflow execution, 250 request limit, and API lookups
- 23:23 Enhancements, auditing, and workflow step limits
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] >> Hello, my name is Thomas Carter and I am a call support engineer at SailPoint and I'm very happy to be presenting to you automating conditional access with an identity governance bot. The scope of this project is to increase productivity, reduce risk, reduce approval fatigue, and streamline access access approvals. Thank you so much for joining me. So, to start off, today's agenda will be a quick overview of how all this works, a few use cases for this project, a tenant setup, a live demo, some identified enhancements that can be utilized, how to audit and produce logs for this project, and some identified enhancements that can be utilized. So, how does this all work? Now, this project allows the customer to set up a process in which access requests can be automatically assessed…