
Building real-time identity security with SSF: Architecture, events & workflows
Source: YouTube · SailPoint · published Jul 1, 2026 · 32:49
SailPoint has adopted the OpenID Foundation's Shared Signals Framework (SSF) to replace slow, per-vendor integrations with a standardized, real-time method for exchanging identity security events 0:57-1:18.
Key Takeaways:
• SSF uses transmitters and receivers to push signed Security Event Tokens (SETs) containing subject identifiers and event data, replacing scheduled aggregation with instant signaling 2:17-2:34.
• As a transmitter, SailPoint detects identity changes (e.g., termination), maps them to events like session revocation, and pushes the signed token to all registered receivers 5:28-6:33.
• As a receiver, SailPoint validates incoming signatures, correlates the event to a full identity profile to prevent "ghost events," and triggers automated workflows 7:00-7:30.
• The primary value add is correlated identity context, allowing security teams to react to bare signals with the full picture of who the user is and what they access 4:53-5:09.
• The roadmap includes mapping internal signals (like outlier scores) to SSF events, expanding vendor coverage, and persisting correlated events as audit records on the identity timeline 7:51-9:04.
SSF enables comprehensive, near-real-time security responses—like instantly revoking access across Jamf, Okta, and Microsoft 365 from a single termination event—without writing custom per-vendor code 20:04-20:30.
Sources:
- 0:57-1:18 The case for shared signals and replacing per-vendor integrations
- 2:17-2:34 SSF mental model: transmitters, receivers, streams, and SET payloads
- 4:53-5:09 The value of correlated identity context for security teams
- 5:28-6:33 Outbound transmitter pipeline: trigger, evaluate, sign, and push
- 7:00-7:30 Inbound receiver flow: validation, correlation, and workflow triggers
- 7:51-9:04 Roadmap: internal signals, broader vendor coverage, and audit persistence
- 20:04-20:30 Real-world impact: one event triggering action across multiple vendor systems
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] >> Okay. Hi, everyone. My name is Ketan Owascar, principal engineer at SailPoint. Over the next 30 minutes, I will introduce the shared signals framework, the OpenID Foundation standard, and who we have adopted it in the identity security cloud to move from periodic exchange to real-time identity signaling. Let me set out where we will go. The agenda has seven parts. The case for shared signals, the framework itself, the platform architecture we built, the transmitter and receiver in detail, the road map, and a live demo. Let us begin with the motivation. First, the case for shared signals. Why real-time identity signaling matters at the platform layer. Today, identity tools and security tools talk through integrations, which vary vendor to vendor. So, coverage is uneven, rollout i…