Leveraging the APIs to build missing certifications

Leveraging the APIs to build missing certifications

Source: YouTube · SailPoint · published Jul 1, 2026 · 27:54

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

Jeffrey Milanovich demonstrates how to leverage SailPoint's Python SDK and APIs to build a non-standard "access owner" certification that cannot be achieved using out-of-the-box configuration alone 3:34-3:45.

Key Takeaways:
• Out-of-the-box SailPoint certifications only support individual, governance group, or manager as certifiers, meaning access owners cannot natively certify their own entitlements 6:15-6:34.
• While workflows were considered, the 250-iteration loop limit made them unviable for large campaigns, leading to the selection of the Python SDK for its ability to chain API calls and handle complex logic 9:49-10:48.
• The solution creates a search-based access certification assigned to a placeholder governance group, then uses a Python script to programmatically reassign each access item to its actual owner 14:02-15:48.
• The script includes safeguards like a default certifier fallback for unowned items and a check to prevent assigning a user as both reviewer and reviewee 20:18-21:57.

This approach provides a repeatable, auditable method to consolidate access reviews into a single campaign. Future enhancements could include full automation via Lambda triggers or building a custom UI with SailPoint's UI toolkit 26:41-27:34.

Sources:

  • 3:34-3:45 Introduction of the access owner certification use case
  • 6:15-6:34 Limitations of out-of-the-box certifier options
  • 9:49-10:48 Why the Python SDK was chosen over workflows
  • 14:02-15:48 Setting up the base search-based certification with a governance group
  • 20:18-21:57 Handling default certifiers and preventing self-review conflicts
  • 26:41-27:34 Future improvements like automation and templating

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[music] >> Hi. My name is Jeffrey Milanovich. I'm with Instrumental Identity, and today my presentation is about leveraging the APIs to build non-standard certifications. A little bit about us at Instrumental Identity. We're an independent consulting company and a SailPoint partner for many years, and we work with our clients uh uh ISC and IIQ projects. Now, when you're growing your governance program, um you'll be working on many different types of certifications, and you'll have many factors that need to be taken into consideration. Um so, you'll have uh existing certifications that come from either uh manual processes or other um programs that are being replaced by SailPoint. Um you'll have auditor requirements if there are net new certifications, um and you may have uh internal company…