
From static access to adaptive identity: How identity works in a world of change
Source: YouTube · SailPoint · published Jul 1, 2026 · 29:04
Identity drift—the gradual, invisible divergence of user access from its intended secure state—requires shifting from static, scheduled reviews to adaptive identity systems that continuously reevaluate access in real time 2:02-2:12 9:52-9:58.
Key Takeaways:
• Organizations typically rely on a "set and forget" model where access is provisioned but rarely cleaned up as roles change, causing access to drift silently 1:26-1:36.
• The traditional static model (assign, store, review) remains essential for compliance but acts only as a snapshot, failing to capture the constant flow of modern cloud and SaaS environments 5:46-5:55 7:52-8:01.
• Adaptive identity uses the same foundational building blocks but adds continuous feedback, making access decisions context-driven rather than calendar-driven 10:09-10:26.
• SailPoint enables this through programmable tools like event triggers, APIs, and just-in-time (JIT) provisioning, which automatically revokes ephemeral access when tasks complete 13:05-13:45.
• A live demo showed an ISC workflow instantly detecting an employee's department change to trigger automatic manager notifications and audit logging without manual tickets or admin credentials 26:24-27:07.
Adaptive identity doesn't replace your existing identity foundation; it fills the dangerous gaps between review cycles to keep access aligned with reality.
Sources:
- 2:02-2:12 Definition of identity drift
- 1:26-1:36 The "set and forget" access model
- 7:52-8:01 Periodic reviews as snapshots of a river
- 10:09-10:26 Four pillars of adaptive identity
- 13:05-13:45 Programmable tools and JIT provisioning
- 26:24-27:07 Demo recap comparing adaptive vs. traditional approaches
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] >> Hello, my name is Samantha Holstein and I am a senior developer advocate here at SailPoint. And today we are going to be talking about how identity actually works in a world that doesn't stand still and how we as builders and as developers about access in constantly changing systems. Let's start with a question. I want you all to think about the last time maybe you or someone on your team got promoted, moved to a new project, or maybe you brought on a new contractor for a few months. What happened to their access? Not what was supposed to happen, but what actually happened. If the honest answer is we reviewed it eventually or I think maybe someone filed a ticket, you're in the right place. That's exactly the gap that we're going to talk about today. Let's jump in. So here's the …