WardeDocs Administrators Connectors People using Warde warde.app

Start here

Warde documentation

How to install, set up and run Warde, connect it to your identity system, and use it to ask for, approve and review access.

Warde is a ServiceNow application for access requests, access removal and user access reviews. People ask for access in your portal, the right people approve it, and your identity engine or a ServiceNow task carries out the change. Warde records who has what and why, and keeps that history as evidence.

Pick your guide

GuideForStart with
Administrator guideThe ServiceNow and identity team who install, set up and run WardeInstall Warde, then Guided Setup
Connector guidesWhoever owns the identity system Warde connects toHow connectors work
User guideEveryone who asks for, approves or reviews accessAsk for access

How Warde fits together

  1. Engines. Warde connects to the system that holds your access today: SailPoint Identity Security Cloud, SailPoint IdentityIQ or Microsoft Entra ID Governance. For applications with no identity engine behind them, ServiceNow tasks do the work.
  2. Import. Warde imports each engine's applications, entitlements, accounts and who holds what, and matches each account to a ServiceNow user.
  3. Onboard. An administrator takes each application through Collection Onboarding: an owner, a support group, an approval policy, who may ask for it, and plain names for its entitlements.
  4. Request. People ask for access with the Request Access form in your portal, for themselves or for others, and see what they hold on My Access.
  5. Approve. Approval policies send each request through the right approvers in order, with separation of duties checked on the way.
  6. Fulfil. The engine grants the access, or a ServiceNow task goes to the team that owns the application. A request reads done only when the change is confirmed.
  7. Review. Access review campaigns ask managers and owners to keep or remove what people hold, and removals go back through the same path.

Words used in these guides

WordMeaning
EngineA system Warde reads access from and writes access to, such as SailPoint or Entra ID. The ServiceNow task engine is the one with no external system.
CollectionOne application or source of access in an engine, such as an ISC source or an Entra application. Its entitlements are what people ask for.
EntitlementOne piece of access a person can hold: a group, a role, an app role, a licence, an access profile.
AccountA person's login in an engine. Each account is matched to one ServiceNow user.
HoldingA person holding an entitlement, with how it was granted and when.
Access bundleA set of entitlements requested, approved and granted together.
Approval policyThe approvers a request goes to, in stages, and what happens when a rule finds nobody.
CampaignOne run of an access review, with its scope and reviewers frozen when it starts.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to hello@warde.app.

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.