WardeDocs Administrators Connectors People using Warde warde.app

Connector guides

SailPoint Identity Security Cloud

Connect Warde to SailPoint Identity Security Cloud so it reads sources, roles and access, and sends grants and removals as ISC access requests.

With an ISC engine, ISC stays the system of record. Warde reads its sources, entitlements, roles and access profiles, matches each ISC identity's accounts to a ServiceNow user, and sends every grant and removal to ISC as an access request.

Before you start

You need:

1. Prepare ISC

Create a service identity

Create an identity for Warde and give it the ORG_ADMIN user level. Below ORG_ADMIN, ISC lists no entitlements, hides the status of the changes Warde sends, and refuses every removal.

Create a personal access token

Sign in as the service identity and create a personal access token. Warde stores the token's client ID and secret and exchanges them for a bearer token on each call. ISC's access request APIs need a token that acts as a user, which is why Warde uses a personal access token rather than an API client.

Give the token the scopes the ORG_ADMIN user level allows. If your policy restricts token scopes, keep at least these, which Warde relies on by name:

ScopeWhy
sp:search:readTo find a person who has no account on a source yet, by searching the correlation attribute
idn:entitlement:readTo read each entitlement's request configuration for the daily approval audit
idn:identity-history:readOptional. Needed before you switch on the role revocability or access profile reads below.
sp:my-personal-access-tokens:readOptional. Engine health then warns 30 days before the token expires.

Note the token's expiry date. When it expires, every call fails until you create a new token and enter it in Guided Setup.

Make the correlation attribute searchable

ISC search finds only identity attributes marked searchable. Mark the attribute you will use in Bind accounts to users as searchable in ISC.

Remove ISC approval steps from managed items

ISC applies its own approval steps to access requests, including Warde's. Warde has already run the approval, so an ISC approval step makes every change approved twice. Clear the approval schemes on the sources, roles, access profiles and entitlements Warde manages. The daily approval audit names any managed item that still has an approval step, and engine health shows them.

2. Set the endpoint in ServiceNow

  1. Open Connections & Credentials > Connections & Credential Aliases and open SailPoint ISC.
  2. Open its HTTP connection, SailPoint ISC - connection.
  3. Set Connection URL to https://<tenant>.api.identitynow.com, with nothing after it.
  4. Save.

3. Add the engine

In Guided Setup step 2, select Add an engine:

FieldValue
Engine nameSuch as SailPoint ISC (production)
ConnectorSailPoint ISC
Connection aliasSailPoint ISC
Client IDThe personal access token's client ID
Client secretThe personal access token's secret

Select Create engine, then Test connection. A pass means ISC accepted the token and listed sources.

Optional settings

On the engine form in the Admin Workspace:

FieldValue
Rate limit budgetAbout 100 calls in each 10-second window suits ISC's published limits
Connector configuration{"version_map": {...}} repoints an endpoint to a different ISC API version. Leave it empty unless support asks.

In Warde > Properties, under Inbound sync:

PropertyDefaultWhat it does
x_66256_warde.sync.isc_role_assignmentstrueReads each identity's role assignments
x_66256_warde.sync.isc_access_reasonstrueReads why ISC gave each piece of access: requested, given by a role's membership criteria, or added in the source
x_66256_warde.sync.isc_access_profile_assignmentsfalseReads access profiles given to a person directly rather than through a role. Without it, those are left out of My Access and reviews. Needs idn:identity-history:read.
x_66256_warde.sync.isc_role_revocabilityfalseAsks ISC which roles it will remove. A role ISC will not remove then goes to a person. Needs idn:identity-history:read and the ORG_ADMIN, HELPDESK or REPORT_ADMIN user level.

4. Bind accounts to users

In Guided Setup step 3, set the engine's pair, for example Engine attribute employeeNumber and ServiceNow user field employee_number. Use the attribute you marked searchable.

5. Run the first sync

In Guided Setup step 4, select Sync now, then Refresh until the counts settle. A large tenant can take hours; the assignment read pauses after three hours and resumes on the next run.

What Warde reads

ISCBecomes in Warde
Each sourceA collection, named by ISC. Rename it in ISC and Warde follows.
Each source's entitlementsEntitlements in that collection
Roles and access profilesEntitlements in a collection named <engine name>: Roles & Access Profiles
What a role or access profile containsLinks, so a review shows the role rather than its parts
Each accountAn account, matched to a user through its ISC identity. Uncorrelated accounts become orphans.
Account entitlements and role assignmentsHoldings, with why ISC gave each one

Only accounts can be read as a delta in ISC; everything else is a full read at the full-sweep interval.

End dates. ISC keeps a role's end date itself. For entitlements and access profiles, Warde keeps the end date and removes the access when it passes.

Approval audit. A separate job, Warde sync: approval audit, runs daily at 04:00. It finds managed items with an ISC approval step and reads the token's expiry. Sync now does not run it, so those health notes first appear the morning after you connect.

What Warde writes

Every grant and removal is an ISC access request (POST /v3/access-requests), carrying Warde's reference in its client metadata.

Finding the right identity. Warde uses the identity behind the person's account on that source. With no account, it uses the person's single identity on this engine, or searches the correlation attribute. If the search finds two identities, nothing is sent and the request goes to a person.

Refusals. A removal ISC says cannot be revoked, or of something not requestable, goes to a person. A removal refused because one is already outstanding is adopted rather than sent again.

When ISC does not answer. If a request times out or a gateway answers instead of ISC, Warde pauses writes to the engine and, on the next try, looks for the request in ISC by Warde's own submit reference instead of sending it again. If it is still not found after 30 minutes, the work goes to a person and is not sent again.

ISC account enable and disable are not automated; they go to a person.

Health and troubleshooting

The health check lists one page of sources with the token. Engine health also reports refused reads, managed items with an ISC approval step, and a token close to expiry.

MessageWhat to do
Accepted the client ID and secret but refused to list sourcesThe token works but lacks permission. Check the service identity's user level.
Listed no entitlementsGive the service identity the ORG_ADMIN user level
Refused to show the status of access requests (403)Give the service identity the ORG_ADMIN user level
Nothing was sent: not clear who in ISC this access change is forThe person has no account on the source and the correlation search found none or two. Check the correlation pair and that the attribute is searchable.
No usable connection URLSet the connection URL on SailPoint ISC - connection, with https://

Log lines for this connector start [Warde sync] and [Warde dispatch]. See Health, alerts and logs.

Endpoints Warde calls

MethodEndpointUsed for
POST/oauth/tokenExchanging the token for a bearer token
GET/v3/sourcesCollections, and the health check
GET/v2024/entitlementsEntitlements
GET/v3/accounts, /v3/accounts/{id}/entitlementsAccounts and what they hold
GET/v2025/identities, /v2025/identities/{id}Identities
GET/v3/roles, /v3/access-profilesRoles and access profiles
GET/v2025/identities/{id}/role-assignmentsRole assignments
POST/v3/searchFinding an identity by the correlation attribute
POST/v3/access-requestsGrants and removals
GET/v3/access-request-statusFollowing a request
GET/v2024/entitlements/{id}/entitlement-request-configThe approval audit
GET/v2025/historical-identities/{id}/access-items, .../eventsOptional: access profiles and role revocability
GET/v3/personal-access-tokensOptional: token expiry

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to hello@warde.app.

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.