TLDR: SailPoint governs every app that supports identity standards. But most enterprise app portfolios include dozens to hundreds of apps that don’t (no SCIM, no API, or no path to a connector). Cerby connects to those apps using UI automation and AI, extends SailPoint’s governance to the full portfolio, and keeps connectors working automatically when apps change. The result is complete, fully automated coverage, with no manual processes filling the gaps. This article maps out how, and how you can too.
Imagine building a fence around your home. You find out some sections of the ground won’t hold a standard post, so those areas stay open. You tell yourself those insecure gaps are just part of the property and accept them.
Come to find out, your perimeter can be completely secure, and those gaps aren’t problems you simply have to accept.
Of course, we’re not actually talking about fences here. At least not the kind in your yard. Many teams accept similar gaps in their identity perimeter, and you don’t have to.
In our world, this might look like a project management app the operations team adopted two years ago, a handful of vendor portals from an old partnership, or a legacy application from an acquisition that was never integrated. These are tools the business purchased without involving IT, and it happens all the time.
These are accepted risks. And they exist because of the apps, not the governance platform. Many apps (especially business-critical ones) don’t support SCIM or user management APIs, so there’s no conventional path to bringing them into SailPoint. So they sit outside the governance program: they’re reviewed manually if anyone remembers to, governed inconsistently, or excluded from the scope the program can claim to cover.
This is the problem SailPoint and Cerby solve.
SailPoint and Cerby are official integration partners, working together to secure your entire security perimeter. SailPoint governs identity across applications that support standard protocols. Cerby extends that governance to disconnected apps (those that lack SCIM, user management APIs, or native connector support), so organizations can run a complete governance program across their full app portfolio through the platform they already use.
What is SailPoint and How Does it Work
SailPoint leads enterprise identity governance for good reason. Access certifications, separation-of-duties enforcement, automated provisioning and deprovisioning, and audit-ready access data—it all runs through a single platform across every application that supports a standard protocol.
A significant portion of every enterprise app portfolio was built by vendors who never adopted identity standards. We’re talking legacy tools, proprietary SaaS platforms, vertical market software, or consumer-grade tools that business teams use because they worked and no one stopped them. These apps don’t expose the interfaces a connector depends on. There's just nothing to connect to.
So the workarounds grow, and we deem the problem unsolvable. Flat file exports that feed SailPoint access data on a schedule are stale the moment they are generated and potentially incomplete by the time they are processed. Another common workaround is provisioning and deprovisioning tickets by human administrators, wherever a human admin can log in and make the change by hand. Or certification campaigns that simply exclude the apps no one has figured out how to include.
Connected and covered were never the same thing. The gap between them is where the real exposure lives, and it’s also where identity teams spend a surprising amount of time. But now, they don’t have to.
What Does Cerby Do and How Does It Work
Cerby does not ask disconnected apps to support identity standards. Rather, it connects to them the way an admin would (through the application’s own admin interface), then automates that process at scale and maintains it when the app changes.
There are three core parts of the product that make this work:
Scout maps the application before Cerby automates anything. It learns the admin interface the way an experienced admin would approach a new tool: where users live, how roles and entitlements are assigned, what the provisioning workflow looks like from start to finish. The output is a connector trained on the actual application.
The CHAOS Engine runs the governance workflows. It pulls live user and entitlement data directly into SailPoint’s identity catalog. It provisions access for new employees, updates roles when someone changes teams, and revokes access the moment someone is offboarded. Every step runs the same way, every time, with no interpretation required and no human in the loop.
Drift handles what happens when apps change. Vendors update their interfaces. Fields get renamed. Steps get added to workflows. Traditional connectors break when this happens and stay broken until an engineer finds time to fix them. Drift monitors live integrations continuously, detects shifts, and repairs the connector automatically before a breakage creates a coverage gap or surfaces in an audit.
No API documentation is required, and new apps can go live in days. What was that about an unsolvable problem, again? 😎
How SailPoint and Cerby Work Together
Think of this duo as your identity’s Batman and Robin. While we argue about who is who, all you need to know is that our integration does not change how SailPoint works. It remains the system of record for identity governance — where policies live, where certifications run, where approvals are managed, and where audit evidence is stored. Cerby is the execution layer between SailPoint and the apps that SailPoint could not previously reach.
Here is what that looks like:
- App onboarding: When a disconnected app needs to come into the governance program, Scout learns it. There is no connector build project, no requirement for the vendor to support any identity standard, and the app is operational in days.
- Live entitlement surfacing: Cerby pulls real-time user and entitlement data from the app and surfaces it into SailPoint’s identity catalog. Current data, accurate at the time of any certification, access review, or audit query (not a flat file from last Thursday).
- Lifecycle automation: SailPoint runs automated joiner/mover/leaver on disconnected apps through Cerby. Cerby provisions access for new hires, updates it when someone changes teams, and revokes it on departure, so the same lifecycle SailPoint runs everywhere else now reaches apps that never supported it.
- Closed-loop remediation: When a SailPoint certification campaign flags inappropriate access on a disconnected app, Cerby revokes it. There’s no admin ticket required, and no open finding waits on a manual step.
- Self-healing: When the app’s interface changes, Drift detects it and repairs the connector before coverage breaks. The governance program stays continuous.
SailPoint stays in command. Cerby carries its policies into the apps that were always out of reach. I think we just realized which one of us is Batman …
Where Cerby + SailPoint Deliver Immediate Value
The SailPoint and Cerby integration applies across many situations identity teams experience often. Here are a few worth discussing:
Joiner/mover/leaver for apps outside the IdP: Imagine a new hire joins the creative team. Figma, Canva, or a niche tool the team has relied on for two years gets provisioned automatically because Cerby carries the lifecycle workflow from SailPoint into apps that have never supported it. When that employee leaves, the same automation handles the offboarding across every disconnected app in their access profile.
Certification campaigns with real coverage: This is the moment when an access certification runs across the full portfolio, not just the portion IT manages. When a reviewer certifies out an entitlement, the change happens. With no ticket or admin waiting to log in.
Contractor and agency offboarding: All companies work with some number of contractors or vendors. When one of those relationships ends, the same automated workflow that handles employee offboarding revokes access across every platform they touched (shared credentials, brand tools, ad platforms, you name it). Say goodbye to checklists or any fears of lingering access discovered in the next audit cycle … or seven years later.
Scaling coverage without scaling the backlog: The average acquisition typically introduces 20-100 new applications into a company’s estate. Some support SCIM and connect to SailPoint immediately. The rest get onboarded through Cerby in days, without a connector build project for each one. The governance program scales with the business rather than falling further behind it.
Why This Matters Now
The disconnected app problem has been around for years, but there are a few events making it more relevant and urgent.
AI tools are proliferating faster than IAM programs can keep up with. Every new AI application added to the enterprise is a potential disconnected app—a system that holds access and permissions, lacks a connector, and doesn't show up in the governance program. The number of apps outside the program is growing exponentially.
Auditors have moved past “which apps are in your IGA program” to “which apps are excluded and why.” The answer “we couldn't connect them” is increasingly treated as a finding rather than an explanation. Coverage gaps add audit prep time that compounds with every review cycle.
Identity teams are also being asked to govern more with the same headcount. Manual processes that worked when the app portfolio was smaller and the team was larger do not scale. Flat file exports, ticket-based provisioning, and spreadsheet access reviews were always workarounds. The cost of running them becomes clearer as the portfolio grows and the compliance pressure increases.
SailPoint + Cerby does not require rebuilding the governance program. It extends the one that already exists to apps that were never included.
Frequently Asked Questions
Are SailPoint and Cerby partners?
Yes. SailPoint and Cerby are official integration partners. Cerby is certified to integrate with both SailPoint IdentityIQ and SailPoint Identity Security Cloud. The integration extends SailPoint's governance to applications that do not support standard identity protocols, enabling complete portfolio coverage through the platform SailPoint customers already use.
What does Cerby add to SailPoint?
Cerby covers apps SailPoint cannot reach through traditional connectors—applications that lack SCIM or user management APIs. For those apps, Cerby automates provisioning and deprovisioning, surfaces live entitlement data in SailPoint's identity catalog, enables closed-loop remediation on certification findings, and automatically maintains connectors when app interfaces change. There is no custom connector development required.
How does the integration actually work?
SailPoint remains the governance system of record, where policies, certifications, approvals, and audit records live. Cerby acts as the execution layer for disconnected apps. Scout learns each app's admin interface. The CHAOS Engine runs governance workflows. Drift keeps connectors current when apps change. Live entitlement data flows continuously from Cerby into SailPoint's catalog.
What types of apps does Cerby connect to?
Cerby connects to any web-based application with an admin interface, whether it supports SCIM, SAML, or another identity standard. Common use cases include business SaaS tools adopted outside IT procurement, legacy and on-premises applications, proprietary vertical software, marketing and brand platforms, social media accounts, and any application the vendor never designed for enterprise identity integration.
Does Cerby replace SailPoint?
No. Cerby does not replace any part of SailPoint. SailPoint remains the identity governance platform. Cerby extends what SailPoint can govern to the applications traditional connectors cannot reach. The governance model, certification campaigns, access policies, and audit records all stay in SailPoint.
Does this work with IdentityIQ or only Identity Security Cloud?
Both. Cerby is certified for SailPoint IdentityIQ and SailPoint Identity Security Cloud. Connectors trained in an IIQ environment move to ISC without rework, which makes Cerby useful for customers in the middle of a platform migration — disconnected apps stay covered throughout the transition rather than becoming a project to defer.
What is the business case?
Coverage is the primary case. A governance program that doesn't reach every app in the portfolio delivers only a fraction of its potential value. monday.com expanded from 70% to 100% app coverage in 12 months, eliminated 3,300 hours of manual lifecycle work, recovered $400,000 in process costs, and achieved 280% total ROI. The secondary case is risk reduction: disconnected apps outside the governance program carry active access with no deprovisioning automation and no audit trail.
Is Cerby also a fence business?
No, of course not. That was a metaphor to make the problem easy to understand, and to help us write to you like a human, not a robot.
The Big Picture
Let’s go back to the fence for a moment. The problem was never the fence's quality or how it was built. It was that areas of the ground couldn’t hold a post, so those stretches stayed open, creating risk. And everyone agreed to call that normal or even unsolvable.
SailPoint built the fence. Cerby is what lets you finally drive a post into the ground that never should have held one, without touching a single board of the fence itself. The certifications, policies, and audit trail all stay exactly where they were. What changes is that there’s no more open ground.
An identity team that finishes a certification campaign knowing which apps were left out isn’t running a bad program. They’re running a program inside an incomplete perimeter. SailPoint + Cerby closes that gap. Coverage stops meaning “the apps we could reach” and starts meaning every app in the portfolio.
That change shows up in your audit readiness, in deprovisioning that actually happens instead of waiting on a ticket, and in the hours identity teams spend on manual work that shouldn’t exist in the first place.
If you want to know what your own coverage number looks like, there’s a reasonable place to start the conversation. If you’re curious, let’s talk.

SailPoint & Cerby are integration partners. Cerby is certified for both SailPoint IdentityIQ & SailPoint Identity Security Cloud.
Keep going with the SailPoint + Cerby conversation
Want to go a little deeper? In The Real Cost of Manually Governing Applications, Neil McGlennon from SailPoint and Bel Lepe from Cerby talk through the cost, risk, and day-to-day work of manually governing disconnected applications.