A focused course, tailored for you
The SailPoint IdentityIQ Build Playbook for Broker-Dealer IAM
From entitlement catalogue and birthright bundles to certifier-load tuning and audit-defensible joiner-mover-leaver flows in a regulated retail brokerage.
A leaver in HR yesterday still has an active AD account, Salesforce role, and Aladdin entitlement this morning. The certification campaign your SOX auditor is watching is stuck at 62 percent reviewer completion. The HR feed dropped two termination rows overnight and the deprovisioning workflow did not fire. You are the IdentityIQ engineer holding all three. This course is the build playbook that closes those gaps and leaves an audit trail your SOX 404 walk-through cannot fault.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
An IAM SailPoint developer inside a US retail brokerage does not get to treat IdentityIQ as a generic IGA platform. The certifier population is regulated. The leaver SLA is measured by FINRA-relevant supervisory rules, not by an internal NPS score. The entitlement catalogue is contaminated by twenty years of trading-desk role drift. The HR feed is fragile. The Salesforce and AD connectors quietly disagree about authoritative source. The certification campaign load is so heavy that line managers click-through without reading, which destroys the control. And the SOX general controls auditor is going to sample a leaver and a privileged-access change and a quarterly certification, and the artefacts you produce out of IdentityIQ are the evidence. The job is not configuring SailPoint. The job is configuring SailPoint so that the SOX 404 control walk-through, the internal audit IAM review, the FINRA inspection sample, and the line manager certifier all get a clean answer from the same source of truth. That requires entitlement catalogue work most teams skip, birthright modelling most teams over-engineer, certification design most teams template, and HR-feed handling most teams treat as someone else's problem.
What you walk away with
- Stand up an entitlement catalogue that an internal auditor and an application owner can both reconcile, with documented authoritative source per application.
- Model birthright access by job code and supervisory hierarchy so a new hire is productive on day one without over-entitlement.
- Rewrite the joiner-mover-leaver workflow rules so an HR feed outage degrades safely instead of leaving orphan accounts.
- Design certification campaigns line managers actually complete, with reviewer load under the threshold where click-through behaviour starts.
- Produce SOX 404 walk-through evidence and FINRA inspection artefacts directly from IdentityIQ without after-the-fact spreadsheet work.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules with downloadable BeanShell rule templates and workflow XML for every module.
- Entitlement catalogue intake template and application-owner attestation form.
- Joiner, mover, and leaver workflow rule packs with graceful-degradation patterns for HR feed outages.
- Certification campaign design templates with reviewer-load calculation worksheets.
- SOX 404 control-narrative templates and FINRA inspection evidence-package templates.
- Hand-built implementation playbook tailored to your specific connector mix and certifier population.
- Thirty-day money-back guarantee.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours, learning environment account provisioned and the hand-built implementation playbook delivered alongside it.
Modules 1 to 4 cover the operating frame, entitlement catalogue, HR feed, and birthright design. Two to four hours.
Modules 5 to 7 cover joiner, mover, and leaver workflow build. Four to six hours plus rule customisation.
Modules 8 to 10 cover certification design, role mining, and access request UX. Three to five hours.
Modules 11 to 12 cover SOX and FINRA evidence production and the build-to-run handover. Two to three hours.
Total self-paced commitment: roughly twelve to twenty hours across two to four weeks.
Before and after
Certification campaigns stall, leavers occasionally retain access past SLA, the entitlement catalogue is contaminated with deprecated entries, the HR feed is fragile, and producing SOX walk-through evidence is a manual spreadsheet exercise.
Certifications close on time with reviewer load under the click-through threshold, leaver workflows survive HR feed outages without orphan accounts, the entitlement catalogue is application-owner-attested, and SOX and FINRA evidence is a one-click report out of IdentityIQ.
What happens if you do not address this
A single leaver who retains active trading-application access past the SOX timing control becomes a books-and-records issue at the next 404 walk-through. The remediation cost (control-failure remediation memo, expanded audit sampling, potential FINRA inquiry) is many multiples of the time investment to fix the workflows now. The IAM developer who fixed it before the auditor sampled it is the IAM developer who keeps the platform and earns the next promotion cycle.
Who it is for
An IdentityIQ developer or senior IAM engineer inside a US broker-dealer or wealth-management firm with a regulated certifier population, a SOX 404 obligation, a fragile HR feed, an AD plus Salesforce plus trading-application connector mix, and a quarterly access certification campaign that has been getting heavier each cycle. You write BeanShell, you tune workflows, you debug IIQ logs at the rule-execution level, and you sit between HR, AD operations, application owners, internal audit, and the SOX control owner.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable BeanShell rule templates, workflow XML, catalogue intake forms, certification design worksheets, and SOX and FINRA evidence-package templates for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Twelve to twenty hours total, self-paced, sequenced so each module's downloadable artefact is usable inside your IdentityIQ environment the same day.
Why $199 is the right number
SailPoint's own training catalogue is product-feature-focused and does not address the broker-dealer regulatory context, the SOX 404 control narrative, or the FINRA inspection evidence pattern. Vendor implementation partners deliver against statement-of-work scope and do not transfer the build skill. Generic IGA conference talks describe maturity models without the rule code an engineer can run on Monday. This course is the build-level work product an in-house IAM engineer needs.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.