Skip to main content
Image coming soon

The SailPoint IdentityIQ Build Playbook for Broker-Dealer IAM

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The SailPoint IdentityIQ Build Playbook for Broker-Dealer IAM

From entitlement catalogue and birthright bundles to certifier-load tuning and audit-defensible joiner-mover-leaver flows in a regulated retail brokerage.

A leaver in HR yesterday still has an active AD account, Salesforce role, and Aladdin entitlement this morning. The certification campaign your SOX auditor is watching is stuck at 62 percent reviewer completion. The HR feed dropped two termination rows overnight and the deprovisioning workflow did not fire. You are the IdentityIQ engineer holding all three. This course is the build playbook that closes those gaps and leaves an audit trail your SOX 404 walk-through cannot fault.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

An IAM SailPoint developer inside a US retail brokerage does not get to treat IdentityIQ as a generic IGA platform. The certifier population is regulated. The leaver SLA is measured by FINRA-relevant supervisory rules, not by an internal NPS score. The entitlement catalogue is contaminated by twenty years of trading-desk role drift. The HR feed is fragile. The Salesforce and AD connectors quietly disagree about authoritative source. The certification campaign load is so heavy that line managers click-through without reading, which destroys the control. And the SOX general controls auditor is going to sample a leaver and a privileged-access change and a quarterly certification, and the artefacts you produce out of IdentityIQ are the evidence. The job is not configuring SailPoint. The job is configuring SailPoint so that the SOX 404 control walk-through, the internal audit IAM review, the FINRA inspection sample, and the line manager certifier all get a clean answer from the same source of truth. That requires entitlement catalogue work most teams skip, birthright modelling most teams over-engineer, certification design most teams template, and HR-feed handling most teams treat as someone else's problem.

What you walk away with

  • Stand up an entitlement catalogue that an internal auditor and an application owner can both reconcile, with documented authoritative source per application.
  • Model birthright access by job code and supervisory hierarchy so a new hire is productive on day one without over-entitlement.
  • Rewrite the joiner-mover-leaver workflow rules so an HR feed outage degrades safely instead of leaving orphan accounts.
  • Design certification campaigns line managers actually complete, with reviewer load under the threshold where click-through behaviour starts.
  • Produce SOX 404 walk-through evidence and FINRA inspection artefacts directly from IdentityIQ without after-the-fact spreadsheet work.

The 12 modules

Module 1. The Broker-Dealer IAM Operating Picture
What an IAM SailPoint developer at a US retail brokerage is actually accountable for, beyond the SailPoint product surface. The regulated certifier population, the SOX 404 control owners who depend on your artefacts, the FINRA supervisory rules that turn a leaver gap into a books-and-records event, and the trading-desk realities (Aladdin, order management systems, Salesforce Financial Services Cloud, legacy mainframe entitlements) that the platform has to model. Sets the frame for every later technical module.
Module 2. Entitlement Catalogue Cleanup at Scale
How to take a twenty-year contaminated entitlement set across AD, Salesforce, ServiceNow, and trading applications, and produce a catalogue an application owner will sign and an internal auditor will accept. Naming conventions, owner attestation, aggregation cadence, deprecated-entitlement handling, and the BeanShell rules that mark entitlements requestable versus non-requestable. Downloadable catalogue intake template and owner-attestation form.
Module 3. Authoritative Source, HR Feed, and the Identity Cube
Why the identity cube is only as good as the HR feed underneath it, and what to do when the feed is fragile. Workday or PeopleSoft connector tuning, hire and termination row handling, contractor and dual-employment edge cases, and the rules that decide what the cube does when HR drops a row overnight. Includes a graceful-degradation pattern so a feed outage does not silently leave leavers active.
Module 4. Birthright Access by Job Code
Modelling birthright bundles off job code, business unit, and supervisor relationship without producing the role explosion that makes every certification campaign unmanageable. The trade-off between fine-grained roles and bundle simplicity, the join rules that decide which bundle a new hire actually gets, and the SOX control narrative for why birthright access does not require a separate approval flow.
Module 5. Joiner Workflow That Survives Day-One
Building the joiner workflow so a new financial advisor or operations analyst is productive in the trading application stack on their first morning without any access request tickets. The HR-event-triggered provisioning rules, the AD account creation pattern, the Salesforce user provisioning with profile and permission set assignment, and the trading-application connector ordering. Downloadable workflow XML and BeanShell rule pack.
Module 6. Mover Workflow and the Quiet-Accumulation Problem
Why movers are the hardest population for IAM and what to do about it. The rule pack that detects job-code changes, the entitlement diff calculation, the supervisory approval pattern when a mover gains access that crosses a segregation-of-duties boundary, and the automatic deprovisioning of access the mover no longer needs. Designed for the front-office-to-middle-office and advisor-to-supervisor moves that dominate brokerage.
Module 7. Leaver Workflow With Audit-Defensible Timing
The leaver workflow that satisfies both the SOX timing control and the FINRA supervisory expectation. HR-event-triggered termination, the AD account disable pattern, the Salesforce user deactivation, the trading-application revocation order, the contractor end-date handling, and the orphan-account reconciliation that catches what the HR feed missed. Includes the evidence package an auditor will accept without follow-up sampling.
Module 8. Certification Campaign Design That Reviewers Finish
Why a 62 percent reviewer completion at day nine is a control failure, not a reviewer problem, and what to redesign. Reviewer load calculation, campaign segmentation by application criticality, the certifier-friendly UI choices, the escalation rules when a campaign stalls, and the closeout artefacts the SOX control owner needs. Designed to keep reviewer load under the click-through threshold where attestation behaviour breaks down.
Module 9. Role Mining Off Historical Access
How to mine roles from existing access patterns without producing the role explosion problem. The IdentityIQ role discovery workflow, the manual curation step that turns a mined role into a usable bundle, the role-owner attestation flow, and the rollback pattern when a candidate role does not survive review. Includes the role-mining decision log every internal auditor will ask for.
Module 10. Access Request UX and ServiceNow Ticket Reduction
How to redesign the access request experience so ServiceNow ticket volume drops and self-service adoption rises. The lifecycle-event preprovisioning that eliminates day-one tickets, the request catalogue layout that reduces wrong-item requests, the approval routing that handles supervisor and application owner in one pass, and the rejection pattern that does not leave the requester confused. Outcome target is measurable ticket reduction in one quarter.
Module 11. SOX 404 Evidence and FINRA Inspection Artefacts
What the SOX 404 IT general controls walk-through actually samples, what the FINRA inspection asks for when it touches IAM, and how to produce both from IdentityIQ directly. The control-narrative mapping, the evidence-package templates per control, the sampling-defence approach, and the corrective-action workflow when an exception is found. Designed so quarterly evidence production becomes a recurring report job, not a fire drill.
Module 12. From Build to Run: Sustaining the Platform
The handover from build to steady-state operation. Rule code review standards, the IdentityIQ release management pattern across dev and prod, the patching and version-upgrade approach, the on-call playbook for connector failures, and the relationship structure with HR operations, AD operations, application owners, internal audit, and the SOX control owner. Closes the course with the operating cadence an in-house IAM engineer needs to defend the platform across financial-statement-audit cycles.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

When the HR feed drops a termination row overnight and you have to detect the orphan account before the SOX auditor samples it.
When a quarterly certification campaign stalls at sub-70 percent reviewer completion and the control owner asks why.
When a financial advisor moves from a branch role to a supervisory role and quietly accumulates access neither HR nor the previous manager flagged.
When the FINRA inspection sample lands and you have one week to produce leaver-timing evidence and supervisory access change evidence from IdentityIQ.

What you get with this course

  • Twelve written modules with downloadable BeanShell rule templates and workflow XML for every module.
  • Entitlement catalogue intake template and application-owner attestation form.
  • Joiner, mover, and leaver workflow rule packs with graceful-degradation patterns for HR feed outages.
  • Certification campaign design templates with reviewer-load calculation worksheets.
  • SOX 404 control-narrative templates and FINRA inspection evidence-package templates.
  • Hand-built implementation playbook tailored to your specific connector mix and certifier population.
  • Thirty-day money-back guarantee.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours, learning environment account provisioned and the hand-built implementation playbook delivered alongside it.

Modules 1 to 4 cover the operating frame, entitlement catalogue, HR feed, and birthright design. Two to four hours.

Modules 5 to 7 cover joiner, mover, and leaver workflow build. Four to six hours plus rule customisation.

Modules 8 to 10 cover certification design, role mining, and access request UX. Three to five hours.

Modules 11 to 12 cover SOX and FINRA evidence production and the build-to-run handover. Two to three hours.

Total self-paced commitment: roughly twelve to twenty hours across two to four weeks.

Before and after

Before

Certification campaigns stall, leavers occasionally retain access past SLA, the entitlement catalogue is contaminated with deprecated entries, the HR feed is fragile, and producing SOX walk-through evidence is a manual spreadsheet exercise.

After

Certifications close on time with reviewer load under the click-through threshold, leaver workflows survive HR feed outages without orphan accounts, the entitlement catalogue is application-owner-attested, and SOX and FINRA evidence is a one-click report out of IdentityIQ.

What happens if you do not address this

A single leaver who retains active trading-application access past the SOX timing control becomes a books-and-records issue at the next 404 walk-through. The remediation cost (control-failure remediation memo, expanded audit sampling, potential FINRA inquiry) is many multiples of the time investment to fix the workflows now. The IAM developer who fixed it before the auditor sampled it is the IAM developer who keeps the platform and earns the next promotion cycle.

Who it is for

An IdentityIQ developer or senior IAM engineer inside a US broker-dealer or wealth-management firm with a regulated certifier population, a SOX 404 obligation, a fragile HR feed, an AD plus Salesforce plus trading-application connector mix, and a quarterly access certification campaign that has been getting heavier each cycle. You write BeanShell, you tune workflows, you debug IIQ logs at the rule-execution level, and you sit between HR, AD operations, application owners, internal audit, and the SOX control owner.

Who this is NOT for. This is not for SailPoint sales engineers, IdentityNow administrators looking for cloud-only guidance, IGA program managers who do not write rules themselves, or people who want a vendor-neutral identity-governance overview. The course is build-level IdentityIQ work for a regulated US brokerage population.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable BeanShell rule templates, workflow XML, catalogue intake forms, certification design worksheets, and SOX and FINRA evidence-package templates for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Twelve to twenty hours total, self-paced, sequenced so each module's downloadable artefact is usable inside your IdentityIQ environment the same day.

Why $199 is the right number

SailPoint's own training catalogue is product-feature-focused and does not address the broker-dealer regulatory context, the SOX 404 control narrative, or the FINRA inspection evidence pattern. Vendor implementation partners deliver against statement-of-work scope and do not transfer the build skill. Generic IGA conference talks describe maturity models without the rule code an engineer can run on Monday. This course is the build-level work product an in-house IAM engineer needs.

FAQ

Does this require an existing IdentityIQ deployment?
Yes. The course assumes IdentityIQ is installed and at least the HR and AD connectors are running. It is build work for the engineer responsible for the platform, not a from-zero installation guide.
Is IdentityNow covered?
No. The course is IdentityIQ specific. Workflow XML, BeanShell rules, and rule-execution logging are IIQ constructs.
How current are the regulatory references?
The SOX 404 control narrative and FINRA supervisory rule references are mapped to the current control framework an external auditor will sample. The playbook is updated when the underlying control framework changes.
Does the implementation playbook account for my specific connector mix?
Yes. The hand-built implementation playbook delivered alongside course access is tailored to the specific connectors, certifier populations, and HR feed pattern of your firm.
What if my role is on the architecture side rather than rule writing?
The course still applies. The architectural modules (1, 4, 11, 12) cover the operating frame, role model, evidence production, and build-to-run handover. The rule and workflow modules will read as design review rather than personal build, which is appropriate for architecture-level accountability.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.