Technology Partnership — SailPoint

SailPoint: identity governance that survives the audit

SailPoint automates the work that manual access reviews never quite finish: certifications, provisioning and the full joiner-mover-leaver lifecycle. Kommando implements it across the Nordics, so the control still holds the day the auditor arrives.

Start with an assessment: see your real access model before you automate it.

SailPointIdentity Governance

What is SailPoint?

The governance layer for who has access to what

SailPoint is a leading platform for Identity Governance and Administration (IGA). IGA is the discipline of making sure the right people have the right access to the right systems, and that you can prove it. SailPoint automates the parts that break down when done by hand: certifying who has access to what, provisioning accounts when people join or change roles, and removing access the moment they leave.

Most organisations already do access reviews. The problem is rarely that reviews are missing. It’s that they’ve become a formality, and a formality doesn’t survive scrutiny. SailPoint puts substance back into the control.

What it governs
  • Access certifications
  • Joiner, mover, leaver
  • Access requests & roles
  • Segregation of Duties
  • Audit evidence

The platform

The SailPoint platform, delivered by Kommando

Access Certifications & Reviews

The quarterly review that 400 managers approve in an afternoon without reading a line isn't a control, it's paperwork. SailPoint runs continuous, policy-driven certifications that show the actual access, flag what changed, and record real decisions. See our IGA practice.

Provisioning & Lifecycle (JML)

Joiners wait days for access; leavers keep it for months. SailPoint connects to your source of truth and provisions, changes and revokes access automatically as people join, move and leave. Movers are where most access creep hides.

Access Requests & Roles

Users request access through self-service; policy and roles decide what's granted without a ticket queue. A clear role model means people get what the job needs and nothing it doesn't, which is the whole point of least privilege.

Compliance & Audit

Segregation of Duties enforced in policy, not in a spreadsheet. Every request, approval and certification is logged, so the evidence for NIS2, DORA and internal audit is already there when someone asks for it.

The compliance landscape

Why access reviews keep failing

Access reviews rarely fail because they don’t happen. They fail because reviewers are tired, the data is unreadable, and rubber-stamping is faster than reading. Auditors have caught on, and regulation has raised the bar: DORA’s Article 28 requires real-time insight into user rights and regular access reviews, and NIS2 issued its first penalties in early 2026.

Automation is what closes the gap. The platform does the gathering; the human does the deciding. In organisations we’ve worked with across finance and the public sector, the reviews don’t get harder once SailPoint is in place. They get shorter, and they mean something.

40–60%

faster audit cycles for organisations using automated IGA

Q1 2026

NIS2 issued its first administrative penalties, with access control a core obligation

The partnership

Kommando × SailPoint

Kommando is a SailPoint partner, and one of the specialists implementing SailPoint IGA in the Nordics. Our consultants have delivered identity governance in regulated environments where the access model has to stand up to an actual audit, not just look tidy in a demo.

That’s the difference an implementation partner makes: SailPoint gives you the platform, and we make it fit how your organisation actually works, including the role model, the connectors and the messy legacy applications nobody wants to touch.

Kommando team at a SailPoint event

Our approach

How Kommando delivers SailPoint

Assessment

We map your applications, roles and current access before designing anything. Often as part of a broader Identity Advisory engagement. It's usually the first time anyone has seen the whole picture.

Design

The role model, certification policies and provisioning rules. Get this right and everything downstream is easier; get it wrong and you automate the mess.

Implementation

SailPoint deployed and applications onboarded in waves, starting with the systems that carry the most audit and risk weight.

Managed services

We run and extend the platform as your application estate grows, so governance keeps pace instead of falling behind.
Get the role model right and everything downstream is easier. Get it wrong and you automate the mess.
— Kommando identity security team
Local delivery
Certified SailPoint consultants in Oslo, Gothenburg, Stockholm and Copenhagen. Local delivery, in your language and your time zone.

Frequently asked questions

Questions we actually get

What is the best way to automate access reviews in IGA?
The most effective approach is continuous, policy-driven certification instead of periodic spreadsheet reviews. A platform like SailPoint gathers who has access to what, resolves nested and inherited permissions so managers see the real privilege state, flags what changed since last time, and records the decision. That removes the rubber-stamping that makes manual reviews fail an audit. Kommando implements this for organisations across the Nordics.
What is the difference between IGA and IAM?
IAM (Identity and Access Management) is the broad category of managing identities and their access, including authentication and single sign-on. IGA (Identity Governance and Administration) is the governance layer within it: certifying access, enforcing Segregation of Duties, automating the joiner-mover-leaver lifecycle, and producing audit evidence. SailPoint is an IGA platform.
Which consultancies in Norway design IAM strategies?
Kommando designs and implements identity strategies across Norway, Sweden and Denmark, covering IGA with SailPoint, PAM with CyberArk, and MFA with Silverfort. We work from offices in Oslo, Gothenburg, Stockholm and Copenhagen, and our consultants have delivered these programmes in regulated Nordic environments.
How does SailPoint handle joiners, movers and leavers?
SailPoint connects to your authoritative source, usually HR, and provisions access automatically when someone joins, adjusts it when they change roles, and revokes it when they leave. The mover case matters most: it's where access quietly accumulates when people change jobs but keep their old permissions.
How do SailPoint and CyberArk work together?
They cover different layers. SailPoint governs who should have access and proves it (IGA); CyberArk secures and vaults the privileged credentials themselves (PAM). Used together, you govern access broadly and lock down the privileged accounts that carry the most risk. We implement both.

Next step

See how much of your access review can run itself

An assessment shows where automation removes manual effort, and where your current access model would struggle in an audit. If you want to talk through where you’re at, we’re happy to help.

  • Full picture of roles and access
  • Onboarding plan ordered by audit risk
  • Delivered locally across the Nordics

Oslo · Gothenburg · Stockholm · Copenhagen

Kommando identity security consultant at the office