Technology Partnership — SailPoint
SailPoint: identity governance that survives the audit
SailPoint automates the work that manual access reviews never quite finish: certifications, provisioning and the full joiner-mover-leaver lifecycle. Kommando implements it across the Nordics, so the control still holds the day the auditor arrives.
Start with an assessment: see your real access model before you automate it.
What is SailPoint?
The governance layer for who has access to what
SailPoint is a leading platform for Identity Governance and Administration (IGA). IGA is the discipline of making sure the right people have the right access to the right systems, and that you can prove it. SailPoint automates the parts that break down when done by hand: certifying who has access to what, provisioning accounts when people join or change roles, and removing access the moment they leave.
Most organisations already do access reviews. The problem is rarely that reviews are missing. It’s that they’ve become a formality, and a formality doesn’t survive scrutiny. SailPoint puts substance back into the control.
- Access certifications
- Joiner, mover, leaver
- Access requests & roles
- Segregation of Duties
- Audit evidence
The platform
The SailPoint platform, delivered by Kommando
Access Certifications & Reviews
The quarterly review that 400 managers approve in an afternoon without reading a line isn't a control, it's paperwork. SailPoint runs continuous, policy-driven certifications that show the actual access, flag what changed, and record real decisions. See our IGA practice.
Provisioning & Lifecycle (JML)
Joiners wait days for access; leavers keep it for months. SailPoint connects to your source of truth and provisions, changes and revokes access automatically as people join, move and leave. Movers are where most access creep hides.
Access Requests & Roles
Users request access through self-service; policy and roles decide what's granted without a ticket queue. A clear role model means people get what the job needs and nothing it doesn't, which is the whole point of least privilege.
Compliance & Audit
Segregation of Duties enforced in policy, not in a spreadsheet. Every request, approval and certification is logged, so the evidence for NIS2, DORA and internal audit is already there when someone asks for it.
The compliance landscape
Why access reviews keep failing
Access reviews rarely fail because they don’t happen. They fail because reviewers are tired, the data is unreadable, and rubber-stamping is faster than reading. Auditors have caught on, and regulation has raised the bar: DORA’s Article 28 requires real-time insight into user rights and regular access reviews, and NIS2 issued its first penalties in early 2026.
Automation is what closes the gap. The platform does the gathering; the human does the deciding. In organisations we’ve worked with across finance and the public sector, the reviews don’t get harder once SailPoint is in place. They get shorter, and they mean something.
faster audit cycles for organisations using automated IGA
NIS2 issued its first administrative penalties, with access control a core obligation
The partnership
Kommando × SailPoint
Kommando is a SailPoint partner, and one of the specialists implementing SailPoint IGA in the Nordics. Our consultants have delivered identity governance in regulated environments where the access model has to stand up to an actual audit, not just look tidy in a demo.
That’s the difference an implementation partner makes: SailPoint gives you the platform, and we make it fit how your organisation actually works, including the role model, the connectors and the messy legacy applications nobody wants to touch.
Our approach
How Kommando delivers SailPoint
Assessment
Design
Implementation
Managed services
Get the role model right and everything downstream is easier. Get it wrong and you automate the mess.
Frequently asked questions
Questions we actually get
What is the best way to automate access reviews in IGA?
What is the difference between IGA and IAM?
Which consultancies in Norway design IAM strategies?
How does SailPoint handle joiners, movers and leavers?
How do SailPoint and CyberArk work together?
Next step
See how much of your access review can run itself
An assessment shows where automation removes manual effort, and where your current access model would struggle in an audit. If you want to talk through where you’re at, we’re happy to help.
- Full picture of roles and access
- Onboarding plan ordered by audit risk
- Delivered locally across the Nordics
Oslo · Gothenburg · Stockholm · Copenhagen