← Writing

Identity & access

SailPoint ISC vs IdentityIQ

I've spent real time in both. Here's the honest version of why Identity Security Cloud is the better bet for most teams — and the cases where IdentityIQ still earns its keep.

SailPoint sells two identity-governance products that look like cousins and behave like different generations.IdentityIQ(IIQ) is the on-prem workhorse a lot of large enterprises still run.Identity Security Cloud(ISC, once called IdentityNow) is the SaaS platform SailPoint now builds most of its future on. If you're choosing today, I think ISC wins for the large majority of teams — not because IIQ is bad, but because the model underneath it has aged.

IIQ is a toolkit; ISC is a product

IIQ is astonishingly flexible. It's a Java application you host yourself, and almost anything can be customized — rules in BeanShell, workflows in XML, provisioning logic tuned to the exact shape of your org. That power is real, and for a genuinely unusual environment it can be the only thing that fits.

But that flexibility is also the bill. You own the servers, the database, the app tier, the upgrades. A major version upgrade is a project, not a Tuesday. All that custom BeanShell becomes yours to maintain forever, and the person who wrote it eventually leaves. I've watched teams spend more energy keeping IIQ running than governing identity with it.

The question isn't "can IIQ do this?" It almost always can. It's "who's going to maintain the thing you built to make it do this?"

What you actually operate

The clearest way to see the difference is to draw the box around "stuff you have to run and maintain." WithIdentityIQ, that box is enormous:

You / your team Own and operate the entire stack below on-premises
↓  host & maintain everything  ↓
IIQ app servers The Java application, on your machines your servers
Database The identity warehouse your DB
Connectors + custom code BeanShell rules, XML workflows yours to maintain forever
Upgrades · patching · scaling · backups A planned project every single time the hidden cost

IdentityIQ: total control, and total operational ownership. Everything in these boxes is yours.

WithIdentity Security Cloud, most of that box belongs to SailPoint, and you're left with the part that's actually about governance:

SailPoint · multi-tenant cloud Hosts, patches, scales, and continuously ships new features not your problem
↓  you connect through  ↓
V3 & Search APIs A real first-class interface to automate and build on API-first
Configuration Sources, roles, policies — configured, not coded no servers to run
Built-in AI Recommendations trained on cross-customer signal a cloud-only edge
You own: configuration & integrations only Time goes to governance, not infrastructure weeks to value, not months

ISC: you give up some deep customization and get back your whole operations budget.

Where ISC pulls ahead

ISC is multi-tenant SaaS, and that one fact cascades into most of its advantages:

  • No infrastructure tax.SailPoint runs it. You stop patching servers and start configuring governance. Time to first value drops from months to weeks.
  • Continuous delivery.Features land automatically instead of waiting for a heavyweight upgrade you have to plan and test. You're always on current.
  • API-first by design.ISC's V3 and search APIs are the real interface, not an afterthought bolted onto a UI. That makes it far easier to automate, integrate, and build on top of — which matters more every year.
  • Cross-tenant intelligence.Because it's cloud, SailPoint can train access recommendations and outlier detection on signal from across its customer base. That's data no single on-prem IIQ install can ever see.

The honest caveats

ISC trades some of IIQ's deep customizability for that simplicity. If your governance genuinely needs bespoke, deeply-nested workflow logic that the platform doesn't model, you'll feel the guardrails. IIQ also remains the answer for organizations that, for regulatory or sovereignty reasons, cannot run identity in someone else's cloud. And migrating years of IIQ customization to ISC is a real piece of work — SaaS doesn't mean "free lunch."

So the honest framing isn't "ISC good, IIQ bad." It's this: IIQ was built for a world where you ran everything yourself and customization was the whole point. ISC is built for a world where you'd rather spend your team's time on outcomes than on infrastructure, and where an API and a stream of improvements beat a folder of BeanShell. For most teams starting today, that second world is simply the one we live in.

My take

If you're greenfield, start on ISC and don't look back. If you're on IIQ and it's stable, don't rip it out on principle — but do plan the direction of travel, because that's where SailPoint's attention and its AI features are going. I wrote more about that AI shift inhow AI actually fits into IAM.