IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Keeper & SailPoint link governance to privileged access

Keeper & SailPoint link governance to privileged access

Thu, 1st Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Keeper Security and SailPoint have launched an integration linking SailPoint's identity governance platform with KeeperPAM to automate privileged access governance across the two systems.

The integration connects SailPoint's identity governance and administration platform directly to Keeper's privileged access management system through a software connector. Roles and entitlements defined in SailPoint are automatically provisioned into KeeperPAM, including team memberships, shared folders, roles, nodes, records and administrative permissions.

Access decisions made in governance workflows can then flow into the privileged access vault without separate manual action. The arrangement also supports deprovisioning and entitlement changes when users change roles or leave an organisation.

For many businesses, identity governance and privileged access management have remained separate control layers. In practice, governance systems decide who should have access, while privileged access tools enforce those decisions for sensitive accounts and systems.

Without a direct link between the two, security teams often have to manually replicate approved changes in a vault or administrator console. That can create delays, inconsistencies or leave credentials in place after access should have been withdrawn.

Keeper said credentials are not exposed to SailPoint during the process, preserving its zero-knowledge model. Every grant, update and revocation is logged in both platforms, giving organisations an audit trail across governance and enforcement actions.

The integration also extends access certification reviews. When SailPoint runs a scheduled review, the process now includes privileged credentials, non-human identities and other identities managed by Keeper, creating a single record across both systems.

Security gap

Keeper cited its own 2026 research showing that 96% of senior IT leaders believe disconnected security tools create exploitable gaps. The same research found that 64% do not yet operate with fully consolidated privileged access governance.

Those figures reflect a broader issue in identity and access management, where companies have spent years adding separate governance, authentication and privileged account controls. Integrating those layers has become a bigger focus as security teams face pressure to tighten oversight of both human users and service or machine identities.

Federal and regulated environments are another target for the integration. Keeper said it supports requirements for account management, least-privilege enforcement and privileged credential control in environments that follow NIST Special Publication 800-53 Rev. 5.

It also said it holds FedRAMP High certification, FIPS 140-3 validation and a place on the CISA Continuous Diagnostics and Mitigation Approved Products List. Those credentials are likely to matter for public sector buyers assessing whether identity and privileged access tools meet procurement and compliance standards.

Market context

The deal highlights how identity vendors are trying to close operational gaps rather than simply add more stand-alone controls. Governance systems have long handled approvals, role definitions and periodic certification, while privileged access products have focused on vaulting credentials, enforcing role-based access and limiting standing privileges.

Bringing the two together can reduce the administrative burden on security teams that otherwise need to reconcile separate records of who was approved for access and who actually received it. It also addresses a common audit problem: reviewers can see governance decisions, but not always the final state of privileged credentials in downstream systems.

"The organizations that properly implement identity security understand that governance is only as strong as its enforcement," said Darren Guccione, Chief Executive Officer and Co-founder of Keeper Security.

"Seamless integration between IGA and PAM covering any type of human and non-human identity is an enormous gap for most enterprises. Our integration with SailPoint solves this," Guccione said.

The integration is available now for organisations already using SailPoint for identity governance and KeeperPAM for privileged access management.