Search for SailPoint ISC today and you will meet three names for what SailPoint's own developer documentation calls one product: IdentityNow, Identity Security Cloud and, since August 2026, SailPoint Human Fabric. This guide explains what the platform does, how it is built, how it differs from SailPoint IdentityIQ (IIQ), and what changed in 2026, with every claim sourced and dated.
Quick answer: SailPoint Identity Security Cloud (ISC) is SailPoint Technologies' cloud-native identity governance platform. It builds one identity per person from HR and directory data, models access as access profiles and roles, automates joiner, mover and leaver changes, and runs access reviews and separation-of-duties checks. It was previously called IdentityNow, and SailPoint announced SailPoint Human Fabric as its evolution on 4 August 2026.
Already know what ISC is?
This page is the explainer. For the platform comparison read SailPoint IIQ vs ISC and IIQ vs IdentityNow; for the course itself see the SailPoint ISC training guide.
What is SailPoint ISC (Identity Security Cloud)?
SailPoint Identity Security Cloud (ISC) is SailPoint Technologies' cloud-native, multi-tenant identity governance and administration (IGA) platform, delivered as software-as-a-service. SailPoint ISC decides who gets access to which applications, automates joiner, mover and leaver changes, runs access reviews, and enforces separation-of-duties policies for employees, contractors and non-human accounts.
The problem it solves is access sprawl: permissions pile up as people change teams, and nobody can answer "who has access to what, and why?" at audit time. Governance platforms such as SailPoint ISC keep one central record of identities and access. For the wider category, see our explainer on identity governance and administration (IGA) and the broader overview what SailPoint is and what it sells.
Is SailPoint ISC the same as IdentityNow, and what is SailPoint Human Fabric?
SailPoint Identity Security Cloud (ISC) is the same product as IdentityNow under a newer name. On 4 August 2026 SailPoint announced SailPoint Human Fabric as the evolution of Identity Security Cloud, and SailPoint's developer documentation states the product is the same and only the name has changed.
| Name | Status in October 2026 | Where you will still see it |
|---|---|---|
| IdentityNow | Original product name | Older tutorials, resumes, community posts and the old certification names |
| Identity Security Cloud (ISC) | Name used in most 2026 job descriptions | Job ads, training courses, SailPoint University, practitioner discussions |
| SailPoint Human Fabric (SHF) | Announced 4 August 2026 as the evolution of ISC | SailPoint's product pages and developer documentation |
Sources: SailPoint announcement (4 August 2026) and SailPoint developer documentation. The documentation states: "The product is the same — only the name has changed."
Practitioners have not all adopted the new name: a SailPoint Developer Community thread on the rename, started on 22 September 2026, drew mostly critical replies. For learners the practical rule is simple. Expect ISC, IdentityNow and Human Fabric to be used interchangeably in interviews and job ads, and write "SailPoint Identity Security Cloud (ISC)" on a resume. Our guide to what happened to IdentityNow covers the older name in detail.
What does SailPoint ISC actually do?
SailPoint ISC does five jobs: it builds one identity per person from authoritative sources such as HR systems, models access as entitlements, access profiles and roles, automates provisioning as people join, move and leave, runs certification campaigns, and enforces separation-of-duties policies against rules such as SOX.
Identity profiles
Combine accounts from HR, directories and applications into one identity, with lifecycle states such as active, leaver or on leave.
Access model
Entitlements roll up into access profiles, and access profiles into roles, so access is requested and reviewed in business terms.
Certification campaigns
Managers and owners periodically confirm or revoke access, producing the audit evidence regulators ask for.
Separation of duties
Policies flag toxic combinations, such as the same person creating and approving a payment.
Third-party summaries add self-service access requests, role mining, and pre-built policy libraries for SOX, HIPAA and PCI-DSS (SecurityScientist overview). Our deep dives on access certification and separation-of-duties policy show how those controls behave in practice.
How does SailPoint ISC work: tenant, virtual appliance and sources?
SailPoint ISC works in three layers: a SailPoint-hosted multi-tenant tenant that holds identities and policy, virtual appliance (VA) clusters inside the customer network that reach on-premises systems, and sources, which are connector-based links to each application. Practitioners onboard an application by creating a source, aggregating its accounts and correlating them to identities.
A SailPoint Developer Community architecture thread by Rohit Wekhande describes the VA as a Linux-based appliance, recommends at least two VAs per cluster, and says VAs handle outbound communication between the tenant and target systems through queue-based requests (SailPoint Developer Community). Because the tenant is SaaS, SailPoint operates the core platform; the customer operates the VAs. The same thread notes that Active Directory needs the IQService component for provisioning, although aggregation works without it.
The working sequence for onboarding one application follows the same thread:
Create the source
Choose an out-of-the-box connector, enter connection details and test the connection.
Update the account schema
Tell ISC which account attributes to read from the application.
Aggregate accounts and entitlements
Pull accounts and their access from the application into the tenant.
Correlate accounts to identities
Match each account to a person using correlation rules, so one identity owns many accounts.
Shape identities with profiles, lifecycle states and transforms
Identity profiles define attributes and lifecycle states; JSON transforms reshape values such as usernames or departments.
Package access into access profiles and roles
Group entitlements so requests, reviews and provisioning work at business level.
For the appliance layer see what a SailPoint ISC virtual appliance is; for the data-shaping layer read SailPoint ISC transforms explained. Practitioners who have only used the on-premises product will find the same governance ideas wrapped in a different delivery model, covered in IIQ-to-ISC migration skills.
What are the 2026 AI and agent features in SailPoint ISC?
In 2026 SailPoint added AI features around ISC: on 9 March 2026 it introduced a Harbor Pilot agent for guided access requests and new connectors to discover AI agents from platforms including Microsoft 365 Copilot, Databricks, Amazon Bedrock and Salesforce Agentforce. SailPoint also said a next-generation certification engine and a Separation of Duties revamp would follow in late 2026.
SailPoint's 4 August 2026 Human Fabric announcement organises the platform around three pillars: Discover, which uses the SailPoint Identity Graph and AI to find hidden access risk; Govern, which automates lifecycle controls and AI-guided reviews; and Protect, which enforces just-in-time access to reduce standing privilege (SailPoint press release, 9 March 2026, SailPoint blog, 4 August 2026).
What this means for a learner: the AI layer sits on top of the governance foundation. Sources, correlation, identity profiles, transforms, access profiles, certifications and separation of duties are still what implementation work is made of, so learning them first remains the sound order.
How is SailPoint ISC different from SailPoint IdentityIQ (IIQ)?
SailPoint ISC is a SailPoint-hosted SaaS platform configured mainly through sources, transforms, APIs and workflows, while SailPoint IdentityIQ (IIQ) is software the customer deploys and runs, extended through BeanShell rules and Java. Both implement the same governance ideas, which is why many employers ask for both skill sets.
| Dimension | SailPoint ISC | SailPoint IdentityIQ (IIQ) |
|---|---|---|
| Delivery | SaaS, multi-tenant, hosted by SailPoint; VAs for on-premises systems | Software installed and operated by the customer |
| Customisation | Transforms (JSON), APIs, workflows, configuration | BeanShell and Java rules, XML objects, plugins |
| Upgrades | SailPoint rolls releases out to the tenant | Customer plans installs, upgrades and patches |
| Typical work | New cloud deployments and IIQ-to-ISC migrations | Large existing estates, integrations and rule-heavy customisation |
Comparison compiled by IAM Careers from SailPoint documentation, community threads and 2026 job postings.
IAM Careers teaches IIQ in its live online SailPoint IIQ training program, which follows a 14-module IIQ curriculum, and teaches ISC in the separate SailPoint ISC course. The full comparison, with job-market data, is in SailPoint IIQ vs ISC.
Want to see ISC and IdentityIQ side by side?
Attend a free 60-minute live demo before you decide. No payment, no commitment. Ask which platform suits your background.
Who hires for SailPoint ISC skills, and can freshers learn ISC?
Naukri listed 904 SailPoint ISC-related openings in India on 9 July 2026, ahead of 685 IdentityIQ-specific listings, led by Bengaluru, Delhi NCR and Hyderabad. Wipro advertised a SailPoint ISC Developer role on 13 July 2026 that required three to five years of identity and access management experience and made ISC expertise mandatory.
The Wipro description (Wipro careers page) also lists cloud security knowledge across Azure, AWS and GCP, ITIL service delivery and security frameworks such as NIST and ISO 27001, and calls the SailPoint administrator certification advantageous. It shows the usual pattern: ISC roles reward people who already understand IAM, so freshers should build IT and IAM fundamentals first. Our dated breakdown of the ISC job market in India and ISC salary guide covers cities, employers and pay bands, and the IAM career paths page maps the wider ladder.
Outside India, the same governance demand exists. In the United States, SOX audit requirements are a common reason enterprises buy identity governance platforms such as SailPoint ISC; in the United Kingdom, FCA expectations and UK GDPR play a similar role for banks and insurers. See SailPoint jobs in the USA and SailPoint jobs in the UK for market data.
How do you learn SailPoint ISC, and what does it cost?
To learn SailPoint ISC, start with IAM and IGA fundamentals, then practise sources, transforms, identity profiles, access profiles, certifications and separation of duties. IAM Careers' live online SailPoint ISC course costs Rs. 27,000, runs as a 45-day live program on Zoom taught by Kiran, who has 10+ years in IAM, and limits each batch to 15 learners.
The hard part of ISC is practice, not theory. SailPoint sells ISC to organisations, so individuals cannot buy a personal copy, and self-taught learners often stall at the first real source. Structured training with guided hands-on labs closes that gap. Our how to learn SailPoint ISC guide sets out the full roadmap, and free ISC learning resources lists what exists at no cost. IAM Careers provides career guidance, resume support and interview preparation, but never guarantees a job.
If you are weighing official exams as well, read SailPoint ISC certification cost in India. Every class is live and every class is recorded in the LMS. Ask on WhatsApp (+91 93909 81953) for the next batch date.
Frequently Asked Questions
Explore More from IAM Careers
Learn SailPoint ISC With a Live Trainer
IAM Careers' live online SailPoint ISC training: Rs. 27,000, 45-day live program on Zoom, maximum 15 learners per batch, recordings in the LMS. Ask on WhatsApp (+91 93909 81953) for the next batch date. Attend a free 60-minute demo first. No payment. No commitment.
SailPoint Technologies is the product vendor; IAM Careers is an independent training provider and issues an IAM Careers certificate of completion, not an official SailPoint certification. Product names mentioned are trademarks of their owners and are used for identification only.