Autonomous Identity Security for all
Download resourcesAbout this session
Kacey Maher, a senior solutions consultant at SailPoint with 25 years in identity governance, explains why role-based access control exists and how AI can make it sustainable. He covers the case for roles (shared language for access, faster provisioning, least privilege, auditability), then contrasts three design strategies: enterprise-wide RBAC (thorough but prone to role explosion), use-case-based roles tied to a project such as onboarding a new application, and targeted roles for a specific population like bank tellers or seasonal workers, arguing real programs blend all three. He walks through top-down business-role analysis versus bottom-up IT-role mining from applications, stresses cleaning up access before modeling roles, and gives practical rollout tips: agree on an authoritative data source such as job title, ship roles without entitlements first to test assignment logic, then attach access gradually. The second half describes SailPoint's AI features: peer-group-based outlier detection that runs nightly access reviews, access history and review recommendations, and role insight suggestions that flag entitlements to add or roles to refactor as the organization changes, turning role maintenance from a periodic overhaul into continuous, incremental correction.
Learn how to leverage the power of Data Science and Artificial Intelligence in your organization’s Identity Security program from day 1 to maximize value and immediately lower your Identity Security risk. Kacey Maher will dive into how organizations can leverage autonomous identity security in the foundational phases of a program, the impact it has on program timelines/outcomes, and highlight how to “do more with less” while achieving higher levels of maturity.
Key takeaways
- Pick a design strategy deliberately: enterprise-wide RBAC covers everything but risks role explosion, so blend it with use-case roles tied to a project and targeted roles for high-turnover populations.
- Clean up existing access before modeling roles from it, especially on legacy applications; role design on dirty data is garbage in, garbage out.
- Agree with HR and application owners on an authoritative data source, such as job title, before basing birthright roles on it, or the roles will drift as the data changes.
- Roll out new roles without entitlements first to validate assignment logic at scale, then attach access gradually rather than provisioning everything at once.
- Use peer-group outlier detection to run access reviews continuously instead of once a year, so inappropriate access is caught and roles refactored while the change is still traceable.
Speakers

Kacey is a Jack-of-all-trades IT professional with 25 years of industry experience, 18+ of which have been spent exclusively working in the Identity Security space. Initially working as a Windows/Unix/DB administrator, he has worn many hats… Read moreRead less
Kacey is a Jack-of-all-trades IT professional with 25 years of industry experience, 18+ of which have been spent exclusively working in the Identity Security space. Initially working as a Windows/Unix/DB administrator, he has worn many hats throughout his extensive career: As an IAM analyst and architect he has designed, delivered, upgraded and supported complex large scale IAM solutions for industry leaders in the Healthcare, Finance, Insurance, Retail, Education and Government Spaces; as a trainer he has developed and delivered IAM training programs for everything from beginner-level admins to expert-level custom integrators; as a Senior Manager at multiple Big4 consulting firms he has lead teams in the successful delivery of IAM and security related work engagements; and now currently leverages his years of real-world implementation experience to help organizations identify the right answers to their burning Identity Security challenges. Kacey’s combined backgrounds give him a unique holistic view of the Identity Security space, the challenges and pitfalls encountered when implementing identity security programs, and how organizations can leverage industry leading offerings to overcome them.
