SailPoint SaaS Connector
Manage identity and access to Keeper vaults with the SailPoint SaaS connector.

Overview
The Keeper Security connector provides identity governance for your Keeper enterprise through SailPoint Identity Security Cloud (ISC).
The connector aggregates accounts and refreshes individual accounts. It also aggregates node, team, role, folder, and record entitlements. You can create, update, enable, disable, and delete Keeper accounts.
This integration is going live soon. ETA August 2026
Features
Entitlement Aggregation
List roles available in your Keeper organization.
List teams available in your Keeper organization.
List nodes available in your Keeper organization.
List records and their permissions.
List folders and their permissions.
Account Aggregation
List users from your Keeper organization in SailPoint.
Map users to their existing Keeper Vault entitlements.
Account Update
Invite users from SailPoint and provision a Keeper Vault for each invited user.
Update the user's name and email in SailPoint
Assign available roles, teams, and nodes through SailPoint entitlement assignments.
Share records and folders through SailPoint record and folder entitlement provisioning.
Enable or disable access to the Keeper Vault through SailPoint.
Delete an account. This transfers its Keeper Vault to the target user configured in
sailpoint-app-setup, then removes the departing Keeper account.
Example use case
Invite User to Keeper Vault and share record
Complete Keeper account setup
The user accepts the Keeper invitation from their email. They then complete their vault setup.
The user's vault must be active before you share records directly with them. For invitation details, see Creating and Inviting Users.
Prerequisites
Keeper enterprise with administrative access to manage users, teams, roles, and sharing.
Keeper Commander Service Mode API v2 running and reachable from SailPoint or your approved network path, with a valid Service Mode API key.
SailPoint ISC administrator permissions to create sources, configure correlation, and run aggregations.
Commander Service Mode Setup
To keep zero-knowledge and end-to-end encryption, Commander Service Mode runs on your infrastructure and is the only path the SailPoint connector uses to talk to Keeper.
Use sailpoint-app-setup to create the Docker-based Service Mode deployment and SailPoint-specific settings in one flow.
Before you start
Install Keeper Commander on a workstation.
Prefer a dedicated Keeper service account with rights to manage enterprise users and to share the folders/records you will govern from ISC.
Log in to Commander with that account:
Ensure Docker is available on the host where Service Mode will run.
Run SailPoint setup
The command runs in two phases and writes a docker-compose.yml with a Commander-only service (no separate SailPoint container).
Phase 1 — Service Mode / Docker
Creates the shared folder, Docker config record, KSM application, and client config, then prompts for:
Port
Local port for Commander Service Mode. Default: 8900.
Enable ngrok?
Optional public URL via ngrok. Default: No.
Ngrok Auth Token
Required if ngrok is enabled.
Ngrok Custom Domain
Optional (for example myapp.ngrok.io). Press Enter to skip.
Enable Cloudflare?
Asked only if ngrok is disabled. Default: No.
Cloudflare Tunnel Token
Required if Cloudflare is enabled.
Cloudflare Custom Domain
Required if Cloudflare is enabled (for example commander.company.com).
Ngrok and Cloudflare are mutually exclusive. For SailPoint ISC (SaaS), the Service Mode URL must be reachable from SailPoint’s connector runtime. If Commander is on a private network, enable ngrok or Cloudflare Tunnel and use that public HTTPS URL as Keeper Commander Service Mode API URL in the source.
Queue mode (API v2) is enabled automatically. The command allowlist is limited to SailPoint-safe operations (user lifecycle and sharing). Secret-bearing commands such as get, export, and find-password are excluded.
Phase 2 — SailPoint options
Allow folder shares?
Whether SailPoint may manage folder share entitlements (share-folder / nsf-share-folder). Default: Yes.
Allow record shares?
Whether SailPoint may manage record share entitlements (share-record / nsf-share-record). Default: Yes.
Allow role assignment?
Whether SailPoint may assign roles via enterprise-user / enterprise-role. Default: Yes.
Allow team assignment?
Whether SailPoint may assign teams via enterprise-user. Default: Yes.
Transfer target email
Active user that receives vault data when SailPoint offboards via transfer-user. (required)
Interval seconds
How often Commander re-checks invited users and applies queued entitlements after they become Active. Default: 60. Minimum: 15.
Disabled capabilities are rejected by Service Mode (HTTP 403). Nodes are never gated —
--noderemains available for invites and moves.
Resources created (defaults):
Shared folder
Commander Service Mode - SailPoint
KSM application
Commander Service Mode - KSM App
Docker config record
Commander Service Mode Docker Config
SailPoint config record
Commander Service Mode SailPoint Config
Docker service / container
commander-sailpoint / keeper-service-sailpoint
Re-running setup rewrites
docker-compose.yml(manual edits are lost) but preserves queued pending entitlements on the SailPoint config record.
Deploy
Delete the local config.json before starting Docker so the container does not conflict with the same device token. Docker loads its own config through KSM.
Values for the ISC source
After the service is healthy:
Keeper Commander Service Mode API URL — public base URL without
/api/v2/(tunnel URL if you enabled ngrok/Cloudflare, otherwise your reachable host URL).Keeper Commander Service Mode API Key — from the Docker/service config record created during setup (stored in the vault after the container starts Service Mode).
Use those values in Source configuration.
Deferred entitlements (Invited users)
Keeper cannot fully apply some entitlements until the user is Active. Commander queues role, team, folder, and record grants requested while the user is still Invited, then applies them after activation (on the poll interval from Phase 2).
This matches ISC create behavior: initial roles / teams on create are applied once the user becomes active.
Optional CLI flags
--folder-name
Shared folder name
--app-name
KSM application name
--config-record-name
Docker/service config record name
--sailpoint-record-name
SailPoint config record name
--config-path
Path to Commander config.json
--timeout
Device timeout (default: 30d)
--skip-device-setup
Skip device registration if already configured
Source Configuration
Log in to SailPoint with administrator credentials. Go to Admin → Sources.

On the Sources page, click Create New. Search for Keeper Security, then select Configure.

Configure the source with a Source Name, Description, and Owner, then click Continue.

Under Configuration, set up the Keeper Commander Service Mode authentication credentials.

When configuration is complete, click Review and Test to verify the connection between Service Mode and SailPoint.

Entitlement Aggregation
After establishing the connection between Service Mode and SailPoint, run entitlement aggregation.
This step collects and lists available nodes, roles, teams, records, and folders with their permissions.
The Keeper Security SaaS Connector supports the following entitlement types.
Entitlement types
Node
An organizational unit in the Keeper enterprise hierarchy. Each user belongs to one node.
Team
A group of Keeper users. Assign this entitlement to add a user to the team.
Role
A role in Keeper. Assign this entitlement to grant its permissions.
Folder
Access to a shared folder, including its assigned permission level. This supports classic and nested shared folders (NSF).
Record
A record shared directly with a user, including its assigned permission level. This supports classic and nested shared folders (NSF).
Under Entitlement Management, click Entitlement Aggregation, then click Start Aggregation.

After entitlement aggregation completes, view the entitlements under Entitlements.

Account Aggregation
After entitlement aggregation completes, run account aggregation. This imports users from your Keeper enterprise and maps each user to their assigned entitlements and existing access.
Under Account Management, click Account Aggregation, then click Start Aggregation.

After aggregation completes, view the accounts under Accounts.

Select a user to view their assigned entitlements.

Entitlement Assignment
Follow these steps to assign entitlements.
Set up an access profile in SailPoint. See the official SailPoint documentation.
Under Manage → Entitlements in the access profile, select the entitlement to assign to the access profile.

After configuring the access profile, create a SailPoint role. Add the access profile and assign users who need its entitlements. See the official SailPoint documentation for creating roles.
Under Manage Access, add the access profile created earlier.

Click Define Assignment, then add the account or identity that needs the entitlement.

When configuration is complete, turn on Enable Role and apply the changes to provision the entitlements.
This provisions the entitlement to the user and assigns the teams, roles, and records configured in the SailPoint role.
Troubleshooting and logging
To review provisioning activity and troubleshoot errors, go to Admin → Identity Management → Activities.


Last updated

