IAM Data Onboarding for Compliance
Bringing Rippling's identity and access report data into Automated Compliance so provisioning and access-review monitors could use the right source of truth.
Overview
Access-review evidence depends on records of who has access to what, when access was granted, and when it was removed. Those records lived with the Identity and Access Management (IAM) team, but Automated Compliance could not yet use them directly for some workflows. Customers still had to bridge the gap with exports and uploads.
The integration closed part of that gap for provisioning and access-review evidence. I partnered with the IAM team to bring their ledger and report data into Automated Compliance, so monitors could use it directly instead of depending on a separate manual collection step.
What I built
The ownership boundary was explicit: IAM owned the identity data, and I owned the Automated Compliance integration. My side was identifying the reportable datasets we needed, scoping report access to eligible customers, and fixing report joins so IAM rows surfaced. I also migrated beta monitors onto the new fields.
After the migration, IAM-backed provisioning monitors could use the same report-template pattern as other automated evidence paths. The report joins and field changes mattered because a monitor needed to see the relevant app access history before it could evaluate the evidence.
We kept the compliance interpretation on our side. IAM supplied the access records; Automated Compliance used them to evaluate a requirement and present its evidence. That let us reuse the source data without asking the IAM team to own compliance behavior.
Collaboration
I partnered with the IAM team on source records, report fields, customer access gating, and the boundary between identity ownership and compliance interpretation.
Outcome
- Provisioning and access-review reports can run against IAM-backed data.
- Provisioning and access-review evidence moved into report-backed monitors for workflows that had relied on exports or incomplete paths.
For this integration, making the data available was only part of the job. We also had to establish which customers could access it, get the joins right, and move existing monitors onto the fields they would actually use.