Identity & Access · SAP BTP · SAP Cloud Identity Services
Financial Services SAP Ariba SAP BTP SAP Cloud Identity Services
How a 145-year-old mutual insurer automated identity provisioning from SailPoint to SAP Ariba via SAP Cloud Identity Services
A Large Mutual Insurance and Financial Services Company Delivered 2026
Mindset configured closed-loop, automated identity provisioning from SailPoint Identity Security Cloud into SAP Ariba in four weeks, replacing a manual, file-based process and giving the company's broader identity-modernization program a clean SAP integration.
By the numbers
-
4 weeks
From kickoff to a validated, working integration
-
0
Manual steps in the Ariba identity lifecycle
-
3 systems connected
SailPoint ISC, SAP Cloud Identity Services, SAP Ariba
Before
File-based and manual SAP Ariba provisioning
- User creation, role changes, and deactivations in SAP Ariba handled manually or via file-based processes.
- No automated bridge between the SailPoint identity authority and SAP, leaving access lifecycle events dependent on manual hand-offs.
- Identity modernization program in progress with a gap in the SAP integration layer.
After
Closed-loop automated identity lifecycle
- SAP Cloud Identity Services configured as the bridge between SailPoint ISC and SAP Ariba, with the full identity lifecycle automated.
- Role and entitlement provisioning into Ariba driven directly by SailPoint access requests, no manual steps.
- BTP governance deliverables and platform enablement in place for the internal team to own and extend.
Why this matters
A large mutual insurer mid-migration from SailPoint IdentityIQ to SailPoint Identity Security Cloud needed its SAP Ariba access lifecycle automated as part of the broader program. Four weeks to a working integration, no manual hand-offs, no disruption to the enterprise effort running in parallel.
The challenge
The company was already deep into an enterprise-wide identity modernization, moving its whole user base from SailPoint IdentityIQ on-premises to SailPoint Identity Security Cloud. As that migration progressed, one integration gap stood out: SAP Ariba still relied on file-based and manual provisioning. New employees, role changes, and deactivations had to be handled by hand, which meant delays, inconsistencies, and real exposure every time someone's access status changed.
The SAP piece had to slot cleanly into an existing enterprise program. It could not be a standalone build that created its own governance overhead. And with SailPoint already chosen as the identity authority, the answer had to route through SailPoint's cloud platform, not around it.
What we did
Mindset ran a focused four-week engagement to configure SAP Cloud Identity Services as the bridge between SailPoint Identity Security Cloud and SAP Ariba. The work started with a blueprint of the current SAP and BTP architecture, then modeled the desired future state with governance recommendations, a BTP services decision-tree document, and a toolset recommendation plan.
The core integration connected three systems: SailPoint Identity Security Cloud as the identity authority, SAP Cloud Identity Services handling the provisioning pipeline through Identity Directory and Identity Provisioning Service, and SAP Ariba as the downstream target. The configuration covered the full identity lifecycle: user creation and activation, attribute and role changes, and deactivation with automated access removal. Role and entitlement provisioning into Ariba flows directly from SailPoint access requests, with no manual steps in between.
The engagement also covered broader BTP platform enablement, including sub-account structure, shared services, trust and authentication configuration, and system connections. Mindset's BTP Cost Forecasting and Consumption tool was installed to give the team visibility into platform spending. The work was delivered fully remote alongside the company's internal teams and their SailPoint resources.
The outcomes
Automated, closed-loop identity provisioning from SailPoint Identity Security Cloud to SAP Ariba replaced the previous file-based and manual process. The company's SAP access lifecycle now runs without manual hand-offs: user creation, role and attribute changes, and deactivation all execute automatically when SailPoint processes an access event.
The integration was designed to fit inside an existing enterprise program rather than run alongside it, so the delivery approach mattered as much as the configuration. Four weeks from kickoff to a validated, working integration gave the broader modernization effort a completed milestone without disrupting parallel workstreams.
The project builds on an earlier BTP Enablement Workshop that established the platform foundation, and the governance deliverables produced here give the company's internal team the architecture documentation and decision framework to run and extend the configuration themselves.
If we built this today
Concept · not delivered scopeIdentity provisioning that checks its own work.
This is a forward-looking concept, not the scope we delivered on this engagement. It is the build we would reach for now, grounded in SAP that ships today.
This engagement bridged SailPoint's identity cloud to SAP Ariba through SAP Cloud Identity Services, and today the same closed-loop provisioning could carry an agent that watches every sync and flags the ones that drift before anyone files a ticket.
The data product
Governed identity-events data product on SAP Business Data Cloud
A governed dataset of provisioning events, job runs, and entitlement state pulled from SAP Cloud Identity Services and SAP Ariba. It grounds the agent in what was actually granted, to whom, and when, so a proposed correction is backed by real history rather than a guess.
Data product on SAP Business Data Cloud
The Joule agent
Identity Provisioning Reconciler
Watches the SailPoint Identity Security Cloud to SAP Cloud Identity Services to SAP Ariba flow and reads every provisioning job, target read and write, and entitlement mapping. When a sync drifts, a job fails, or an Ariba account lands without its expected role, it drafts the correction and the reason for a human to approve.
SAP Cloud Identity Services (Identity Directory, Identity Provisioning), SAP BTP, SAP Ariba · PROPOSE · Provisioning sync success rate and time to correct a failed or drifted entitlement
The Fiori app
SAP Cloud Identity Services admin console, with Joule in the launchpad
Honest category note. There is no S/4HANA Business AI Fiori app that owns cross-system identity provisioning. This work lives in the SAP Cloud Identity Services admin console and SAP BTP, where Joule can sit alongside to explain a failed provisioning job and propose the fix.
A BTP capability, not a Fiori app.
We'd mine the real provisioning process in SAP Signavio first, map the identity and BTP service landscape in SAP LeanIX, and lean on MIND accelerators to carry the old file-based provisioning over to the new agent-watched flow.
What we built
-
Full identity lifecycle automated: create, update, deactivate
Automated SailPoint ISC to SAP Ariba provisioning
End-to-end identity lifecycle integration connecting SailPoint Identity Security Cloud, SAP Cloud Identity Services (Identity Directory and IPS), and SAP Ariba, replacing file-based and manual user provisioning.
-
Access changes flow directly from SailPoint access events
Role and entitlement provisioning into Ariba
Automated role and entitlement provisioning driven by SailPoint access requests, eliminating manual Ariba access steps for new and changing users.
-
Architecture and governance documentation for internal team use
BTP architecture blueprint and governance deliverables
As-is architecture review and future-state model, plus a BTP services recommendation plan and a best-practices decision-tree document for platform governance.
-
Platform foundation ready for ongoing SAP cloud integration
BTP platform enablement
Sub-account structure, shared services, trust and authentication configuration, and system connections aligned to the enterprise SAP landscape.
-
Ongoing platform cost visibility
BTP Cost Forecasting and Consumption tool
Mindset's BTP cost management tool installed to give the team visibility into platform spending as the SAP cloud footprint grows.
-
Internal team equipped to own and extend the integration
IT-stakeholder advisory on Cloud Identity Services
Advisory sessions with IT stakeholders on SAP Cloud Identity Services architecture, guiding the team on how the provisioning integration fits the broader enterprise identity platform.