1"use strict";(globalThis.webpackChunkorbisid_docs=globalThis.webpackChunkorbisid_docs||[]).push([[9022],{7952(e,s,n){n.r(s),n.d(s,{assets:()=>l,contentTitle:()=>c,default:()=>a,frontMatter:()=>d,metadata:()=>t,toc:()=>o});const t=JSON.parse('{"id":"target-systems/saviynt","title":"Saviynt","description":"Description","source":"@site/docs/target-systems/saviynt.md","sourceDirName":"target-systems","slug":"/target-systems/saviynt","permalink":"/docs/target-systems/saviynt","draft":false,"unlisted":false,"tags":[],"version":"current","sidebarPosition":42,"frontMatter":{"sidebar_position":42,"title":"Saviynt"},"sidebar":"mainSidebar","previous":{"title":"SAP S/4HANA","permalink":"/docs/target-systems/sap-s4hana"},"next":{"title":"SCIM 2.0","permalink":"/docs/target-systems/scim"}}');var i=n(4848),r=n(8453);const d={sidebar_position:42,title:"Saviynt"},c="Saviynt",l={},o=[{value:"Description",id:"description",level:2},{value:"System Type Classification",id:"system-type-classification",level:2},{value:"Version Support",id:"version-support",level:2},{value:"Supported Protocol",id:"supported-protocol",level:2},{value:"What OrbisID Discovers",id:"what-orbisid-discovers",level:2},{value:"NHI Subtype Classification",id:"nhi-subtype-classification",level:2},{value:"Connection Requirements",id:"connection-requirements",level:2},{value:"Required Permissions",id:"required-permissions",level:3},{value:"Credential Mapping",id:"credential-mapping",level:3},{value:"Network Requirements",id:"network-requirements",level:3},{value:"Configuration Steps",id:"configuration-steps",level:2},{value:"Troubleshooting",id:"troubleshooting",level:2}];function h(e){const s={code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,r.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(s.header,{children:(0,i.jsx)(s.h1,{id:"saviynt",children:"Saviynt"})}),"\n",(0,i.jsx)(s.h2,{id:"description",children:"Description"}),"\n",(0,i.jsxs)(s.p,{children:["The Saviynt connector uses the ",(0,i.jsx)(s.strong,{children:"Saviynt REST API"})," to discover user accounts, security groups, entitlements, and access request data within a Saviynt Enterprise Identity Cloud (EIC) deployment. It authenticates using an API token and provides visibility into IGA-governed access across connected applications and enterprise systems."]}),"\n",(0,i.jsx)(s.h2,{id:"system-type-classification",children:"System Type Classification"}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"Field"}),(0,i.jsx)(s.th,{children:"Value"})]})}),(0,i.jsxs)(s.tbody,{children:[(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"System Type"})}),(0,i.jsx)(s.td,{children:"Application"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"Default Scan Priority"})}),(0,i.jsx)(s.td,{children:"500"})]})]})]}),"\n",(0,i.jsx)(s.h2,{id:"version-support",children:"Version Support"}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"OrbisID Edition"}),(0,i.jsx)(s.th,{style:{textAlign:"center"},children:"Supported"})]})}),(0,i.jsxs)(s.tbody,{children:[(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Community"}),(0,i.jsx)(s.td,{style:{textAlign:"center"},children:"No"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Pro"}),(0,i.jsx)(s.td,{style:{textAlign:"center"},children:"Yes"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Enterprise"}),(0,i.jsx)(s.td,{style:{textAlign:"center"},children:"Yes"})]})]})]}),"\n",(0,i.jsx)(s.h2,{id:"supported-protocol",children:"Supported Protocol"}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"Protocol"}),(0,i.jsx)(s.th,{style:{textAlign:"center"},children:"Port"}),(0,i.jsx)(s.th,{children:"Notes"})]})}),(0,i.jsx)(s.tbody,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"REST API (HTTPS)"}),(0,i.jsx)(s.td,{style:{textAlign:"center"},children:"443 TCP"}),(0,i.jsx)(s.td,{children:"Bearer token via OAuth 2.0 password grant"})]})})]}),"\n",(0,i.jsx)(s.h2,{id:"what-orbisid-discovers",children:"What OrbisID Discovers"}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"Data"}),(0,i.jsx)(s.th,{children:"Source"})]})}),(0,i.jsxs)(s.tbody,{children:[(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"User accounts"}),(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"POST /ECM/api/v5/getUsers"})})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Security groups (entitlements)"}),(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"POST /ECM/api/v5/getEntitlements"})})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Group memberships"}),(0,i.jsx)(s.td,{children:"Derived from user entitlement assignments"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"User enabled state"}),(0,i.jsxs)(s.td,{children:[(0,i.jsx)(s.code,{children:"statuskey"})," field (1 = active)"]})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Risk scores"}),(0,i.jsxs)(s.td,{children:[(0,i.jsx)(s.code,{children:"riskScore"})," per user"]})]})]})]}),"\n",(0,i.jsx)(s.h2,{id:"nhi-subtype-classification",children:"NHI Subtype Classification"}),"\n",(0,i.jsx)(s.p,{children:"This connector does not assert an NHI (Non-Human Identity) subtype directly \u2014 accounts are classified via the naming-pattern catalogue rules and AI classifier (Tier B) only. This connector queries global Identities rather than per-target Accounts, and Saviynt's own Account-Type concept lives on a different object entirely, a structural gap outside the scope of connector-level NHI classification."}),"\n",(0,i.jsx)(s.h2,{id:"connection-requirements",children:"Connection Requirements"}),"\n",(0,i.jsx)(s.h3,{id:"required-permissions",children:"Required Permissions"}),"\n",(0,i.jsx)(s.p,{children:"Create a dedicated Saviynt service account with access to the API endpoints."}),"\n",(0,i.jsx)(s.p,{children:"Minimum permissions:"}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"SAV Role"})," with ",(0,i.jsx)(s.code,{children:"View User"})," and ",(0,i.jsx)(s.code,{children:"View Entitlement"})," permissions"]}),"\n",(0,i.jsx)(s.li,{children:"API access enabled for the service account"}),"\n"]}),"\n",(0,i.jsx)(s.h3,{id:"credential-mapping",children:"Credential Mapping"}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"OrbisID Field"}),(0,i.jsx)(s.th,{children:"Value"})]})}),(0,i.jsxs)(s.tbody,{children:[(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"credential.username"})}),(0,i.jsx)(s.td,{children:"Saviynt service account username"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"credential.password"})}),(0,i.jsx)(s.td,{children:"Saviynt service account password"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsxs)(s.td,{children:[(0,i.jsx)(s.code,{children:"system.ipAddress"})," (the ",(0,i.jsx)(s.strong,{children:"IP Address / Hostname"})," field)"]}),(0,i.jsxs)(s.td,{children:["Saviynt tenant hostname (e.g., ",(0,i.jsx)(s.code,{children:"myorg.saviyntcloud.com"}),")"]})]})]})]}),"\n",(0,i.jsx)(s.h3,{id:"network-requirements",children:"Network Requirements"}),"\n",(0,i.jsx)(s.p,{children:"The OrbisID server must have HTTPS access to the Saviynt tenant on port 443."}),"\n",(0,i.jsx)(s.h2,{id:"configuration-steps",children:"Configuration Steps"}),"\n",(0,i.jsxs)(s.ol,{children:["\n",(0,i.jsx)(s.li,{children:"In the Saviynt EIC console, create a service account with read-only SAV Role"}),"\n",(0,i.jsxs)(s.li,{children:["Create a ",(0,i.jsx)(s.strong,{children:"Credential"})," in OrbisID:","\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Username:"})," Saviynt service account username"]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Password:"})," Saviynt service account password"]}),"\n"]}),"\n"]}),"\n",(0,i.jsxs)(s.li,{children:["Navigate to ",(0,i.jsx)(s.strong,{children:"Systems \u2192 Add System"})]}),"\n",(0,i.jsx)(s.li,{children:"Fill in the fields:"}),"\n"]}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"Field"}),(0,i.jsx)(s.th,{children:"Value"})]})}),(0,i.jsxs)(s.tbody,{children:[(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"Name"})}),(0,i.jsxs)(s.td,{children:["Descriptive name (e.g., ",(0,i.jsx)(s.code,{children:"Saviynt EIC \u2013 Production"}),")"]})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"OS Type"})}),(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"Saviynt"})})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"System Type"})}),(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"Application"})})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"IP Address / Hostname"})}),(0,i.jsx)(s.td,{children:"Saviynt tenant hostname"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.strong,{children:"Credential"})}),(0,i.jsx)(s.td,{children:"The scanning credential"})]})]})]}),"\n",(0,i.jsxs)(s.ol,{start:"5",children:["\n",(0,i.jsxs)(s.li,{children:["Click ",(0,i.jsx)(s.strong,{children:"Test Connection"})]}),"\n",(0,i.jsxs)(s.li,{children:["Click ",(0,i.jsx)(s.strong,{children:"Save"})]}),"\n"]}),"\n",(0,i.jsx)(s.h2,{id:"troubleshooting",children:"Troubleshooting"}),"\n",(0,i.jsxs)(s.table,{children:[(0,i.jsx)(s.thead,{children:(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.th,{children:"Symptom"}),(0,i.jsx)(s.th,{children:"Likely Cause"}),(0,i.jsx)(s.th,{children:"Resolution"})]})}),(0,i.jsxs)(s.tbody,{children:[(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"Authentication failed"})}),(0,i.jsx)(s.td,{children:"Invalid credentials"}),(0,i.jsx)(s.td,{children:"Verify service account credentials in the Saviynt console"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"No users returned"}),(0,i.jsx)(s.td,{children:"API access not enabled"}),(0,i.jsx)(s.td,{children:"Enable API access for the service account in Saviynt"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:(0,i.jsx)(s.code,{children:"403 Forbidden"})}),(0,i.jsx)(s.td,{children:"Missing SAV Role permissions"}
1),(0,i.jsx)(s.td,{children:"Grant View User and View Entitlement permissions"})]}),(0,i.jsxs)(s.tr,{children:[(0,i.jsx)(s.td,{children:"Rate limit errors"}),(0,i.jsx)(s.td,{children:"Too many API requests"}),(0,i.jsx)(s.td,{children:"Reduce scan frequency or increase the scan interval"})]})]})]})]})}function a(e={}){const{wrapper:s}={...(0,r.R)(),...e.components};return s?(0,i.jsx)(s,{...e,children:(0,i.jsx)(h,{...e})}):h(e)}},8453(e,s,n){n.d(s,{R:()=>d,x:()=>c});var t=n(6540);const i={},r=t.createContext(i);function d(e){const s=t.useContext(r);return t.useMemo(function(){return"function"==typeof e?e(s):{...s,...e}},[s,e])}function c(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:d(e.components),t.createElement(r.Provider,{value:s},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.