.png)
One Identity Integration Guide
Connect One Identity Manager, Active Roles, Safeguard, and Starling services with enterprise systems through product-specific REST APIs, SOAP services, files, and scheduled workflows.
One Identity integration options at a glance
One Identity is a portfolio, so integration mechanisms vary across One Identity Manager, Active Roles, Safeguard, and Starling services. REST APIs are the primary standards-based option for current integrations, while selected products or legacy scenarios may expose SOAP or other web-service interfaces. One Identity Manager also supports synchronization projects, provisioning, import/export processing, and batch-oriented workflows. Product-specific notifications or callbacks may be available, but universal webhook coverage is not confirmed. Martini can consume the applicable API, process JSON or XML, run scheduled reconciliation workflows, transform identity objects, handle controlled batches, and expose a REST API for downstream systems.
Common One Identity integration patterns
Common One Identity data objects used in integrations
Authentication and security considerations
Product-specific authentication
One Identity authentication depends on the selected product, deployment, release, and endpoint. Configured credentials, directory security, roles, sessions, or tokens may apply. Safeguard API workflows use token-based authentication in documented examples, but the exact method must be confirmed for the deployed release.
Least privilege and secret handling
Use dedicated integration identities with only the permissions required for selected objects and operations. Store credentials, tokens, client secrets, and endpoint configuration in Martini environment-managed secrets rather than workflow definitions.
Protect sensitive data
- Use TLS-protected endpoints and access-controlled workflow logs.
- Do not log passwords, tokens, privileged-account secrets, or unnecessary personal data.
- Separate read-only reconciliation from write and provisioning workflows where practical.
- Preserve vendor request and correlation identifiers for controlled auditing.
Operational considerations for One Identity integrations
Product and version differences
One Identity is a portfolio rather than one uniform API. Confirm the product, release, deployment model, licensed features, endpoint paths, object coverage, and authentication method before implementation.
Pagination, limits, and concurrency
Collections of users, groups, accounts, assets, requests, or audit records may be paginated. Follow continuation links, use bounded page sizes, apply server-side filters, and control concurrency. Rate limits and appliance capacity vary by product and deployment.
Idempotency and reconciliation
Use stable object keys, Person or Employee identifiers, directory identifiers, Safeguard identifiers, and external application IDs. Make updates safe to repeat, distinguish already-disabled objects from failures, persist checkpoints, and run periodic reconciliation.
Retries and schema changes
Use bounded exponential backoff for transient failures and route permanent errors to an exception process. Validate response schemas and required fields because API paths and object properties can differ between products and releases.
Testing and recovery
Test full loads, incremental changes, duplicate messages, rejected attributes, approval failures, deprovisioning, API timeouts, and restart behavior in a non-production environment. Include reconciliation reports, dead-letter or exception handling, and manual recovery paths.
Why use Martini instead of scripts or point-to-point integrations?
Adapt to a product portfolio
One Identity integrations vary across Manager, Active Roles, Safeguard, and Starling services. Martini provides a consistent workflow and API-led implementation model while preserving product-specific endpoint, object, and authentication behavior.
Reduce point-to-point complexity
Instead of embedding identity rules in separate scripts, Martini centralizes retrieval, transformation, validation, approvals, target writes, checkpoints, and exception handling in maintainable workflows.
Support multiple integration styles
Martini can consume REST or SOAP services, receive documented callbacks, run scheduled reconciliation, process supported files, and expose a controlled API for downstream systems without requiring a dedicated One Identity connector.
Operate reliably
- Apply reusable mappings and business rules across products and targets.
- Use environment-specific secrets and endpoint configuration.
- Implement pagination, idempotency, retries, checkpoints, and reconciliation.
- Monitor workflow results and preserve useful correlation data without exposing sensitive values.