Ellipse Gradient for Header
Saviynt logo

Saviynt Integration Guide

Integrate Saviynt Enterprise Identity Cloud with enterprise applications through REST APIs, token-based authentication, scheduled workflows, file exchange, and selected event notifications.

Saviynt integration options at a glance

Saviynt Enterprise Identity Cloud primarily integrates through REST APIs for Users, Accounts, Entitlements, Applications, Roles, and Requests. Tenant-configured OAuth 2.0 or bearer-token authentication can secure API access, while selected deployment configurations may support event-oriented notifications. File-based imports and exports provide an alternative for identity and access data, particularly for scheduled or batch processes. Martini can consume Saviynt REST APIs, expose controlled REST endpoints, orchestrate scheduled or event-driven workflows, transform JSON and file payloads, apply validation and business rules, and implement retries, checkpoints, reconciliation, and exception handling. Exact endpoints, permissions, event coverage, and batch behavior should be confirmed for the target tenant.

Integration pointSupported by Saviynt?Common use casesHow Martini supports it
REST APIsYesRetrieve and manage Users, Accounts, Entitlements, Applications, Roles, and Requests, subject to tenant configuration and permissions.Martini can consume Saviynt REST APIs, map JSON payloads, paginate results, apply business rules, and expose reusable workflow or API operations.
Webhooks / outbound callbacksLimitedSelected deployment and integration configurations may provide event-oriented notifications, but universal coverage for object changes is not confirmed.Martini can receive webhook-style notifications when the tenant exposes the required event and can use the notification to retrieve the current Saviynt resource.
Bulk / async / batch processingLimitedLarge identity and access synchronizations may use batch or asynchronous patterns where supported by the configured endpoint or integration design.Martini can process bounded batches, checkpoint progress, monitor job status when available, and handle partial failures. A universal bulk REST model should not be assumed.
File imports and exportsYesCSV or delimited identity and access data can support scheduled inbound imports, outbound exports, validation, and reconciliation in applicable configurations.Martini can retrieve or deliver files through the configured exchange mechanism, transform rows, validate content, and route rejection or duplicate results.
AuthenticationYesTenant-configured OAuth 2.0 or bearer-token patterns, API credentials, service accounts, and Saviynt permissions secure REST integrations.Martini can store credentials and tokens in environment configuration or secrets, invoke authenticated endpoints, and separate tenant environments.
Scheduled synchronizationYesPolling and periodic reconciliation provide an alternative when event coverage is unavailable or limited.Martini scheduler-triggered workflows can retrieve changed or full datasets, maintain checkpoints, compare state, and retry failed work.
Database accessNot confirmedDirect access to Saviynt-managed production data should not be assumed; supported APIs and export mechanisms are the preferred approach.Martini can connect to other approved databases when required, but should not be described as directly connecting to Saviynt's internal database.

How Saviynt exposes data and business events

Saviynt REST APIs

Saviynt's principal integration mechanism is its REST API, which can retrieve and manage Users, Accounts, Entitlements, Applications, Roles, Requests, and related objects according to tenant configuration, API version, and permissions.

Martini implementation pattern

Martini implementation pattern: a workflow authenticates to the configured Saviynt tenant, calls the required endpoint, handles pagination and response validation, maps the result to a canonical model, and writes to or invokes the target system.

Implementation sequence

Authenticate with the tenant-configured token flow
Retrieve the current Saviynt resource or page of results
Validate the response and normalize identifiers
Map fields to the target application model
Apply lifecycle, access, and reconciliation rules
Write the result and store a checkpoint

Saviynt event notifications

Saviynt may support event-oriented notifications or callbacks for selected deployment and integration configurations. Broad webhook coverage for every Users, Accounts, Entitlements, Applications, Roles, or Requests change has not been verified.

Martini implementation pattern

Martini implementation pattern: receive a notification only for confirmed events, validate its authenticity and correlation data, then retrieve the authoritative Saviynt resource through the REST API before processing it. Scheduled polling remains the fallback for unsupported events.

Implementation sequence

Receive the confirmed event notification
Validate the event and correlation information
Retrieve the authoritative Saviynt object
Apply idempotency and business rules
Transform and deliver the result
Record acknowledgement or route failure for retry

Saviynt file exchange

Applicable Saviynt configurations can use file-oriented imports and exports for identity and access data, including scheduled inbound data, outbound extracts, validation results, and reconciliation files.

Martini implementation pattern

Martini implementation pattern: a scheduled workflow obtains or produces the agreed file, parses and validates each row, maps it to Saviynt or a downstream system, and separates accepted, rejected, and duplicate records for operational follow-up.

Implementation sequence

Retrieve or create the agreed identity data file
Parse and validate the file contents
Normalize identifiers and required attributes
Apply duplicate and reconciliation rules
Submit or deliver accepted data
Store rejected rows and processing results

Saviynt authentication

Saviynt REST integrations commonly use tenant-configured OAuth 2.0 or bearer-token authorization, API credentials, and dedicated service identities with permissions for the required objects and operations.

Martini implementation pattern

Martini implementation pattern: keep credentials and token settings in environment-specific secure configuration, acquire or use the configured token, call only permitted Saviynt operations, and handle expiry or authorization failures without exposing secrets in logs.

Implementation sequence

Configure a dedicated Saviynt integration identity
Store credentials and token settings securely
Acquire or provide the configured access token
Call only authorized Saviynt operations
Handle expiry and authorization responses
Audit access without logging secrets

Common Saviynt integration patterns

Pattern 1: Synchronize HR identities to Saviynt

When to use this pattern

Use this pattern for joiner, mover, and leaver processes driven by Workday or SAP SuccessFactors. It combines source identity changes with Saviynt User creation, updates, suspension, or reconciliation.

Integration direction
Workday
Martini
Saviynt
Example Mapping
Saviynt FieldCanonical FieldTarget Field
workerIdpersonIdentifierUser.employeeId
employmentStatuslifecycleStatusUser.status
departmentorganizationUnitUser.department
managerIdmanagerIdentifierUser.manager
Martini implementation pattern

Martini receives an HR event or runs a scheduled workflow, normalizes source attributes, looks up the Saviynt User, and applies an idempotent create-or-update operation. Business rules determine activation, suspension, or termination, while transient failures are retried and permanent validation errors are sent to an exception workflow.

Martini capabilities used
  • workflows
  • API consumption
  • scheduling
  • data mapping
  • business rules
  • error handling

Pattern 2: Reconcile Saviynt accounts and entitlements

When to use this pattern

Use this pattern to compare Saviynt access state with Microsoft Entra ID, Salesforce, SAP S/4HANA, or another managed application and identify missing, stale, or unexpected access.

Integration direction
Saviynt
Martini
Microsoft Entra ID
Example Mapping
Saviynt FieldCanonical FieldTarget Field
Account.nameaccountIdentifieruserPrincipalName
Entitlement.nameaccessIdentifiergroupOrRoleName
Account.statusaccountStateaccountEnabled
Martini implementation pattern

A scheduled Martini workflow pages through Saviynt Accounts and Entitlements, normalizes identifiers, retrieves the target state, and compares both models. Idempotent updates are submitted only when required; exceptions, partial failures, and unmatched access are recorded for remediation or review.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination and checkpoints
  • data mapping
  • comparison rules
  • retry handling

Pattern 3: Route Saviynt access requests to ServiceNow

When to use this pattern

Use this pattern when selected Saviynt Requests require IT workflow, exception handling, fulfillment tracking, or notification in ServiceNow.

Integration direction
Saviynt
Martini
ServiceNow
Example Mapping
Saviynt FieldCanonical FieldTarget Field
Request.requestIdrequestIdentifiernumber
Request.requestedForsubjectIdentifierrequested_for
Request.statusgovernanceStatusstate
Request.justificationbusinessJustificationdescription
Martini implementation pattern

Martini retrieves Requests on a schedule or processes a confirmed event notification, validates the request, maps it to a ServiceNow record, and stores cross-system correlation identifiers. Duplicate detection, status rules, and retry handling prevent repeated tickets and distinguish business rejection from transport failure.

Martini capabilities used
  • REST API orchestration
  • event and schedule triggers
  • data mapping
  • business rules
  • idempotency
  • error handling

Pattern 4: Synchronize Saviynt application catalog metadata

When to use this pattern

Use this pattern to synchronize Saviynt Applications and related catalog metadata with ServiceNow or an internal application catalog when ownership, lifecycle, requestability, or descriptions must remain aligned.

Integration direction
Saviynt
Martini
ServiceNow
Example Mapping
Saviynt FieldCanonical FieldTarget Field
Application.nameapplicationNamename
Application.ownerownerIdentifierowned_by
Application.descriptiondescriptionshort_description
Application.statuslifecycleStatusinstall_status
Martini implementation pattern

Martini retrieves application metadata through the Saviynt REST API, maps and validates catalog fields, applies ownership and lifecycle rules, and upserts the target record. If event coverage is unavailable, scheduled full or incremental reconciliation provides consistent recovery and drift detection.

Martini capabilities used
  • workflow orchestration
  • scheduled synchronization
  • API consumption
  • mapping and transformation
  • validation
  • reconciliation

Applications commonly integrated with Saviynt

Saviynt commonly participates in identity lifecycle, access governance, provisioning, reconciliation, and privileged access processes. The exact operations and integration direction depend on the target tenant, enabled modules, API permissions, and application-specific interfaces.

Application Scenario Direction Martini Pattern
Workday Synchronize worker identities, employment status, departments, managers, and lifecycle events for joiner, mover, and leaver processes. Workday → Martini → Saviynt Martini receives an HR event or runs a scheduled workflow, normalizes worker attributes, looks up the Saviynt User, and performs an idempotent create or update through the Saviynt REST API. Validation failures are routed to an exception path.
SAP SuccessFactors Supply HR identity data to support lifecycle synchronization and access governance. SAP SuccessFactors → Martini → Saviynt A Martini workflow retrieves or receives worker changes, maps organizational and employment fields to Saviynt Users, applies activation and termination rules, and checkpoints successful processing for replay.
ServiceNow Coordinate applications, access requests, approvals, incidents, exceptions, and fulfillment status between identity governance and IT workflows. Saviynt → Martini → ServiceNow Martini polls or receives selected Saviynt request events, maps request and approval details into ServiceNow records, and optionally writes fulfillment or exception status back to Saviynt. Retries and correlation identifiers prevent duplicate tickets.
Microsoft Entra ID Govern users, groups, accounts, applications, and access assignments across the identity governance and directory environments. Microsoft Entra ID → Martini → Saviynt Martini orchestrates reconciliation workflows between the two platforms, normalizes immutable identifiers, compares lifecycle and access state, and submits only required changes after business-rule evaluation.
Okta Reconcile identities, groups, applications, and lifecycle state between identity platforms where both participate in access governance. Okta → Martini → Saviynt Martini retrieves source and target states, maps group and account identifiers, applies conflict rules, and records unmatched or rejected items for review. Supported Saviynt operations must be confirmed for the tenant.
Salesforce Govern Salesforce users, profiles, permission sets, and account lifecycle through Saviynt access processes. Saviynt → Martini → Salesforce Martini reads Saviynt access or lifecycle decisions, transforms them into Salesforce-specific operations, and reconciles resulting account state back to Saviynt where supported.
SAP S/4HANA Govern accounts and enterprise roles associated with SAP business applications. SAP S/4HANA → Martini → Saviynt Martini coordinates account and role reconciliation, maps SAP identifiers to Saviynt Accounts and Entitlements, batches eligible changes, and separates transient API failures from business validation errors.
CyberArk Coordinate privileged account ownership, governance, access review, and related identity security processes. Saviynt → Martini → CyberArk Martini orchestrates approved ownership or access-state exchanges, applies least-privilege and approval rules, and retains correlation data for reconciliation. Exact interfaces and direction depend on the deployment.

How to build a Saviynt integration in Martini

Objective

Establish tenant-specific access to Saviynt using a dedicated integration identity and the configured token-based authentication method.

Instructions in Martini

  • Confirm the Saviynt tenant, API version, token flow, and required permissions.
  • Store credentials, tokens, and environment-specific values in secure Martini configuration.
  • Use separate credentials for development, test, and production.

Objective

Select an event, schedule, or API entry point that matches the required timeliness and the confirmed Saviynt event coverage.

Instructions in Martini

  • Use a confirmed event notification only for supported objects and events.
  • Use scheduler-triggered polling when event coverage is limited or unverified.
  • Expose a Martini REST API when Saviynt or another system must invoke controlled integration logic.

Objective

Obtain the authoritative Saviynt Users, Accounts, Entitlements, Applications, Roles, or Requests data needed for processing.

Instructions in Martini

  • Call the relevant Saviynt REST endpoint or process the agreed import or export file.
  • Implement endpoint-specific pagination and bounded batches.
  • Persist a checkpoint, cursor, or last successful synchronization marker where appropriate.

Objective

Coordinate retrieval, enrichment, validation, target calls, and operational outcomes in a maintainable Martini workflow.

Instructions in Martini

  • Separate transport, transformation, business-rule, and target-write stages.
  • Use correlation identifiers across Saviynt and downstream systems.
  • Branch permanent validation failures from transient errors.

Objective

Convert Saviynt payloads and files into a canonical model and then into the target system's schema.

Instructions in Martini

  • Normalize immutable identifiers, status values, dates, ownership, and access names.
  • Validate required attributes and tenant-specific enumerations.
  • Protect sensitive identity and access data in logs and intermediate payloads.

Objective

Enforce lifecycle, approval, entitlement, reconciliation, and idempotency rules before modifying a target system.

Instructions in Martini

  • Use create-or-update logic based on stable identifiers.
  • Prevent duplicate Users, Accounts, Requests, or Entitlements during replay.
  • Apply least-privilege and exception-routing rules appropriate to the process.

Common Saviynt data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
UsersSynchronize worker identity, lifecycle, ownership, organization, manager, and employment attributes.Workday, SAP SuccessFactors, Microsoft Entra ID, Okta, SalesforceMartini normalizes identifiers and attributes, validates lifecycle status, performs idempotent create or update operations, and records reconciliation results.
AccountsRepresent technical or application accounts associated with users or service identities.Microsoft Entra ID, Okta, Salesforce, SAP S/4HANA, CyberArkMartini maps account identifiers and status, compares source and target state, and routes provisioning or reconciliation failures for retry or review.
EntitlementsRepresent permissions, access rights, groups, roles, or other assignable privileges.Microsoft Entra ID, Salesforce, SAP S/4HANA, CyberArkMartini transforms entitlement metadata, applies approval and assignment rules, and detects missing, stale, or unexpected access.
ApplicationsDescribe connected applications and managed target systems in the access catalog.ServiceNow, internal application catalogs, Microsoft Entra IDMartini synchronizes ownership, descriptions, lifecycle status, requestability, and related metadata using scheduled or event-assisted workflows.
RequestsTrack access requests, account changes, approvals, fulfillment, or revocation activities.ServiceNow, Jira, application provisioning processesMartini retrieves or receives request information, routes selected requests, updates downstream status where supported, and preserves correlation identifiers.
RolesBundle business, technical, or application access for governance and assignment processes.SAP S/4HANA, Microsoft Entra ID, Salesforce, internal access catalogsMartini maps role identifiers and metadata, applies eligibility rules, and supports reconciliation or catalog synchronization subject to tenant operations.

Authentication and security considerations

Tenant-specific authentication

Saviynt integrations commonly use OAuth 2.0 or bearer-token authorization where enabled, together with API credentials, service accounts, and tenant-specific permissions. The exact token endpoint, grant type, and credential model must be confirmed in the deployed tenant.

Least-privilege access

  • Use a dedicated integration identity rather than an individual administrator account.
  • Grant only the permissions required for Users, Accounts, Entitlements, Applications, Roles, and Requests.
  • Keep development, test, and production credentials separate.

Protect identity data

  • Store credentials and tokens in secure Martini environment configuration or secrets management.
  • Do not expose tokens, passwords, or unnecessary entitlement payloads in logs.
  • Apply appropriate retention and access controls to audit records and error payloads.

Operational considerations for Saviynt integrations

Pagination and checkpoints

Confirm the pagination model and page-size behavior for every Saviynt endpoint. Use bounded batches and persist progress so a failed synchronization can resume without restarting the entire population.

Rate limits and retries

Confirm tenant-specific quotas and concurrency limits. Apply backoff for throttling and transient 5xx responses, while routing authorization and validation failures for intervention instead of repeatedly retrying them.

Idempotency and reconciliation

Use immutable identifiers, explicit create-or-update logic, correlation IDs, and deterministic comparisons to prevent duplicate Users, Accounts, Requests, or Entitlements. Prefer incremental markers where supported; otherwise use periodic full reconciliation.

Schema and tenant variation

API behavior can depend on the Saviynt release, endpoint version, enabled modules, and tenant configuration. Validate required fields, enumerated values, status transitions, custom attributes, and critical operations with contract tests before production rollout.

Why use Martini instead of scripts or point-to-point integrations?

Reusable orchestration

Martini provides workflows and APIs for coordinating Saviynt with HR, directory, IT workflow, SaaS, and privileged access systems without embedding the entire integration in a single script.

Controlled transformation

Mappings, validation, business rules, and reusable integration logic make identity and access transformations explicit and maintainable as systems or tenant configurations change.

Operational resilience

Scheduled and event-assisted processing can combine checkpoints, pagination, retries, exception paths, idempotency, and monitoring. This provides more controlled recovery than ad hoc point-to-point code.

Flexible integration surface

Martini can consume Saviynt REST APIs, process supported files, and expose controlled REST APIs for callbacks or application-specific orchestration. It does not require a dedicated vendor connector for these standards-based patterns.

Frequently asked questions

How can Saviynt be integrated with enterprise systems?

Saviynt Enterprise Identity Cloud can integrate through REST APIs for Users, Accounts, Entitlements, Applications, Roles, and Requests. Applicable configurations may also use token-based authentication, file imports and exports, scheduled synchronization, and selected event notifications or callbacks.

Can Martini integrate with Saviynt?

Yes. Martini can integrate with Saviynt by consuming its REST APIs, authenticating with the tenant's configured token method, processing supported files, and receiving selected event notifications where the tenant exposes the required mechanism. Martini workflows can map, validate, reconcile, and orchestrate downstream actions.

Do I need a connector to integrate Saviynt with Martini?

No. A dedicated Saviynt connector is not required. Martini can use Saviynt's confirmed native integration mechanisms, primarily REST APIs and token-based authentication, together with supported file exchange and selected event notifications.

Is there any extra Lonti cost to integrate Saviynt with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Saviynt. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Saviynt, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.

Which Saviynt integration methods should be used?

REST APIs are the primary current mechanism for identity and access objects. File-based imports and exports can support applicable batch scenarios, while scheduled polling is appropriate when event coverage is limited. GraphQL and current SOAP APIs were not verified and should not be assumed.

Does Saviynt provide webhooks or event notifications?

Saviynt may support event-oriented notifications or callbacks for selected configurations, but broad webhook coverage for every object change was not verified. Confirm the specific event and delivery behavior; Martini can use scheduled REST polling when notifications are unavailable.

How does Martini synchronize and transform Saviynt data?

Martini can retrieve paginated Saviynt data or process files, map it to a canonical model, apply lifecycle and access rules, and write to downstream systems. Checkpoints, stable identifiers, idempotent upserts, and reconciliation logic support incremental or periodic full synchronization.

How are Saviynt errors, retries, and duplicates handled?

Martini can classify authentication, authorization, validation, throttling, transport, and business-rule failures; retry transient responses with backoff; and route permanent failures to exception handling. Correlation identifiers and stable Saviynt object keys help prevent duplicate processing and support replay.