•   Next SailPoint IIQ Batch Starts July 15th, 2026 — Limited to 25 Seats. Register for Free Demo.   •   100% Live Online — LMS Recordings Included   •   Batch Capped at 25 Students   •   LMS Portal Access Included   •   Placement Assistance Provided   •   Next SailPoint IIQ Batch Starts July 15th, 2026 — Limited to 25 Seats. Register for Free Demo.   •   100% Live Online — LMS Recordings Included   •   Batch Capped at 25 Students   •   LMS Portal Access Included   •   Placement Assistance Provided
SailPoint Academy Logo
Technical  •  9 min read

What Is an Identity Cube in SailPoint IIQ? The Concept Every Beginner Must Master

If you understand the Identity Cube, the rest of SailPoint IdentityIQ falls into place. Here is what it is, how aggregation and refresh build it, and why every aggregation, certification, and provisioning action in IIQ revolves around it.

SailPoint Academy Team June 9, 2026 Updated June 2026
1
Core IIQ Concept
14
Modules Build On It
360°
View of Each User
2 Months
Live Training
Register for Free Demo
60 minutes. Live on Zoom. No payment required.

Successfully Registered!

Our team will reach you on WhatsApp within 2 hours.

No spam. No payment required. 100% free demo.
Identity Cube in SailPoint IdentityIQ — a unified 360-degree view of one user's identity data

What Is an Identity Cube in SailPoint IIQ?

An Identity Cube in SailPoint IdentityIQ (IIQ) is a single, unified profile of one real person — built by combining all of that person's accounts and entitlements from every connected system into one record. It is the platform's 360-degree view of who a user is and what they can access across the entire organisation.

Think of it like this. In a large bank, one employee — let's call her Priya — might have a Windows login through Active Directory, an email account, a database login, an SAP account, and access to three internal applications. To a security team, those are five or six disconnected accounts scattered across different systems. SailPoint's job is to pull all of those scattered accounts together and say: "All of these belong to Priya." That combined, correlated, single record is Priya's Identity Cube.

The one-line definition to remember: An Identity Cube is the single source of truth for one user — a correlated collection of all their accounts, entitlements, roles, risk score, and history, presented as one logical identity. Per SailPoint's official IdentityIQ documentation, it is a multi-dimensional data model that offers a single, logical representation of each managed user.

The word "cube" is deliberate. A cube has many faces and dimensions — and an Identity Cube holds many dimensions of a person at once: their HR attributes, their accounts, their permissions, their policy status, and their risk level. Once you truly understand the Identity Cube, every other concept in IIQ — aggregation, certification, lifecycle events, provisioning — becomes far easier, because they all read from or write to the Cube.

What's Inside an Identity Cube?

An Identity Cube holds five categories of data about a person, gathered from across the enterprise. Understanding these five layers is the fastest way to grasp what the Cube actually represents.

Identity Attributes

Core facts about the person — name, employee ID, job title, department, manager, location and status. These usually come from the authoritative HR source.

Linked Accounts

Every account the person owns across connected applications — Active Directory, email, databases, SAP and more — correlated and tied to this one Cube.

Entitlements & Roles

The specific permissions the user holds in each application, plus the business and IT roles assigned or detected for them.

Risk Score

A calculated score reflecting how risky the user's combined access is — driven by sensitive entitlements, policy violations and access patterns.

Policy & Compliance Status

Whether the user breaches any Segregation of Duties (SoD) or other policies, plus their history in past access certifications.

This is why the Cube is so powerful for governance. Instead of an auditor checking six systems one by one to understand Priya's access, they open one Cube and see everything at once — and so can the access certification campaigns, reports, and provisioning workflows that depend on it.

Identity Cube vs Identity Warehouse — What's the Difference?

The Identity Warehouse is the central repository that stores all Identity Cubes in IIQ; an Identity Cube is the individual record for one person inside that repository. This is one of the most common points of confusion for beginners — and a frequent interview question — so it is worth fixing in your mind early.

AspectIdentity CubeIdentity Warehouse
What it isOne person's complete identity recordThe central store of all identities
ScopeA single userEvery user in the organisation
AnalogyOne file in the cabinetThe whole filing cabinet
Where you see itOpen an individual identity to view their CubeThe Identity Warehouse list / search screen in IIQ
ContainsAttributes, accounts, entitlements, roles, riskThe full collection of every Cube

In short: the Warehouse is the collection, the Cube is the unit. When you search a person in the Identity Warehouse and click into them, the detailed screen you land on — with all their accounts and entitlements — is their Identity Cube.

How Is an Identity Cube Created in SailPoint IIQ?

An Identity Cube is created through two processes working together: aggregation (pulling data in) and identity refresh (making sense of it and finalising it). Here is the exact sequence IIQ follows, which maps directly to Modules 3 and 4 of the curriculum.

  1. Aggregate the authoritative source. You connect an authoritative source — typically an HR system like Workday or SAP HR — and run identity aggregation. IIQ reads each HR record and creates one Identity Cube per unique person, populating core attributes such as name, title, department and manager.
  2. Aggregate non-authoritative accounts. You run account aggregation against applications such as Active Directory, a database, or Salesforce to pull in the accounts and entitlements each person holds in those systems.
  3. Correlate accounts to the right Cube. IIQ uses correlation logic to match each aggregated account to the correct Identity Cube — so Priya's AD account, email and SAP login all attach to Priya's Cube rather than floating uncorrelated.
  4. Run the Refresh Identity Cube task. The identity refresh task finalises the links, recalculates assigned and detected roles, evaluates policies, updates risk scores, and persists the complete state into the Identity object.
  5. Review the Cube in the Identity Warehouse. You open the person in the Identity Warehouse and confirm attributes, linked accounts, entitlements, roles and risk score are all correct before certifications or provisioning run against it.

The detail beginners miss

An authoritative source is what creates a Cube (it decides who exists as a person). A non-authoritative source only adds accounts and entitlements to an existing Cube. Aggregating Active Directory alone will not create clean Cubes if your authoritative HR source hasn't run first — a mistake that causes thousands of uncorrelated accounts in real projects.

Aggregation vs Identity Refresh — The Distinction That Trips People Up

Aggregation pulls raw account and entitlement data from a connected application into IIQ; identity refresh then processes that data — correlating accounts, recalculating roles, running policies and updating risk scores. Put simply: aggregation brings the data in, refresh makes sense of it.

This is one of the most reliably asked SailPoint interview questions, and getting it wrong signals you've only watched videos, not understood the platform. According to SailPoint's documentation, aggregation tasks can flag identities that were updated so that a later refresh processes only those changed identities — which is how large enterprises keep millions of Cubes current without reprocessing everyone every night.

QuestionAggregationIdentity Refresh
What does it do?Pulls accounts & entitlements from an application into IIQCorrelates, recalculates roles, runs policy, updates risk
Works onOne application at a timeThe Identity Cubes themselves
Creates the Cube?Authoritative aggregation creates CubesFinalises and persists the Cube
When it runsFirst — to bring data inAfter aggregation — to process it

If you want the full picture of how these jobs are configured and scheduled, our deep dive on SailPoint online training walks through where aggregation and refresh sit in the 14-module program.

Want to see a real Identity Cube being built live?

Attend a free 60-minute live demo before you decide — no payment, no commitment. Watch a trainer aggregate a source and refresh a Cube on a real IIQ instance.

Attend Free Demo

A Worked Example: Following One Employee's Cube

The clearest way to understand the Identity Cube is to follow one person through their lifecycle. Here is Priya, a new joiner at a BFSI GCC in Hyderabad, and what happens to her Cube at each stage — which is exactly how the concept connects to IIQ's Lifecycle Events module.

Day 1 — Joiner

HR creates Priya's record in Workday. The next authoritative aggregation reads that record and creates a brand-new Identity Cube for Priya, populated with her name, title (Risk Analyst), department, and manager. At this point her Cube exists but has no application accounts yet.

Week 1 — Accounts attach

A joiner lifecycle event automatically provisions Priya an Active Directory account and email. When those systems are aggregated and correlated, the accounts link to her Cube. Her Cube now shows two linked accounts and the entitlements that come with them. A refresh recalculates her roles and gives her an initial risk score.

Month 6 — Mover

Priya transfers from the Risk team to Treasury. HR updates her department in Workday; the next aggregation and refresh update her Cube. IIQ now detects she has Risk-team access she no longer needs — visible instantly on her Cube — so the Treasury manager can request removal during the next certification.

Year 2 — Leaver

Priya resigns. HR marks her terminated in Workday. The leaver lifecycle event reads her Cube, finds every linked account, and de-provisions them all — because the Cube already knows every system she ever touched. Without the Cube, the security team would have to hunt down each account manually.

The takeaway: Every joiner, mover, and leaver action in IIQ works because the Identity Cube already holds the complete, correlated picture of the person. Learn more in our guide to SailPoint IIQ Lifecycle Events.

Where the Identity Cube Fits in the IIQ Curriculum

The Identity Cube is not a single lesson you finish and move past — it is the spine that runs through the entire SailPoint IdentityIQ curriculum. Here is how the concept threads through the modules SailPoint Academy covers in its live program.

Module 3: Application Onboarding

  • Authoritative vs non-authoritative apps create vs enrich Cubes
  • Identity Mapping defines the Cube's attributes
  • Correlation links accounts to the right Cube

Module 4: SailPoint Jobs

  • Aggregation Job brings accounts into the Cube
  • Refresh Job finalises and persists the Cube
  • Scheduling keeps every Cube current

Module 7: Role Management

  • Roles are assigned and detected on the Cube
  • RBAC reads each Cube's entitlements

Module 11: Access Certification

  • Certifications review the access stored in each Cube
  • Reviewers approve or revoke Cube entitlements

Module 12: Lifecycle Events

  • Joiner, Mover, Leaver, Rehire act on the Cube
  • Leaver de-provisions every account on the Cube

Module 9: Risk Score

  • Risk is calculated per Cube
  • Sensitive entitlements raise the Cube's score

For the complete module-by-module breakdown, see our SailPoint IIQ curriculum guide or the full course curriculum page.

Why the Identity Cube Matters for Compliance and Your Career

The Identity Cube is the foundation every audit, certification, and compliance report in IIQ stands on — which is precisely why enterprises in regulated industries invest so heavily in keeping Cubes clean. When a manager certifies who has access to what, or an auditor proves a control to a regulator, they are reading from Identity Cubes.

RBI & SOX Audits

Periodic access certification — mandated for BFSI in India and SOX-regulated GCCs — reads directly from Identity Cubes. Stale Cubes mean failed audits.

DPDP Act 2023

India's data protection law requires enterprises to prove who can access personal data. The Cube is the record that answers that question per person.

Leaver Risk

A complete Cube ensures no orphaned account is left active when someone leaves — the single biggest insider-risk gap auditors look for.

For your career, this means the Identity Cube is non-negotiable knowledge. Whether you target an IAM Analyst, SailPoint Consultant, or IIQ Developer role, every interview assumes you can explain the Cube cold. Our SailPoint career path guide for India maps where this skill takes you.

How Interviewers Test Your Identity Cube Knowledge

Interviewers rarely ask "what is an Identity Cube?" directly — they test whether you truly understand it by asking adjacent questions where a memorised definition falls apart. Here are the real questions that separate people who understand the Cube from people who have only read about it.

"What creates an Identity Cube?"

Correct answer: authoritative aggregation. A non-authoritative source only adds accounts to an existing Cube — it does not create one.

"Difference between aggregation and refresh?"

Aggregation brings data in; refresh correlates, recalculates roles, runs policy and updates risk on the Cube.

"Why is an account uncorrelated?"

Because correlation logic couldn't match it to a Cube — often the authoritative source hasn't created that person's Cube yet, or the correlation rule is wrong.

"Where does a certification get its data?"

From the entitlements stored on each Identity Cube — which is why a refresh must run before a certification campaign launches.

For a complete set of practice questions with model answers, see our SailPoint IIQ interview questions guide.

Frequently Asked Questions

An Identity Cube in SailPoint IdentityIQ is a single, unified profile of one real person, built by combining all their accounts and entitlements from every connected system into one record. It holds the person's attributes (name, manager, department), every account they own across applications, their entitlements and roles, risk score, and policy status. It gives administrators a 360-degree view of what a user can access across the organisation — the single source of truth all governance and compliance decisions are based on.
The Identity Warehouse is the central repository that stores all Identity Cubes — think of it as the filing cabinet. An Identity Cube is the individual file for one person inside that cabinet. The Warehouse is the collection; the Cube is the single, detailed 360-degree record of one user's accounts, entitlements, and access. In the IIQ user interface, the Identity Warehouse is where you search and open any individual Identity Cube.
It is created through aggregation followed by refresh. First, IIQ aggregates identity data from an authoritative source such as Workday or SAP HR and creates one Cube per unique person. Then account aggregation pulls in accounts from non-authoritative applications like Active Directory, and correlation links those accounts to the correct Cube. Finally, the Refresh Identity Cube task finalises the links, recalculates roles and risk scores, and persists everything into the Identity object that is the Cube.
Aggregation pulls raw account and entitlement data from a connected application into IIQ. Identity refresh processes that aggregated data — correlating accounts to Cubes, recalculating roles, running policies, and updating risk scores. Aggregation brings the data in; refresh makes sense of it and finalises the Cube. Most enterprises run aggregation on a schedule and then a refresh so Cubes reflect the latest state. This distinction is a very common SailPoint interview question.
Yes — in practice they refer to the same thing. Internally IdentityIQ stores the data as an Identity object; the term Identity Cube is the conceptual name for that complete, multi-dimensional record of one user. When practitioners say "Cube" they mean the full picture: identity attributes plus all linked accounts, entitlements, roles, risk score, and history. The word "Cube" emphasises that it combines many dimensions of identity data into one container.
Access certification campaigns and compliance reports read directly from Identity Cubes. When a manager reviews who has access to what during a certification, they are reviewing the entitlements stored in each person's Cube. If the Cube is stale or accounts are not correlated correctly, the certification shows wrong data and audits fail. Accurate Cubes are the foundation for SOX, RBI, and DPDP compliance — which is why enterprises invest heavily in clean aggregation and refresh.
No. Understanding what an Identity Cube is, how it is built, and how to read it requires no programming — it is a configuration and concept topic IAM analysts and consultants work with daily. Coding (BeanShell, Java-like rules) only becomes relevant when you customise correlation logic or identity-mapping rules for complex sources. Most beginners master the Identity Cube concept in their first week of structured training without writing any code.
Master IIQ From the Foundation Up

Ready to Learn SailPoint IIQ the Right Way?

Start with the Identity Cube and build all 14 modules on a solid foundation. Attend a free 60-minute live demo — see a real Cube built on a live IIQ instance. No payment. No commitment.

Explore More from SailPoint Academy

SailPoint Academy Home SailPoint IIQ Course Full IIQ Curriculum What Is SailPoint IdentityIQ? Lifecycle Events Explained Access Certification Guide IIQ Curriculum: 14 Modules IIQ Interview Questions IAM Career Paths
Book A Free Demo Call Now WhatsApp