Start here
Warde documentation
How to install, set up and run Warde, connect it to your identity system, and use it to ask for, approve and review access.
Warde is a ServiceNow application for access requests, access removal and user access reviews. People ask for access in your portal, the right people approve it, and your identity engine or a ServiceNow task carries out the change. Warde records who has what and why, and keeps that history as evidence.
Pick your guide
| Guide | For | Start with |
|---|---|---|
| Administrator guide | The ServiceNow and identity team who install, set up and run Warde | Install Warde, then Guided Setup |
| Connector guides | Whoever owns the identity system Warde connects to | How connectors work |
| User guide | Everyone who asks for, approves or reviews access | Ask for access |
How Warde fits together
- Engines. Warde connects to the system that holds your access today: SailPoint Identity Security Cloud, SailPoint IdentityIQ or Microsoft Entra ID Governance. For applications with no identity engine behind them, ServiceNow tasks do the work.
- Import. Warde imports each engine's applications, entitlements, accounts and who holds what, and matches each account to a ServiceNow user.
- Onboard. An administrator takes each application through Collection Onboarding: an owner, a support group, an approval policy, who may ask for it, and plain names for its entitlements.
- Request. People ask for access with the Request Access form in your portal, for themselves or for others, and see what they hold on My Access.
- Approve. Approval policies send each request through the right approvers in order, with separation of duties checked on the way.
- Fulfil. The engine grants the access, or a ServiceNow task goes to the team that owns the application. A request reads done only when the change is confirmed.
- Review. Access review campaigns ask managers and owners to keep or remove what people hold, and removals go back through the same path.
Words used in these guides
| Word | Meaning |
|---|---|
| Engine | A system Warde reads access from and writes access to, such as SailPoint or Entra ID. The ServiceNow task engine is the one with no external system. |
| Collection | One application or source of access in an engine, such as an ISC source or an Entra application. Its entitlements are what people ask for. |
| Entitlement | One piece of access a person can hold: a group, a role, an app role, a licence, an access profile. |
| Account | A person's login in an engine. Each account is matched to one ServiceNow user. |
| Holding | A person holding an entitlement, with how it was granted and when. |
| Access bundle | A set of entitlements requested, approved and granted together. |
| Approval policy | The approvers a request goes to, in stages, and what happens when a rule finds nobody. |
| Campaign | One run of an access review, with its scope and reviewers frozen when it starts. |