Skip to content
By IAM

The Top 10 User Provisioning and Governance Tools (2026)

Ten provisioning and access governance platforms compared on connectors, SCIM support, certification and separation of duties, verified September 2026.

The short answer: if you run Microsoft, buy Entra ID Governance at $7 per user per month before you look at anything else. If you need deep governance across a messy multi-vendor estate, shortlist SailPoint, Saviynt, and Omada. If you run Okta, Okta Identity Governance is the lowest-friction path. If your compliance problem is SAP or Oracle transaction-level separation of duties, the generic platforms will not reach it and you need the vendor's own access control product.

The problem this category solves is not "creating accounts." It is proving, to an auditor, that every person and every service has exactly the access they should have and nothing more. It means showing when that access was granted, who approved it, and when it was removed. Provisioning is the plumbing. Governance is the evidence.

Most organizations buy the plumbing, skip the evidence, and then spend three weeks of an audit cycle exporting spreadsheets from twelve systems. This guide covers the ten platforms that do both, what each is genuinely best at, and where the market moved in the last twelve months, which was a lot.

A note on scope, because these two pages get confused. This page is about provisioning mechanics and access governance: SCIM connectors, certification campaigns, separation of duties, role mining, and audit evidence. The companion guide to identity lifecycle management covers the joiner, mover, leaver orchestration that sits in front of it: HR events, day-one readiness, and same-day offboarding. Most buyers need both, and several vendors appear on both lists, but the evaluation questions are different.


How We Evaluated

Last verified: September 2026.

For this refresh we read each vendor's own product documentation and published pricing where it exists, the IETF specifications that define SCIM, and the acquisition and funding announcements that changed ownership in this market during 2025 and 2026. Vendor claims about connector counts and AI features were treated as marketing until documented.

Five things decided the rankings. First, connector reality: how many systems it provisions out of the box, and how bad the custom connector work is for the ones it does not cover. Second, SCIM support, inbound and outbound, because that determines whether adding a SaaS application is a configuration task or a project. Third, governance depth: certification campaigns, separation of duties, role mining, and whether the audit export is something a compliance team can actually hand over. Fourth, time to first value, because a platform that takes a year to deploy has a year of unmanaged access behind it. Fifth, who owns the vendor now, since three platforms in this market changed hands in the last nine months.

On experience: I founded LoginRadius and scaled it past a billion identities, so the provisioning and directory-synchronization failure modes described here are ones I have watched break in production, generally at the connector layer and generally at 2am. That is the vantage point this guide is written from. It is not a hands-on lab test of all ten platforms, and no such test is claimed. Pricing is quoted only where the vendor publishes it; everything else in this market is quote-driven.


What Changed in This Market in 2026

Four moves matter if your shortlist is more than a year old.

ServiceNow bought Veza. The deal was announced in December 2025 and closed on March 2, 2026 at around $1 billion. Veza's Access Graph, which maps effective permissions down to individual data objects and tables rather than stopping at group membership, is now part of the ServiceNow platform. If ServiceNow is already your system of record for workflow and approvals, that changes the build-versus-buy calculation. If it is not, ask hard questions about standalone availability and pricing.

Saviynt raised $700 million. The KKR-led round closed in December 2025 at roughly a $3 billion valuation, with Sixth Street Growth, TenEleven, and Carrick Capital participating. That is a very large war chest for an independent challenger to SailPoint, and it removes the "will they still be here in five years" objection that used to appear in enterprise RFPs.

SailPoint is public again. It listed on NASDAQ in February 2025 under the ticker SAIL after four years under Thoma Bravo. Public-company discipline generally means published roadmaps and predictable release cadence, which helps buyers, and quarterly revenue pressure, which does not always help pricing.

CyberArk is now part of Palo Alto Networks, in a roughly $25 billion deal that closed on February 11, 2026. Delinea, which acquired Fastpath in 2024 to add identity governance to its privileged access line, completed its StrongDM acquisition on March 5, 2026 and is now the largest independent in privileged access. If your governance requirement includes privileged accounts, read the privileged access management comparison alongside this page.


SCIM in 2026: What Actually Changed

SCIM is the reason modern provisioning is configuration rather than code, and it is worth understanding precisely because most buyers treat "supports SCIM" as a binary checkbox when it is not.

The core specifications are RFC 7643 (the schema) and RFC 7644 (the protocol), both published in 2015. The important thing for a 2026 buyer is that the standard is still moving, and the new pieces solve problems that caused real production pain.

RFC 9865, published October 2025, added cursor-based pagination. Index-based pagination breaks in predictable ways when the directory changes mid-sync, which is how large tenants end up with users silently skipped during a full reconciliation. Cursor pagination fixes that, and providers advertise support through the /ServiceProviderConfig endpoint so clients can discover which method is available.

RFC 9967, published May 2026, defines a SCIM profile for Security Event Tokens. This is the big one. It adds asynchronous, event-driven provisioning: instead of an application polling for changes on a schedule, the identity provider pushes a signed event when something changes. It updates both RFC 7643 and RFC 7644, adding an optional asynchronous request capability. Practically, it means the gap between "employee terminated in the HR system" and "access revoked in the SaaS app" stops being a function of your sync interval.

RFC 9944, also May 2026, adds device schema extensions, which matters as device identity becomes part of access decisions.

Four questions are worth asking any platform. Which SCIM version and which extensions does it implement? Does it support inbound SCIM as well as outbound? Does it handle cursor pagination? Does it support event-driven provisioning, or only scheduled sync? Ask for the answer in writing. For the mechanics of setting it up, see the SCIM provisioning guide, and for how SCIM relates to the authentication protocols it is usually confused with, the SCIM vs SAML comparison.


Quick Comparison

Platform Best For Deployment Published Pricing Governance Strength Owner
SailPoint Identity Security Cloud Broadest enterprise governance across mixed estates SaaS, with IdentityIQ still supported on-premises Quote only Deepest connector library and access intelligence Public, NASDAQ: SAIL
Microsoft Entra ID Governance Microsoft-centric organizations Cloud-native $7 per user per month add-on Lifecycle workflows, access packages, PIM Microsoft
Saviynt Identity Cloud Converged IGA, PAM, and app access governance SaaS Quote only Application access governance and SoD Independent, KKR-backed
Omada Identity Cloud Time-boxed, prescriptive IGA deployments SaaS and hybrid Quote only Best-practice framework, strong compliance reporting Independent
Okta Identity Governance Okta shops adding governance without a second vendor Cloud-native In Core Essentials suite from $14 per user per month, or as an add-on Access certification and requests inside Okta Okta
One Identity Manager Complex hybrid AD, SAP, and legacy estates On-premises and SaaS Quote only Cross-application governance depth Quest, Clearlake and Vector
IBM Verify Identity Governance Regulated enterprises with mainframe and hybrid systems On-premises and SaaS Quote only Certification, role management, risk scoring IBM
Oracle Identity Governance Oracle-heavy enterprises On-premises and cloud Quote only SoD controls tied to Oracle applications Oracle
SAP Access Control and Cloud IAG SAP estates with transaction-level SoD obligations On-premises and cloud Quote only, part of SAP GRC Transaction-level SoD no generic platform matches SAP
OpenText NetIQ IGA Regulated sectors needing role mining on legacy systems On-premises and SaaS Quote only Role analytics and continuous compliance OpenText

1. SailPoint Identity Security Cloud

Best for: large and mid-to-large enterprises with a genuinely mixed application estate and regulated audit obligations.

SailPoint is the reference platform in identity governance, and it earns that position on connector breadth and access intelligence rather than on price or ease of deployment. Identity Security Cloud is the SaaS product, built on the Atlas platform. IdentityIQ is the customer-hosted product that thousands of enterprises still run, and SailPoint has announced no end-of-life for it, which matters if you are evaluating a migration and want to know how long your current skills stay relevant.

What it does well: the connector library is the largest in the market, covering cloud and on-premises applications, databases, mainframe systems, and the long tail of business applications that nobody else has built for. Access certification campaigns are mature: you can scope them by application, by risk, by manager, or by entitlement, and the reviewer experience is good enough that managers actually complete them instead of rubber-stamping. Role mining analyzes existing access patterns to propose roles rather than requiring you to design them on a whiteboard first, which is the step that historically killed IGA projects. The machine learning recommendations flag outlier access, meaning entitlements one person has that nobody in a comparable role has, which is the single most productive place to start cleaning up an inherited environment.

The 2026 context: SailPoint returned to the public markets in February 2025 on NASDAQ. For buyers that means published financials and a predictable roadmap, and it also means the vendor is under quarterly revenue pressure, which tends to show up in renewal negotiations. Price accordingly and negotiate multi-year.

Honest weakness: cost and implementation time. A full SailPoint deployment covering provisioning, certification, and role management routinely runs six to twelve months and usually needs a specialist integration partner. The connector breadth does not eliminate custom connector work for homegrown applications, and that work is where timelines slip. Organizations under 1,000 employees will generally find the total cost of ownership hard to justify against Entra ID Governance or Okta Identity Governance.


2. Microsoft Entra ID Governance

Best for: any organization whose directory is already Entra ID, which is most organizations.

Entra ID Governance is the governance layer on top of Entra ID. For Microsoft-centric estates it is the default answer for a simple reason: it is priced as a per-user add-on rather than a platform deal, and it needs no second vendor relationship.

Published pricing, which is rare in this market: Microsoft lists Entra ID Governance at $7 per user per month on an annual commitment, available to Entra ID P1 and P2 customers. Entra ID P1 is $7 per user per month and P2 is $10. The Entra Suite, which bundles governance with network access, identity protection, and identity verification, is $12 per user per month and requires an existing P1 subscription. If you already hold Microsoft 365 E5, check what you own before buying anything; a meaningful share of organizations pay twice for capabilities E5 already includes.

What it does well: Lifecycle Workflows automate the joiner, mover, and leaver sequences off HR attributes. Entitlement management packages applications, groups, and SharePoint sites into access packages that users request and owners approve, with expiry dates attached, which is the single most effective control against access accumulating silently over a five-year tenure. Access reviews run recurring certification campaigns over groups, applications, and privileged roles. Privileged Identity Management provides time-bound, approval-gated elevation for administrative roles, and it is genuinely good.

Honest weakness: governance depth outside the Microsoft estate. Provisioning to non-Microsoft SaaS applications works through the Entra gallery and SCIM, and that covers the common cases well, but for on-premises legacy systems, mainframes, and custom applications the connector story is thin next to SailPoint, Saviynt, or One Identity. Separation of duties is also weaker than the dedicated IGA platforms; Entra does not do transaction-level SoD analysis, so if your requirement comes from SOX controls over an ERP, this will not satisfy it on its own. For organizations evaluating whether to stay on Microsoft at all, see the Entra ID alternatives guide.


3. Saviynt Identity Cloud

Best for: enterprises that want IGA, privileged access, and application access governance converged on one platform.

Saviynt is the strongest independent challenger to SailPoint, and the December 2025 funding round removed the last structural argument against it. The platform converges identity governance, privileged access management, application access governance, identity security posture management, and access gateways, which is a genuinely different architecture from stitching an IGA platform to a separate PAM product.

Application access governance is the differentiator. Saviynt goes deeper into the business applications that generate the compliance obligation in the first place, meaning SAP, Oracle, Workday, and the ERP layer, with fine-grained entitlement and SoD analysis inside those applications rather than treating them as opaque endpoints. For a finance organization whose audit findings all trace back to ERP access combinations, that is the capability that matters.

The 2026 context: the $700 million round led by KKR at roughly a $3 billion valuation funds a heavy push into non-human and AI agent identity governance. Treat the AI agent governance claims the way you would treat any 2026 vendor AI claim, and ask for a reference customer running it in production. The underlying problem is real though. Service accounts and agents now outnumber employees in most estates, and almost nobody certifies their access.

Honest weakness: Saviynt carries much of the same implementation weight as SailPoint. It is an enterprise platform with an enterprise deployment timeline, and the breadth of the converged platform means more configuration surface, not less. Smaller organizations should not read "converged platform" as "simpler."


4. Omada Identity Cloud

Best for: mid-to-large enterprises that want governance depth with a deployment that finishes.

Omada's distinguishing characteristic is prescriptiveness. Where SailPoint and Saviynt give you a platform and a great many choices, Omada ships an opinionated best-practice framework and a time-boxed deployment methodology. For organizations that have already failed one IGA project, that constraint is a feature rather than a limitation.

What it does well: identity lifecycle automation with a strong connector library, compliance reporting built around the frameworks auditors actually cite, recurring access certification, and configurable policy enforcement. The reporting is a genuine strength; the output is designed to be handed to an auditor rather than re-formatted first.

Honest weakness: the prescriptive model is a poor fit if your requirements are genuinely unusual, because you are fighting the framework rather than using it. Omada also has less market presence in North America than SailPoint or Saviynt, which shows up in the size of the partner and consultant pool you can hire from.


5. Okta Identity Governance

Best for: organizations already standardized on Okta Workforce Identity.

Okta Identity Governance adds access requests, access certification, and reporting to the Okta platform. For Okta customers it is the shortest path from "we have SSO and provisioning" to "we can survive an access audit."

Published pricing: Okta lists Core Essentials at $14 per user per month and Essentials at $17, both including Adaptive MFA, Privileged Access, Lifecycle Management, and Access Governance, with 50 Workflows. The Starter suite at $6 per user per month covers SSO, MFA, Universal Directory, and 5 Workflows but not governance. Identity Governance is also sold as a standalone add-on. There is a $1,500 annual contract minimum on Workforce Identity.

What it does well: the integration network is the largest in SaaS identity, so provisioning to cloud applications is configuration rather than engineering. Okta Workflows is a genuinely capable no-code orchestration engine, and it is what lets teams build the conditional logic that governance policies need without writing connectors. Certification campaigns run inside the same console your administrators already use, which raises completion rates more than any feature comparison suggests.

Honest weakness: governance depth is shallower than the dedicated IGA platforms. Role mining, SoD analysis, and coverage of on-premises legacy systems are all weaker, and large regulated enterprises frequently end up running Okta for access and SailPoint or Saviynt for governance, which is two licences and two integration efforts. Cost also climbs quickly once you move past the Starter suite. If you are reassessing Okta entirely, see the Okta Workforce Identity alternatives guide.


6. One Identity Manager

Best for: large enterprises with genuinely heterogeneous estates, particularly Active Directory plus SAP plus legacy.

One Identity Manager is the platform enterprises pick when the environment is too varied for a cloud-first product to cover. It handles Active Directory, SAP, Unix, mainframe, and cloud systems from one governance model, with unusually deep SAP support for a non-SAP vendor.

What it does well: cross-application governance where the applications do not agree on anything. Self-service access request with approval routing that can model complex organizational hierarchies. Attestation and recertification workflows. Delegated administration that lets business units manage their own access within policy boundaries, which is how you make governance scale past the identity team's headcount.

The portfolio context: One Identity also owns OneLogin, acquired in 2021 and still actively developed, which gives it a cloud SSO and lifecycle product alongside the enterprise governance platform. If you are already a One Identity customer, ask how the two roadmaps relate before assuming they converge.

Honest weakness: the interface and the deployment model show their age relative to cloud-native competitors, and the product is powerful in the way that demands specialists. Implementation is long. Ongoing administration needs people who know the platform specifically, and that skill pool is smaller than SailPoint's.


7. IBM Verify Identity Governance

Best for: regulated enterprises with hybrid and mainframe environments already invested in IBM.

IBM Verify Identity Governance, formerly IBM Security Verify Governance, covers automated provisioning and deprovisioning, access certification, role management, and risk-based access scoring, with the hybrid deployment flexibility that large regulated organizations need when not everything can move to SaaS.

What it does well: mainframe and legacy system coverage that cloud-native platforms simply do not attempt. Risk scoring that prioritizes which access to review first, which matters when a full certification campaign across a large enterprise is otherwise unmanageable. Integration with the wider IBM security portfolio if you already run it.

Honest weakness: feature breadth comes with configuration complexity, and IBM enterprise software carries the licensing and procurement overhead that implies. For organizations not already committed to IBM, the platform rarely wins on its own merits against SailPoint or Saviynt.


8. Oracle Identity Governance

Best for: enterprises whose critical applications are Oracle.

Oracle Identity Governance handles the full provisioning and deprovisioning cycle, role management, access certification, and SoD controls, with the deepest available integration into Oracle E-Business Suite, Oracle Database, Fusion applications, and the rest of the Oracle estate.

What it does well: if your SoD obligations sit inside Oracle applications, Oracle understands its own entitlement model in a way a generic connector cannot. Provisioning into Oracle Database roles and Fusion security is native rather than approximated.

Honest weakness: outside Oracle, the platform is unremarkable, and the connector story for non-Oracle systems does not compete with SailPoint. Implementation is long, licensing is entangled with broader Oracle agreements, and the user experience lags the market. Buy it because your estate is Oracle, not because you compared feature lists.


9. SAP Access Control and SAP Cloud Identity Access Governance

Best for: SAP estates with SOX or equivalent obligations over financial transactions.

This is the entry on the list with the clearest and narrowest justification. SAP Access Control, part of the SAP GRC portfolio, and its cloud counterpart SAP Cloud Identity Access Governance, perform separation of duties analysis at the transaction and authorization object level inside SAP. No generic IGA platform reaches that depth, because the analysis requires understanding what an SAP transaction code actually permits rather than which role contains it.

What it does well: transaction-level SoD rule sets that map to the control objectives auditors test. Emergency access management, the firefighter process, with full logging of what a privileged user did during an elevated session. Risk analysis before access is granted rather than detection afterwards.

Honest weakness: it governs SAP and effectively nothing else. Organizations end up running it alongside a general IGA platform, which means two systems, two sets of evidence, and a reconciliation problem at audit time. It is also complex to implement and to keep current as the SAP landscape changes. Saviynt and One Identity are the two general platforms with the strongest claim to reducing how much of this you need.


10. OpenText NetIQ IGA

Best for: regulated enterprises needing role mining and continuous compliance across older systems.

OpenText NetIQ Identity Governance and Administration, inherited through the Micro Focus acquisition, provides automated lifecycle management, role mining and analytics, policy enforcement, and continuous compliance monitoring, with particular strength on the mixed legacy environments common in government, healthcare, and utilities.

What it does well: role analytics on estates where nobody knows what the roles should be, which is the honest starting position for most organizations that have never run an IGA programme. Continuous compliance monitoring rather than point-in-time certification. Flexible deployment for organizations that cannot move everything to SaaS.

Honest weakness: product direction under OpenText is the open question, as it is for several assets acquired in that transaction. Implementation is complex, the partner ecosystem is smaller than SailPoint's, and the roadmap is less visible than a buyer would like. Ask for written roadmap commitments before signing a multi-year deal.


The Challengers Worth a Slot in the RFP

The ten above are the platforms that win enterprise deals. Four newer products are worth adding to a shortlist, particularly if your estate is SaaS-heavy and your problem is speed rather than depth.

Veza, now part of ServiceNow. Its Access Graph resolves effective permissions down to specific data objects, tables, and resources rather than stopping at group membership. That answers the question auditors actually ask, which is not "who is in this group" but "who can read this table." Post-acquisition, confirm standalone availability and pricing before building a plan around it.

ConductorOne. Modern access management and IGA covering access reviews, requests, lifecycle automation, and entitlement governance, with a focus on converting standing access into time-bound grants. The right shape for an organization whose problem is accumulated standing privilege across SaaS rather than mainframe governance.

Lumos. Combines an internal application store, self-service access requests, and access reviews. It competes simultaneously against SaaS management tools and against IGA platforms, which tells you where it sits: strong on the SaaS estate, lighter on everything else.

Delinea, via Fastpath. Delinea acquired Fastpath in April 2024, adding IGA and SoD analysis to a privileged access platform, and completed its StrongDM acquisition in March 2026. If your governance requirement is concentrated in privileged accounts and ERP access rather than the full workforce, this combination covers more of the problem than a general IGA platform would. See the Delinea alternatives guide if it is your incumbent and you are reassessing.

For the full vendor landscape across categories, the identity map governance category tracks this market as it moves, and the identity governance and administration comparison covers the IGA-specific evaluation in more depth.


How to Choose

Your directory is Entra ID and your applications are mostly SaaS: Entra ID Governance at $7 per user per month. Check your Microsoft 365 entitlements first, then buy the add-on. Revisit only when a connector gap or an SoD requirement forces it.

You run Okta and need to pass an access audit next quarter: Okta Identity Governance. Shortest distance between here and a completed certification campaign. Accept that role mining and legacy coverage are weaker.

Mixed estate, regulated industry, real audit findings: SailPoint, Saviynt, and Omada. Run all three through a proof of concept against your worst application, not your easiest one. That is the only part of the evaluation that predicts the deployment.

Your compliance problem is SAP or Oracle transaction-level SoD: the vendor's own product, plus a general platform for everything else. Plan for the reconciliation work between them; it is the part that gets underestimated.

Heterogeneous legacy plus SAP plus Active Directory: One Identity Manager, with IBM and OpenText NetIQ as alternates if you have an existing relationship.

SaaS-heavy, no mainframe, standing access is the problem: look at ConductorOne and Lumos before committing to an enterprise platform. You may not need the weight.

Whatever you pick, sequence it correctly. Get provisioning working and reliable before you run a certification campaign. Certifying access that your provisioning cannot revoke produces a list of findings and no remediation, which is worse than not having run the campaign, because now it is documented.


Frequently Asked Questions

What is the difference between user provisioning and identity governance?

Provisioning automates creating, modifying, and removing accounts across connected systems based on lifecycle events. Governance adds policy enforcement, access certification, separation of duties, and audit reporting on top. Provisioning answers "how do we grant and remove access efficiently?" Governance answers "is this access appropriate, and can we prove it?" Modern platforms combine both, but they are separate capabilities with separate failure modes, and organizations routinely buy the first while assuming they bought the second.

Do I need a separate governance platform if I already use Okta or Entra ID for SSO?

SSO handles authentication and basic provisioning. It does not, by itself, give you certification campaigns, separation of duties enforcement, role-based access design, or audit-ready reporting. Both vendors now sell governance as an add-on: Entra ID Governance at $7 per user per month, Okta Identity Governance inside the Core Essentials suite or standalone. For most organizations that add-on is enough. For regulated enterprises with ERP SoD obligations or heavy legacy estates, it is not, and Okta environments in that position commonly pair with SailPoint or Saviynt.

What is separation of duties and why does it matter?

Separation of duties prevents one person from controlling multiple steps in a sensitive process. The classic example is that the person who can create a vendor record should not also be able to approve payments to it, because together those permissions enable fraud. SoD controls are required by SOX for financial systems, by FDA regulations in pharmaceutical manufacturing, and by various banking regulations. Governance platforms enforce SoD by blocking policy-violating combinations at provisioning time and detecting existing violations for remediation. The detection half is usually where organizations discover how bad the inherited situation is.

How long does an implementation take?

Traditional enterprise platforms such as SailPoint, Saviynt, and One Identity typically run six to twelve months to first production value, covering connector work, role engineering, and policy configuration. Cloud-native options such as Entra ID Governance, Okta Identity Governance, and Omada can reach initial deployment in eight to sixteen weeks using pre-built connectors and prescriptive workflows. The variable that dominates every estimate is custom connector development for legacy and homegrown applications. Count those applications before you accept any timeline.

What does SCIM support actually mean when a vendor claims it?

Less than buyers assume. Ask four specific questions. Does it support inbound SCIM as well as outbound, since many products only push? Which schema extensions does it implement beyond the core user and group resources? Does it support cursor-based pagination, standardized in RFC 9865 in October 2025, or only index-based pagination that can silently skip users during large syncs? Does it support event-driven provisioning through the SCIM Security Event Token profile, standardized in RFC 9967 in May 2026, or only scheduled polling? The last one determines how fast a termination propagates.

How do we govern service accounts and AI agents?

The same way as people, and almost nobody does. Non-human identities now outnumber human ones in most cloud estates, and they are the accounts least likely to be certified, most likely to hold standing privilege, and least likely to have a named owner. Start by requiring every service account to have a human owner recorded in the governance platform, then include them in certification campaigns, then work toward short-lived credentials instead of static ones. Saviynt, SailPoint, and the ServiceNow-Veza combination all now market agent identity governance; the underlying discipline matters more than the feature.

How is this different from identity lifecycle management?

Lifecycle management is the orchestration layer: HR events trigger joiner, mover, and leaver sequences so that a new hire has their access on day one and a departure loses it the same day. Governance is the assurance layer: it verifies the result is correct and produces the evidence. Lifecycle management is an operations problem measured in hours and days. Governance is a compliance problem measured in audit findings. The identity lifecycle management comparison covers the first; this page covers the second. For the broader workforce identity platform decision that sits above both, see the IAM solutions comparison.


Final Take

Buy governance at the level your audit actually requires, not at the level the vendor demo implies. Most organizations running Microsoft or Okta should start with the native add-on, prove out certification campaigns on their three riskiest applications, and only move to a dedicated platform when a specific gap forces it. The gap, when it comes, is almost always the same one: a legacy or ERP system that the native connector cannot reach, and an auditor who will not accept a spreadsheet.

Get the provisioning plumbing reliable first. Certification without working deprovisioning produces documented findings you cannot remediate, which is the worst outcome available. Then instrument the non-human identities, because they are the ones nobody is watching and the ones that will outnumber your employees before this guide is a year older.


Published 2025, last verified September 2026. ServiceNow completed its acquisition of Veza on March 2, 2026. Saviynt closed a $700 million round led by KKR in December 2025. Palo Alto Networks completed its acquisition of CyberArk on February 11, 2026, and Delinea completed its acquisition of StrongDM on March 5, 2026. Only Microsoft and Okta publish list pricing in this category; every other figure requires a quote. Verify current pricing and roadmap commitments with each vendor before procurement.

Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:

Get the newsletter

New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.

Tell us what you read most (optional)