Not who has access — which access is dangerous. Gurucul Identity Analytics scores entitlements and access patterns for risk, surfacing excess privilege, dormant high-risk access and the permissions that accumulate across a decade of role changes and never get removed.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — answered by definition
Where data lives
Yours, if you self-host
Gartner’s own 2025 MQ text confirms the platform runs SaaS, cloud OR self-hosted. Self-hosted puts collection scope and physical storage under your control — on-premises or your own cloud account, in India if you choose — which is how you hold 180 days of logs in Indian jurisdiction and evidence it.
Two things we could NOT verify
Air-gap, and any India region
A genuine air gap is marketed but we could not confirm it independently, and self-hosted is not the same thing — air-gap affects licence activation, threat-intel updates and support access. We also found no evidence of a vendor-run India data region. Get both in writing before you commit.
Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs stay producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it becomes unambiguous is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, self-hosting stops being a preference. Note too that people in India and data in India are different things — the Pune engineering centre is real, and it is not a data region.
Quick answer
This page covers Gurucul Identity Analytics — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Scoring entitlements and access patterns for risk rather than cataloguing them — excess privilege, dormant high-risk access, and permissions accumulated across years of role changes.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Identity Analytics |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Monitored users — grows with headcount |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
SIEM, behavioural analytics, identity analytics, network traffic analysis and SOAR run against the same data rather than as separately licensed products stitched together. Gurucul built the analytics first in 2010 and grew the SIEM around them, which is why there is one store and one query surface rather than two that disagree.
Confirmed in Gartner's own 2025 Magic Quadrant text. Self-hosted is the option that matters for a regulated Indian buyer, because it puts collection scope and physical storage under your control — which is how you hold 180 days of logs in Indian jurisdiction and evidence it to an auditor.
Models how each user and entity normally behaves, correlates identity, access and activity, and scores deviation. This is what catches the attacker who signs in correctly with stolen credentials — every step permitted, so no rule fires.
Entitlements and access patterns are scored for risk on the same platform, so when behavioural analytics flags a user an analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated.
Telemetry from existing endpoint, network, cloud and identity products is ingested rather than replaced. Test connector depth on your own stack during the proof of concept: rich normalised telemetry and forwarded alerts are both called integrations, and only one supports an investigation.
Playbooks and automated response ship on the platform rather than as a separate product with its own meter, which is how several competitors price it. Stage automated response carefully before letting it act on production.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Runs on infrastructure you control where a mandate requires it — confirmed by Gartner rather than only by the vendor.
Collects logs and telemetry from endpoint, network, identity, cloud and SaaS sources into one platform.
Correlates entitlements and access data with activity so detections carry who-can-do-what context, not just what happened.
Adds wire-level evidence to the same timeline — which matters most when a compromised endpoint's own telemetry cannot be trusted.
Models normal behaviour per user and entity and scores deviation, catching credential abuse and insider misuse that break no rule.
Builds risk across identity, endpoint and network signals rather than treating each alert as an isolated event.
Surfaces excess privilege, dormant high-risk access and permissions accumulated across years of role changes.
Ships and updates detection logic so the platform produces useful alerts without a dedicated detection-engineering function.
Analysts move from a risk score to the underlying activity on the same platform, without exporting to a second tool.
Automated response workflows included on the platform rather than licensed separately with their own meter.
Endpoint protection, XDR and Security Copilot.
Where identity analytics sits.
The analyst-assist layer.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
Organisations grant access competently and revoke it poorly. Somebody joins in one role, moves to a second, covers a third temporarily during a busy quarter, and is promoted into a fourth — and at each step access is added because the work requires it. Almost nothing is ever taken away, because removal has a cost if you get it wrong and no cost at all if you do not bother. After a decade, long-tenured employees hold the union of every role they have ever occupied. No individual grant was a mistake. The aggregate is one of the most exploitable conditions in your estate, and it is invisible to a review process that examines grants one at a time.
The reason conventional access reviews fail is not laziness, it is that they ask the wrong person the wrong question. A manager handed a list of two hundred entitlement names in system-generated notation cannot tell you which matter, so they approve all of them — which is rational, and produces an audit trail that proves nothing. Scoring access for risk inverts it: instead of asking "is all of this approved", you ask "here are the eleven entitlements that are genuinely dangerous, are these eleven still needed". That is a question a manager can actually answer, and the resulting evidence means something to a regulator.
Access nobody uses is not harmless — it is the ideal target, because misuse of it produces no deviation from a pattern of legitimate use, for the simple reason that there is no pattern. High-privilege entitlements that have sat unused for a year are simultaneously the easiest to remove without business disruption and the most valuable to an attacker who obtains them. Surfacing that intersection is one of the highest-return outputs of identity analytics, and it is one of the few security recommendations that reliably meets no resistance from the business.
Because this runs on the same platform as the SIEM and UEBA, access risk and threat detection reason over one picture of who your users are. That has a concrete consequence during an investigation: when behavioural analytics flags a user, the analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated — context that turns an ambiguous risk score into a decision. Running access governance and detection on separate platforms means answering that question by correlating two systems that disagree about your directory.
We want to be precise about scope, because the categories are adjacent and vendors blur them. Identity Analytics tells you what access is risky and gives you evidence. It does not run your joiner-mover-leaver workflow, it does not provision or deprovision accounts, and it does not own your certification campaigns end to end. If you have an IGA platform — SailPoint, Saviynt, One Identity — this complements it by adding risk intelligence to decisions that platform executes. If you do not have one, this will not become one, and you should not buy it expecting that. TechBag sells IGA products too, and we will tell you which problem you actually have before you buy for the other one.
Choose Identity Analytics when you can list who has access but cannot say which access is dangerous, and when a regulator expects evidence that you review it meaningfully rather than ceremonially. It is strongest for Indian BFSI buyers under RBI and SEBI expectations, particularly alongside the SIEM, where the shared identity model earns its keep during investigations. Do not choose it as your first identity purchase if you have no governance platform at all — fix provisioning and JML first, because analytics on top of an unmanaged identity estate mostly produces an accurate description of chaos.
This is part of the REVEAL platform, so the deployment question is the platform's: SaaS, cloud or self-hosted. If a regulator or contract requires infrastructure you control, that is the reason Gurucul is on your shortlist at all, and it should be settled before features.
Peer groups and access risk are both bounded by directory quality. Leavers still active, roles that do not match actual jobs, and unowned service accounts all produce output you cannot act on. This work improves your posture regardless of vendor, so start it before procurement finishes.
Identity, endpoint and cloud control-plane telemetry first — they carry the highest detection value per unit of effort. Resist the urge to connect everything at once; a smaller, well-understood set produces better baselines than a large noisy one.
Behavioural models must observe normal before deviation means anything, and that is weeks rather than days. Agree the period up front with everyone who will evaluate the deployment, and resist heavy suppression during the noisy phase — early over-tuning tends to survive long after the reason for it is gone.
Turn the output into a documented review rhythm with named owners and dated decisions. The evidence trail is worth as much as the findings when RBI or SEBI ask how you govern access, and it is far easier to maintain than to reconstruct.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Behavioural scoring found an account takeover our rule-based SIEM had logged and ignored for eleven days.”
“The identity context is what makes the scores actionable. Without it you are guessing at why someone scored high.”
“Budget the directory clean-up first. We did not, and spent six weeks arguing with output we could not trust.”
“Smaller vendor than the alternatives we shortlisted. The trade is a slimmer ecosystem for faster access to real engineers.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
2025 MQ Leader — and the only one that self-hosts.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
One data model — SIEM, UEBA, identity and NTA.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Gurucul | Securonix | Exabeam | Microsoft Sentinel | Splunk ES |
|---|---|---|---|---|---|
| 2025 Gartner MQ | Leader — first year, after 3 as Visionary | Leader, 6 consecutive years | Leader, 6th time | Leader | Leader, 11th consecutive |
| Self-hosted / on-premises | YES — SaaS, cloud or self-hosted per Gartner | No — control plane is always their cloud | Via LogRhythm, a second platform | Cloud-only on Azure | Yes, and priced accordingly |
| Pricing axis | Per asset / per user, OR data volume / EPS | GB/day in tiered bands | Monitored users and sources | Per GB ingested per day | Ingest or workload — the priciest here |
| Behavioural analytics | The founding capability, built 2010 | The founding capability | The founding capability | UEBA included | Available, add-on heritage |
| India data residency | Self-hosted: yours. No vendor India region found | BYO-AWS/Snowflake can hold data in India | Self-hosted via LogRhythm | Azure India regions available | Self-hosted: yours to place |
| Vendor scale | Bootstrapped boutique — no war chest | VC-backed, ~450 engineers in India | Post-merger with LogRhythm | Microsoft | Cisco-owned |
| Analyst breadth | Gartner-specific — absent from 2025 Forrester Wave | In both Gartner and Forrester | In both | In both | In both |
| The thing to plan around | Air-gap unverified; confirm the pricing axis | No air-gap at all; 120% default overage | Two platforms post-merger | Azure portal retires 31 Mar 2027 | Untuned, it is the costliest log archive there is |
| Best fit | On-premises mandates needing an analyst-recognised product | Cloud-accepting estates wanting retention solved | User-based economics, or on-prem via LogRhythm | Microsoft estates with E5 | Engineers who will build with it |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Gurucul Identity Analytics is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Gurucul can meter per asset or per user as an alternative to per-gigabyte ingest. That is the comparison worth modelling, because it is the one that changes behaviour: on an ingest-priced SIEM every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Move both sliders — the assets you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number, since Gurucul is quote-only. It is the shape: asset counts change slowly, log volume only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. And remember the precision that matters here: Gurucul offers per-asset pricing as an alternative to per-GB, not instead of it — data-volume and EPS options exist on the same list. Which axis you land on is negotiated, so make it a clause rather than an assumption.
Identity Analytics is part of the platform rather than a separate meter. The scope question matters more than the price question: this is analytics, not identity governance. It tells you which access is risky and evidences it. It does not run your joiner-mover-leaver workflow, provision accounts or own certification campaigns end to end — so it complements an IGA platform rather than replacing one. TechBag sells IGA products too, and we will tell you which problem you actually have. INR with GST.
Not a separate meter
Analytics, not IGA
Why BFSI buyers look here
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does a mandate require the platform on infrastructure we control? That decides the shortlist.
Is our directory clean enough for peer groups and access risk to mean anything?
Do our service accounts have named owners who can adjudicate an alert about them?
How many weeks will we allow before judging output quality?
Are we clear this is part of the platform rather than a standalone purchase?
What do we already own that this must work with rather than replace?
What review cadence and audit trail will we maintain for RBI or SEBI?
If we need a genuine air gap, do we have it in writing? Self-hosted is not the same thing.
Has our risk function accepted a bootstrapped boutique competing with hyperscalers?
If the deployment constraint does not bind us, have we priced Sentinel and Securonix too?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.