Talk to us
by GuruculTechBag Intel Page

Gurucul Identity Analytics

Not who has access — which access is dangerous. Gurucul Identity Analytics scores entitlements and access patterns for risk, surfacing excess privilege, dormant high-risk access and the permissions that accumulate across a decade of role changes and never get removed.

Risk, not inventoryRBI / SEBI access evidenceAnalytics — not an IGA suite

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
The question
which access is dangerous
Risk, not inventory
India fit
access governance you can demonstrate
RBI / SEBI evidence
Integration
shared with the SIEM and UEBA
One identity model
Scope limit
complements governance, does not replace it
Analytics, not IGA

Data residency & processing — answered by definition

Where data lives

Yours, if you self-host

Gartner’s own 2025 MQ text confirms the platform runs SaaS, cloud OR self-hosted. Self-hosted puts collection scope and physical storage under your control — on-premises or your own cloud account, in India if you choose — which is how you hold 180 days of logs in Indian jurisdiction and evidence it.

Two things we could NOT verify

Air-gap, and any India region

A genuine air gap is marketed but we could not confirm it independently, and self-hosted is not the same thing — air-gap affects licence activation, threat-intel updates and support access. We also found no evidence of a vendor-run India data region. Get both in writing before you commit.

Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs stay producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it becomes unambiguous is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, self-hosting stops being a preference. Note too that people in India and data in India are different things — the Pune engineering centre is real, and it is not a data region.

Quick answer

Gurucul Identity Analytics answers a question most access-review processes cannot: not who has access, but which access is actually dangerous. Identity Access Analytics scores entitlements and access patterns for risk rather than cataloguing them — surfacing excess privilege, dormant high-risk access nobody has used in a year, and the permissions that accumulate around people across a decade of role changes and never get removed. That accumulation is the specific problem. Most organisations grant access competently and revoke it poorly, so after several years a long-tenured employee holds the union of every role they have ever had. No individual grant was wrong. The aggregate is a serious risk, and a conventional access review that asks a manager to tick a list of entitlements they do not understand will never find it. Risk scoring changes the question from "is this access approved" to "is this access dangerous, and is it being used". For Indian BFSI buyers this maps onto real regulatory expectation. RBI and SEBI both expect demonstrable access governance with evidence, and Gurucul publishes India-specific material mapped to SEBI's CSCRF — unusual for a vendor this size, and a signal the India go-to-market is deliberate. Because it runs on the REVEAL platform, access risk and threat detection share one identity model, so the SIEM knows what a user should be able to do when it judges what they did. One honest limit: this is analytics, not an identity governance suite. It tells you what is risky and evidences it. It does not run your joiner-mover-leaver workflow or provision accounts, so it complements an IGA product rather than replacing one. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Gurucul Identity Analytics — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
Gurucul Identity Analytics (IAA) — on the REVEAL platform
Vendor
Gurucul — founder-CEO Saryu Nayyar, still in post
The question it answers
Which access is DANGEROUS, not merely which exists
Finds
Excess privilege · dormant high-risk access · accumulated permissions
India relevance
RBI and SEBI access-review evidence; SEBI CSCRF material published
Shares
One identity model with the SIEM and UEBA
Deployment
Follows the platform: SaaS, cloud or self-hosted
Data residency
Yours if self-hosted; no vendor India region found
Data processing
Same platform — access risk and detection reason over one model
What it is NOT
Not IGA — it does not provision accounts or run JML workflow
Buy in India via
TechBag — INR, GST, scoped against your IGA if you have one
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Scoring entitlements and access patterns for risk rather than cataloguing them — excess privilege, dormant high-risk access, and permissions accumulated across years of role changes.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolIdentity Analytics
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownMonitored users — grows with headcount
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
One data model

REVEAL platform

The converged layer

SIEM, behavioural analytics, identity analytics, network traffic analysis and SOAR run against the same data rather than as separately licensed products stitched together. Gurucul built the analytics first in 2010 and grew the SIEM around them, which is why there is one store and one query surface rather than two that disagree.

02
SaaS, cloud or self-hosted

Deployment

Yours to choose

Confirmed in Gartner's own 2025 Magic Quadrant text. Self-hosted is the option that matters for a regulated Indian buyer, because it puts collection scope and physical storage under your control — which is how you hold 180 days of logs in Indian jurisdiction and evidence it to an auditor.

03
Baselines and deviation

Behavioural engine

UEBA in the core

Models how each user and entity normally behaves, correlates identity, access and activity, and scores deviation. This is what catches the attacker who signs in correctly with stolen credentials — every step permitted, so no rule fires.

04
Access risk and detection together

Identity model

Shared

Entitlements and access patterns are scored for risk on the same platform, so when behavioural analytics flags a user an analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated.

05
The tools you already own

Ingestion

Vendor-neutral

Telemetry from existing endpoint, network, cloud and identity products is ingested rather than replaced. Test connector depth on your own stack during the proof of concept: rich normalised telemetry and forwarded alerts are both called integrations, and only one supports an investigation.

06
Response on the same data

SOAR

Included

Playbooks and automated response ship on the platform rather than as a separate product with its own meter, which is how several competitors price it. Stage automated response carefully before letting it act on production.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Deploy

Self-hosted, cloud or SaaS

Runs on infrastructure you control where a mandate requires it — confirmed by Gartner rather than only by the vendor.

Collect
Ingest

Broad source collection

Collects logs and telemetry from endpoint, network, identity, cloud and SaaS sources into one platform.

Collect
Identity

Identity and access context

Correlates entitlements and access data with activity so detections carry who-can-do-what context, not just what happened.

Collect
Network

Network traffic analysis

Adds wire-level evidence to the same timeline — which matters most when a compromised endpoint's own telemetry cannot be trusted.

Detect
UEBA

Behavioural baselines

Models normal behaviour per user and entity and scores deviation, catching credential abuse and insider misuse that break no rule.

Detect
Risk

Accumulated risk scoring

Builds risk across identity, endpoint and network signals rather than treating each alert as an isolated event.

Detect
Access

Entitlement risk

Surfaces excess privilege, dormant high-risk access and permissions accumulated across years of role changes.

Detect
Content

Maintained detection content

Ships and updates detection logic so the platform produces useful alerts without a dedicated detection-engineering function.

Respond
Investigate

Score to raw events

Analysts move from a risk score to the underlying activity on the same platform, without exporting to a second tool.

Respond
SOAR

Playbooks and automation

Automated response workflows included on the platform rather than licensed separately with their own meter.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Gurucul (official)·Platform

Gurucul REVEAL — Platform Overview

Where identity analytics sits.

Gurucul (official)·AI

Gurucul AI SOC Analyst

The analyst-assist layer.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Identity Analytics

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

Accumulated privilege is the risk nobody reviews

Organisations grant access competently and revoke it poorly. Somebody joins in one role, moves to a second, covers a third temporarily during a busy quarter, and is promoted into a fourth — and at each step access is added because the work requires it. Almost nothing is ever taken away, because removal has a cost if you get it wrong and no cost at all if you do not bother. After a decade, long-tenured employees hold the union of every role they have ever occupied. No individual grant was a mistake. The aggregate is one of the most exploitable conditions in your estate, and it is invisible to a review process that examines grants one at a time.

02

Risk scoring changes the question managers are asked

The reason conventional access reviews fail is not laziness, it is that they ask the wrong person the wrong question. A manager handed a list of two hundred entitlement names in system-generated notation cannot tell you which matter, so they approve all of them — which is rational, and produces an audit trail that proves nothing. Scoring access for risk inverts it: instead of asking "is all of this approved", you ask "here are the eleven entitlements that are genuinely dangerous, are these eleven still needed". That is a question a manager can actually answer, and the resulting evidence means something to a regulator.

03

Dormant access is where the risk concentrates

Access nobody uses is not harmless — it is the ideal target, because misuse of it produces no deviation from a pattern of legitimate use, for the simple reason that there is no pattern. High-privilege entitlements that have sat unused for a year are simultaneously the easiest to remove without business disruption and the most valuable to an attacker who obtains them. Surfacing that intersection is one of the highest-return outputs of identity analytics, and it is one of the few security recommendations that reliably meets no resistance from the business.

04

It shares an identity model with your detection

Because this runs on the same platform as the SIEM and UEBA, access risk and threat detection reason over one picture of who your users are. That has a concrete consequence during an investigation: when behavioural analytics flags a user, the analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated — context that turns an ambiguous risk score into a decision. Running access governance and detection on separate platforms means answering that question by correlating two systems that disagree about your directory.

05

The honest limit: this is analytics, not identity governance

We want to be precise about scope, because the categories are adjacent and vendors blur them. Identity Analytics tells you what access is risky and gives you evidence. It does not run your joiner-mover-leaver workflow, it does not provision or deprovision accounts, and it does not own your certification campaigns end to end. If you have an IGA platform — SailPoint, Saviynt, One Identity — this complements it by adding risk intelligence to decisions that platform executes. If you do not have one, this will not become one, and you should not buy it expecting that. TechBag sells IGA products too, and we will tell you which problem you actually have before you buy for the other one.

06

The honest positioning

Choose Identity Analytics when you can list who has access but cannot say which access is dangerous, and when a regulator expects evidence that you review it meaningfully rather than ceremonially. It is strongest for Indian BFSI buyers under RBI and SEBI expectations, particularly alongside the SIEM, where the shared identity model earns its keep during investigations. Do not choose it as your first identity purchase if you have no governance platform at all — fix provisioning and JML first, because analytics on top of an unmanaged identity estate mostly produces an accurate description of chaos.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

2010
Gurucul founded — UEBA was the starting point
Company
2025
Named a Gartner MQ Leader (first year)
Gartner 2025
4.49/5
Gartner Peer Insights across 109 reviews
Peer Insights 2026
3 deployment models
SaaS, cloud or self-hosted — Gartner-confirmed
Gartner 2025
1 platform
Shared data model across SIEM, UEBA, identity and NTA
Gurucul
180 days
CERT-In retention, answerable by self-hosting
CERT-In 2022

What your Gurucul Identity Analytics rollout looks like

Week 1Assess

Confirm the deployment mandate

This is part of the REVEAL platform, so the deployment question is the platform's: SaaS, cloud or self-hosted. If a regulator or contract requires infrastructure you control, that is the reason Gurucul is on your shortlist at all, and it should be settled before features.

Weeks 1–3Assess

Fix the identity data first

Peer groups and access risk are both bounded by directory quality. Leavers still active, roles that do not match actual jobs, and unowned service accounts all produce output you cannot act on. This work improves your posture regardless of vendor, so start it before procurement finishes.

Weeks 3–8Deploy

Onboard sources in priority order

Identity, endpoint and cloud control-plane telemetry first — they carry the highest detection value per unit of effort. Resist the urge to connect everything at once; a smaller, well-understood set produces better baselines than a large noisy one.

Weeks 6–14Tune

Let it baseline before you judge it

Behavioural models must observe normal before deviation means anything, and that is weeks rather than days. Agree the period up front with everyone who will evaluate the deployment, and resist heavy suppression during the noisy phase — early over-tuning tends to survive long after the reason for it is gone.

OngoingOperate

Review access risk on a cadence a regulator would recognise

Turn the output into a documented review rhythm with named owners and dated decisions. The evidence trail is worth as much as the findings when RBI or SEBI ask how you govern access, and it is far easier to maintain than to reconstruct.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
Behavioural scoring found an account takeover our rule-based SIEM had logged and ignored for eleven days.
Head of Security Operations
Banking
Financial Services
The identity context is what makes the scores actionable. Without it you are guessing at why someone scored high.
SOC Manager
Financial Services
Insurance
Budget the directory clean-up first. We did not, and spent six weeks arguing with output we could not trust.
Security Architect
Insurance
Manufacturing
Smaller vendor than the alternatives we shortlisted. The trade is a slimmer ecosystem for faster access to real engineers.
IT Director
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
GuruculThis page

2025 MQ Leader — and the only one that self-hosts.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
GuruculThis page

One data model — SIEM, UEBA, identity and NTA.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Gurucul Identity Analytics vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionGuruculSecuronixExabeamMicrosoft SentinelSplunk ES
2025 Gartner MQLeader — first year, after 3 as VisionaryLeader, 6 consecutive yearsLeader, 6th timeLeaderLeader, 11th consecutive
Self-hosted / on-premisesYES — SaaS, cloud or self-hosted per GartnerNo — control plane is always their cloudVia LogRhythm, a second platformCloud-only on AzureYes, and priced accordingly
Pricing axisPer asset / per user, OR data volume / EPSGB/day in tiered bandsMonitored users and sourcesPer GB ingested per dayIngest or workload — the priciest here
Behavioural analyticsThe founding capability, built 2010The founding capabilityThe founding capabilityUEBA includedAvailable, add-on heritage
India data residencySelf-hosted: yours. No vendor India region foundBYO-AWS/Snowflake can hold data in IndiaSelf-hosted via LogRhythmAzure India regions availableSelf-hosted: yours to place
Vendor scaleBootstrapped boutique — no war chestVC-backed, ~450 engineers in IndiaPost-merger with LogRhythmMicrosoftCisco-owned
Analyst breadthGartner-specific — absent from 2025 Forrester WaveIn both Gartner and ForresterIn bothIn bothIn both
The thing to plan aroundAir-gap unverified; confirm the pricing axisNo air-gap at all; 120% default overageTwo platforms post-mergerAzure portal retires 31 Mar 2027Untuned, it is the costliest log archive there is
Best fitOn-premises mandates needing an analyst-recognised productCloud-accepting estates wanting retention solvedUser-based economics, or on-prem via LogRhythmMicrosoft estates with E5Engineers who will build with it
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Gurucul Identity Analytics fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Gurucul Identity Analytics if…

  • You can list who has access but not which access is dangerous
  • RBI or SEBI expect evidence you review access meaningfully, not ceremonially
  • You already have an IGA platform this can add risk intelligence to
  • Accumulated privilege across role changes is a known problem you cannot quantify

Choose Securonix if…

  • Cloud is acceptable and you want the larger vendor with a six-year Leader run
  • 365 days of hot searchable data as standard matters to your investigations
  • You accept there is no air-gapped or on-premises option in any configuration

Choose Microsoft Sentinel if…

  • You are standardised on Microsoft 365 with E5 — first-party logs ingest free
  • Azure India regions answer your residency question directly
  • You accept cloud-only on Azure, and the portal migration by 31 Mar 2027

Choose Elastic or Wazuh if…

  • You need a genuine air gap and have platform engineers to operate it
  • You would rather trade analyst standing for deployment freedom and cost control
  • Wazuh’s core is free under GPLv2; Elastic self-manages at the Basic tier

Gurucul Identity Analytics is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Gurucul can meter per asset or per user as an alternative to per-gigabyte ingest. That is the comparison worth modelling, because it is the one that changes behaviour: on an ingest-priced SIEM every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Move both sliders — the assets you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number, since Gurucul is quote-only. It is the shape: asset counts change slowly, log volume only ever goes up. Indicative Indian-market rates.

750
25010,000
150
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. And remember the precision that matters here: Gurucul offers per-asset pricing as an alternative to per-GB, not instead of it — data-volume and EPS options exist on the same list. Which axis you land on is negotiated, so make it a clause rather than an assumption.

An ingest-metered SIEM, at your GB/day
₹4,50,00,000
Saved vs an ingest-priced SIEM user meter
₹4,11,00,000
₹20,55,00,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Identity Analytics is part of the platform rather than a separate meter. The scope question matters more than the price question: this is analytics, not identity governance. It tells you which access is risky and evidences it. It does not run your joiner-mover-leaver workflow, provision accounts or own certification campaigns end to end — so it complements an IGA platform rather than replacing one. TechBag sells IGA products too, and we will tell you which problem you actually have. INR with GST.

Part of the platform

Includedin the REVEAL entitlement

Not a separate meter

  • Shares one identity model with the SIEM and UEBA
  • Access risk and detection reason over one picture
  • You are really deciding on the platform

What it is NOT

scope limit

Analytics, not IGA

  • Does not provision or deprovision accounts
  • Does not run joiner-mover-leaver workflow
  • Complements SailPoint, Saviynt or One Identity

India relevance

RBI / SEBIaccess-review evidence

Why BFSI buyers look here

  • Turns tick-box reviews into answerable questions
  • Gurucul publishes SEBI CSCRF material
  • The audit trail is worth as much as the findings

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Deployment

Does a mandate require the platform on infrastructure we control? That decides the shortlist.

2
Identity data

Is our directory clean enough for peer groups and access risk to mean anything?

3
Service accounts

Do our service accounts have named owners who can adjudicate an alert about them?

4
Baselining

How many weeks will we allow before judging output quality?

5
Scope

Are we clear this is part of the platform rather than a standalone purchase?

6
Existing tools

What do we already own that this must work with rather than replace?

7
Evidence

What review cadence and audit trail will we maintain for RBI or SEBI?

8
Air-gap

If we need a genuine air gap, do we have it in writing? Self-hosted is not the same thing.

9
Vendor scale

Has our risk function accepted a bootstrapped boutique competing with hyperscalers?

10
Alternatives

If the deployment constraint does not bind us, have we priced Sentinel and Securonix too?

FAQ

Questions buyers ask

As part of the platform, and this shapes the whole evaluation. Gurucul sells the REVEAL platform, which converges SIEM, user and entity behaviour analytics, identity analytics, network traffic analysis and SOAR onto one data model. Gurucul Identity Analytics is one of the things that platform does, not a standalone product with its own meter that you bolt onto a SIEM from somebody else. That has a genuine upside and a genuine constraint, and you should weigh both. The upside is architectural: because everything runs on one data model, an analyst moves between a risk score, the access that produced it and the raw events without switching tools or waiting on an export. The common alternative — a SIEM from one vendor and analytics from another — means storing your data twice, learning two query languages, and reconciling two systems that disagree about your directory. The constraint is commercial: you are really deciding whether to buy Gurucul Next-Gen SIEM, and this capability is a reason to choose it rather than an independent purchase you can make alongside a competitor's platform. If you already run a SIEM you are committed to and want only this capability, say so early — that is a different shortlist, and we would rather scope it properly than sell you a platform to use one part of.

Ready to evaluate Gurucul Identity Analytics?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.