Talk to us
by IBMTechBag Intel Page

IBM Verify Identity Governance

Your auditors ask who approved each access right. Your spreadsheets can’t say — IBM Verify Identity Governance provisions, reviews and reports on access, writes segregation-of-duties rules as business activities, and runs on premises or in the cloud, so the audit trail can stay on your own servers in India.

SoD written as business activitiesRoles mined from real entitlementsOn premises or cloud, quoted

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Usage-based; IBM prints no rate, so the meter is agreed in the quote
Quote
Deployment
IBM offers both; the self-hosted route is the one that keeps data on your hardware
On-prem or cloud
Analysts
Gartner publishes no IGA Magic Quadrant; IBM’s 2025 Access Management Leader claim is for Verify access
No IGA MQ
India
Install it in an Indian data centre; no India region is documented for the cloud edition
Your servers

Quick answer

IBM Verify Identity Governance provisions, audits and reports on user access through lifecycle, compliance and analytics capabilities, on premises or in the cloud. Its segregation-of-duties model is written as business activities rather than role pairs, and at Exostar it mined 10,000 entitlements into a few hundred business roles. Pricing is usage-based and quoted, and an on-premises install keeps the data on your own servers in India. Read more ↓ Show less ↑
Part 01 · Orient

The IBM platform family

This page covers IBM Verify Identity Governance — IBM’s IGA product in the Verify family. The rest:

Quick facts

30-second orientation
Product
Provisioning, access audit and reporting across the identity lifecycle, with activity-based SoD
Maker
IBM; Chairman and CEO Arvind Krishna since April 2020
Family
One of nine products IBM lists under Verify; the governance line formerly sold as IGI
Deployment
On premises or in the cloud, according to IBM’s product page
Price
Usage-based and quoted; IBM publishes no rate for it
SoD model
Activity-based: conflicts defined as business activities, beyond role-pair rules
Role evidence
Exostar: 10,000 entitlements condensed into a few hundred business roles
Onboarding
Commercial International Bank (Egypt) gives new hires access in under a day
India
Self-hosted, the data stays on your servers; no Indian hosting is documented for the cloud edition
In India via
TechBag — SoD activity mapping, an itemised INR quote with GST, a pilot review campaign
Part 02 · Learn

Understand identity governance before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is identity governance?

It decides who should hold which access, removes what is no longer needed, and keeps evidence for the auditor.

Tickets and spreadsheets vs governed access — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionTickets and SoD spreadsheetsIBM Verify Identity Governance
Who grants accessA ticket an admin works through laterLifecycle provisioning from the joiner event
Proof a change happenedThe ticket was closed, so we assume itClosed loop: the target’s result is read back
How SoD is writtenPairs of technical roles in a spreadsheetBusiness activities that conflict
Where roles come fromMonths of workshops and guessworkMined from entitlements people really hold
Audit evidenceScreenshots gathered before the visitReports on access and activity on demand
What it is NOT—A PAM vault, SSO, or a published price

The cheapest test is a pilot: mine one system’s entitlements, define three conflicting activities, and see what the first review finds.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where access is granted and removed

Lifecycle

Lifecycle management

Provisioning follows a person from joining to leaving; IBM calls it closed-loop, so a change approved in governance is pushed to the target and its result read back.

02
Where access is questioned and proved

Compliance

Compliance and audit

Reviews ask owners whether access should stay, and segregation-of-duties checks are written as business activities, which IBM says goes past role-based SoD models.

03
Where entitlements turn into roles

Analytics

Analytics and reporting

Reporting covers user access and activity, and mining condenses raw entitlements into business roles, as Exostar did with 10,000 entitlements and a few hundred roles.

04
Where the governance data lives

Hosting

On premises or in the cloud

IBM sells it to run on premises or in the cloud. Self-hosted, the identity data and audit trail sit on servers you own, which settles the residency question by construction.

Lifecycle, compliance and analytics in one product — installed in your data centre or taken from IBM’s cloud.

Part 03 · Evaluate

Six capabilities. Lifecycle, compliance, analytics.

IBM Verify Identity Governance decides who should hold access and proves it, with SoD rules written as business activities.

Lifecycle
Provisioning

Joiner to leaver, in one flow

Access is created, changed and withdrawn as a person joins, moves and leaves, under IBM’s lifecycle capabilities.

Lifecycle
Closed loop

Approved means applied

Provisioning is closed-loop: what governance approves is sent to the target system, and the outcome comes back to be checked.

Compliance
Access review

Audit who holds what

Owners and managers confirm or remove access in review cycles, leaving the record of each decision an auditor will ask for.

Compliance
Activity SoD

Conflicts as business tasks

Toxic combinations are defined as activities, such as creating a vendor and paying it, instead of pairs of technical roles.

Analytics
Role mining

Roles found, not invented

Mining reads the entitlements people already hold; Exostar turned 10,000 of them into a few hundred business roles this way.

Analytics
Reporting

Access and activity, reported

Reports cover what users can reach and what they did with it, the evidence trail behind IBM’s compliance and analytics claims.

See it, don’t just read it

Background explainers from IBM Technology

IBM publishes no product demo for Identity Governance on its channels; these are IBM Technology explainers on roles, RBAC vs ABAC, and IAM.

IBM Technology (official)·Explainer, December 2022

Roles and Identity Access Management

A topic explainer, not a product demo: how roles group permissions, the idea behind role mining and role-based review.

IBM Technology (official)·Explainer, June 2024

Role-based access control (RBAC) vs. Attribute-based access control (ABAC)

An explainer on two access models; useful background before deciding how far roles or attributes should drive your governance.

IBM Technology (official)·Explainer, August 2022

Identity & Access Management (IAM)

A general IAM primer from IBM’s technology channel; it covers the field this product governs, not the product itself.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why IBM Verify Identity Governance

Access piles up with every move and project. Governance takes it back and proves it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

SoD written the way auditors think

Most SoD engines compare pairs of roles. IBM describes activity-based governance that moves past that: a conflict is two business activities, such as raising a vendor and approving its payment, so the rule survives a role redesign and reads the way a bank’s risk team writes it.

02

Roles mined from real entitlements

Role design by committee is where governance programmes stall. IBM’s Exostar case went the other way: 10,000 entitlements were translated into a few hundred business roles. Starting from what people hold gives reviewers roles they recognise and fewer decisions per campaign.

03

On your own servers, if the regulator prefers

IBM sells it on premises and in the cloud. For an Indian bank or insurer that wants the identity store and audit trail in its own data centre, self-hosting answers storage and processing at once, with no reliance on a SaaS region statement.

04

Where it stops

No public price, so usage-based quotes make early comparison hard. IBM states no connector count; name and confirm every target system. No India region is documented for the cloud edition, and privileged vaulting is a separate Verify product powered by Delinea.

The idea
SoD written as business activities
The residency
Self-host it on servers in India
The price
Usage-based, quoted; no list rate
Proof, not promises

The numbers behind the platform

10000 entitlements
analysed at Exostar and translated into a few hundred business roles
— Customer
<1 day
for new-hire access at Commercial International Bank in Egypt, per IBM’s page
— Customer
3 capability areas
IBM names for the product: lifecycle, compliance and analytics
— Vendor
2 hosting models
offered by IBM: on premises in your data centre, or in the cloud
— Vendor
9 Verify products
on IBM’s Verify list, of which Identity Governance is the governance one
— Vendor
0 list prices
published; IBM meters usage and quotes each deal, so ask how it counts
— Vendor

What your IBM Verify Identity Governance rollout looks like

Weeks 1–2Model

Name the conflicts that matter

List the business activities that must never sit with one person, such as vendor creation and payment, with risk and audit.

Weeks 3–6Decide

Mine before you design

Load entitlements from the main systems and let mining propose roles, then have owners trim them rather than draw them from scratch.

Month 2Pilot

Choose where it runs

Decide on premises or cloud; for Indian data on your hardware, size the self-hosted install in your own data centre.

Month 3Prove

Connect and close the loop

Wire the HR source and the riskiest target systems, then confirm that approved changes come back verified from each one.

Months 4–6Commit

Run the first full campaign

Launch a review over the mined roles, measure completion and revocations, and hand the activity-based SoD report to audit.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
46+ reviews*
78% would recommend
SoD and compliance4.4
Role mining4.2
Provisioning4.0
Ease of implementation3.4
Value for money3.6
5★
38%
4★
40%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our auditors stopped arguing about role names once the SoD rules said ‘create vendor’ and ‘release payment’ in plain words.”
Head of IT Risk
BFSI
Insurance
“Mining our entitlements first gave us draft roles in weeks; the committee only had to argue about the edge cases.”
IAM Architect
Insurance
Banking
“We run it in our own data centre in Mumbai, which closed the residency question before the regulator could raise it.”
CISO
Banking
Telecom
“Closed-loop provisioning let us show audit that approved leaver removals had really landed in each target system.”
Identity Operations Lead
Telecom
Manufacturing
“Ask about every connector by name. Our core system needed extra work that was not in the first statement of work.”
Programme Manager
Manufacturing
Healthcare
“Strong governance, but the usage-based quote took several rounds before finance could compare it with the others.”
IT Procurement Lead
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Identity Governance Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
IBM Verify Identity GovernanceThis page

Usage-based and quoted; activity-based SoD.

Grid 02 · The architecture

Hosting Choice × Governance Depth

The grid nobody publishes — how many ways the product can be hosted, India included, vs how deep its SoD, review and role-mining features go.

Deep but one hosting modelDeep, hosted your wayLighter, single modelFlexible but thinner
IBM Verify Identity GovernanceThis page

On-prem or cloud; activity SoD and mined roles.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

IBM Verify Identity Governance vs the IGA field

Against SailPoint Identity Security Cloud, SailPoint IdentityIQ, One Identity Manager, OpenText NetIQ Identity Governance and Symantec IGA — on hosting, connectors, price, SoD, role mining and India.

DimensionIBM Verify Identity GovernanceSailPoint Identity Security CloudSailPoint IdentityIQOne Identity ManagerOpenText NetIQ Identity GovernanceSymantec IGA
What it isIGA in the Verify familySailPoint’s SaaS IGASailPoint, self-hostedQuest-owned IGACatalog IGA + NetIQ IDMEx-CA identity suite
DeploymentOn premises or cloudSaaS onlyYour data centre onlyOn-prem or On DemandSelf-hosted or SaaSYour Linux, any cloud
ConnectorsCount not publishedHundreds of appsMature, portableSAP-certified15 template familiesApps plus mainframe
Pricing modelUsage-based, quotedPer-identity suitesLicence plus your stackPerpetual or termPer managed identityQuote; metric unknown
Published entry priceNot publishedNot publishedNot publishedNot publishedNot publishedNot published
Included vs add-onPAM is a separate SKUSAP SoD extraSoftware onlyGovernance built inIDM licensed apartSuite; confirm modules
Scale and limitsNo ceiling printedHard under 1,000Bounded by your infraNo ceiling printed500 GB SaaS capNot published
Reviews and SoDActivity-based SoDDeep, documentedCode-level rulesEvent-led attestationMicro-certificationsReviews; SoD unstated
Role miningMined at ExostarDocumentedDocumentedDocumentedUp to 1,000 candidatesNot documented
IntegrationsVerify familyAdd-on modulesSame model as ISCOneLogin, SafeguardIDM, ServiceNow, SCIMMainframe, Oracle 23ai
India storageSelf-host in IndiaAWS MumbaiYour Indian siteSelf-host for IndiaYour hardware, not SaaSWherever you host it
SupportTerms in the contractSet at signatureSupported, no EOLTiered support24x5, Sev 1 on-callBroadcom portal
Lock-in and exitRoles and rules rebuiltSaaS, shared model2–3 year migrationSwitch modelsYour databaseData in your DB
Best fitActivity-based SoDLarge regulated SaaSMust stay on-premSAP-heavy estatesNetIQ IDM shopsCA-lineage estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose IBM Verify Identity Governance if…

  • ✓Your auditors and risk team want segregation-of-duties rules written as business activities, not as pairs of technical roles
  • ✓You would rather mine roles from the entitlements people already hold than run months of role-design workshops
  • ✓The regulator or your board prefers the identity store and audit trail on servers in your own Indian data centre

Compare alternatives if…

  • ✓You want SaaS with a documented Indian storage region — SailPoint Identity Security Cloud keeps Indian tenants in AWS Mumbai
  • ✓Deep SAP governance is the centre of the programme — One Identity Manager holds an SAP-certified integration
  • ✓You already provision with NetIQ Identity Manager or CA identity tools — OpenText and Broadcom extend what you run

Do not expect…

  • ✓A public price or an INR rate card for the governance product
  • ✓A connector count on IBM’s page, or an IBM-hosted Indian region for the cloud edition
  • ✓A Gartner IGA Leader badge — Gartner runs no IGA Magic Quadrant to place anyone in

IBM Verify Identity Governance is one of 22 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do manual access reviews cost you?

Drag the sliders (identities under governance; staff-hour cost). Estimates model reviewer, approver and admin time spent on access tickets, review campaigns and audit evidence at an assumed 1.5 hours per identity a year, with 70% of it removed by automated provisioning and mined roles. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual access-governance cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: IBM prices Verify Identity Governance on usage and quotes every deal, with no INR list. The on-premises route adds your own servers and database to the cost; privileged vaulting is a separate Verify product. TechBag defines your SoD activities and target systems first, then gets the quote itemised in INR with GST.

On premises

Best for regulated estates keeping data in India

  • Usage-based licence on quote
  • Runs on servers you own and operate
  • Infrastructure and upgrades are yours

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Cloud

Best where SaaS is acceptable

  • Usage-based subscription on quote
  • IBM runs the platform
  • No India region documented

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Gap definition

Is the real problem leaver automation, access reviews or SoD? IGA of this depth is a quarters-long programme.

2
SoD activities

Can risk and audit list the conflicting business activities now, or must that work be scoped before licences?

3
Hosting

On premises or cloud? If Indian residency is required, plan the self-hosted install; no India cloud region is documented.

4
Connectors

Which target systems matter most, and has IBM confirmed a connector for each of them by name, in writing?

5
Role data

Are entitlements clean enough to mine? Exostar condensed 10,000; how many do you hold, and in which systems?

6
HR source

Which HR system drives joiners and leavers, and how often are its records late or wrong today?

7
Privileged access

Do admin accounts need a vault too? That is Verify Privileged Identity, powered by Delinea, and quoted apart.

8
Licence

What usage metric does the quote count, at what volume, for how long? Ask for INR with GST and the services line.

FAQ

Questions buyers ask

It is IBM’s identity governance and administration product, one of nine on IBM’s Verify list. IBM describes it as a way to provision, audit and report on user access and activity through lifecycle, compliance and analytics capabilities. It was formerly sold as IGI, and runs on premises or in the cloud.

Ready to evaluate IBM Verify Identity Governance?

Model the reviewer hours your access reviews cost today, or let a TechBag advisor scope a pilot that mines roles from one system and tests your SoD activities.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.