Your auditors ask who approved each access right. Your spreadsheets can’t say — IBM Verify Identity Governance provisions, reviews and reports on access, writes segregation-of-duties rules as business activities, and runs on premises or in the cloud, so the audit trail can stay on your own servers in India.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers IBM Verify Identity Governance — IBM’s IGA product in the Verify family. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It decides who should hold which access, removes what is no longer needed, and keeps evidence for the auditor.
What consolidation actually replaces, dimension by dimension.
| Dimension | Tickets and SoD spreadsheets | IBM Verify Identity Governance |
|---|---|---|
| Who grants access | A ticket an admin works through later | Lifecycle provisioning from the joiner event |
| Proof a change happened | The ticket was closed, so we assume it | Closed loop: the target’s result is read back |
| How SoD is written | Pairs of technical roles in a spreadsheet | Business activities that conflict |
| Where roles come from | Months of workshops and guesswork | Mined from entitlements people really hold |
| Audit evidence | Screenshots gathered before the visit | Reports on access and activity on demand |
| What it is NOT | — | A PAM vault, SSO, or a published price |
The cheapest test is a pilot: mine one system’s entitlements, define three conflicting activities, and see what the first review finds.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Provisioning follows a person from joining to leaving; IBM calls it closed-loop, so a change approved in governance is pushed to the target and its result read back.
Reviews ask owners whether access should stay, and segregation-of-duties checks are written as business activities, which IBM says goes past role-based SoD models.
Reporting covers user access and activity, and mining condenses raw entitlements into business roles, as Exostar did with 10,000 entitlements and a few hundred roles.
IBM sells it to run on premises or in the cloud. Self-hosted, the identity data and audit trail sit on servers you own, which settles the residency question by construction.
Lifecycle, compliance and analytics in one product — installed in your data centre or taken from IBM’s cloud.
IBM Verify Identity Governance decides who should hold access and proves it, with SoD rules written as business activities.
Access is created, changed and withdrawn as a person joins, moves and leaves, under IBM’s lifecycle capabilities.
Provisioning is closed-loop: what governance approves is sent to the target system, and the outcome comes back to be checked.
Owners and managers confirm or remove access in review cycles, leaving the record of each decision an auditor will ask for.
Toxic combinations are defined as activities, such as creating a vendor and paying it, instead of pairs of technical roles.
Mining reads the entitlements people already hold; Exostar turned 10,000 of them into a few hundred business roles this way.
Reports cover what users can reach and what they did with it, the evidence trail behind IBM’s compliance and analytics claims.
IBM publishes no product demo for Identity Governance on its channels; these are IBM Technology explainers on roles, RBAC vs ABAC, and IAM.
A topic explainer, not a product demo: how roles group permissions, the idea behind role mining and role-based review.
An explainer on two access models; useful background before deciding how far roles or attributes should drive your governance.
A general IAM primer from IBM’s technology channel; it covers the field this product governs, not the product itself.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most SoD engines compare pairs of roles. IBM describes activity-based governance that moves past that: a conflict is two business activities, such as raising a vendor and approving its payment, so the rule survives a role redesign and reads the way a bank’s risk team writes it.
Role design by committee is where governance programmes stall. IBM’s Exostar case went the other way: 10,000 entitlements were translated into a few hundred business roles. Starting from what people hold gives reviewers roles they recognise and fewer decisions per campaign.
IBM sells it on premises and in the cloud. For an Indian bank or insurer that wants the identity store and audit trail in its own data centre, self-hosting answers storage and processing at once, with no reliance on a SaaS region statement.
No public price, so usage-based quotes make early comparison hard. IBM states no connector count; name and confirm every target system. No India region is documented for the cloud edition, and privileged vaulting is a separate Verify product powered by Delinea.
List the business activities that must never sit with one person, such as vendor creation and payment, with risk and audit.
Load entitlements from the main systems and let mining propose roles, then have owners trim them rather than draw them from scratch.
Decide on premises or cloud; for Indian data on your hardware, size the self-hosted install in your own data centre.
Wire the HR source and the riskiest target systems, then confirm that approved changes come back verified from each one.
Launch a review over the mined roles, measure completion and revocations, and hand the activity-based SoD report to audit.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our auditors stopped arguing about role names once the SoD rules said ‘create vendor’ and ‘release payment’ in plain words.”
“Mining our entitlements first gave us draft roles in weeks; the committee only had to argue about the edge cases.”
“We run it in our own data centre in Mumbai, which closed the residency question before the regulator could raise it.”
“Closed-loop provisioning let us show audit that approved leaver removals had really landed in each target system.”
“Ask about every connector by name. Our core system needed extra work that was not in the first statement of work.”
“Strong governance, but the usage-based quote took several rounds before finance could compare it with the others.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Usage-based and quoted; activity-based SoD.
The grid nobody publishes — how many ways the product can be hosted, India included, vs how deep its SoD, review and role-mining features go.
On-prem or cloud; activity SoD and mined roles.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against SailPoint Identity Security Cloud, SailPoint IdentityIQ, One Identity Manager, OpenText NetIQ Identity Governance and Symantec IGA — on hosting, connectors, price, SoD, role mining and India.
| Dimension | IBM Verify Identity Governance | SailPoint Identity Security Cloud | SailPoint IdentityIQ | One Identity Manager | OpenText NetIQ Identity Governance | Symantec IGA |
|---|---|---|---|---|---|---|
| What it is | IGA in the Verify family | SailPoint’s SaaS IGA | SailPoint, self-hosted | Quest-owned IGA | Catalog IGA + NetIQ IDM | Ex-CA identity suite |
| Deployment | On premises or cloud | SaaS only | Your data centre only | On-prem or On Demand | Self-hosted or SaaS | Your Linux, any cloud |
| Connectors | Count not published | Hundreds of apps | Mature, portable | SAP-certified | 15 template families | Apps plus mainframe |
| Pricing model | Usage-based, quoted | Per-identity suites | Licence plus your stack | Perpetual or term | Per managed identity | Quote; metric unknown |
| Published entry price | Not published | Not published | Not published | Not published | Not published | Not published |
| Included vs add-on | PAM is a separate SKU | SAP SoD extra | Software only | Governance built in | IDM licensed apart | Suite; confirm modules |
| Scale and limits | No ceiling printed | Hard under 1,000 | Bounded by your infra | No ceiling printed | 500 GB SaaS cap | Not published |
| Reviews and SoD | Activity-based SoD | Deep, documented | Code-level rules | Event-led attestation | Micro-certifications | Reviews; SoD unstated |
| Role mining | Mined at Exostar | Documented | Documented | Documented | Up to 1,000 candidates | Not documented |
| Integrations | Verify family | Add-on modules | Same model as ISC | OneLogin, Safeguard | IDM, ServiceNow, SCIM | Mainframe, Oracle 23ai |
| India storage | Self-host in India | AWS Mumbai | Your Indian site | Self-host for India | Your hardware, not SaaS | Wherever you host it |
| Support | Terms in the contract | Set at signature | Supported, no EOL | Tiered support | 24x5, Sev 1 on-call | Broadcom portal |
| Lock-in and exit | Roles and rules rebuilt | SaaS, shared model | 2–3 year migration | Switch models | Your database | Data in your DB |
| Best fit | Activity-based SoD | Large regulated SaaS | Must stay on-prem | SAP-heavy estates | NetIQ IDM shops | CA-lineage estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
IBM Verify Identity Governance is one of 22 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (identities under governance; staff-hour cost). Estimates model reviewer, approver and admin time spent on access tickets, review campaigns and audit evidence at an assumed 1.5 hours per identity a year, with 70% of it removed by automated provisioning and mined roles. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: IBM prices Verify Identity Governance on usage and quotes every deal, with no INR list. The on-premises route adds your own servers and database to the cost; privileged vaulting is a separate Verify product. TechBag defines your SoD activities and target systems first, then gets the quote itemised in INR with GST.
Best for regulated estates keeping data in India
Best for a broader rollout
Best where SaaS is acceptable
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is the real problem leaver automation, access reviews or SoD? IGA of this depth is a quarters-long programme.
Can risk and audit list the conflicting business activities now, or must that work be scoped before licences?
On premises or cloud? If Indian residency is required, plan the self-hosted install; no India cloud region is documented.
Which target systems matter most, and has IBM confirmed a connector for each of them by name, in writing?
Are entitlements clean enough to mine? Exostar condensed 10,000; how many do you hold, and in which systems?
Which HR system drives joiners and leavers, and how often are its records late or wrong today?
Do admin accounts need a vault too? That is Verify Privileged Identity, powered by Delinea, and quoted apart.
What usage metric does the quote count, at what volume, for how long? Ask for INR with GST and the services line.
Model the reviewer hours your access reviews cost today, or let a TechBag advisor scope a pilot that mines roles from one system and tests your SoD activities.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.