Your auditor asks who approved each person’s access. A spreadsheet is not an answer — OpenText NetIQ Identity Governance builds one catalog of who has what, runs the reviews and SoD checks auditors ask for, and hands every change to Identity Manager — on your own servers or as OpenText’s SaaS.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText NetIQ Identity Governance — access governance, with NetIQ Identity Manager for provisioning. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It answers who should have what, asks the right people to confirm it on a schedule, and keeps the evidence.
What consolidation actually replaces, dimension by dimension.
| Dimension | Spreadsheet reviews, ticketed leavers | OpenText NetIQ Identity Governance |
|---|---|---|
| Who has what | Exports from each app, merged by hand | One published catalog of identities and permissions |
| Periodic review | Spreadsheets emailed to managers | Review campaigns with reasons and an audit trail |
| Toxic combinations | Found by the auditor, after the fact | SoD policies checked at request and in the catalog |
| Leavers | A ticket, if HR remembers to raise it | Identity Manager removes access from the HR event |
| Proof the change happened | The admin says it was done | Next collection verifies each fulfilled item |
| What it is NOT | — | PAM, single sign-on, or a published price list |
The cheapest test is one review: collect your directory and one risky application, run it in preview with two managers, and see what it finds.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Collectors pull identities, accounts and permissions from AD, Entra ID, SAP, Workday and other sources; you publish each collection into one catalog that every review reads.
Review definitions, segregation-of-duties policies, risk scoring and technical or business roles all run against the published catalog, with data policies watching for drift.
A self-service Access Request app routes each ask through approval policies and SoD checks; a separate Workflow Engine runs custom approvals and remediation steps.
Approved changes go to Identity Manager, ServiceNow, SCIM, REST or a manual fulfiller; in the SaaS edition a Cloud Bridge agent per data centre carries the traffic.
One catalog from many collectors — reviews, SoD and risk on top, and Identity Manager carrying out each change.
NetIQ Identity Governance proves who should have what, and Identity Manager makes it so.
Collector templates cover AD and eDirectory, Entra ID, SAP, Workday, Salesforce, Google, ServiceNow, JDBC, SCIM and CSV feeds.
Identity and application sources can collect change events, so the catalog updates on a move or leave without a full re-collection.
Data policies detect added or removed entities and attribute changes in published data, then trigger a remediation or a review.
Review definitions cover user access, accounts, permissions and roles, with preview mode before a live run and reasons on each decision.
A policy violation can open a focused review of only the affected items, run beside the scheduled campaign instead of a full re-run.
Separation-of-duties policies flag conflicting permissions at request time and in the catalog, opening cases an owner must approve or resolve.
Risk levels combine factors such as open SoD violations and permission risk into a score per user, recalculated on a schedule you set.
Automatic or visual mining proposes technical-role candidates from who holds what, up to a thousand suggestions, for you to edit and promote.
Business roles bundle permissions by job or team, carry their own approval policy, and can provision or remove access as membership changes.
Users request applications, permissions or roles; approval policies route each ask and check SoD before anything is granted.
Changesets go to Identity Manager, ServiceNow, SCIM, REST or a person, and the next collection confirms the change really happened.
NetIQ Identity Manager 25.2 provisions and deprovisions accounts from HR events, with drivers for Workday, SAP, Epic and Microsoft.
Running a user access review, comparing two users’ permissions, the SaaS catalog, and governing OpenText Content Management access.
Builds a user access review definition, runs it and works through the reviewer’s screen.
Compares two users’ permissions side by side to spot access one of them should not hold.
The governance catalog as it appears inside OpenText’s SaaS identity service.
Brings permissions from OpenText Content Management under the same reviews as other apps.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Identity Governance decides who should have what; NetIQ Identity Manager 25.2 creates and removes the accounts from HR events, with drivers for Workday, SAP, Epic and Microsoft. A revoked review item becomes a removed account, and the next collection proves it.
The self-hosted edition runs on Tomcat with PostgreSQL or Oracle inside your own data centre. The SaaS edition comes with a production and a staging tenant, and a Cloud Bridge agent reaches on-premises systems. Few IGA products still offer both.
Data policies watch the catalog for added, removed or changed entries, and a violation can open a micro-certification of just those items. Medica, a US health plan, says its access audit took 13 business days. OpenText was an Overall Leader in KuppingerCole’s 2024 IGA compass.
There is no public price, and self-hosting means you patch Tomcat and the database. The SaaS keeps certification data in the console for 90 days and caps data at 500 GB. Identity Manager Advanced Edition carried CVE-2024-12799, rated 10.0. Privileged sessions need a PAM product.
Separate the leaver problem from the review problem; if Identity Manager or HR feeds are missing, plan provisioning first.
Choose self-hosted or SaaS, count the managed identities for the licence, and list the five systems auditors ask about.
Build collectors for the directory, HR and those five systems, clean entitlement names, then publish the first catalog.
Run a user access review in preview mode with two managers, fix confusing items, then go live with evidence export.
Load SoD policies and risk factors, connect fulfilment through Identity Manager or ServiceNow, and turn on micro-certs.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our quarterly access review used to be forty spreadsheets. Now managers get one task list and the evidence exports itself.”
“We already ran Identity Manager, so leavers were handled. Governance added the certification trail our auditor wanted.”
“Micro-certification is the useful part: a toxic SAP pair opens a small review that day, not at the half-year campaign.”
“Role mining proposed sensible starting roles, but cleaning entitlement names before collection took longer than mining.”
“Self-hosting kept everything in our data centre, which settled the regulator question. Patching Tomcat is now ours.”
“Capable, but the first collectors needed a specialist partner, and the quote took rounds to settle the identity count.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
KuppingerCole’s 2024 Overall Leader in IGA; quote-only.
The grid nobody publishes — how many ways it can be run, India included, vs how deep the reviews, SoD and role mining go.
Self-hosted or SaaS; micro-certs, SoD cases, role mining.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against SailPoint Identity Security Cloud, SailPoint IdentityIQ, One Identity Manager, Okta Identity Governance and Idira Identity Governance — on deployment, connectors, price, reviews, India and exit.
| Dimension | OpenText NetIQ Identity Governance | SailPoint Identity Security Cloud | SailPoint IdentityIQ | One Identity Manager | Okta Identity Governance | Idira Identity Governance |
|---|---|---|---|---|---|---|
| What it is | IGA + NetIQ IDM | SailPoint’s SaaS IGA | SailPoint, self-hosted | Governance-first IGA | IGA on the Okta platform | Zilla-based, Palo Alto |
| Deployment | Self-hosted or SaaS | SaaS only | Self-hosted only | On-prem or On Demand | SaaS only | SaaS only |
| Connectors | 15 template families | Hundreds of apps | Broad, carries across | SAP Certified | Broad, via Okta | Auto-discovery |
| Pricing model | Per managed identity | Suites, per identity | Licence + your infra | Per identity | Per user, monthly | Per identity, yearly |
| Published entry price | Not published | Not published | Not published | Not published | $17/user/month | Not published |
| Included vs add-on | IDM licensed apart | SAP SoD is extra | You add the infra | Governance in one | Bundled in Essentials | PAM sold separately |
| Scale and limits | 500 GB SaaS cap | Identity-based suites | Sized by your servers | Not published | Small floor | Not published |
| Reviews and SoD | Micro-certs + SoD cases | Deep, documented | Flexible rules engine | Attestation + SoD | Campaigns + SoD | AI-assisted reviews |
| Role mining | Automatic or visual | Documented | Documented | Documented | Documented | Documented |
| Integrations | IDM, ServiceNow, SCIM | Broad catalog | Same model as ISC | OneLogin, Safeguard | Workflows, Slack, Teams | Idira PAM, secrets |
| India storage | Self-host in India | AWS Mumbai | Your data centre | On-prem in India | India tenants, 2026 | Not documented |
| Support | 24x5, Sev 1 on-call | Terms in the quote | Supported, no EOL | Tiered offerings | 99.99% uptime | Terms in the quote |
| Lock-in and exit | Your database | SaaS, IIQ path back | 2–3 year migration | Choose either model | Tied to Okta | Tied to Idira |
| Best fit | IDM shops, self-hosted | Large regulated SaaS | Must stay on-prem | SAP-heavy, either model | Okta already in place | Idira PAM customers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText NetIQ Identity Governance is one of 22 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (identities in scope; reviewer-hour cost). Estimates model the time managers and IT spend gathering access lists, chasing review sign-offs and handling leavers at an assumed 1.5 hours per identity a year, with 70% of it removed by automated collection, reviews and fulfilment. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: OpenText licenses Identity Governance per managed identity and quotes both the self-hosted and the SaaS edition. Identity Manager is a separate licence, and its limited Governance entitlement covers catalog features only, not reviews. TechBag counts the identities first, then quotes in INR with GST.
Best where data must stay on your servers
Best for a broader rollout
Best for teams that do not want to run it
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is the audit finding about missing reviews, or about leavers keeping access? The second is an Identity Manager job first.
How many managed identities, including contractors and service accounts, will the per-identity licence count?
Self-hosted in your Indian data centre, or the SaaS edition with a Cloud Bridge agent in each data centre?
Which systems hold the risky access — core banking, SAP, HRMS — and is there a collector template for each?
Will changes go out through Identity Manager, ServiceNow, SCIM or a manual fulfiller, and who confirms them?
Who writes the toxic-pair rules, and who owns each SoD case when a violation is found?
SaaS keeps certification data 90 days in the console and reports 3 years; does your auditor need more?
Does the quote split Governance from Identity Manager, name the edition and term, and come in INR with GST?
Count the identities and the systems your auditor asks about first, or let a TechBag advisor scope a pilot that runs one access review in preview mode.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.