Access certification stops at the application — while the spreadsheet exported from it sits in a folder half the department can open. Data Access Security governs the data itself: discovery, classification, over-privilege detection and reviews of data assets.
Data residency & processing
This module handles metadata about your most sensitive information — classifications, locations, access patterns and entitlements for personal data, financial records and intellectual property. Even where file contents stay in your systems, a map of where sensitive data lives is itself sensitive. Establish what leaves your environment versus what is analysed in place, because that varies by connector. SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024 — its ninth point of presence globally. SailPoint’s own words: an environment“completely isolated from other AWS Regions—no data will be replicated, backed up, or stored in any other AWS Region.” That is the strongest documented India data-storage position of any IGA vendor we carry. It is a statement about STORAGE. SailPoint does not separately document where data is processed, and we are not going to infer it — if processing location is part of your obligation rather than storage, ask SailPoint directly and get the answer in writing.
On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Data Access Security — governance for the data. The rest of the portfolio:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Governance for the data itself — discovery, classification, over-privilege detection and fine-grained reviews of data assets across cloud, on-prem and SaaS. An add-on to Identity Security Cloud.
What consolidation actually replaces, dimension by dimension.
| Dimension | Application-level review only | Data Access Security (SailPoint) |
|---|---|---|
| What gets reviewed | The application | The data asset itself |
| The exported spreadsheet | Invisible to the review | Discovered and classified |
| Where sensitive data is | Nobody actually knows | Discovered across cloud, on-prem, SaaS |
| Over-broad folders | Found after the incident | Proactively identified |
| External share links | Created and forgotten | Detected and reviewable |
| Machine access to data | Never reviewed | Governed alongside people |
| The DPDP question | Answered with an app report | Answered about the data |
| ⚠️ The hard part | (varies) | Classification tuning is a real phase |
Governs the DATA rather than the application — discovery, classification, over-privilege and external-sharing detection, and fine-grained reviews of data assets across cloud, on-prem and SaaS. Honest: it is an ADD-ON to Identity Security Cloud, classification tuning is a real project phase that decides whether the whole thing works, and it does NOT replace DLP — that is data in motion, a different question.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Finding sensitive information across cloud, on-premises and SaaS environments — personal data, financial records, intellectual property. Most organisations genuinely do not know where their sensitive data has ended up, because it moves: exported, copied into working folders, attached, shared. Discovery is the uncomfortable first deliverable and usually the one that justifies the project.
Automatic classification with consistent tagging and sensitivity labels, integrating third-party classification tags where you already have them. This is where the project succeeds or fails: classification quality determines everything downstream, because over-classify and you drown reviewers in false positives, under-classify and you miss the data you were protecting. Budget this as a tuning phase, not a switch.
Proactively identifying access that is broader than it should be, detecting externally shared sensitive content, and highlighting regulated or high-risk entitlements. The typical finding is a folder with far wider access than anyone intended, created years ago for a project that ended, holding data nobody remembers putting there.
Access reviews conducted against data assets themselves rather than only the applications that produce them, with rich data context so a reviewer can make a real decision. This is the capability that answers a DPDP-style question, because the question is about personal data rather than about an application.
Applying least-privilege policies for every identity, removing defunct accounts holding sensitive access, and using dynamic and customisable policies to reduce the manual effort of maintaining that state. Discovery without enforcement produces a report; this is the part that changes the position.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
Data Access Security governs who can reach the data itself — the exports, the shared folders, the team sites — not just the applications, an add-on to portfolio, and paired with the human firewall.
Finding personal data, financial records and intellectual property wherever it has ended up across cloud, on-premises and SaaS. The first deliverable, and usually the one that surprises people most — data moves further than anyone models. Where it actually is.
Classifying sensitive data automatically rather than relying on users to label it correctly, which they never do consistently. The quality of this step determines the value of everything built on top of it. Get this right or nothing else matters.
Applying labels consistently across the estate, and integrating third-party classification tags where you have already invested in them. Nobody wants to reclassify data twice because two tools disagree. Your existing tags, respected.
Identifying access that is broader than it should be — typically a folder opened up for a project that ended years ago and never narrowed. The finding that makes the business case concrete. Wider than anyone intended.
Finding sensitive content shared outside the organisation — the link created for a supplier, never revoked, still live. In SaaS collaboration platforms this accumulates silently and at speed. The link nobody revoked.
Finding and removing accounts that still hold access to sensitive data but belong to nobody current. The overlap between stale identity and sensitive data is precisely where the worst incidents start. Nobody's account, real access.
Applying least-privilege policy for every identity against data assets, with dynamic and customisable policies that reduce the manual effort of holding that line as the estate changes. Narrow it, and keep it narrow.
Surfacing the entitlements that touch regulated data so review effort concentrates where the consequence is greatest, rather than spreading evenly across everything. Review where it matters most.
Certification conducted against the data itself with rich context, rather than only against the applications. The capability that answers a DPDP-style question about personal data, which no application-level review can. Certify the data, not the app.
Governing access for both people and non-human identities — the service account with read access to a sensitive share is a common and rarely reviewed exposure. The account nobody thinks of as a person.
An add-on to the SailPoint platform rather than a standalone product, so identity context flows into data governance and vice versa. Worth knowing before scoping it as a point purchase. Add-on, not standalone.
This governs who can reach data where it sits. A DLP product concerns itself with data leaving — blocked uploads, monitored email, endpoint controls. They answer different questions and buyers conflate them regularly. Complementary, not substitutes. Different question from DLP.
The platform this extends.
The platform this add-on extends.
How the suites and add-ons fit together.
The sibling add-on for external identities.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and where the difficulty actually lives.
This is the argument, and it turns on the shape of the question a regulator actually asks. What application-level certification proves: that a named person should have access to a named system. That is genuinely valuable and it is what most identity governance programmes deliver. It is also, on its own, an incomplete answer to a data-protection question. Why the gap exists: personal data does not stay inside applications. It is exported to a spreadsheet for a board pack, copied into a working folder during a project, attached to an email, uploaded to a team site, shared with a supplier through a link that was never revoked. Each of those copies is real personal data with real access attached, and none of it appears in an application access review because it no longer lives in the application. What the DPDP Act asks: where is the personal data, who can reach it, and how do you know. A regulator is not asking which systems process personal data — they are asking about the data. If your evidence is a certification report showing that finance-system access was reviewed, you have answered a different question from the one asked, and an auditor with any experience will notice. What Data Access Security adds: discovery of where sensitive data actually is, classification so you know what it is, identification of who can reach it including through over-broad folder permissions and stale external links, and access reviews conducted against the data assets themselves with enough context for a reviewer to decide. Where this genuinely matters: organisations with substantial unstructured data — shared drives, SharePoint and Teams sites, cloud object storage — which is most enterprises of any age. The value: an answer to the question actually being asked, rather than a good answer to an adjacent one. TechBag scopes it against your real unstructured estate.
We would rather tell you where the difficulty lives than let you discover it in month four, because this is the part that separates a successful deployment from an expensive report. Why classification is the crux: every downstream capability depends on it. Over-privileged access detection, external sharing alerts, fine-grained certification, least-privilege enforcement — all of them act on what classification says is sensitive. If classification is wrong, the entire output is wrong in a way that is hard to see. The two failure modes, and both are common. Over-classification floods reviewers with false positives: everything looks sensitive, so nothing is treated as sensitive, and within two cycles people are approving in bulk to clear the queue. Under-classification quietly misses the data you bought the product to protect, and produces confident reports about an estate you have not actually covered. Neither failure announces itself. What that means for your project plan: budget classification tuning as a genuine phase with named effort, not as a configuration step during deployment. Expect to iterate — run classification, sample the results against what you know, adjust the rules, run again. Involve people who understand the business meaning of the data, because a classifier tuned only by IT will systematically misjudge which finance and HR content actually matters. What helps: SailPoint integrates third-party classification tags, so if you have already invested in labelling through Microsoft Purview or similar, that work carries forward rather than being redone. Start where you have existing labels and expand outward. The honest read: this is a harder product to deploy well than application governance, and anyone presenting it as a switch has not run one. It is worth it where the unstructured estate is large and the questions are real. The value: a capability whose difficulty is stated up front so you can plan for it. TechBag budgets the tuning phase explicitly.
Buyers conflate these two regularly, sometimes with a vendor's encouragement, and ending up with the wrong one is expensive. What Data Access Security does: governs access to data at rest. It finds where sensitive data lives, works out who can reach it, narrows that access to what is appropriate, and produces reviews and evidence about the state of access. The question it answers is who can reach this data. What DLP does: controls data in motion. It watches for sensitive data leaving — uploaded to a personal cloud account, attached to an outbound email, copied to a USB device — and blocks or alerts. The question it answers is where is this data going. Why the distinction is practical rather than pedantic: they fail differently and they cover different moments. Perfect DLP does not tell you that a folder containing customer records has been readable by the whole company for three years, because nothing is moving. Perfect data access governance does not stop somebody with legitimate access from emailing a file to a personal address. An organisation with only one of them has a real, specific gap and should know which. How they work together: access governance narrows who can reach sensitive data, which shrinks the population DLP has to watch and reduces false positives. DLP catches the misuse of access that governance has already deemed appropriate. Sequencing usually favours governance first, because narrowing access reduces DLP noise substantially. What to check in your own estate: if you already run a DLP product, ask what it tells you about access to data at rest. If the answer is nothing, you have found the gap. If you have neither, start with the question your regulator is actually asking. The value: clarity about which problem you are solving, before you buy either. TechBag sells both kinds of product and will tell you which gap you have.
The commercial structure is worth stating plainly, as with the other SailPoint add-ons. What it is: Data Access Security is an add-on to SailPoint Identity Security Cloud, not a standalone product. Buying it means buying or already running the platform, which is enterprise-priced, quote-only, and carries implementation costs across the category of typically two to three times licence. When the arithmetic works: you already run Identity Security Cloud, or are buying it for broader governance reasons, and you have substantial sensitive unstructured data. Then this is an incremental decision, identity context flows between application and data governance, and reviewers work in one place rather than two. That integration is a genuine advantage over buying a separate data-security product. When it does not: your entire requirement is data discovery and classification, with no wider identity governance driver. Buying the SailPoint platform for that is a heavy answer, and there are dedicated data security posture management products — including several we sell — that address it directly and cost less. We would rather point you at one than sell a programme that is mostly unused. The middle case, which is common: you need both, but not at the same time. Application-level governance usually comes first because it is where audit findings land, and data access governance follows once that foundation exists and the classification investment can be justified. Sequencing it that way is usually cheaper and always less risky than doing everything at once. What we will not do: present an add-on as a point solution and let the platform price arrive during procurement. The value: a genuinely integrated data governance capability for organisations already committed to the platform. TechBag scopes it inside that decision, and will say when a dedicated DSPM product is the better answer.
Data Access Security discovers sensitive data across cloud, on-premises and SaaS environments, classifies it automatically with consistent tagging and sensitivity labels, integrates third-party classification tags, identifies over-privileged access and externally shared content, removes defunct accounts holding sensitive access, enforces least-privilege policy for human and machine identities, and enables fine-grained access reviews of data assets with the context reviewers need. Where it genuinely wins: it answers a question application-level certification cannot. Under the DPDP Act a regulator asks where personal data is and who can reach it — not which applications process it — and personal data does not stay inside applications. For an organisation with substantial unstructured data and real regulatory exposure, that gap is the whole point. Being part of the SailPoint platform means identity context flows both ways, which a separate data-security tool cannot match. Where something else fits better, plainly: if data discovery and classification is your entire requirement with no wider identity governance driver, a dedicated data security posture management product will address it more directly and cost less — we sell those too. If your concern is data leaving rather than who can reach it at rest, that is DLP and a different purchase. And if your unstructured estate is genuinely small, the effort here outweighs the benefit. The limits to weigh: it is an add-on, so it assumes the platform and its economics; classification quality determines whether the whole thing works, and tuning it is a real project phase rather than a configuration step; it does not replace DLP; and it is harder to deploy well than application governance. So the honest positioning: a capability that closes a real and increasingly-examined gap, for organisations already committed to identity governance with sensitive data at scale. TechBag scopes it within the platform decision and sequences it after application governance where that is the sensible order, in INR with GST.
Where does personal data live outside the applications that produce it, who can reach it, and how would you evidence that? If your honest answer is that you would produce an application certification report, you have found the gap this product addresses. If your unstructured estate is genuinely small, you may not need it.
If you are Microsoft-centric, you may already hold Purview licensing and never have configured it. Establish that before buying anything — we would rather you configure what you own. If you have existing classification labels, they carry forward into SailPoint's classification, which materially shortens the project.
Run discovery, sample the classification results against what you actually know about the data, adjust the rules, run again. Involve people who understand the business meaning of the content, because a classifier tuned only by IT will misjudge which finance and HR material matters. This phase determines whether everything downstream works.
Application-level certification usually comes first because that is where audit findings land; data access governance follows once the foundation exists. TechBag sequences it that way where it makes sense, and invoices in INR with GST.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our regulator asked where customer personal data lives and who can reach it. Our access certification reports answered a different question entirely, and everyone in the room knew it.”
“Discovery found a folder with quarterly exports going back six years, readable by an entire department. It had been created for a project that ended in 2019.”
“Classification tuning took longer than the deployment. Budget it as a phase with real effort — we did not at first and the first review cycle was unusable because everything looked sensitive.”
“Because we already had Purview labels, integrating those meant we did not reclassify from scratch. That saved months and the estimate had assumed we would.”
“Honest: we thought this replaced our DLP. It does not — it governs who can reach data at rest, DLP watches data leaving. TechBag explained the difference before we bought, which saved an awkward discovery.”
“The externally shared links were the finding nobody expected. Supplier links created years ago, never revoked, still live and still resolving.”
“Service accounts with read access to sensitive shares was the exposure we had genuinely never reviewed. Nobody thinks of them as identities until something goes wrong.”
“Worth knowing it is an add-on to the platform. We sequenced application governance first and added this the following year, which was the right order and cheaper.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data access governance market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Data governance with native identity context. This page's product.
The grid nobody publishes — how well sensitive data is classified vs how finely access can be reviewed.
Strong, but classification tuning is a real phase.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Microsoft Purview, Varonis, Securiti, DLP products and doing nothing — honest lanes. Microsoft-centric and already licensed for Purview? Configure what you own first. Worried about data LEAVING? That is DLP, a different question.
| Dimension | SailPoint DAS | Microsoft Purview | Varonis | Securiti | A DLP product | App-level review only |
|---|---|---|---|---|---|---|
| Position | Data governance inside an IGA platform | Native to Microsoft estates | Data-centric security specialist | DSPM and privacy platform | Data in MOTION — different question | What most organisations have now |
| Governs data at rest | Yes — the point of it | Yes | Yes — deep | Yes | No — watches data leaving | No |
| Identity context integrated | Native — same platform as IGA | Via Entra | Own model | Own model | Not its purpose | Yes, but only for apps |
| Beyond Microsoft estates | Cloud, on-prem AND SaaS | Strongest inside Microsoft | Broad | Broad | Varies | n/a |
| Buyable standalone | ⚠️ No — an add-on to the platform | Yes, in M365 licensing | Yes | Yes | Yes | n/a |
| Best fit | Already on SailPoint, sensitive data at scale | Microsoft-centric estates already licensed | Data security as the primary discipline | DSPM and privacy as the driver | Stopping data LEAVING | Nothing — the DPDP gap stays open |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Data Access Security is one of 16 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (data-asset count; IT hourly cost as a loaded rate). Estimates contrast manually hunting for sensitive data when somebody asks — exports, shared folders, stale external links — against continuous discovery and classification with reviewable access. NB: this does NOT model the classification tuning phase, which is real effort and decides whether the output is usable, nor the platform cost, since this is an add-on. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
QUOTE-ONLY, and an ADD-ON to SailPoint Identity Security Cloud rather than a standalone product — so it assumes the platform and its economics, where implementation typically runs 2–3× licence. Budget a genuine CLASSIFICATION TUNING PHASE on top: that is where these deployments succeed or fail, and it is effort rather than configuration. If data discovery is your ONLY driver with no wider identity governance requirement, a dedicated DSPM product costs less and we will say so. TechBag scopes it inside the platform decision, in INR with GST.
Best alongside the platform you already run
Best for a broader rollout
Best budgeted before you start
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Has anyone asked WHERE personal data lives and who can reach it? An app-level certification report answers a different question, and auditors notice.
Microsoft-centric? You may already hold Purview licensing and never have configured it. Check before buying anything.
Do you have classification labels already? SailPoint integrates third-party tags, so that investment carries forward instead of being redone.
Have you budgeted tuning as a real project phase? Over-classify and reviewers drown; under-classify and you miss what you were protecting.
Are you clear this is data AT REST, not data in motion? If your worry is data leaving, that is DLP and a different purchase.
How much sensitive data sits in shared drives, SharePoint, Teams and object storage? If genuinely little, the effort may outweigh the benefit.
Do you understand this assumes Identity Security Cloud? If data is your only driver, a dedicated DSPM product costs less.
Have you ever reviewed which service accounts can read sensitive shares? It is a common and rarely examined exposure.
Where does personal data live outside the applications that produce it, who can reach it, and how would you evidence that? If the honest answer is an application certification report, you have found the gap. Check what Purview licensing you already own first — then let a TechBag advisor scope it, budget the classification phase, and sequence it sensibly.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.