Identity Security Cloud answers the three questions an auditor asks — who has access, should they, and can you prove it — with certification campaigns, SoD policy and an evidence trail. From the #1 vendor by revenue in IGA, running in AWS Mumbai since November 2024.
Data residency & processing
SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024 — its ninth point of presence globally. SailPoint’s own words: an environment“completely isolated from other AWS Regions—no data will be replicated, backed up, or stored in any other AWS Region.” That is the strongest documented India data-storage position of any IGA vendor we carry. It is a statement about STORAGE. SailPoint does not separately document where data is processed, and we are not going to infer it — if processing location is part of your obligation rather than storage, ask SailPoint directly and get the answer in writing.
On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Identity Security Cloud — the platform. The rest of the portfolio:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
The identity governance category leader’s flagship — certification campaigns, SoD policy, role mining and the evidence trail an auditor accepts, on the Atlas core. Runs in AWS Mumbai for Indian customers.
What consolidation actually replaces, dimension by dimension.
| Dimension | Manual reviews in a spreadsheet | Identity Security Cloud (SailPoint) |
|---|---|---|
| The access review | A spreadsheet emailed to managers | Campaigns with business context |
| Evidence | Reconstructed after the audit asks | Recorded as decisions are made |
| Roles | Designed on a whiteboard | Mined from real entitlement data |
| Toxic combinations | Found after the incident | SoD rules, before the grant |
| Leavers | Removed when someone remembers | Revoked on the HR event |
| Machine accounts | Nobody owns them | Discovered, classified, owned |
| India data | (varies — often unstated) | AWS Mumbai, isolated — for STORAGE |
| The real cost | (varies) | 2–3× licence — budget the programme |
The identity governance category leader — #1 by revenue in Gartner’s 2024 market-share research, with the strongest documented India data-storage position in the category (AWS Mumbai, isolated, since Nov 2024). Honest: implementation typically costs 2–3× the licence, below ~1,000 identities the economics are hard, the Mumbai statement covers STORAGE not processing, and there is NO Gartner Magic Quadrant for IGA — so nobody leads one.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
SailPoint calls the platform core Atlas, and its job is to hold one coherent model of every identity and entitlement across your estate, whatever system they actually live in. Everything above it — certification, provisioning, policy, analytics — reads from that single model. This is why connector work dominates an IGA project: the platform is only as good as the completeness of what it has ingested.
Access granted on day one, updated when someone changes role, and revoked on the last day — driven by HR or directory events rather than by a ticket somebody remembers to raise. Necessary but not sufficient: this is provisioning, and it is the half that cheaper products also do. It matters because it keeps the data clean enough for the governance half to mean anything.
Managers and application owners periodically confirm that the access their people hold is still appropriate. The engineering challenge is not running the campaign but making it meaningful — a review that presents raw entitlement names to a manager who does not recognise them produces rubber-stamping, which is worse than no review because it manufactures false assurance.
Role mining derives roles from what people actually hold rather than from a whiteboard exercise. This matters because designed role models tend to describe the organisation somebody wished for; mined ones describe the one that exists. Expect this to be a real analytical project rather than a configuration step — it is a substantial part of why implementation costs what it does.
SoD rules stop one person holding combinations of access that together enable fraud — raising a purchase order and approving it, creating a vendor and paying it. This is the capability auditors in regulated Indian sectors ask about most directly, and the one lifecycle-only products cannot answer at all.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
Identity Security Cloud produces the evidence that access was reviewed and understood — not just that accounts were created and removed — the flagship of portfolio, and paired with the human firewall.
A single model spanning employees, contractors, service accounts and machine identities across cloud, SaaS and on-premises systems. You cannot govern what you have not ingested — which is why connector coverage, not feature count, decides how useful this becomes. See the whole estate, or govern half of it.
Finding the granular permissions inside each application and correlating them to the people who hold them. The unglamorous foundation of everything else, and the part that surfaces how much access nobody could account for. The inventory before the argument.
Identifying outliers, over-privileged accounts and access that looks nothing like a peer group's. Useful precisely because it directs a certification campaign at the access most likely to be wrong, rather than asking managers to review everything equally. Point the review where the risk is.
Accounts created on the first day and removed on the last, driven by HR or directory events. The half that also exists in cheaper tools — buy SailPoint for what sits above it, not for this alone. Day one, and more importantly the last day.
Scheduled reviews where owners confirm access is still appropriate, with the context needed to make that a real decision rather than a click-through. The capability most buyers arrive for, usually after an audit finding. The review that survives scrutiny.
Deriving roles from actual entitlement data, then managing them as the organisation changes. A genuine analytical project rather than a switch — and a substantial share of why implementation costs what it does. Budget it as work, not configuration.
Detecting and preventing toxic combinations of access before they are granted, and finding the ones already out there. The question regulated Indian auditors ask most directly, and the one provisioning-only tools cannot answer. The combination, not the permission.
People request access through a catalogue, approvals route by policy, and provisioning happens automatically on approval. Reduces the ticket load and, more usefully, produces a record of why each grant was made. Requests with a reason attached.
Every decision, approval and revocation recorded in a form you can hand to an auditor. This is the actual deliverable of an IGA programme — everything else is how you produce it. What you hand over when asked.
Connectors to the applications that must be governed, with SAP GRC Firefighter access, BeyondTrust, macOS password reset and JDBC provisioning added in September 2025. Scope this list before you sign — it predicts your timeline better than any other single factor. The connector list IS the project plan.
Discovery, classification and ownership of machine accounts — service accounts, bots and shared accounts — with sub-types and multiple ownership assignments added September 2025. In most estates these now outnumber people and are governed least. The population nobody reviews.
Live since 27 November 2024, SailPoint's ninth point of presence, described as completely isolated from other AWS regions with nothing replicated, backed up or stored elsewhere. The strongest documented India data-storage position in this category — and a statement about storage, not processing. Storage, documented. Processing, ask.
The platform, demonstrated by SailPoint.
The platform, introduced by SailPoint.
A product-marketing walkthrough of the suites.
The contractor and partner add-on.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — starting with the cost reality most buyers meet late.
If you take one thing from this page, take this: third-party reporting consistently puts SailPoint implementation at two to three times licence cost, and that ratio is the single most common source of buyer surprise in this category. Why it costs that: the work in an identity governance programme is not installing software. It is connectors — every application that must be governed needs one, and the ones without a supported connector need custom work. It is role modelling — deriving roles from real entitlement data is a genuine analytical project, and the data is always messier than anyone expects. And it is certification design — building campaigns that managers can actually complete meaningfully, which requires knowing what each entitlement means in business terms rather than showing them a technical string. None of that is padding, and none of it is SailPoint being difficult. It is what enterprise identity governance actually involves, and any vendor in this category carries the same shape of cost. What to do about it: build the budget around the programme rather than the software, and price the connector list explicitly before you commit — that single exercise predicts your timeline better than anything else in the evaluation. Be actively suspicious of a proposal where services look cheap relative to licence: it usually means the scope has not been examined, and the number will move later, after you have signed. The size threshold this implies: below roughly a thousand identities, the fixed cost of the programme is difficult to justify against the benefit, and a lighter provisioning product is often the honest answer. We will tell you when that is the case rather than take the order. The value: a category-leading platform whose true cost is knowable in advance if you scope the connectors first. TechBag prices the programme, not the licence.
A lot of organisations buy identity governance when what they actually needed was provisioning, and the distinction is worth being precise about because it decides how much you should spend. What provisioning does: creates accounts when people join, updates them when roles change, removes them when people leave. This is joiner-mover-leaver automation. It is genuinely valuable, it solves a real operational pain, and several products do it well for a fraction of SailPoint's cost — including SailPoint's own lighter competitors and, for that matter, tools already inside Microsoft Entra or Okta. What governance adds: the access certification campaign, the segregation-of-duties rule, and the attestation evidence trail. The difference is that governance produces something you can hand to a person who is entitled to ask. When your auditor says 'show me that access to the core banking system was reviewed last quarter and that the reviewer understood what they were approving', provisioning has no answer and governance does. How to tell which you need: look at what triggered the project. If it was a slow onboarding process, that is provisioning. If it was an audit finding, a regulatory examination, or a question from a client's security team, that is governance. If it was both, you need governance and you will get provisioning with it — but do not pay governance prices for a provisioning problem. Why we press this: an identity governance programme that was really a provisioning requirement is expensive, slow and ultimately judged a disappointment, and the disappointment is avoidable by asking one question at the start. The value: the capability that produces defensible evidence, which is what separates this from cheaper alternatives. TechBag establishes which problem you actually have before quoting.
SailPoint's India data position is the strongest of any IGA vendor we carry, and it deserves to be stated precisely rather than enthusiastically. What is documented: SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024 — its ninth point of presence globally. SailPoint's own description is a highly available multi-tenant SaaS environment, completely isolated from other AWS regions, with no data replicated, backed up or stored in any other AWS region. That isolation language is unusually specific; most vendors in this category either have no India region at all, or describe one without naming the region or the isolation properties. What that covers, precisely: replication, backup and storage. Those are the three things named. Where it stops: SailPoint does not separately document where data is PROCESSED, and we are not going to infer it from a storage statement. For most Indian buyers this makes no practical difference, because the obligation concerns where data rests. For some it does: if you are IRDAI-regulated, the 2023 audit annexure asks a direct yes/no question about whether ICT logs are held in India, and processing location can become a separate answer you have to give. On CERT-In specifically, worth clearing up because it is widely overstated: the 180-day ICT log retention duty falls on you as the regulated entity, not on SailPoint, and CERT-In's own FAQ permits storage outside India provided logs can be produced to the authorities in reasonable time. What to do: get the region and the sub-processor list written into the contract rather than relying on a marketing page, and if processing location is genuinely part of your obligation, ask SailPoint directly. The value: a documented, specific India storage position — and an honest boundary around what it does not say. TechBag helps you get both in writing.
SailPoint leads this category, and the precise form of that claim matters more than it might seem. What is true and citable: Gartner's Market Share: Security Software, Worldwide 2024 ranks SailPoint first by revenue in identity governance and administration. That is a real position from a real Gartner document — it says the market spends more with SailPoint in this category than with anyone else. The financials corroborate the scale: $1.125 billion ARR in FY2026, up 28 percent, with SaaS ARR of $746 million growing 38 percent, and customers above $1 million ARR up 62 percent year on year. Because SailPoint is public again on the Nasdaq, those numbers are disclosed in filings rather than asserted in marketing — which is more than can be said for most of its competitors, several of which publish no financials at all. What is NOT true, and what you will see claimed: there is no Gartner Magic Quadrant for identity governance and administration. The current Gartner research in this category is a Market Guide, published 2 October 2025, and Market Guides name representative vendors rather than positioning them as Leaders. The last IGA Magic Quadrant appears to have been published in 2019. So any vendor page in this category claiming an 'IGA MQ Leader' position today is misreading a document that no longer exists in that form, and that should make you read the rest of that page more carefully. A corroborating detail we find persuasive: SailPoint's own accolades page, which would certainly advertise an MQ Leader placement if one existed, cites no IGA Magic Quadrant at all. The value: genuine, checkable category leadership — stated in the form the evidence actually supports. TechBag would rather be precise than impressive.
Identity Security Cloud is the flagship of the identity governance category leader: joiner-mover-leaver automation, access certification campaigns, role modelling and mining, segregation-of-duties policy, self-service access requests, machine identity discovery, and the attestation evidence trail that is the actual deliverable of an IGA programme — all on the Atlas core, and running in the AWS Mumbai region for Indian customers since November 2024. Where it genuinely wins: depth of governance, the breadth of the connector catalogue, the documented India storage position, and the fact that as a public company its scale is verifiable rather than asserted. For a large regulated Indian enterprise that must produce defensible access reviews, it is frequently the strongest answer in the category and the easiest shortlist to defend internally. Where something else fits better, plainly: Saviynt converges IGA with privileged access management and Application Access Governance, and that AAG module — SAP and ERP segregation-of-duties analysis — is a genuine differentiator if your estate is SAP-heavy; its Bengaluru hub is also its largest global innovation centre. Idira (the rebranded CyberArk, now Palo Alto Networks) makes sense if you already run that PAM and want governance to reach privileged accounts in the same campaign, though IGA is a supporting module there rather than the flagship. Omada is pure IGA and faster to deploy, but has no India office at all. And if your real requirement is provisioning speed rather than audit evidence, a lighter product will serve you better for far less. The limits to weigh: implementation typically costs two to three times licence; below roughly a thousand identities the economics are hard; pricing is quote-only with no published rate card; the Mumbai statement covers storage and not processing; and Thoma Bravo retains roughly 88 percent, making SailPoint a controlled company. So the honest positioning: the category leader, genuinely, for organisations large enough to absorb an enterprise programme. TechBag scopes it against Saviynt and against doing less, in INR with GST.
An audit finding, a regulatory examination or a client security questionnaire means governance. A slow onboarding process means provisioning, and there are much cheaper answers. Also settle whether your obligation speaks about data STORAGE or PROCESSING — SailPoint documents the Mumbai region for storage and does not separately document processing, and for a small number of buyers that distinction is decisive.
List every application that must be governed. Identify which have supported connectors and which need custom work, and get that priced. This single exercise predicts your timeline and your services cost better than any other part of the evaluation, and it is the part most proposals leave vague until after signature.
Run one campaign against one meaningful application with real reviewers. The test is not whether the campaign completes — it is whether the managers understood what they were approving. If entitlements appear as raw technical strings, you will get rubber-stamping, which manufactures false assurance. Budget the work of describing entitlements in business language.
Bring applications into governance in order of risk rather than convenience. TechBag supports the rollout, tracks the connector backlog, gets the Mumbai region and sub-processor list into the contract, and invoices in INR with GST.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our auditor asked us to prove that access to the core banking platform had been reviewed and that the reviewers understood what they approved. Before SailPoint we could produce a spreadsheet. Now we produce an evidence trail.”
“The Mumbai region was the reason we shortlisted it at all. Our compliance team had ruled out two competitors that could not tell us which region our identity data would sit in.”
“Budget for the programme, not the licence. Our services cost more than twice the software and that was with a well-scoped connector list. TechBag told us that up front, which is why it was a plan rather than a surprise.”
“Role mining against our real entitlement data was humbling. The roles we thought we had and the roles we actually had were different documents. That analysis was worth the project on its own.”
“Honest: we were too small. Around 700 identities, and the economics never quite worked. TechBag said so during scoping and we went with a lighter provisioning tool. They were right and it cost them the sale.”
“Certification campaigns only became useful once we invested in describing entitlements in business language. Presented as raw technical strings, managers just clicked approve on everything.”
“We compared it properly against Saviynt. For our SAP-heavy estate their Application Access Governance was the better answer and we said so. For the rest of the group SailPoint won.”
“Being able to check the ARR figures in an actual filing rather than a press release mattered to our procurement team more than I expected.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Category leader by revenue. This page's product.
The grid nobody publishes — how deep the governance goes vs how fast you get there.
Deepest governance; heaviest implementation.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Saviynt, Idira (the rebranded CyberArk), One Identity, Omada and Okta — honest lanes. The edge here is governance depth and a documented Mumbai region. SAP-heavy with SoD as the driver? Saviynt’s AAG genuinely goes further, and we sell it.
| Dimension | SailPoint ISC | Saviynt | Idira (was CyberArk) | One Identity | Omada | Okta IGA |
|---|---|---|---|---|---|---|
| Position | Category leader by revenue | Converged IGA+PAM+AAG | IGA module in a PAM platform | Established, on-prem heritage | Pure IGA, European | Governance beside access mgmt |
| Certification depth | Deep — the reference implementation | Deep | Strong (Zilla lineage) | Deep | Deep, standards-driven | Lighter |
| SAP / ERP SoD | Via Access Risk Management | AAG — a genuine differentiator | Present | Present | Partner-led | Not a focus |
| India data region | AWS MUMBAI, documented + isolated | India tenants, regions unnamed | Not documented | Not documented | No India region at all | Regional presence |
| India engineering | Pune since 2011, 200+ (2023) | Bengaluru — LARGEST global hub, 650+ | Regional | Regional | No India office | Regional |
| Financials verifiable | Public (Nasdaq: SAIL) — in filings | Private — not disclosed | Within Palo Alto Networks | Within Quest | Private — not disclosed | Public (Nasdaq: OKTA) |
| Implementation burden | 2–3× licence — the honest warning | Reported as heavy | Quarters-long | Substantial | Faster — config over code | Lighter |
| Best fit | Large regulated estates needing defensible evidence | SAP-heavy estates; converged IGA+PAM | Where you already run that PAM | On-prem heritage estates | Faster pure-IGA, if India is not a constraint | Where Okta is already the access layer |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Identity Security Cloud is one of 16 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (identity count; IT hourly cost as a loaded rate). Estimates contrast manual access reviews — spreadsheets emailed to managers, evidence reconstructed after the auditor asks, leavers removed when somebody remembers — against automated certification with a recorded evidence trail. NB: this models the REVIEW effort saved. It does NOT model implementation, which typically costs 2–3× the licence and is the larger number — scope the connector list to size that. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
SailPoint is QUOTE-ONLY with no published rate card, and we will not print the third-party figures circulating (“$11 per identity”, “$825k for 2,500 identities”) because they are blog estimates, not SailPoint’s. The number that matters more: third-party reporting consistently puts IMPLEMENTATION at 2–3× licence cost — connectors, role modelling and certification design are real work. Budget the programme, price the connector list before committing, and be suspicious of any proposal where services look cheap. Below ~1,000 identities the economics are hard to justify and we will say so. TechBag obtains the quote and invoices in INR with GST.
Best for defensible access reviews
Best for a broader rollout
Best budgeted before you sign
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Did an auditor trigger this, or a slow onboarding process? The second is a much cheaper problem — do not pay governance prices for it.
Have you listed every application that must be governed and priced the ones without supported connectors? This drives your timeline more than anything else.
Is your budget built around implementation rather than licence? Third-party reporting puts services at 2–3× the software — a proposal where they look cheap has not been scoped.
Do you have more than roughly a thousand identities? Below that the fixed programme cost is genuinely hard to justify.
Does your obligation concern where data is STORED or PROCESSED? Mumbai is documented for storage; processing is not separately documented.
In the pilot, did reviewers understand what they were approving? Raw entitlement strings produce rubber-stamping, which is worse than no review.
Is ERP segregation of duties the real driver? If so, compare Saviynt's Application Access Governance module seriously before deciding.
Comfortable that Thoma Bravo retains ~88%, making SailPoint a controlled company? Worth weighing on a decade-long platform commitment.
Start with what triggered the project — an audit finding means governance, a slow onboarding process means provisioning and costs far less. Then price the connector list, because it drives everything. Or let a TechBag advisor qualify it honestly against Saviynt and against doing less; we have talked buyers out of this product when they were under a thousand identities.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.