IdentityIQ is SailPoint’s on-premises identity governance platform — running in your own data centre, which answers residency and processing by construction. And the correction worth making: there is no announced end-of-life, whatever you have been told.
Data residency & processing
IdentityIQ runs on infrastructure you own, which answers residency and processing together by construction — there is no region to confirm and no sub-processor list to negotiate, because the software never leaves your building. That is the cleanest possible answer where a regulator specifies where the SYSTEM runs rather than only where data rests, and it is a genuine advantage over any SaaS deployment including SailPoint’s own. The trade is that you own the infrastructure, upgrades, tuning and disaster recovery— real cost that belongs in the comparison.
On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers IdentityIQ — the on-premises line. The rest of the portfolio:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
SailPoint’s on-premises identity governance platform — certification, provisioning, role mining, SoD and the evidence trail, running in your own data centre. No end-of-life has been announced.
What consolidation actually replaces, dimension by dimension.
| Dimension | A migration you did not need yet | IdentityIQ (SailPoint) |
|---|---|---|
| Where it runs | (cloud: a region you confirm) | Your data centre |
| Residency | A vendor commitment about storage | By construction — no region to ask about |
| Processing location | Often unanswered separately | Same building as storage |
| Rules & workflow | (cloud: configuration-driven) | You can write the logic |
| Infrastructure | (cloud: absorbed by the vendor) | ⚠️ Yours — upgrades, tuning, DR |
| New capability | (cloud: lands here first) | Follows later |
| End of life | (the claim you keep hearing) | NONE announced |
| Migration | (framed as urgent) | 2–3 years, when YOU choose |
On-premises identity governance that answers residency AND processing by construction — and a rules engine more flexible than the cloud platform’s. The correction that matters: no end-of-life has been announced, and migrations take 2–3 years in parallel, so anyone using a date to create urgency is selling a project. Honest trade: you own infrastructure, upgrades, tuning and DR, and new capability lands in the cloud first.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
IdentityIQ is installed on infrastructure you own and control. For an organisation whose regulator has been explicit about where systems may run, that is not a preference — it is the requirement, and it answers both storage and processing questions by construction because the software never leaves your building. No region to confirm, no sub-processor list to negotiate.
IdentityIQ's rules and workflow engine is more flexible than Identity Security Cloud's. The cloud platform trades granularity for configuration-driven simplicity, which suits most organisations well. If your governance logic is genuinely unusual — the kind where you write rules rather than select policies — that flexibility is something you would give up by moving, and it is the second most common reason estates stay.
Access certification campaigns, joiner-mover-leaver provisioning, role modelling and mining, segregation-of-duties policy and the attestation evidence trail. This is not a lesser product than the cloud platform — it is the same discipline delivered differently, and for years it was the product that made SailPoint the category leader.
You own the infrastructure, the upgrade cycle, the database tuning, the availability and the disaster recovery. All of that is real cost and real staffing that the cloud platform absorbs on your behalf. Weigh it honestly: on-premises is cheaper on paper and rarely cheaper in total unless residency or rules flexibility genuinely require it.
SailPoint runs an upgrade programme with a free assessment that typically takes four weeks, and configured connectors, objects and rules can carry across because both platforms share an identity model and connectivity framework. The path exists and is reasonably well trodden. What does not exist is a date by which you must take it.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
IdentityIQ runs identity governance inside your own data centre — no region to confirm, no processing question left open — the on-premises line of portfolio, and paired with the human firewall.
Installed in your data centre, on servers you control, inside your network. The answer to a residency requirement that a SaaS region cannot fully satisfy — because there is no region to ask about. Your building, your rules.
Finding granular permissions inside each application and correlating them to the people holding them. The foundation of governance, and usually the moment an organisation learns how much access it could not account for. The inventory nobody had.
Reporting on entitlements, campaign progress and policy violations — running against a database you own, which for some auditors is itself the point. Query it directly if you need to.
Scheduled reviews where managers and application owners confirm access is still appropriate, with the evidence trail an auditor asks for. The same discipline as the cloud platform, delivered on your own infrastructure. The review, on your kit.
Accounts created on joining, updated on role change and revoked on departure, driven by HR or directory events rather than by a ticket somebody remembers. Day one, and the last day.
More flexible than Identity Security Cloud's, which is precisely why complex estates stay. If your governance logic needs writing rather than configuring, this is the capability you would lose by migrating. Write the logic, do not select it.
Deriving roles from actual entitlement data and managing them as the organisation changes. A genuine analytical project in either deployment model — and a substantial part of why implementation costs what it does. Real work, not configuration.
Detecting and preventing toxic combinations of access — raising a purchase order and approving it, creating a vendor and paying it. The question regulated Indian auditors ask most directly. The combination, not the permission.
Requests through a catalogue, approvals routed by policy, provisioning on approval — and a record of why each grant was made. Requests with a reason attached.
Including the legacy and in-house systems that are often the reason an estate is on-premises in the first place. Scope this list before anything else — it predicts your timeline more reliably than any other factor. The connector list IS the plan.
A free assessment taking around four weeks, with configured connectors, objects and rules able to carry across since both platforms share an identity model. Available when you want it — and there is no date by which you must. The option, not the deadline.
The database, the servers, the upgrade cycle, the tuning, the DR plan — all yours. Real cost and real staffing that the cloud platform would absorb. On-premises is cheaper on paper and rarely cheaper in total unless residency or rules flexibility genuinely require it. Be honest in the business case.
The platform this sits alongside.
The cloud platform IdentityIQ sits alongside.
What the migration target actually looks like.
The contractor and partner add-on.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely justifies staying on-premises — and when it does not.
This is the correction worth making, because a great deal of noise in this market says otherwise and that noise has a commercial motive. The facts: SailPoint has announced no end-of-life for IdentityIQ. It still sells it, still supports it, and thousands of enterprises still run it in production. A typical migration to Identity Security Cloud takes two to three years, with both platforms running in parallel for most of that period. Industry commentary describes this as a decade-scale transition rather than a cliff, and skills in IdentityIQ remain in demand accordingly. Why the noise exists: a migration is a large services engagement. Systems integrators and consultancies have an entirely rational interest in framing it as urgent, and the framing is often sincere — cloud genuinely is where new capability lands first. But urgency and benefit are different arguments, and only one of them is being made when someone tells you the clock is running. What that means for your planning: treat migration as a roadmap decision you time against your own drivers — a hardware refresh, a data-centre exit, a capability you actually need that only exists in the cloud platform. Not as a deadline someone else set. If none of those drivers is present this year, staying is a legitimate answer and not technical debt. What we will not do: pretend there is no case for moving. New capability does land in Identity Security Cloud first, the operational burden of running IdentityIQ yourself is real, and for most organisations the cloud platform is where they will end up. The point is that you choose when. The value: a fully supported on-premises governance platform with no forced end date. TechBag scopes the migration honestly, including the option of not doing it yet.
Every cloud identity governance evaluation in India eventually reaches the same conversation about data regions, and IdentityIQ sidesteps it entirely. The problem it solves: for a SaaS product, residency is a question you have to ask, get answered in writing, and then keep checking. Even where the answer is good — SailPoint's own Identity Security Cloud runs in AWS Mumbai with explicit isolation language, which is the strongest documented position in this category — you are relying on a vendor commitment about storage, and processing location is typically a separate question that often goes unanswered. What on-premises gives you: the software runs on servers in your building, on infrastructure you own. There is no region to confirm, no sub-processor list to negotiate, no distinction between where data is stored and where it is processed, because both are simply where you put the machine. For a public-sector body, a defence-adjacent contractor, or a bank whose regulator has been explicit about system location, that is not a preference — it is the requirement. Who this genuinely matters for: organisations under a regulator that names system location rather than data location; estates where an air-gapped or network-isolated deployment is mandated; and buyers whose own clients impose residency terms they must be able to evidence rather than assert. What it costs you: you own the infrastructure, the upgrades, the tuning, the availability and the disaster recovery. That is real money and real staffing, and it is why on-premises is cheaper on paper and rarely cheaper in total. The honest test: if residency or rules flexibility do not genuinely require on-premises, the cloud platform will probably cost you less overall. The value: residency and processing answered by construction rather than by contract. TechBag will tell you when you do not actually need that.
The less-discussed reason complex estates remain on IdentityIQ has nothing to do with residency. It is that the on-premises rules and workflow engine bends further than the cloud platform's. What the difference is: IdentityIQ lets you write governance logic. Identity Security Cloud favours configuration — you select and parameterise policies rather than author them. For the large majority of organisations that trade is a clear win: configuration is faster to implement, easier to hand over, less fragile across upgrades, and does not require someone on staff who understands the rules language. That is exactly why SailPoint made it. Where it bites: estates whose governance logic is genuinely unusual. Approval chains that depend on conditions the platform does not model natively. Certification scoping driven by business rules specific to your organisation. Provisioning logic that has to reconcile systems nobody else has. If your current IdentityIQ implementation contains rules that took real engineering to write, the honest question in any migration assessment is whether those rules can be expressed as configuration — and sometimes the answer is no, or not without changing the process they encode. How to test it before deciding: take your three most complex governance rules and ask specifically how each would be implemented in Identity Security Cloud. Not whether the platform 'supports' the requirement in general terms — how those three would actually be built. That conversation tells you more about your migration than any feature comparison. The value: flexibility that is genuinely lost in the move, and worth knowing about before somebody assures you the migration is like-for-like. TechBag runs that three-rules test as part of any migration assessment.
Nothing about on-premises deployment changes the fundamental cost shape of an identity governance programme, and it is worth saying so because the licence sometimes looks cheaper and misleads people. What stays the same: implementation typically runs two to three times licence cost, in either deployment model. The work is connectors to your applications, role modelling against real entitlement data, and designing certification campaigns that managers complete meaningfully rather than rubber-stamp. None of that gets cheaper because the software runs in your building. And below roughly a thousand identities, the fixed programme cost is difficult to justify against the benefit regardless of where it runs. What is different, and worse: you add the infrastructure, the upgrade cycle, the database administration, the availability engineering and the disaster-recovery plan. Those are ongoing costs with names and salaries attached, and they do not appear on the licence quote. A business case that compares an on-premises licence against a SaaS subscription without pricing the operational side is comparing two different things. What is different, and better: no per-identity subscription growing every year, and no renegotiation at renewal. For a large, stable identity population over a long horizon, that can genuinely work out. The honest arithmetic: model both over five years including staff time, not three years including licence only. Most organisations that do this properly find the cloud platform wins unless residency or rules flexibility force the issue — and the ones for whom it does not win usually know exactly why. The value: a clear-eyed comparison rather than a licence-line one. TechBag builds the five-year model with the operational cost included, and will tell you when it does not favour us.
IdentityIQ is SailPoint's on-premises identity governance platform: access certification, lifecycle provisioning, role modelling and mining, segregation-of-duties policy and the attestation evidence trail, running on infrastructure you own. Where it genuinely wins: residency and processing answered by construction rather than by contract, which for regulated public-sector, defence-adjacent and some BFSI buyers is the requirement rather than a preference; and a rules engine more flexible than the cloud platform's, which matters for estates whose governance logic is genuinely unusual. Both are real advantages and neither is nostalgia. Where the cloud platform fits better, plainly: SailPoint Identity Security Cloud absorbs the infrastructure, upgrades, tuning and availability burden, gets new capability first, and runs in the AWS Mumbai region with documented isolation — which satisfies most Indian residency obligations without you owning a data centre. For the majority of organisations, that is the better answer, and we would rather say so than sell you infrastructure you did not need. Where something else fits better: if your driver is provisioning speed rather than audit evidence, a lighter product costs far less. If your estate is SAP-heavy and segregation-of-duties analysis is the point, look at Saviynt's Application Access Governance. And below roughly a thousand identities, an enterprise IGA programme is hard to justify in any deployment model. The limits to weigh: you own the operational burden and it is not small; new capability lands in the cloud platform first; implementation still runs two to three times licence; and pricing is quote-only. So the honest positioning: IdentityIQ remains a fully supported, capable product with no end-of-life, and it is the right answer when residency or rules flexibility genuinely require on-premises. When they do not, the cloud platform usually costs less in total. TechBag models both over five years, in INR with GST.
Does your regulator specify where the SYSTEM runs, or only where data rests? If it is the latter, SailPoint's AWS Mumbai region probably satisfies it and the cloud platform will cost you less in total. On-premises earns its operational burden when the requirement is genuinely about system location, or when you are air-gapped.
If you are weighing a migration, take your three most complex governance rules and ask specifically how each would be built in Identity Security Cloud — not whether the platform 'supports' the requirement, but how those three would actually be implemented. That conversation tells you more than any feature comparison, and it is where the rules-engine difference becomes concrete.
Compare on-premises licence plus infrastructure, DBA time, upgrade cycles, availability engineering and DR against the SaaS subscription. Three years and licence-only is the comparison that misleads. Scope the connector list in this phase too — it drives implementation cost in either model.
A hardware refresh, a data-centre exit, or a capability that only exists in the cloud platform — those are drivers. 'It is end-of-life' is not, because it is not true. TechBag reviews the position annually and invoices in INR with GST.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our regulator asks where the system runs, not where the data rests. On-premises answers that in one sentence and no cloud region does. That is the entire reason we are still here.”
“We were told three times that IdentityIQ was end-of-life. It is not, and SailPoint confirmed as much. We planned a migration on our own timetable instead of somebody else's.”
“The three-rules test was the useful part of our migration assessment. Two of our complex approval rules translated cleanly to configuration. The third did not, and knowing that changed the plan.”
“Honest warning: the licence looked cheaper than the SaaS subscription and the total was not. Once we costed the DBA time, the upgrade cycle and the DR plan, the gap closed almost entirely.”
“New capability shows up in the cloud platform first. We accepted that trade for residency reasons, but it is a real trade and worth going in with your eyes open.”
“TechBag modelled both options over five years with our staff costs included. It did not favour the on-premises option for us and they said so, which is why we trusted the rest of the analysis.”
“The rules engine is why we stayed. Our certification scoping logic is genuinely unusual and it took real engineering to write. Nobody has yet shown us how to express it as configuration.”
“Connector work dominated the project, exactly as we were warned. Two legacy in-house applications took longer than everything else combined.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
On-premises governance. This page's product.
The grid nobody publishes — how far the rules engine bends vs how much you must run yourself.
Deep and flexible; you own the operations.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Identity Security Cloud, One Identity Manager, Saviynt, ManageEngine and Omada — honest lanes. The first comparison is against SailPoint’s OWN cloud platform: if you have no hard on-premises requirement, it costs less in total and we will say so.
| Dimension | IdentityIQ | Identity Security Cloud | One Identity Manager | Saviynt | ManageEngine AD360 | Omada |
|---|---|---|---|---|---|---|
| Position | SailPoint on-premises | SailPoint's cloud platform | Established, on-prem heritage | Converged IGA+PAM+AAG | AD-centric governance modules | Pure IGA, European |
| Runs on-premises | Yes — the whole point | No — SaaS only | Yes | SaaS | Yes | Cloud Private in your Azure tenant |
| Residency answered | By construction — both storage and processing | AWS Mumbai, documented for STORAGE | By construction if on-prem | India tenants, regions unnamed | By construction if on-prem | No India region |
| Rules flexibility | Write the logic — more flexible | Configuration-driven | Highly customisable | Configuration-driven | Limited | Config over code by design |
| Who runs the infrastructure | ⚠️ You do — real cost | SailPoint | You do | Saviynt | You do (on-prem) | Omada (standard cloud) |
| New capability first | Follows the cloud platform | Lands here first | Steady | Cloud-paced | Steady | Cloud-paced |
| Best fit | Regulators that name system LOCATION; unusual rules logic | Most organisations — less to run, Mumbai region | On-prem heritage estates | SAP-heavy estates needing ERP SoD | AD-centric estates wanting lighter governance | Pure IGA where India presence is not a constraint |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
IdentityIQ is one of 16 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (identity count; IT hourly cost as a loaded rate). Estimates contrast manual access reviews against automated certification. NB: this models the REVIEW effort saved, and for on-premises there are two costs it does NOT model — implementation at 2–3× licence, and the infrastructure, upgrade, DBA and DR burden you take on. Model five years with staff time included before comparing against a SaaS subscription. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only, with no published rate card. Two cost layers for on-premises. The same category economics apply — implementation typically runs 2–3× licence, because connectors, role modelling and certification design are the real work in either deployment model. AND you own infrastructure, upgrades, database administration, availability and DR — ongoing costs with salaries attached that never appear on a licence quote. Model FIVE years with staff time included; three years licence-only favours on-premises misleadingly. TechBag builds that model and will tell you when it does not favour us.
Best when system location is mandated
Best for a broader rollout
Best costed before you compare
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does your regulator name where the SYSTEM runs, or only where data rests? Only the first genuinely requires on-premises.
Have you been told IdentityIQ is end-of-life? It is not — no EOL has been announced. Ask whoever told you where they got the date.
Can your three most complex governance rules be expressed as configuration in the cloud platform? Ask HOW, not WHETHER.
Does your comparison include DBA time, upgrade cycles, availability and DR? Licence-only comparisons favour on-prem misleadingly.
Have you scoped and priced every application needing a connector? This drives implementation cost in either deployment model.
Are you comfortable that new features land in Identity Security Cloud first? That trade is real and permanent.
More than roughly a thousand identities? Below that an enterprise IGA programme is hard to justify however it is deployed.
Do you have the DBA and infrastructure capability in-house, or would you be buying it? That cost belongs in the business case.
Start with the requirement: does your regulator specify where the SYSTEM runs, or only where data rests? If the latter, the AWS Mumbai region probably satisfies it and the cloud platform costs less. If you are weighing a migration, run the three-rules test first. Or let a TechBag advisor model both options over five years with your staff costs included.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.