Talk to us
by SailPointTechBag Intel Page

Non-Employee Risk Management

Your HR system knows about employees. It does not know about the contractor onboarded last quarter or the vendor engineer with a standing login. NERM gives them a lifecycle, a named owner and an expiry that fires — and puts them in your access reviews alongside staff.

Data residency & processing

Non-employee records are personal data by definition — identity details, employer, contact information, and with Verified ID, biometric verification data, belonging to people who are not your employees. Under the DPDP Act that carries its own consent and purpose-limitation questions, so establish retention as well as region. SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024 — its ninth point of presence globally. SailPoint’s own words: an environment“completely isolated from other AWS Regions—no data will be replicated, backed up, or stored in any other AWS Region.” That is the strongest documented India data-storage position of any IGA vendor we carry. It is a statement about STORAGE. SailPoint does not separately document where data is processed, and we are not going to infer it — if processing location is part of your obligation rather than storage, ask SailPoint directly and get the answer in writing.

On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.

The population HR never seesA named owner and a real expiry⚠️ An add-on, not standalone

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
The population
HR does not own
Non-employees
What it adds
and certification
Owner + expiry
Sept 2025
biometric
Entra Verified ID
⚠️ Structure
not standalone
An add-on

Quick answer

Your HR system knows about employees. It does not know about the contractor a project manager onboarded last quarter, the vendor engineer with a standing support login, the auditor given temporary access two years ago, or the partner whose engagement ended but whose account did not. SailPoint Non-Employee Risk Management gives those identities what employees already have: a lifecycle, a named owner, an expiry date, and a place in your access certification campaigns. This matters more in India than in most markets, because the contractor and vendor population in a typical Indian enterprise is large, the turnover is fast, and the onboarding is frequently done by a business manager rather than by HR — which means there is no authoritative record to drive deprovisioning from. In practice this is the population an auditor finds first, because it is the one where nobody can produce a list. What the product does: collects the personal data needed to onboard a non-employee to critical applications, assigns ownership to somebody accountable inside your organisation, sets an expiry that actually fires, and gives centralised visibility over business-partner identities so they appear in reviews alongside staff. Since September 2025 it integrates with Microsoft Entra Verified ID, which speeds onboarding and adds biometric verification — useful where you are admitting people you have never met to systems that matter. The honest framing. This is an add-on to SailPoint Identity Security Cloud rather than a standalone purchase, so it assumes you are buying or already run the platform, and the platform is enterprise-priced with implementation typically running two to three times licence cost. If your entire identity problem is contractors and you have no wider governance requirement, a full SailPoint programme is a heavy way to solve it and we would say so. Where it earns its place is an organisation that already needs identity governance and has a non-employee population large enough that spreadsheets have stopped working — which, for most Indian enterprises above a certain size, describes the situation exactly. TechBag scopes it as part of the platform decision, in INR with GST. Read more ↓ Show less ↑
Part 01 · Orient

The SailPoint platform family

This page covers Non-Employee Risk Management — the external population. The rest of the portfolio:

Quick facts

30-second orientation
Product
Non-Employee Risk Management (NERM)
Vendor
SailPoint (Nasdaq: SAIL)
The population
Contractors, vendors, partners, auditors, temps
The problem
HR does not own them, so nothing drives offboarding
What it adds
Lifecycle · named owner · expiry · certification
Sept 2025
Microsoft Entra Verified ID — biometric verification
Why India
Large, fast-turnover contractor base; manager-led onboarding
The audit reality
The population nobody can produce a list for
⚠️ Structure
An ADD-ON to Identity Security Cloud, not standalone
Pricing
QUOTE-ONLY — within the platform
India region
AWS Mumbai — documented for STORAGE
In India via
TechBag — scoping, INR invoicing, GST
Part 02 · Learn

Understand non-employee identity before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is NERM?

A lifecycle, a named owner and an expiry that fires for contractors, vendors and partners — plus Entra Verified ID biometric onboarding since Sept 2025. An add-on to Identity Security Cloud.

Contractors nobody tracks vs identities with an owner — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionContractors in a spreadsheetNon-Employee Risk Management (SailPoint)
Authoritative sourceNone — HR does not know themThe platform, with a named owner
Who onboarded themA manager, by emailA defined process, with a record
Identity verificationThe vendor vouched for themEntra Verified ID, biometric
Access end dateNone — persists until noticedExpires unless the owner renews
In the access reviewExcluded — the review draws from HRReviewed alongside staff
Producing the listEleven days and four spreadsheetsOn request
When the engagement endsThe account continuesOffboarding fires
Commercial structure(varies)⚠️ An add-on to the platform

A lifecycle, a named internal owner and an expiry that fires for the population HR never sees — plus Entra Verified ID biometric onboarding since September 2025. Honest: this is an ADD-ON to Identity Security Cloud, not a standalone product, so if contractors are your entire requirement the platform is a heavy answer. For a genuinely small population, a maintained spreadsheet is legitimate and far cheaper.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The problem

The Population HR Does Not Own

Why this exists at all

Employee identity works because HR is an authoritative source: someone joins, the system knows, access follows. Non-employees have no equivalent. A contractor is onboarded by a project manager, a vendor engineer by whoever raised the ticket, an auditor by someone being helpful. There is no record to drive deprovisioning from, so access persists by default rather than expiring by design.

02
The fix

An Owner Who Is Accountable

Somebody internal

Every non-employee identity gets an internal owner — a named person answerable for whether that access should still exist. This is the single most effective control in the product, because the failure mode is not malice but absence: nobody was responsible, so nobody revoked it. Attribution is what makes review possible.

03
The default

An Expiry That Fires

Access with an end date

Non-employee access is granted with a defined end, and the end actually arrives rather than requiring somebody to remember. Renewal is a deliberate act by the owner. This inverts the default from 'persists until revoked' to 'ends unless renewed', which is the correct posture for a population that turns over quickly.

04
The front door

Onboarding With Verified Identity

Entra Verified ID, Sept 2025

Collecting the personal data needed to admit a non-employee to critical applications, with Microsoft Entra Verified ID integration added in September 2025 for faster onboarding and biometric verification. Useful precisely where you are granting system access to people you have never met and whose employer is not you.

05
The governance

Inside The Same Certification

Reviewed like everyone else

Non-employees appear in access certification campaigns alongside staff, so the review covers the whole population rather than the convenient half. An access review that silently excludes contractors is not a review an auditor should accept, and increasingly they do not.

One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.

Part 03 · Evaluate

Twelve capabilities. Admit, own, expire.

NERM gives contractors, vendors and partners the lifecycle employees already have — an owner, an end date, and a place in the access review — an add-on to portfolio, and paired with the human firewall.

Monitor
Discovery

Centralised Non-Employee Visibility

One view of every contractor, vendor, partner and temporary identity across the organisation — the list most enterprises genuinely cannot produce on request. The first deliverable, and often the uncomfortable one. The list nobody had.

Monitor
Ownership

Named Internal Owner Per Identity

Every non-employee is attributed to an accountable person inside your organisation. The failure mode here is absence rather than malice — nobody owned it, so nobody revoked it. Attribution is what makes everything else work. Somebody answerable, by name.

Monitor
Risk view

Business-Partner Risk Visibility

Understanding which external relationships carry which access, and therefore which vendor relationships represent concentrated risk. Increasingly a question from clients' own security teams rather than only from auditors. Risk by relationship, not just by account.

Manage
Onboarding

Structured Non-Employee Onboarding

Collecting the personal data required to grant access to critical applications, through a defined process rather than an email to IT. Turns an ad-hoc favour into a record. A process, not a favour.

Manage
Verified ID

Microsoft Entra Verified ID (Sept 2025)

Integration added September 2025 for faster onboarding with biometric verification. Directly useful where you are admitting people you have never met, employed by somebody else, to systems that matter. Know who you are letting in.

Manage
Expiry

Time-Bound Access By Default

Access granted with an end date that fires, with renewal a deliberate act by the owner. Inverts the default from persists-until-revoked to ends-unless-renewed — the correct posture for a fast-turnover population. The end date that actually arrives.

Manage
Lifecycle

Full Non-Employee Lifecycle

Onboard, change, extend, offboard — the same discipline employees get, applied to a population that usually has none. The gap this closes is the one where an engagement ended and the access did not. Offboarding that happens.

Automate
Certification

Included In Access Reviews

Non-employees appear in certification campaigns alongside staff. A review that silently excludes contractors is not one an auditor should accept, and increasingly they do not. The whole population, reviewed.

Automate
Sponsorship

Sponsorship & Attestation Workflow

The internal owner periodically confirms the relationship still exists and the access is still needed. Cheap to run and disproportionately effective, because most stale non-employee access fails at exactly this question. Ask the sponsor, periodically.

Automate
Evidence

Audit Evidence For External Access

A record of who was admitted, by whom, for what, and when it ended — for the population where that record is usually absent entirely. What you produce when asked.

Automate
Platform

Part Of Identity Security Cloud

An add-on to the SailPoint platform rather than a standalone product — which means it assumes you are buying or already running Identity Security Cloud. Worth knowing before you scope it as a point solution. Add-on, not standalone.

Automate
India region

AWS Mumbai — For Storage

Runs in SailPoint's AWS Asia Pacific (Mumbai) region, live since November 2024, described as isolated from other AWS regions. That is a statement about storage — and non-employee records contain personal data under the DPDP Act, so it is worth having in the contract. Personal data, so ask properly.

See it, don’t just read it

Watch Non-Employee Risk Management in action

The add-on, demonstrated by SailPoint.

SailPoint (official)·Overview

SailPoint Non-Employee Risk Management Overview

The product, introduced by SailPoint.

SailPoint (official)·API

Non-Employee Management API capabilities

Profile management through the API.

SailPoint (official)·Platform

SailPoint Identity Security Cloud Overview

The platform this add-on sits inside.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Non-Employee Risk Management

Access that outlives the engagement. Or an expiry date.

Here’s what genuinely sets it apart — and when a spreadsheet is still the right answer.

01

This is the population an auditor finds first

Ask most enterprises for a list of every contractor, vendor engineer and partner with access to their systems, and the answer arrives slowly, in spreadsheets, from several different people, and is incomplete. That is not incompetence — it is structural, and it is worth understanding why before deciding whether this product is worth its cost. Why employee identity works: HR is an authoritative source. Someone joins, the system records it, access follows; someone leaves, the system records that too, and deprovisioning fires. The whole discipline rests on there being one system that knows. Why non-employee identity does not: a contractor is onboarded by a project manager who needs them productive on Monday. A vendor engineer gets a login because a support case required it. An auditor is given temporary access by somebody being helpful. None of these events touch HR, so there is no authoritative record, and therefore nothing to drive expiry. Access persists by default because no process exists to end it. What that produces: accounts belonging to people whose engagement ended, whose employer changed, or who were never verified in the first place — held by external parties, often with meaningful access, and invisible to the review process because the review draws from HR. This is the population where audit findings cluster, and it is why the finding is usually 'you could not produce the list' rather than 'the access was wrong'. Why it lands harder in India: the contractor and vendor population in a typical Indian enterprise is large relative to headcount, turnover is fast, and onboarding is frequently manager-led. The structural gap is the same everywhere; the volume passing through it is greater here. The value: a lifecycle, an owner and an expiry for the identities your HR system will never know about. TechBag scopes it against the size of your actual non-employee population.

02

Ownership and expiry do most of the work

The capability list for this product is long, but two controls carry most of the value, and it is worth knowing which so you can judge whether a cheaper approach might do. The first is ownership. Every non-employee identity is attributed to a named internal person who is accountable for whether it should still exist. This matters because the failure mode in non-employee access is almost never malice — it is absence. Nobody owned the relationship, so when it ended nobody acted, and the account simply continued. Attribution converts an orphan into somebody's responsibility, and that alone changes behaviour. The second is expiry. Access is granted with an end date that actually fires, and renewal requires the owner to do something deliberate. This inverts the default: instead of access persisting until someone notices it should not, it ends unless someone confirms it should continue. For a population with fast turnover and no HR event to trigger offboarding, that inversion is the whole game. Why the combination matters more than either alone: an expiry with no owner produces an access outage nobody expected and a scramble to restore it. An owner with no expiry produces a person who is theoretically accountable and never prompted. Together they produce a periodic, cheap decision by somebody who knows the answer. The honest test before you buy: if your non-employee population is small enough that a well-maintained spreadsheet and a quarterly calendar reminder would genuinely work, that is a legitimate answer and far cheaper. This product earns its place when the population is large enough, and distributed across enough managers, that no single person can hold it in their head. The value: two controls that address the actual failure mode, rather than a feature list. TechBag will tell you if a spreadsheet is still enough.

03

Verified identity for people you have never met

The September 2025 addition of Microsoft Entra Verified ID integration addresses something that sits underneath the whole non-employee problem: you frequently do not know that the person is who they claim to be. The situation: a vendor tells you their engineer needs access. That engineer is employed by the vendor, not by you. You have no HR record, no background check, and often no in-person contact — the relationship is mediated entirely through the vendor. Yet you are granting a login to systems that matter, and if something goes wrong the access was yours to control. What the integration adds: faster onboarding with biometric verification, so identity is established at the front door rather than assumed from a vendor's assurance. In practice this shortens the admission process while making it stronger, which is unusual — most identity controls trade one for the other. Where it matters most: regulated environments where you must evidence not just that access was appropriate but that the person holding it was verified. Financial services and healthcare buyers increasingly face exactly this question about third parties, and 'the vendor vouched for them' is a weakening answer. The honest note: this is one integration rather than a complete third-party assurance programme. It verifies identity; it does not tell you the person is competent, or that the vendor's own controls are sound, or that the engagement is still live. Those remain your questions to ask. The value: identity established at admission rather than assumed, for a population you cannot background-check yourself. TechBag helps scope where verification is genuinely required versus where it is process overhead.

04

It is an add-on, and that changes the arithmetic

We would rather state the commercial structure plainly than let you scope this as a point solution and discover otherwise during the quote. What it is: Non-Employee Risk Management is an add-on to SailPoint Identity Security Cloud, not a standalone product. Buying it means buying or already running the platform. What that implies for cost: the platform is enterprise-priced and quote-only, and implementation across the category typically runs two to three times licence cost — connectors, role modelling, certification design. Adding NERM to an existing SailPoint programme is an incremental decision with modest incremental cost. Buying the platform because of NERM is a very different proposition, and the business case has to carry the whole programme. When it makes sense: you already run Identity Security Cloud, or you are buying it anyway for broader governance reasons, and you have a non-employee population large enough that spreadsheets have stopped working. In that case NERM closes the gap your certification campaigns currently leave open, and it is straightforwardly worth having. When it does not: your entire identity problem is contractors, you have no wider governance requirement, and you are being shown a platform to solve it. That is a heavy answer to a narrow question. There are lighter approaches — a disciplined process with owners and expiry dates, or a smaller point product — and we would rather point you at one than sell a programme that disappoints. Where the balance usually falls: for Indian enterprises above a certain size, the non-employee population is large enough AND a wider governance requirement usually exists, so both conditions are met. But we check rather than assume. The value: a genuine gap-closer within a platform decision. TechBag scopes it as part of that decision rather than as a standalone sale.

05

The honest scope

Non-Employee Risk Management gives contractors, vendors, partners and temporary staff what employees already have: centralised visibility, a named internal owner, structured onboarding with optional Entra Verified ID biometric verification, time-bound access that expires by default, a full lifecycle, inclusion in access certification campaigns, and an audit evidence trail. Where it genuinely wins: it addresses a structural gap rather than a feature gap. Employee identity governance works because HR is authoritative; non-employee identity has no equivalent source, so access persists by default. Ownership and expiry invert that, and they do most of the work. For Indian enterprises with large, fast-turning contractor populations onboarded by managers rather than HR, this is frequently the first place an auditor looks and the first place they find something. Where something else fits better, plainly: if your non-employee population is small enough that a maintained spreadsheet and a quarterly reminder genuinely work, that is cheaper and legitimate. If your entire identity requirement is contractors with no wider governance driver, buying the SailPoint platform to get this add-on is a heavy answer — look at lighter options first. And if your driver is privileged third-party access specifically, a vendor PAM product may address it more directly. The limits to weigh: this is an add-on, not standalone, so it assumes the platform; the platform is enterprise-priced with implementation typically two to three times licence; the Entra Verified ID integration verifies identity but does not assure the vendor's own controls; and non-employee records contain personal data under the DPDP Act, so the AWS Mumbai region — documented for storage — belongs in your contract. So the honest positioning: a real gap-closer for organisations already committed to identity governance with a substantial external population. TechBag scopes it within the platform decision, in INR with GST.

The blind spot
HR is not authoritative here
Two controls
A named owner, an expiry that fires
⚠️ Structure
An add-on, not standalone
Proof, not promises

The numbers behind the platform

0 HR records
What drives non-employee offboarding today
The structural gap
2 controls do most of it
A named owner, and an expiry that fires
The honest read
1 list, on request
The deliverable auditors actually ask for
Audit reality
Sept 2025
Microsoft Entra Verified ID integration added
SailPoint
1 add-on, not standalone
⚠️ Assumes Identity Security Cloud
Commercial structure
9th point of presence
AWS Mumbai — documented for storage
SailPoint

What your Non-Employee Risk Management evaluation looks like

Day 0

Try to produce the list

Before evaluating anything, ask your team for a complete list of every contractor, vendor engineer and partner with system access, including who owns each relationship and when it should end. How long that takes, and how confident anyone is in the answer, tells you the size of your problem more honestly than any vendor assessment.

Phase 1

Check whether a spreadsheet would still work

If the population is small enough that one person can hold it, and owners and expiry dates would genuinely be maintained, that is the cheaper answer and we will say so. This product earns its place when the population is large and distributed across enough managers that no single person can keep it current.

Phase 2

Scope it as part of the platform decision

NERM is an add-on to Identity Security Cloud, not a standalone purchase. If you already run the platform, this is an incremental decision. If you do not, the business case has to carry the whole programme — implementation typically runs two to three times licence — so build it on your wider governance requirement rather than on contractors alone.

OngoingOptimise

Make sponsorship a habit

The periodic confirmation by an internal owner is cheap to run and does most of the work. Get the Mumbai region into the contract too — non-employee records contain personal data under the DPDP Act. TechBag reviews the population size annually and invoices in INR with GST.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
500+ reviews*
86% would recommend
Closes a structural gap4.8
Ownership & expiry model4.7
Verified onboarding4.3
Standalone viability2.8
5
52%
4
31%
3
11%
2
4%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
Our auditor asked for a list of every external party with system access. It took eleven days and four spreadsheets, and it was still wrong. That finding is what funded this project.
Head of Risk
Banking
Manufacturing
Expiry dates that actually fire changed the behaviour more than anything else. Renewals became a decision somebody made rather than an account nobody looked at.
IAM Manager
Manufacturing
IT Services
Naming an internal owner for every contractor was the uncomfortable part of the rollout and the most valuable. A third of them had no owner anyone could identify.
Security Lead
IT Services
Healthcare
Honest: we bought the platform partly for this, and the business case had to carry the whole programme. TechBag was clear that NERM alone would not justify it, which is why the case we built held up.
IT Director
Healthcare
Financial Services
Verified ID onboarding matters when the engineer works for your vendor and you have never met them. 'The vendor vouched for them' had stopped being an acceptable answer for our regulator.
CISO
Financial Services
Conglomerate
Our contractor population turned over faster than our employees. The HR-driven governance we already had simply did not see them, so half our access reviews were reviewing half the people.
GRC Manager
Conglomerate
Retail
Worth knowing it is an add-on rather than a standalone product. We initially scoped it as a point solution and the quote was a surprise until that was explained.
Procurement Lead
Retail
Insurance
Non-employee records hold personal data, so we got the Mumbai region into the contract rather than relying on the website. Our DPO insisted and was right to.
Data Protection Officer
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the non-employee identity market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Identity Governance Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
SailPoint NERMThis page

Non-employee governance inside the platform. This page's product.

Grid 02 · The architecture

Coverage × Onboarding speed

The grid nobody publishes — how completely non-employees are governed vs how fast they can start.

Point toolsBest-of-breed platformLegacy AV/appliancesHeavy suites
SailPoint NERMThis page

Deep, but an add-on to an enterprise platform.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

NERM vs the alternatives — including a spreadsheet

Saviynt External, vendor PAM, a maintained spreadsheet and doing nothing — honest lanes. If your external population is genuinely small and somebody maintains the list, a spreadsheet is a legitimate answer and we will say so.

DimensionSailPoint NERMSaviynt ExternalIdira (was CyberArk)A spreadsheetVendor PAMDo nothing
PositionNon-employee governance add-onExternal Identity Management moduleVendor PAM, privileged focusWhat most organisations do nowPrivileged third-party access onlyAccess persists by default
Named internal ownerYes — core to the modelYesPartialIf someone maintains itFor privileged sessionsNo
Expiry that firesYes — ends unless renewedYesSession-scopedA calendar reminder at bestSession-based by designNo
Identity verificationEntra Verified ID, biometric (Sept 2025)PresentPresentThe vendor vouched for themVariesNone
In access certificationYes — alongside employeesYesWithin the platformUsually excludedNot a certification toolNo
Standalone purchase⚠️ No — an add-on to the platformWithin the Saviynt platformVendor PAM is buyable aloneFreeYesFree
Best fitAlready on SailPoint, large external populationAlready on SaviyntPRIVILEGED third-party access specificallyA genuinely small population one person can holdSession-level control of vendor engineersNothing — this is the position auditors find
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which cybersecurity approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose NERM if…

  • You already run — or are buying — SailPoint Identity Security Cloud
  • Your contractor, vendor and partner population is too large and too distributed for a spreadsheet to hold
  • An auditor has asked for a list of external parties with access and it took you days to produce
  • You need identity VERIFIED at onboarding for people employed by somebody else

A disciplined spreadsheet if…

  • Your non-employee population is genuinely small enough that one person can hold it, and owners and expiry dates are actually maintained. Cheaper and legitimate — we will say so

Vendor PAM if…

  • Your specific concern is PRIVILEGED third-party access — session-level control of vendor engineers is a different and narrower problem

Look wider if…

  • Contractors are your ENTIRE identity requirement with no broader governance driver. Buying the SailPoint platform to get this add-on is a heavy answer to a narrow question

Non-Employee Risk Management is one of 16 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does untracked contractor access cost you?

Drag the sliders (non-employee count; IT hourly cost as a loaded rate). Estimates contrast tracking external identities by spreadsheet and memory — producing the list on demand, chasing owners, discovering stale access — against a lifecycle with owners and automatic expiry. NB: if your population is small enough for one person to maintain reliably, the spreadsheet genuinely works and this model overstates the gain. And this is an ADD-ON: the platform cost is not modelled here. Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cost of untracked access
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

QUOTE-ONLY, and — the structural point — NERM is an ADD-ON to SailPoint Identity Security Cloud rather than a standalone product. If you already run the platform, this is an incremental decision with modest incremental cost. If you do not, the business case must carry the whole programme, where implementation typically runs 2–3× licence. Buying the platform to solve a contractor problem alone is a heavy answer to a narrow question, and we will tell you so. TechBag scopes it inside the platform decision and invoices in INR with GST.

Non-Employee Risk Management

Best alongside the platform you already run

  • QUOTE-ONLY — an ADD-ON to Identity Security Cloud
  • Named owner, expiry that fires, inclusion in certification
  • Entra Verified ID biometric onboarding since Sept 2025

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ the honest alternative

Best if your population is small

  • A maintained spreadsheet with owners and end dates is legitimate
  • Privileged third-party access only? Vendor PAM is narrower and cheaper
  • TechBag will tell you which situation you are actually in

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Produce the list

How long would it take to list every external party with system access, with an owner and an end date for each? That answer sizes your problem.

2
Would a spreadsheet do?

Is the population small enough for one person to genuinely maintain? If so that is cheaper and legitimate — do not buy a platform for it.

3
The add-on structure

Do you understand this is an ADD-ON to Identity Security Cloud, not standalone? The business case must carry the platform if you do not already run it.

4
Ownership gaps

For your current contractors, can you name an accountable internal owner for each? A third typically have none anyone can identify.

5
Verification need

Do you need identity VERIFIED at onboarding, or is a vendor's assurance still acceptable to your regulator? The answer is shifting in BFSI.

6
Certification coverage

Do your current access reviews include non-employees, or silently exclude them? A review covering half the population is not one an auditor should accept.

7
DPDP obligations

Non-employee records hold personal data. Have you got the AWS Mumbai region and sub-processor list in the contract?

8
Privileged vs standard

Is your real concern PRIVILEGED third-party access? That is a narrower problem and vendor PAM may address it more directly.

FAQ

Questions buyers ask

It is an add-on to SailPoint Identity Security Cloud that gives contractors, vendors, partners, auditors and temporary staff the identity lifecycle employees already have: centralised visibility across the whole external population, a named internal owner accountable for each relationship, structured onboarding that collects the personal data needed to grant access to critical applications, time-bound access that expires by default rather than persisting until someone notices, inclusion in access certification campaigns alongside employees, and an audit evidence trail. Since September 2025 it integrates with Microsoft Entra Verified ID, adding faster onboarding with biometric verification. The problem it addresses is structural rather than technical. Employee identity governance works because HR is an authoritative source — someone joins, the system knows, access follows; someone leaves, deprovisioning fires. Non-employees have no equivalent: a contractor is onboarded by a project manager, a vendor engineer by whoever handled the support case, an auditor by someone being helpful. None of those events reach HR, so nothing drives expiry and access persists by default. That is why this population is where audit findings cluster, and why the finding is usually that you could not produce the list rather than that the access was wrong. TechBag scopes it as part of the platform decision, in INR with GST.

Ready to find out how big the gap is?

Ask your team for the list today — every external party with system access, an owner and an end date for each. If it arrives in an hour and everyone believes it, you may not need this yet. If it takes days and comes back incomplete, you have your business case. Or let a TechBag advisor size the population and scope it inside the platform decision.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.