Your HR system knows about employees. It does not know about the contractor onboarded last quarter or the vendor engineer with a standing login. NERM gives them a lifecycle, a named owner and an expiry that fires — and puts them in your access reviews alongside staff.
Data residency & processing
Non-employee records are personal data by definition — identity details, employer, contact information, and with Verified ID, biometric verification data, belonging to people who are not your employees. Under the DPDP Act that carries its own consent and purpose-limitation questions, so establish retention as well as region. SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024 — its ninth point of presence globally. SailPoint’s own words: an environment“completely isolated from other AWS Regions—no data will be replicated, backed up, or stored in any other AWS Region.” That is the strongest documented India data-storage position of any IGA vendor we carry. It is a statement about STORAGE. SailPoint does not separately document where data is processed, and we are not going to infer it — if processing location is part of your obligation rather than storage, ask SailPoint directly and get the answer in writing.
On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Non-Employee Risk Management — the external population. The rest of the portfolio:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A lifecycle, a named owner and an expiry that fires for contractors, vendors and partners — plus Entra Verified ID biometric onboarding since Sept 2025. An add-on to Identity Security Cloud.
What consolidation actually replaces, dimension by dimension.
| Dimension | Contractors in a spreadsheet | Non-Employee Risk Management (SailPoint) |
|---|---|---|
| Authoritative source | None — HR does not know them | The platform, with a named owner |
| Who onboarded them | A manager, by email | A defined process, with a record |
| Identity verification | The vendor vouched for them | Entra Verified ID, biometric |
| Access end date | None — persists until noticed | Expires unless the owner renews |
| In the access review | Excluded — the review draws from HR | Reviewed alongside staff |
| Producing the list | Eleven days and four spreadsheets | On request |
| When the engagement ends | The account continues | Offboarding fires |
| Commercial structure | (varies) | ⚠️ An add-on to the platform |
A lifecycle, a named internal owner and an expiry that fires for the population HR never sees — plus Entra Verified ID biometric onboarding since September 2025. Honest: this is an ADD-ON to Identity Security Cloud, not a standalone product, so if contractors are your entire requirement the platform is a heavy answer. For a genuinely small population, a maintained spreadsheet is legitimate and far cheaper.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Employee identity works because HR is an authoritative source: someone joins, the system knows, access follows. Non-employees have no equivalent. A contractor is onboarded by a project manager, a vendor engineer by whoever raised the ticket, an auditor by someone being helpful. There is no record to drive deprovisioning from, so access persists by default rather than expiring by design.
Every non-employee identity gets an internal owner — a named person answerable for whether that access should still exist. This is the single most effective control in the product, because the failure mode is not malice but absence: nobody was responsible, so nobody revoked it. Attribution is what makes review possible.
Non-employee access is granted with a defined end, and the end actually arrives rather than requiring somebody to remember. Renewal is a deliberate act by the owner. This inverts the default from 'persists until revoked' to 'ends unless renewed', which is the correct posture for a population that turns over quickly.
Collecting the personal data needed to admit a non-employee to critical applications, with Microsoft Entra Verified ID integration added in September 2025 for faster onboarding and biometric verification. Useful precisely where you are granting system access to people you have never met and whose employer is not you.
Non-employees appear in access certification campaigns alongside staff, so the review covers the whole population rather than the convenient half. An access review that silently excludes contractors is not a review an auditor should accept, and increasingly they do not.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
NERM gives contractors, vendors and partners the lifecycle employees already have — an owner, an end date, and a place in the access review — an add-on to portfolio, and paired with the human firewall.
One view of every contractor, vendor, partner and temporary identity across the organisation — the list most enterprises genuinely cannot produce on request. The first deliverable, and often the uncomfortable one. The list nobody had.
Every non-employee is attributed to an accountable person inside your organisation. The failure mode here is absence rather than malice — nobody owned it, so nobody revoked it. Attribution is what makes everything else work. Somebody answerable, by name.
Understanding which external relationships carry which access, and therefore which vendor relationships represent concentrated risk. Increasingly a question from clients' own security teams rather than only from auditors. Risk by relationship, not just by account.
Collecting the personal data required to grant access to critical applications, through a defined process rather than an email to IT. Turns an ad-hoc favour into a record. A process, not a favour.
Integration added September 2025 for faster onboarding with biometric verification. Directly useful where you are admitting people you have never met, employed by somebody else, to systems that matter. Know who you are letting in.
Access granted with an end date that fires, with renewal a deliberate act by the owner. Inverts the default from persists-until-revoked to ends-unless-renewed — the correct posture for a fast-turnover population. The end date that actually arrives.
Onboard, change, extend, offboard — the same discipline employees get, applied to a population that usually has none. The gap this closes is the one where an engagement ended and the access did not. Offboarding that happens.
Non-employees appear in certification campaigns alongside staff. A review that silently excludes contractors is not one an auditor should accept, and increasingly they do not. The whole population, reviewed.
The internal owner periodically confirms the relationship still exists and the access is still needed. Cheap to run and disproportionately effective, because most stale non-employee access fails at exactly this question. Ask the sponsor, periodically.
A record of who was admitted, by whom, for what, and when it ended — for the population where that record is usually absent entirely. What you produce when asked.
An add-on to the SailPoint platform rather than a standalone product — which means it assumes you are buying or already running Identity Security Cloud. Worth knowing before you scope it as a point solution. Add-on, not standalone.
Runs in SailPoint's AWS Asia Pacific (Mumbai) region, live since November 2024, described as isolated from other AWS regions. That is a statement about storage — and non-employee records contain personal data under the DPDP Act, so it is worth having in the contract. Personal data, so ask properly.
The add-on, demonstrated by SailPoint.
The product, introduced by SailPoint.
Profile management through the API.
The platform this add-on sits inside.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and when a spreadsheet is still the right answer.
Ask most enterprises for a list of every contractor, vendor engineer and partner with access to their systems, and the answer arrives slowly, in spreadsheets, from several different people, and is incomplete. That is not incompetence — it is structural, and it is worth understanding why before deciding whether this product is worth its cost. Why employee identity works: HR is an authoritative source. Someone joins, the system records it, access follows; someone leaves, the system records that too, and deprovisioning fires. The whole discipline rests on there being one system that knows. Why non-employee identity does not: a contractor is onboarded by a project manager who needs them productive on Monday. A vendor engineer gets a login because a support case required it. An auditor is given temporary access by somebody being helpful. None of these events touch HR, so there is no authoritative record, and therefore nothing to drive expiry. Access persists by default because no process exists to end it. What that produces: accounts belonging to people whose engagement ended, whose employer changed, or who were never verified in the first place — held by external parties, often with meaningful access, and invisible to the review process because the review draws from HR. This is the population where audit findings cluster, and it is why the finding is usually 'you could not produce the list' rather than 'the access was wrong'. Why it lands harder in India: the contractor and vendor population in a typical Indian enterprise is large relative to headcount, turnover is fast, and onboarding is frequently manager-led. The structural gap is the same everywhere; the volume passing through it is greater here. The value: a lifecycle, an owner and an expiry for the identities your HR system will never know about. TechBag scopes it against the size of your actual non-employee population.
The capability list for this product is long, but two controls carry most of the value, and it is worth knowing which so you can judge whether a cheaper approach might do. The first is ownership. Every non-employee identity is attributed to a named internal person who is accountable for whether it should still exist. This matters because the failure mode in non-employee access is almost never malice — it is absence. Nobody owned the relationship, so when it ended nobody acted, and the account simply continued. Attribution converts an orphan into somebody's responsibility, and that alone changes behaviour. The second is expiry. Access is granted with an end date that actually fires, and renewal requires the owner to do something deliberate. This inverts the default: instead of access persisting until someone notices it should not, it ends unless someone confirms it should continue. For a population with fast turnover and no HR event to trigger offboarding, that inversion is the whole game. Why the combination matters more than either alone: an expiry with no owner produces an access outage nobody expected and a scramble to restore it. An owner with no expiry produces a person who is theoretically accountable and never prompted. Together they produce a periodic, cheap decision by somebody who knows the answer. The honest test before you buy: if your non-employee population is small enough that a well-maintained spreadsheet and a quarterly calendar reminder would genuinely work, that is a legitimate answer and far cheaper. This product earns its place when the population is large enough, and distributed across enough managers, that no single person can hold it in their head. The value: two controls that address the actual failure mode, rather than a feature list. TechBag will tell you if a spreadsheet is still enough.
The September 2025 addition of Microsoft Entra Verified ID integration addresses something that sits underneath the whole non-employee problem: you frequently do not know that the person is who they claim to be. The situation: a vendor tells you their engineer needs access. That engineer is employed by the vendor, not by you. You have no HR record, no background check, and often no in-person contact — the relationship is mediated entirely through the vendor. Yet you are granting a login to systems that matter, and if something goes wrong the access was yours to control. What the integration adds: faster onboarding with biometric verification, so identity is established at the front door rather than assumed from a vendor's assurance. In practice this shortens the admission process while making it stronger, which is unusual — most identity controls trade one for the other. Where it matters most: regulated environments where you must evidence not just that access was appropriate but that the person holding it was verified. Financial services and healthcare buyers increasingly face exactly this question about third parties, and 'the vendor vouched for them' is a weakening answer. The honest note: this is one integration rather than a complete third-party assurance programme. It verifies identity; it does not tell you the person is competent, or that the vendor's own controls are sound, or that the engagement is still live. Those remain your questions to ask. The value: identity established at admission rather than assumed, for a population you cannot background-check yourself. TechBag helps scope where verification is genuinely required versus where it is process overhead.
We would rather state the commercial structure plainly than let you scope this as a point solution and discover otherwise during the quote. What it is: Non-Employee Risk Management is an add-on to SailPoint Identity Security Cloud, not a standalone product. Buying it means buying or already running the platform. What that implies for cost: the platform is enterprise-priced and quote-only, and implementation across the category typically runs two to three times licence cost — connectors, role modelling, certification design. Adding NERM to an existing SailPoint programme is an incremental decision with modest incremental cost. Buying the platform because of NERM is a very different proposition, and the business case has to carry the whole programme. When it makes sense: you already run Identity Security Cloud, or you are buying it anyway for broader governance reasons, and you have a non-employee population large enough that spreadsheets have stopped working. In that case NERM closes the gap your certification campaigns currently leave open, and it is straightforwardly worth having. When it does not: your entire identity problem is contractors, you have no wider governance requirement, and you are being shown a platform to solve it. That is a heavy answer to a narrow question. There are lighter approaches — a disciplined process with owners and expiry dates, or a smaller point product — and we would rather point you at one than sell a programme that disappoints. Where the balance usually falls: for Indian enterprises above a certain size, the non-employee population is large enough AND a wider governance requirement usually exists, so both conditions are met. But we check rather than assume. The value: a genuine gap-closer within a platform decision. TechBag scopes it as part of that decision rather than as a standalone sale.
Non-Employee Risk Management gives contractors, vendors, partners and temporary staff what employees already have: centralised visibility, a named internal owner, structured onboarding with optional Entra Verified ID biometric verification, time-bound access that expires by default, a full lifecycle, inclusion in access certification campaigns, and an audit evidence trail. Where it genuinely wins: it addresses a structural gap rather than a feature gap. Employee identity governance works because HR is authoritative; non-employee identity has no equivalent source, so access persists by default. Ownership and expiry invert that, and they do most of the work. For Indian enterprises with large, fast-turning contractor populations onboarded by managers rather than HR, this is frequently the first place an auditor looks and the first place they find something. Where something else fits better, plainly: if your non-employee population is small enough that a maintained spreadsheet and a quarterly reminder genuinely work, that is cheaper and legitimate. If your entire identity requirement is contractors with no wider governance driver, buying the SailPoint platform to get this add-on is a heavy answer — look at lighter options first. And if your driver is privileged third-party access specifically, a vendor PAM product may address it more directly. The limits to weigh: this is an add-on, not standalone, so it assumes the platform; the platform is enterprise-priced with implementation typically two to three times licence; the Entra Verified ID integration verifies identity but does not assure the vendor's own controls; and non-employee records contain personal data under the DPDP Act, so the AWS Mumbai region — documented for storage — belongs in your contract. So the honest positioning: a real gap-closer for organisations already committed to identity governance with a substantial external population. TechBag scopes it within the platform decision, in INR with GST.
Before evaluating anything, ask your team for a complete list of every contractor, vendor engineer and partner with system access, including who owns each relationship and when it should end. How long that takes, and how confident anyone is in the answer, tells you the size of your problem more honestly than any vendor assessment.
If the population is small enough that one person can hold it, and owners and expiry dates would genuinely be maintained, that is the cheaper answer and we will say so. This product earns its place when the population is large and distributed across enough managers that no single person can keep it current.
NERM is an add-on to Identity Security Cloud, not a standalone purchase. If you already run the platform, this is an incremental decision. If you do not, the business case has to carry the whole programme — implementation typically runs two to three times licence — so build it on your wider governance requirement rather than on contractors alone.
The periodic confirmation by an internal owner is cheap to run and does most of the work. Get the Mumbai region into the contract too — non-employee records contain personal data under the DPDP Act. TechBag reviews the population size annually and invoices in INR with GST.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our auditor asked for a list of every external party with system access. It took eleven days and four spreadsheets, and it was still wrong. That finding is what funded this project.”
“Expiry dates that actually fire changed the behaviour more than anything else. Renewals became a decision somebody made rather than an account nobody looked at.”
“Naming an internal owner for every contractor was the uncomfortable part of the rollout and the most valuable. A third of them had no owner anyone could identify.”
“Honest: we bought the platform partly for this, and the business case had to carry the whole programme. TechBag was clear that NERM alone would not justify it, which is why the case we built held up.”
“Verified ID onboarding matters when the engineer works for your vendor and you have never met them. 'The vendor vouched for them' had stopped being an acceptable answer for our regulator.”
“Our contractor population turned over faster than our employees. The HR-driven governance we already had simply did not see them, so half our access reviews were reviewing half the people.”
“Worth knowing it is an add-on rather than a standalone product. We initially scoped it as a point solution and the quote was a surprise until that was explained.”
“Non-employee records hold personal data, so we got the Mumbai region into the contract rather than relying on the website. Our DPO insisted and was right to.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the non-employee identity market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Non-employee governance inside the platform. This page's product.
The grid nobody publishes — how completely non-employees are governed vs how fast they can start.
Deep, but an add-on to an enterprise platform.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Saviynt External, vendor PAM, a maintained spreadsheet and doing nothing — honest lanes. If your external population is genuinely small and somebody maintains the list, a spreadsheet is a legitimate answer and we will say so.
| Dimension | SailPoint NERM | Saviynt External | Idira (was CyberArk) | A spreadsheet | Vendor PAM | Do nothing |
|---|---|---|---|---|---|---|
| Position | Non-employee governance add-on | External Identity Management module | Vendor PAM, privileged focus | What most organisations do now | Privileged third-party access only | Access persists by default |
| Named internal owner | Yes — core to the model | Yes | Partial | If someone maintains it | For privileged sessions | No |
| Expiry that fires | Yes — ends unless renewed | Yes | Session-scoped | A calendar reminder at best | Session-based by design | No |
| Identity verification | Entra Verified ID, biometric (Sept 2025) | Present | Present | The vendor vouched for them | Varies | None |
| In access certification | Yes — alongside employees | Yes | Within the platform | Usually excluded | Not a certification tool | No |
| Standalone purchase | ⚠️ No — an add-on to the platform | Within the Saviynt platform | Vendor PAM is buyable alone | Free | Yes | Free |
| Best fit | Already on SailPoint, large external population | Already on Saviynt | PRIVILEGED third-party access specifically | A genuinely small population one person can hold | Session-level control of vendor engineers | Nothing — this is the position auditors find |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Non-Employee Risk Management is one of 16 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (non-employee count; IT hourly cost as a loaded rate). Estimates contrast tracking external identities by spreadsheet and memory — producing the list on demand, chasing owners, discovering stale access — against a lifecycle with owners and automatic expiry. NB: if your population is small enough for one person to maintain reliably, the spreadsheet genuinely works and this model overstates the gain. And this is an ADD-ON: the platform cost is not modelled here. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
QUOTE-ONLY, and — the structural point — NERM is an ADD-ON to SailPoint Identity Security Cloud rather than a standalone product. If you already run the platform, this is an incremental decision with modest incremental cost. If you do not, the business case must carry the whole programme, where implementation typically runs 2–3× licence. Buying the platform to solve a contractor problem alone is a heavy answer to a narrow question, and we will tell you so. TechBag scopes it inside the platform decision and invoices in INR with GST.
Best alongside the platform you already run
Best for a broader rollout
Best if your population is small
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How long would it take to list every external party with system access, with an owner and an end date for each? That answer sizes your problem.
Is the population small enough for one person to genuinely maintain? If so that is cheaper and legitimate — do not buy a platform for it.
Do you understand this is an ADD-ON to Identity Security Cloud, not standalone? The business case must carry the platform if you do not already run it.
For your current contractors, can you name an accountable internal owner for each? A third typically have none anyone can identify.
Do you need identity VERIFIED at onboarding, or is a vendor's assurance still acceptable to your regulator? The answer is shifting in BFSI.
Do your current access reviews include non-employees, or silently exclude them? A review covering half the population is not one an auditor should accept.
Non-employee records hold personal data. Have you got the AWS Mumbai region and sub-processor list in the contract?
Is your real concern PRIVILEGED third-party access? That is a narrower problem and vendor PAM may address it more directly.
Ask your team for the list today — every external party with system access, an owner and an end date for each. If it arrives in an hour and everyone believes it, you may not need this yet. If it takes days and comes back incomplete, you have your business case. Or let a TechBag advisor size the population and scope it inside the platform decision.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.