SailPoint has unveiled a new AI-powered security platform focused on procurement risk, extending identity governance and administration (IGA) into a domain that has traditionally operated outside the identity management perimeter. The platform addresses a growing recognition that procurement processes, from vendor onboarding to third-party access provisioning, represent one of the largest unmanaged identity risks in the enterprise.

The problem is substantial. Procurement teams routinely grant suppliers, contractors, and third-party vendors access to internal systems, applications, and data repositories. These access decisions are often made in isolation from the identity governance function, creating shadow identities that exist outside the formal IGA lifecycle. When a vendor relationship ends, the associated access is rarely revoked promptly, leaving dormant accounts that threat actors can exploit.

SailPoint’s procurement-focused platform brings several capabilities to bear on this challenge.

The platform integrates procurement workflows with identity governance administration, creating a bridge between the systems that manage vendor relationships and the systems that govern access. When a new vendor is onboarded through procurement, the platform automatically initiates an identity provisioning workflow that assigns appropriate access based on the vendor’s role, contract terms, and risk classification. This ensures that third-party identities are provisioned through the same governance processes as internal employees.

The platform also introduces continuous monitoring of vendor access. Rather than conducting annual access reviews, the system tracks vendor activity patterns and contract status in real time. If a contract expires or a vendor relationship is terminated, the platform can automatically trigger access revocation, closing the gap between the end of a business relationship and the removal of associated access rights.

For IGA practitioners, the procurement risk platform addresses a pain point that has long resisted traditional identity governance tools. Third-party identity lifecycle management is inherently more complex than internal identity governance because the identities are managed by external organisations, the access requirements change frequently, and the governance metadata is fragmented across procurement, legal, and IT systems.

The platform also leverages AI to assess procurement risk scores. By analysing vendor access patterns, data exposure levels, and external threat intelligence, the system assigns a risk score to each third-party identity. These scores feed into access policy decisions, enabling risk-based governance that tightens controls on high-risk vendors while reducing friction for low-risk relationships.

This development signals a broader trend in identity governance administration: the expansion of IGA beyond its traditional focus on internal employees and into the extended enterprise. As organisations increasingly rely on third-party vendors, cloud service providers, and AI agents, the perimeter of identity governance must expand to encompass every identity that touches enterprise resources, regardless of its origin.

For CISOs evaluating identity governance strategies, SailPoint’s procurement risk platform highlights the need to break down the silos between procurement, vendor management, and identity governance. Without this integration, third-party access will remain a blind spot in the identity security posture, regardless of how mature the internal IGA programme may be.