Identity governance and administration is becoming a central security discipline as organisations add cloud services, automation and artificial intelligence. The question is no longer simply who has access, but whether access is justified, current, observable and accountable throughout the identity lifecycle.

That creates a practical problem for security teams. Identity data is distributed across directories, SaaS platforms, infrastructure and specialist tools, while access decisions still need to be made quickly. Manual reviews and disconnected provisioning create entitlement drift, orphaned accounts and audit friction.

Valuation signals and IGA expectations

Debate over SailPoint’s valuation is also a debate about how investors assess identity governance as a software category. Growth expectations reflect cloud, machine and AI-agent use cases, but buyers still demand operational value.

New capabilities may consolidate identity data, automate reviews and extend controls to non-human identities. Buyers should examine connector coverage, workflow maintainability, role-model quality and integration effort.

Procurement implications

Useful measures include provisioning time, revocation time, certification remediation, policy exceptions and unmanaged identities discovered. A platform investment is more defensible when it improves those measures across priority applications.