The reported security incident involving SailPoint highlights a critical paradox in identity governance: the very platforms designed to manage and secure access must themselves be subject to rigorous identity governance.

Identity governance and administration (IGA) platforms occupy a privileged position in the security stack. They integrate with directory services, HR systems, and critical applications, often holding credentials that enable broad access across an organisation’s infrastructure. When an IGA vendor experiences a security incident, the potential blast radius extends to every customer relying on that platform.

From an IGA perspective, this raises the question of vendor governance: how should organisations govern the identity and access practices of their IGA vendor? Traditional vendor risk assessments focus on compliance certifications and security policies, but they may not adequately address the specific risks of identity platform compromise.

Organisations should consider several controls when evaluating IGA vendor security. First, understand the vendor’s own identity governance practices — do they apply the same rigor to their own environment that they prescribe for customers? Second, evaluate the vendor’s incident response capabilities, including notification timelines and forensic support. Third, assess the architectural safeguards that limit the impact of a vendor-side compromise on customer environments.

The broader lesson for the IGA market is that trust in identity platforms must be earned continuously, not assumed. As IGA platforms become more central to enterprise security architecture, the governance of the vendors themselves becomes a critical control point.

For security leaders, the takeaway is to extend identity governance thinking beyond internal access management to include vendor governance. The identity platforms you trust to govern access must themselves be governed.