The access review nobody has time to do is the control every auditor asks for first.

Identity governance answers a question authentication never asks: not “is this really you”, but “should you still have this at all” — who granted it, who reviewed it, who approved the exception, and where is the evidence.

The RBI Master Direction on Information Technology Governance (7 November 2023, in force 1 April 2024) requires need-based access; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require periodic access reviews. Both describe a process, not a product — which is why so many estates own the tool and fail the audit.

Already decided — before the demo

Whether the gap is certification or leaverstwo different products, one shopping trip
How clean your HR data isthe real determinant of the timeline
Which application holds the riskconnectors are the ceiling

Still yours to weigh

Effortweeks · months · quarters
Reviewer contextor rubber-stamping at scale
Machine identitiesthe population nobody certifies
If you’ve never bought one

What identity governance actually is

Three processes with software wrapped around them. Provisioning creates and removes access when someone joins, moves or leaves — ideally from an HR event, not a ticket. Access requests let people ask for more, with an approval path and a record. Certification asks the people who should know, on a schedule, whether each person should still have what they have — and keeps the evidence that they were asked and what they answered.

IGA is not IAM done better. Identity and access management decides whether you get in; governance decides whether you should have been able to in the first place, and proves the decision. It needs different people (business managers, not administrators), different data (HR records and entitlement meaning, not just directory groups), and far more time than buyers expect. The sign-in half is the IAM, SSO & MFA guide; the most dangerous accounts are the PAM guide.

The most common mis-purchase

A full governance platform bought when the actual gap was joiner-mover-leaver in HR. If leavers keep access for weeks because nobody tells IT, you need provisioning driven by an HR event — a months-shorter, far cheaper project than a certification programme.

Often confused withPAM — the accounts that can change or destroy everything·IAM, SSO & MFA — who gets in, before whether they should·Endpoint Protection — identity threat detection beside the governance programme

The three routes of identity and access — and which one is yours

Boundary — the terms this buyer confuses

IGA vs IAM · access review vs provisioning vs certification

One pair buyers merge and three words used as synonyms in the same meeting. These are adjacent scopes, not tiers — and IGA is emphatically not IAM done better.

IGA vs IAM

IAM decides whether you get in: directory, single sign-on, factors, conditional access — an infrastructure purchase, run by administrators, live in weeks. IGA decides whether you should have been able to, and proves it: requests, approvals, reviews, evidence — a process purchase, run with business managers, live in months or quarters. Different question, different people, different timeline.

Provisioning

Creating, changing and removing access when someone joins, moves or leaves — ideally triggered by an HR event rather than a ticket. Answers: does the leaver still have access on Friday? The most common real gap, and available without a full governance programme.

Access review

The recurring look at who has what, usually by manager or application owner. Answers: is this still appropriate? Without usage data and peer context it becomes rubber-stamping at scale — the failure mode the auditor cannot see in the report.

Certification

The formal, evidenced version of the access review: a campaign with scope, deadlines, reviewers, decisions, revocations and an audit trail that survives scrutiny. Answers: can you prove the review happened and that what it decided was actually done? Reviews are the activity; certification is the evidence.

These are adjacent scopes, not tiers. Provisioning moves access, reviews look at it, certification proves the looking happened, and IGA is the platform around all three. IGA is not a better IAM — a product that federates a thousand applications flawlessly can tell an auditor nothing about whether the access behind them was ever justified.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests what documentation establishes (capabilities, depth, connector reach, deployment, effort class, India origin); reviewer context, connector development and HR data quality are prose because they are project realities no datasheet states.

01

Implementation effort

Weeks for report-and-attest on a directory you run, months for campaigns over a connected catalogue, quarters for a modelled programme with role design and SoD. The single most underestimated variable in this category — and it depends more on your HR data than on the product.

02

Joiner-mover-leaver automation depth

Provisioning triggered by an HR event, across which systems, with what removal guarantee. Often the whole of what the buyer actually needed.

03

Access certification workflow

A full campaign engine with scope, deadlines, revocation and evidence — or reports the business attests to. Both satisfy some auditors; only one survives a serious one.

04

Role mining versus role design

Whether roles can be derived from what people actually hold, or must be designed by committee first. Role design projects are where IGA programmes quietly stop.

05

Application connector coverage

Governance is only as good as what it can reach. Broad catalogue, own ecosystem, or directory-only — and the application holding your real risk is the one to name in the demo.

06

Segregation-of-duties rules

Detecting and preventing toxic combinations — the person who both creates and approves a payment. Documented, not established, or absent, per product; material for BFSI.

07

Reporting for RBI, SEBI CSCRF and audit

Whether the evidence comes out in the shape the auditor asks for, or is assembled by a person each quarter.

The narrowing instrument · the reasoning is the product

Narrow 10 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where vendor documentation does not establish a capability it is flagged and stays. Every chip is reversible.

What it can reach

How long you have

India

What it must do

How it must run

Governance depth

Estate size

Reviewer context, connector development and HR data quality are in the notes below rather than chips — they decide whether the programme succeeds, and no datasheet answers them.

Still in10/ 10
Okta logo
~$9–11₹747

per user / month reported as an add-on to Workforce Identity, or inside the Essentials bundle (~$17 per user / month list); certification campaigns, access requests and reporting on Okta's application catalogue

Okta estates that want access reviews and requests governed by the same platform, catalogue and lifecycle they already run — the shortest path from SSO to a defensible certification campaign.

The catch: Governance of what Okta already connects to: applications outside the catalogue need work, and the price sits on top of a per-user identity bill that is already per-capability. Not a fit if Okta is not your identity provider.

Fastest if you run OktaAdd-on pricingCatalogue-bound
Intel page →
Okta logo
In the ~$17 bundle₹1,411

per user / month inside the Essentials bundle list; provisioning and de-provisioning driven by HR or directory events across the connected application catalogue

Estates whose real gap is joiner-mover-leaver — accounts created on day one and removed on the last day — rather than certification campaigns.

The catch: Provisioning, not governance: no certification campaigns, no segregation-of-duties rules, no attestation evidence for an auditor. Frequently the product people actually needed when they went shopping for IGA.

JML automationNo certificationOften the real gap
Intel page →
CyberArk logo

per identity / year on quote within the CyberArk Identity Security Platform; certification, access requests and provisioning that reach privileged accounts as well as standard ones

Regulated estates already running CyberArk that want privileged accounts inside the same certification campaign as everyone else — the gap most IGA products leave open.

The catch: Enterprise-priced and enterprise-paced: implementation is a quarters-long programme, and the strongest case for it assumes you already run CyberArk PAM. An India data region is not documented.

Governs privileged tooQuarters to implementQuote
Intel page →
One Identity logo
Quote

per identity on quote, perpetual or subscription; the deep enterprise IGA platform — role modelling, attestation, SoD, SAP and mainframe connectors, on-premises or SaaS

Large and complex estates — often with SAP, mainframe or heavily regulated processes — that need governance modelled to their own business rules rather than a template.

The catch: The deepest platform here and the longest project: role design and connector work are measured in quarters and frequently need a partner. Overkill for an estate whose gap is joiner-mover-leaver.

Deep enterprise IGASAP + mainframeLongest implementation
Intel page →
One Identity logo
Quote

per managed account on quote; delegated administration, automated provisioning and policy enforcement for Active Directory and Entra ID specifically

Active Directory estates that need delegated administration and automated AD account lifecycle without a full IGA programme.

The catch: Directory-scoped: it governs Active Directory and Entra ID deeply and other applications barely. Certification is basic compared with the full IGA platforms.

AD / Entra-scopedDelegated adminNot full IGA
Intel page →
Securden logo

priced on the number of users, all-inclusive, in line with Securden's other products; access requests, approvals, periodic reviews and reporting, self-hosted or SaaS

Mid-market and Indian estates that want certification campaigns and access requests without an enterprise IGA programme or an enterprise IGA price.

The catch: Segregation-of-duties rule support could not be established from vendor documentation — marked unknown rather than assumed, and material if you are BFSI. Role mining is manual, and documented deployments are mid-market.

All-inclusive pricingIndia-builtSoD: unverified
Intel page →
ARCON logo
Quote (INR)

per identity, quoted in INR; identity lifecycle, access requests and periodic reviews from the Mumbai-built vendor, with reporting shaped for Indian regulatory audits and on-premises as a first-class option

Indian BFSI estates that want governance and the privileged vault from one India-built vendor, with the auditor's report format and the support engineer in the same country.

The catch: Narrower connector reach than the global IGA platforms and role mining is manual; documented governance deployments are smaller than ARCON's PAM footprint — flagged, not ruled out.

India-built (Mumbai)INR + on-premNarrower connectors
Intel page →
ARCON logo

per device or per asset, quoted in INR; continuous configuration and compliance assessment against regulatory baselines, with audit-ready reporting

Indian regulated estates that need continuous evidence of control posture against a baseline, alongside the identity governance programme.

The catch: Compliance assessment, not identity governance: no joiner-mover-leaver automation and no user access certification. It produces evidence about systems, not about who has access to them.

Compliance postureNot user certificationINR
Intel page →
ManageEngine logo
From ~$595₹49,385

per module / year list (ADManager Plus for provisioning and reviews, ADAudit Plus for the audit trail) — per module, not per user; India-built (Zoho), on-premises first

Active Directory estates that need provisioning, periodic access reports and an audit trail quickly, at a price that does not scale with headcount.

The catch: Active Directory-centric governance: certification is report-and-attest rather than a full campaign engine, connector reach beyond the Microsoft world is narrow, and segregation-of-duties support is not established from documentation.

Weeks, not quartersPer moduleAD-centric
Intel page →
Rubrik logo

per identity / year on quote; backup, comparison and object-level restore for Entra ID, Active Directory and Okta — including full forest recovery

Estates whose governance question is the recovery one: a compromised administrator deleted the groups, roles and conditional-access policies, and someone has to put the directory back.

The catch: Not identity governance: no certification, no access requests, no joiner-mover-leaver. It restores the directory after an incident — the adjacent problem, and one no IGA platform solves.

Directory recoveryNot certificationAdjacent purchase
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

Broad connector catalogueRules out CyberArk Identity Governance and Administration, Securden Identity Governance and Administration, ARCON Converged Identity and ARCON Security Compliance Management — governs its own ecosystem well; a broad third-party catalogue is not documented; One Identity Active Roles, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience — narrow connector reach, directory-centric. That leaves Okta Identity Governance, Okta Lifecycle Management and One Identity Manager.

Live in weeksRules out Okta Identity Governance, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity and ARCON Security Compliance Management — a months-long implementation, realistically; CyberArk Identity Governance and Administration and One Identity Manager — a quarters-long programme, realistically. That leaves Okta Lifecycle Management, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience.

Months is acceptableRules out CyberArk Identity Governance and Administration and One Identity Manager — a quarters-long programme, realistically. That leaves Okta Identity Governance, Okta Lifecycle Management, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience.

India-built, INRRules out Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles and Rubrik Identity Resilience — a global vendor; INR quoting is via the channel, not the vendor's own price list. That leaves Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules).

Certification campaignsRules out Okta Lifecycle Management and Rubrik Identity Resilience — no access certification capability; One Identity Active Roles, ARCON Security Compliance Management and ManageEngine AD360 (governance modules) — reports and attestation rather than a full campaign engine. That leaves Okta Identity Governance, CyberArk Identity Governance and Administration, One Identity Manager, Securden Identity Governance and Administration and ARCON Converged Identity.

Joiner-mover-leaverRules out ARCON Security Compliance Management and Rubrik Identity Resilience — no joiner-mover-leaver automation. That leaves Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity and ManageEngine AD360 (governance modules).

Access requestsRules out Rubrik Identity Resilience — neither request workflow nor certification; it solves an adjacent problem. That leaves Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules).

Self-hostedRules out Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration and Rubrik Identity Resilience — SaaS only. That leaves One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules).

Segregation of dutiesRules out Okta Lifecycle Management and Rubrik Identity Resilience — no segregation-of-duties capability. That leaves Okta Identity Governance, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules). It flags Securden Identity Governance and Administration — Segregation-of-duties support not established from vendor documentation and ManageEngine AD360 (governance modules) — Segregation-of-duties support not established from vendor documentation — marked on the cards, not removed.

Role miningRules nothing out on published terms. It flags Okta Identity Governance — Role mining capability not established, Okta Lifecycle Management — Roles must be designed rather than derived, CyberArk Identity Governance and Administration — Role mining capability not established, One Identity Manager — Role mining capability not established, One Identity Active Roles — Roles must be designed rather than derived, Securden Identity Governance and Administration — Roles must be designed rather than derived, ARCON Converged Identity — Roles must be designed rather than derived, ARCON Security Compliance Management — Roles must be designed rather than derived, ManageEngine AD360 (governance modules) — Roles must be designed rather than derived and Rubrik Identity Resilience — Role mining capability not established — marked on the cards, not removed.

Above 10,000 identitiesRules nothing out on published terms. It flags Securden Identity Governance and Administration — Unverified above 10,000 identities, ARCON Converged Identity — Unverified above 10,000 identities and ARCON Security Compliance Management — Unverified above 10,000 identities — marked on the cards, not removed.

Implementation effort is the variable, and it is always underestimatedWeeks for report-and-attest on a directory you already run (ManageEngine AD360, Okta Lifecycle Management). Months for certification campaigns over a connected catalogue (Okta IGA, Securden, ARCON Converged Identity, Active Roles). Quarters for a modelled enterprise programme with role design, SoD rules and SAP or mainframe connectors (One Identity Manager, CyberArk IGA). The effort class in the instrument is this judgement, made from documented capability and deployment shape — your own timeline depends on how clean your HR data is, which is the real variable. TechBag's delivery figures per platform are [TechBag to confirm].

Certification is only as good as the context reviewers getA campaign that shows a manager a list of entitlement names produces rubber-stamping, at scale, on a deadline. The platforms that reduce this show usage data, peer comparison and risk scoring next to each decision. Ask to see the reviewer's screen in the demo — not the administrator's dashboard — and ask what a reviewer sees when they do not recognise an entitlement.

Connectors are the ceilingGovernance reaches exactly as far as its connectors. A broad catalogue (Okta, One Identity Manager) covers mainstream SaaS; ecosystem-scoped products govern their own stack well and others through custom work; directory-centric products (Active Roles, AD360) go deep on Active Directory and Entra ID and shallow elsewhere. The application holding your real risk — the core banking system, the ERP, the internally built one — is the connector to ask about by name, and custom connector development is not in any licence.

The machine identities nobody certifiesCertification campaigns review employees. Service accounts, API consumers, pipeline credentials and AI agent tokens are rarely in scope at all — no manager owns them, no HR event ends them, and they outnumber human identities in most estates. Every product here governs people; the credentials themselves belong in the vault, which is a different purchase. If your auditor has not asked yet, they will.

Under 500 identitiesRules nothing out on published terms: ManageEngine AD360, Okta Lifecycle Management and Securden are sold to small estates, and Microsoft's Entra ID Governance add-on (roughly $4–7 per user per month on top of P1 or P2) may already cover it. One Identity Manager and CyberArk IGA publish no floor but are enterprise-paced. Where a small estate should stop at joiner-mover-leaver and skip certification entirely is delivery judgement: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the timeline named

Each shortlist states what could realistically be live this quarter versus next year. If an auditor is driving this, start from the first row.

The auditor asked for evidence of periodic access reviews — and there is none

Why: Okta IGA runs campaigns over the catalogue you already federate; Securden gives the same on an all-inclusive per-user number; AD360 produces reports and attestation on Active Directory in weeks rather than quarters.

The trade-off: The fast options certify what they can reach — usually the directory and the federated applications. The system holding your real risk may need a connector nobody has built yet.

The actual gap is joiner-mover-leaver, not certification

Why: Accounts created on day one from an HR event and removed on the last day is a provisioning problem, and all three solve it without a governance programme.

The trade-off: None of these gives you certification evidence. Buying full IGA when the gap was leaver automation is the most expensive mistake in this subcategory — and the most common.

Indian BFSI — RBI and SEBI CSCRF reporting, on-premises, in INR

Why: ARCON is Mumbai-built with on-premises as a first-class deployment and reporting shaped for Indian audits; Securden and ManageEngine are India-built with self-hosted options and INR pricing.

The trade-off: Securden's segregation-of-duties support is not documented and AD360's is not either — material for BFSI. Confirm SoD in writing before shortlisting on price.

SAP, mainframe or heavily modelled business rules

Why: One Identity Manager is the deepest platform here for modelled governance with SAP and mainframe connectors; CyberArk IGA reaches privileged accounts in the same campaigns.

The trade-off: Both are quarters-long programmes and usually need a partner. If your timeline is a quarter, one of these will not be live in it — plan the phase, not the platform.

Privileged accounts must be in the same certification campaign as everyone else

Why: The gap most IGA products leave open: standard entitlements are certified while the administrator accounts are governed elsewhere, or not at all. These three pair governance with a vault from the same vendor.

The trade-off: One vendor for both disciplines means one roadmap for two teams that usually work on different timelines. The alternative is two products and a reconciliation process you own.

Already on Okta and want governance without a second platform

Why: Okta IGA is the shortest path from federated SSO to a defensible campaign — same catalogue, same lifecycle, same console; Lifecycle Management alone if provisioning is the real need.

The trade-off: It governs what Okta connects to. Applications outside the catalogue are work, and the per-user add-on lands on top of an identity bill that is already priced per capability.

A compromised admin deleted groups, roles and policies — restore the directory

Why: Rubrik Identity Resilience backs up, compares and restores Entra ID, Active Directory and Okta objects, including full forest recovery — the adjacent problem no IGA platform solves.

The trade-off: This is recovery, not governance: no certification, no requests, no lifecycle. It belongs beside an IGA purchase, never instead of one.

Mid-market, one identity owner, needs something defensible this quarter

Why: Securden's all-inclusive pricing, AD360's per-module list (from about $595 per component per year, which does not scale with headcount) and Okta IGA if you already run Okta are the three realistic quarter-long routes.

The trade-off: Securden and ARCON are flagged unverified above 10,000 identities. Ask for a reference at your size, and be honest about whether you need campaigns or just clean leaver automation.

The spine of the decision

Three effort classes, and the population nobody certifies

Governance products are compared on features and decided by timeline. Place each on what it realistically takes to be live, then ask what it can reach.

Effort 1

Weeks — report and attest

Governance over a directory you already run: provisioning from HR or directory events, periodic access reports, an audit trail. Not a campaign engine, and enough for many auditors.

Effort 2

Months — campaigns over a catalogue

Certification campaigns, access requests and approvals across the applications your identity provider already connects to. The realistic middle, and where most estates should aim.

Effort 3

Quarters — a modelled programme

Role design, segregation-of-duties rules, SAP and mainframe connectors, privileged accounts inside the same campaign. Deep, defensible, and usually needing a partner.

The gap

Machine identities

Service accounts, API consumers, pipeline credentials and agent tokens: no manager owns them, no HR event ends them, and they outnumber your people. Every product here certifies humans; the credentials belong in a vault.

The reviewer test

Ask these before the administrator demo, in this order.

  • Show me the reviewer’s screen, not the dashboard. If a manager sees a list of entitlement names with no usage or peer context, you have bought rubber-stamping with an audit trail.
  • What happens when a reviewer says “remove”? Automatic revocation through the connector, or a ticket someone may action next month? The gap between decision and removal is what a serious auditor tests.
  • Name the application that holds our real risk — is there a connector? Custom connector development is in no licence and on every project plan.
  • How clean is our HR data? Ask internally, first. It decides your timeline more than the product does.

The India layer

What the regulators actually say — and who reports in that shape.

  • The sources, named: the RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (issued 7 November 2023, effective 1 April 2024) requires need-based access and multi-factor authentication for privileged users; SEBI’s CSCRF (August 2024) sets access-management requirements including least privilege for regulated entities; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require privileged access management and periodic access reviews. Each describes a control, not a product.
  • India-built and quoting in INR: ARCON Converged Identity (Mumbai, on-premises first, audit-shaped reporting), Securden (all-inclusive per user), ManageEngine AD360 (Zoho, per module).
  • The honest caveat: Securden’s and AD360’s segregation-of-duties support is not established from vendor documentation — flagged, never ruled out, and worth confirming in writing if you are BFSI.
What breaks as you grow

What changes at 500, 5,000 and 25,000 identities

Governance scales by entitlements and reviewers, not by identities alone. The bill follows the per-identity list; the programme follows how many people must make decisions.

500identities

The gap definition is the constraint

  • Most estates this size need joiner-mover-leaver, not certification — be honest about which, because it is a months-shorter project.
  • Microsoft's Entra ID Governance add-on (roughly $4–7 per user per month on top of P1 or P2) may already cover it; check the invoice first.
  • ManageEngine's per-module list does not scale with headcount, which makes it unusually cheap here.

Put this in your PoC

Run one manual access review in a spreadsheet. What made it painful is the requirement; anything else is a feature you will not use.

5,000identities

Reviewer fatigue and connectors are the constraint

  • Campaigns now involve hundreds of reviewers on a deadline — context and risk scoring decide whether the result means anything.
  • The connector list stops being a checkbox: the ERP, the core system and the internally built application are where the risk and the custom work both live.
  • Role design becomes tempting and dangerous — mine roles from real entitlements before designing any.

Put this in your PoC

Ask a vendor for a campaign completion rate from a reference at your size, and what percentage of decisions were 'approve all'.

25,000identities

Modelling and evidence are the constraint

  • Segregation-of-duties rules, delegated administration and business-role modelling become the programme; a partner is usually involved.
  • Privileged accounts must join the same campaign or the auditor finds the seam; machine identities are the population still outside it.
  • Securden, ARCON Converged Identity and ARCON SCM are flagged unverified at this size — not ruled out; ask for the reference.

Put this in your PoC

Count identities without a human owner. If nobody can name an owner for a service account, no certification campaign will ever cover it.

Okta, CyberArk, One Identity and ManageEngine document large estates; Securden, ARCON Converged Identity and ARCON Security Compliance Management are flagged unverified above 10,000 identities. Where a specific platform strains at your identity count: [TechBag to confirm].

The switching cost

Leaving a governance platform means rebuilding the process, not moving data

The value is in connectors, roles, rules and campaign history — none of which is portable. Switching restarts the programme with the audit clock still running.

Connectors and mappings

Every application connection, attribute mapping and provisioning rule is rebuilt on the new platform, including the custom ones nobody documented.

Exit costRebuild, application by application

Roles and rules

Business roles and segregation-of-duties rules were modelled for the old platform's engine. Re-modelling is the original design project, again.

Exit costRe-model

Campaign history

Past certifications are your evidence that reviews happened. Export what the regulator's retention period requires before the contract ends — it rarely migrates.

Exit costExport the evidence

The gap in coverage

Certification cycles run to a calendar the auditor knows. Time the switch so no cycle is missed; a skipped campaign is a finding regardless of the reason.

Exit costNo missed cycle

Connector rebuild, role re-modelling and evidence export for your estate: [TechBag to confirm] — TechBag scopes it from your connector inventory and audit retention rules.

What it costs

Per identity per month — and then the implementation

What you may already hold, the products priced per identity at three estate sizes in USD and INR, and what the licence line leaves out — which, for governance, is nearly always larger than the licence.

01

Do you already own one?

Four places governance may already sit. Two are real, and one of them is on most Microsoft invoices.

Microsoft Entra ID Governance
Often Access reviews, entitlement management and lifecycle workflows as an add-on at roughly $4–7 per user per month on top of P1 or P2. Real governance for the Microsoft estate; thin for third-party applications.
Microsoft Entra ID P2
Partly Includes Privileged Identity Management — eligible rather than permanent roles with approval and expiry — at about $9–10 per user per month. That is privileged lifecycle, not access certification for the business.
Your identity provider's lifecycle module
Partly Okta Lifecycle Management and similar provision and de-provision from HR events. Real joiner-mover-leaver; no certification, no evidence.
Your HR system
No It knows who joined and left, and it is the trigger every governance programme needs. It grants and removes nothing on its own — the integration is the project.

If the reviews your auditor wants can come from a licence you already hold, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Reported and published meters (INR for scale), worked at 500 / 5,000 / 25,000 identities per year. The implementation is the larger number and it is stated apart, below — a governance licence bought without an implementation budget is a shelf product.

500identities · per year
  • Okta Identity Governance(reported ~$9–11 / user / mo add-on)$54,00066,000 ₹44,82,000₹54,78,000
  • Okta Lifecycle Management(in the ~$17 Essentials bundle list)$1,02,000 ₹84,66,000
  • ManageEngine AD360(from ~$595 / module / yr — per module, not per user)$5951,785 ₹49,385₹1,48,155
  • CyberArk IGA(per identity)Quote
  • One Identity Manager(per identity)Quote
  • One Identity Active Roles(per managed account)Quote
  • Securden IGA(all-inclusive, per user)Quote
  • ARCON Converged Identity(INR, per identity)Quote
  • ARCON Security Compliance Management(INR, per asset)Quote
  • Rubrik Identity Resilience(per identity)Quote
5,000identities · per year
  • Okta Identity Governance(reported ~$9–11 / user / mo add-on)$5,40,0006,60,000 ₹4,48,20,000₹5,47,80,000
  • Okta Lifecycle Management(in the ~$17 Essentials bundle list)$10,20,000 ₹8,46,60,000
  • ManageEngine AD360(from ~$595 / module / yr — per module, not per user)$5951,785 ₹49,385₹1,48,155
  • CyberArk IGA(per identity)Quote
  • One Identity Manager(per identity)Quote
  • One Identity Active Roles(per managed account)Quote
  • Securden IGA(all-inclusive, per user)Quote
  • ARCON Converged Identity(INR, per identity)Quote
  • ARCON Security Compliance Management(INR, per asset)Quote
  • Rubrik Identity Resilience(per identity)Quote
25,000identities · per year
  • Okta Identity Governance(reported ~$9–11 / user / mo add-on)$27,00,00033,00,000 ₹22,41,00,000₹27,39,00,000
  • Okta Lifecycle Management(in the ~$17 Essentials bundle list)$51,00,000 ₹42,33,00,000
  • ManageEngine AD360(from ~$595 / module / yr — per module, not per user)$5951,785 ₹49,385₹1,48,155
  • CyberArk IGA(per identity)Quote
  • One Identity Manager(per identity)Quote
  • One Identity Active Roles(per managed account)Quote
  • Securden IGA(all-inclusive, per user)Quote
  • ARCON Converged Identity(INR, per identity)Quote
  • ARCON Security Compliance Management(INR, per asset)Quote
  • Rubrik Identity Resilience(per identity)Quote

The implementation — stated apart from the licence, because it is usually larger

Weeks-class. Report-and-attest on a directory you already run: internal effort, a few weeks of one person, no partner. ManageEngine AD360 and Okta Lifecycle Management sit here — and for many auditors this is enough.
Months-class. Campaigns over a connected catalogue: connector configuration, campaign design, reviewer training and one full cycle before you trust the output. Budget a named owner for two quarters.
Quarters-class. Modelled programmes with role design, SoD rules and SAP or mainframe connectors: a partner engagement whose services line commonly rivals or exceeds the licence. Ask for the services quote at the same time as the licence quote, or you have not seen the price.
Tier-match: lifecycle is not governance. Okta Lifecycle Management provisions; Okta Identity Governance certifies. One Identity Active Roles is directory-scoped; Identity Manager is the platform. Price the SKU that produces the evidence you were asked for.
Term-match: per identity per month, annual, or per module. Most lines here are per identity billed annually; ManageEngine is per module and does not scale with headcount, which inverts the comparison at 25,000. Normalise before comparing.
The India line. ARCON quotes in INR from Mumbai; Securden and ManageEngine are India-built with INR pricing; the global platforms land in INR with GST through a partner. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The implementation

Connector configuration, role design, campaign setup, reviewer training and one full cycle before the output can be trusted — weeks, months or quarters by class, and at the deep end the services line commonly rivals the licence. Your figure: [TechBag to confirm].

Connector development

The application holding your real risk is frequently the one with no connector. Custom development, testing and maintenance of that integration are in no licence and on every project plan.

The internal time to run campaigns

Every cycle costs hundreds of reviewer-hours across the business, plus a coordinator chasing completion. It recurs quarterly or half-yearly, forever — and it is the cost that decides whether the programme survives year two.

Before you commit

What goes wrong

Documented behaviour and programme outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the second campaign.

Role design projects that never finish

A committee spent three quarters designing business roles for a moving organisation. Mine roles from what people actually hold, ship something, then refine.

Certification campaigns rubber-stamped because reviewers have no context

Managers approved lists of entitlement names they did not recognise, on a deadline. The audit trail is perfect and the control is fictional — ask to see the reviewer's screen.

Connectors missing for the applications that hold the risk

The catalogue covered mainstream SaaS; the core banking system and the ERP were manual spreadsheets. Governance reaches exactly as far as its connectors.

Leaver automation that removes access but leaves the account

The account was disabled in the directory and remained live in three applications and one VPN. Removal must be verified per system, not assumed from the directory.

Buying IGA when the actual gap was joiner-mover-leaver in HR

A months-long governance programme for a problem that needed HR to trigger provisioning. Name the gap precisely before shopping.

Evidence that does not survive the auditor's second question

The report showed the review happened; nobody could show that the revocations were actually executed. Decision and removal are two different records.

Machine identities left outside every campaign

Service accounts and pipeline credentials had no owner, no HR event and no reviewer. They outnumber the humans, and they are not in the campaign.

A programme that stops after the first cycle

The first campaign was resourced as a project and the second was nobody's job. Budget the recurring reviewer hours, or the control lapses quietly.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Identity & Access map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.