Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
Identity governance answers a question authentication never asks: not “is this really you”, but “should you still have this at all” — who granted it, who reviewed it, who approved the exception, and where is the evidence.
The RBI Master Direction on Information Technology Governance (7 November 2023, in force 1 April 2024) requires need-based access; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require periodic access reviews. Both describe a process, not a product — which is why so many estates own the tool and fail the audit.
Already decided — before the demo
Still yours to weigh
Three processes with software wrapped around them. Provisioning creates and removes access when someone joins, moves or leaves — ideally from an HR event, not a ticket. Access requests let people ask for more, with an approval path and a record. Certification asks the people who should know, on a schedule, whether each person should still have what they have — and keeps the evidence that they were asked and what they answered.
IGA is not IAM done better. Identity and access management decides whether you get in; governance decides whether you should have been able to in the first place, and proves the decision. It needs different people (business managers, not administrators), different data (HR records and entitlement meaning, not just directory groups), and far more time than buyers expect. The sign-in half is the IAM, SSO & MFA guide; the most dangerous accounts are the PAM guide.
The most common mis-purchase
A full governance platform bought when the actual gap was joiner-mover-leaver in HR. If leavers keep access for weeks because nobody tells IT, you need provisioning driven by an HR event — a months-shorter, far cheaper project than a certification programme.
Often confused withPAM — the accounts that can change or destroy everything →·IAM, SSO & MFA — who gets in, before whether they should →·Endpoint Protection — identity threat detection beside the governance programme →
The three routes of identity and access — and which one is yours →
One pair buyers merge and three words used as synonyms in the same meeting. These are adjacent scopes, not tiers — and IGA is emphatically not IAM done better.
IGA vs IAM
IAM decides whether you get in: directory, single sign-on, factors, conditional access — an infrastructure purchase, run by administrators, live in weeks. IGA decides whether you should have been able to, and proves it: requests, approvals, reviews, evidence — a process purchase, run with business managers, live in months or quarters. Different question, different people, different timeline.
Provisioning
Creating, changing and removing access when someone joins, moves or leaves — ideally triggered by an HR event rather than a ticket. Answers: does the leaver still have access on Friday? The most common real gap, and available without a full governance programme.
Access review
The recurring look at who has what, usually by manager or application owner. Answers: is this still appropriate? Without usage data and peer context it becomes rubber-stamping at scale — the failure mode the auditor cannot see in the report.
Certification
The formal, evidenced version of the access review: a campaign with scope, deadlines, reviewers, decisions, revocations and an audit trail that survives scrutiny. Answers: can you prove the review happened and that what it decided was actually done? Reviews are the activity; certification is the evidence.
Seven variables decide this purchase. The instrument tests what documentation establishes (capabilities, depth, connector reach, deployment, effort class, India origin); reviewer context, connector development and HR data quality are prose because they are project realities no datasheet states.
Implementation effort
Weeks for report-and-attest on a directory you run, months for campaigns over a connected catalogue, quarters for a modelled programme with role design and SoD. The single most underestimated variable in this category — and it depends more on your HR data than on the product.
Joiner-mover-leaver automation depth
Provisioning triggered by an HR event, across which systems, with what removal guarantee. Often the whole of what the buyer actually needed.
Access certification workflow
A full campaign engine with scope, deadlines, revocation and evidence — or reports the business attests to. Both satisfy some auditors; only one survives a serious one.
Role mining versus role design
Whether roles can be derived from what people actually hold, or must be designed by committee first. Role design projects are where IGA programmes quietly stop.
Application connector coverage
Governance is only as good as what it can reach. Broad catalogue, own ecosystem, or directory-only — and the application holding your real risk is the one to name in the demo.
Segregation-of-duties rules
Detecting and preventing toxic combinations — the person who both creates and approves a payment. Documented, not established, or absent, per product; material for BFSI.
Reporting for RBI, SEBI CSCRF and audit
Whether the evidence comes out in the shape the auditor asks for, or is assembled by a person each quarter.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where vendor documentation does not establish a capability it is flagged and stays. Every chip is reversible.
What it can reach
How long you have
India
What it must do
How it must run
Governance depth
Estate size
Reviewer context, connector development and HR data quality are in the notes below rather than chips — they decide whether the programme succeeds, and no datasheet answers them.

per user / month reported as an add-on to Workforce Identity, or inside the Essentials bundle (~$17 per user / month list); certification campaigns, access requests and reporting on Okta's application catalogue
Okta estates that want access reviews and requests governed by the same platform, catalogue and lifecycle they already run — the shortest path from SSO to a defensible certification campaign.
The catch: Governance of what Okta already connects to: applications outside the catalogue need work, and the price sits on top of a per-user identity bill that is already per-capability. Not a fit if Okta is not your identity provider.

per user / month inside the Essentials bundle list; provisioning and de-provisioning driven by HR or directory events across the connected application catalogue
Estates whose real gap is joiner-mover-leaver — accounts created on day one and removed on the last day — rather than certification campaigns.
The catch: Provisioning, not governance: no certification campaigns, no segregation-of-duties rules, no attestation evidence for an auditor. Frequently the product people actually needed when they went shopping for IGA.

per identity / year on quote within the CyberArk Identity Security Platform; certification, access requests and provisioning that reach privileged accounts as well as standard ones
Regulated estates already running CyberArk that want privileged accounts inside the same certification campaign as everyone else — the gap most IGA products leave open.
The catch: Enterprise-priced and enterprise-paced: implementation is a quarters-long programme, and the strongest case for it assumes you already run CyberArk PAM. An India data region is not documented.

per identity on quote, perpetual or subscription; the deep enterprise IGA platform — role modelling, attestation, SoD, SAP and mainframe connectors, on-premises or SaaS
Large and complex estates — often with SAP, mainframe or heavily regulated processes — that need governance modelled to their own business rules rather than a template.
The catch: The deepest platform here and the longest project: role design and connector work are measured in quarters and frequently need a partner. Overkill for an estate whose gap is joiner-mover-leaver.

per managed account on quote; delegated administration, automated provisioning and policy enforcement for Active Directory and Entra ID specifically
Active Directory estates that need delegated administration and automated AD account lifecycle without a full IGA programme.
The catch: Directory-scoped: it governs Active Directory and Entra ID deeply and other applications barely. Certification is basic compared with the full IGA platforms.

priced on the number of users, all-inclusive, in line with Securden's other products; access requests, approvals, periodic reviews and reporting, self-hosted or SaaS
Mid-market and Indian estates that want certification campaigns and access requests without an enterprise IGA programme or an enterprise IGA price.
The catch: Segregation-of-duties rule support could not be established from vendor documentation — marked unknown rather than assumed, and material if you are BFSI. Role mining is manual, and documented deployments are mid-market.

per identity, quoted in INR; identity lifecycle, access requests and periodic reviews from the Mumbai-built vendor, with reporting shaped for Indian regulatory audits and on-premises as a first-class option
Indian BFSI estates that want governance and the privileged vault from one India-built vendor, with the auditor's report format and the support engineer in the same country.
The catch: Narrower connector reach than the global IGA platforms and role mining is manual; documented governance deployments are smaller than ARCON's PAM footprint — flagged, not ruled out.

per device or per asset, quoted in INR; continuous configuration and compliance assessment against regulatory baselines, with audit-ready reporting
Indian regulated estates that need continuous evidence of control posture against a baseline, alongside the identity governance programme.
The catch: Compliance assessment, not identity governance: no joiner-mover-leaver automation and no user access certification. It produces evidence about systems, not about who has access to them.

per module / year list (ADManager Plus for provisioning and reviews, ADAudit Plus for the audit trail) — per module, not per user; India-built (Zoho), on-premises first
Active Directory estates that need provisioning, periodic access reports and an audit trail quickly, at a price that does not scale with headcount.
The catch: Active Directory-centric governance: certification is report-and-attest rather than a full campaign engine, connector reach beyond the Microsoft world is narrow, and segregation-of-duties support is not established from documentation.

per identity / year on quote; backup, comparison and object-level restore for Entra ID, Active Directory and Okta — including full forest recovery
Estates whose governance question is the recovery one: a compromised administrator deleted the groups, roles and conditional-access policies, and someone has to put the directory back.
The catch: Not identity governance: no certification, no access requests, no joiner-mover-leaver. It restores the directory after an incident — the adjacent problem, and one no IGA platform solves.
Broad connector catalogueRules out CyberArk Identity Governance and Administration, Securden Identity Governance and Administration, ARCON Converged Identity and ARCON Security Compliance Management — governs its own ecosystem well; a broad third-party catalogue is not documented; One Identity Active Roles, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience — narrow connector reach, directory-centric. That leaves Okta Identity Governance, Okta Lifecycle Management and One Identity Manager.
Live in weeksRules out Okta Identity Governance, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity and ARCON Security Compliance Management — a months-long implementation, realistically; CyberArk Identity Governance and Administration and One Identity Manager — a quarters-long programme, realistically. That leaves Okta Lifecycle Management, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience.
Months is acceptableRules out CyberArk Identity Governance and Administration and One Identity Manager — a quarters-long programme, realistically. That leaves Okta Identity Governance, Okta Lifecycle Management, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management, ManageEngine AD360 (governance modules) and Rubrik Identity Resilience.
India-built, INRRules out Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles and Rubrik Identity Resilience — a global vendor; INR quoting is via the channel, not the vendor's own price list. That leaves Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules).
Certification campaignsRules out Okta Lifecycle Management and Rubrik Identity Resilience — no access certification capability; One Identity Active Roles, ARCON Security Compliance Management and ManageEngine AD360 (governance modules) — reports and attestation rather than a full campaign engine. That leaves Okta Identity Governance, CyberArk Identity Governance and Administration, One Identity Manager, Securden Identity Governance and Administration and ARCON Converged Identity.
Joiner-mover-leaverRules out ARCON Security Compliance Management and Rubrik Identity Resilience — no joiner-mover-leaver automation. That leaves Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity and ManageEngine AD360 (governance modules).
Access requestsRules out Rubrik Identity Resilience — neither request workflow nor certification; it solves an adjacent problem. That leaves Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules).
Self-hostedRules out Okta Identity Governance, Okta Lifecycle Management, CyberArk Identity Governance and Administration and Rubrik Identity Resilience — SaaS only. That leaves One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules).
Segregation of dutiesRules out Okta Lifecycle Management and Rubrik Identity Resilience — no segregation-of-duties capability. That leaves Okta Identity Governance, CyberArk Identity Governance and Administration, One Identity Manager, One Identity Active Roles, Securden Identity Governance and Administration, ARCON Converged Identity, ARCON Security Compliance Management and ManageEngine AD360 (governance modules). It flags Securden Identity Governance and Administration — Segregation-of-duties support not established from vendor documentation and ManageEngine AD360 (governance modules) — Segregation-of-duties support not established from vendor documentation — marked on the cards, not removed.
Role miningRules nothing out on published terms. It flags Okta Identity Governance — Role mining capability not established, Okta Lifecycle Management — Roles must be designed rather than derived, CyberArk Identity Governance and Administration — Role mining capability not established, One Identity Manager — Role mining capability not established, One Identity Active Roles — Roles must be designed rather than derived, Securden Identity Governance and Administration — Roles must be designed rather than derived, ARCON Converged Identity — Roles must be designed rather than derived, ARCON Security Compliance Management — Roles must be designed rather than derived, ManageEngine AD360 (governance modules) — Roles must be designed rather than derived and Rubrik Identity Resilience — Role mining capability not established — marked on the cards, not removed.
Above 10,000 identitiesRules nothing out on published terms. It flags Securden Identity Governance and Administration — Unverified above 10,000 identities, ARCON Converged Identity — Unverified above 10,000 identities and ARCON Security Compliance Management — Unverified above 10,000 identities — marked on the cards, not removed.
Implementation effort is the variable, and it is always underestimatedWeeks for report-and-attest on a directory you already run (ManageEngine AD360, Okta Lifecycle Management). Months for certification campaigns over a connected catalogue (Okta IGA, Securden, ARCON Converged Identity, Active Roles). Quarters for a modelled enterprise programme with role design, SoD rules and SAP or mainframe connectors (One Identity Manager, CyberArk IGA). The effort class in the instrument is this judgement, made from documented capability and deployment shape — your own timeline depends on how clean your HR data is, which is the real variable. TechBag's delivery figures per platform are [TechBag to confirm].
Certification is only as good as the context reviewers getA campaign that shows a manager a list of entitlement names produces rubber-stamping, at scale, on a deadline. The platforms that reduce this show usage data, peer comparison and risk scoring next to each decision. Ask to see the reviewer's screen in the demo — not the administrator's dashboard — and ask what a reviewer sees when they do not recognise an entitlement.
Connectors are the ceilingGovernance reaches exactly as far as its connectors. A broad catalogue (Okta, One Identity Manager) covers mainstream SaaS; ecosystem-scoped products govern their own stack well and others through custom work; directory-centric products (Active Roles, AD360) go deep on Active Directory and Entra ID and shallow elsewhere. The application holding your real risk — the core banking system, the ERP, the internally built one — is the connector to ask about by name, and custom connector development is not in any licence.
The machine identities nobody certifiesCertification campaigns review employees. Service accounts, API consumers, pipeline credentials and AI agent tokens are rarely in scope at all — no manager owns them, no HR event ends them, and they outnumber human identities in most estates. Every product here governs people; the credentials themselves belong in the vault, which is a different purchase. If your auditor has not asked yet, they will.
Under 500 identitiesRules nothing out on published terms: ManageEngine AD360, Okta Lifecycle Management and Securden are sold to small estates, and Microsoft's Entra ID Governance add-on (roughly $4–7 per user per month on top of P1 or P2) may already cover it. One Identity Manager and CyberArk IGA publish no floor but are enterprise-paced. Where a small estate should stop at joiner-mover-leaver and skip certification entirely is delivery judgement: [TechBag to confirm].
Each shortlist states what could realistically be live this quarter versus next year. If an auditor is driving this, start from the first row.
Why: Okta IGA runs campaigns over the catalogue you already federate; Securden gives the same on an all-inclusive per-user number; AD360 produces reports and attestation on Active Directory in weeks rather than quarters.
The trade-off: The fast options certify what they can reach — usually the directory and the federated applications. The system holding your real risk may need a connector nobody has built yet.
Why: Accounts created on day one from an HR event and removed on the last day is a provisioning problem, and all three solve it without a governance programme.
The trade-off: None of these gives you certification evidence. Buying full IGA when the gap was leaver automation is the most expensive mistake in this subcategory — and the most common.
Why: ARCON is Mumbai-built with on-premises as a first-class deployment and reporting shaped for Indian audits; Securden and ManageEngine are India-built with self-hosted options and INR pricing.
The trade-off: Securden's segregation-of-duties support is not documented and AD360's is not either — material for BFSI. Confirm SoD in writing before shortlisting on price.
Why: One Identity Manager is the deepest platform here for modelled governance with SAP and mainframe connectors; CyberArk IGA reaches privileged accounts in the same campaigns.
The trade-off: Both are quarters-long programmes and usually need a partner. If your timeline is a quarter, one of these will not be live in it — plan the phase, not the platform.
Why: The gap most IGA products leave open: standard entitlements are certified while the administrator accounts are governed elsewhere, or not at all. These three pair governance with a vault from the same vendor.
The trade-off: One vendor for both disciplines means one roadmap for two teams that usually work on different timelines. The alternative is two products and a reconciliation process you own.
Why: Okta IGA is the shortest path from federated SSO to a defensible campaign — same catalogue, same lifecycle, same console; Lifecycle Management alone if provisioning is the real need.
The trade-off: It governs what Okta connects to. Applications outside the catalogue are work, and the per-user add-on lands on top of an identity bill that is already priced per capability.
Why: Rubrik Identity Resilience backs up, compares and restores Entra ID, Active Directory and Okta objects, including full forest recovery — the adjacent problem no IGA platform solves.
The trade-off: This is recovery, not governance: no certification, no requests, no lifecycle. It belongs beside an IGA purchase, never instead of one.
Why: Securden's all-inclusive pricing, AD360's per-module list (from about $595 per component per year, which does not scale with headcount) and Okta IGA if you already run Okta are the three realistic quarter-long routes.
The trade-off: Securden and ARCON are flagged unverified above 10,000 identities. Ask for a reference at your size, and be honest about whether you need campaigns or just clean leaver automation.
Governance products are compared on features and decided by timeline. Place each on what it realistically takes to be live, then ask what it can reach.
Effort 1
Weeks — report and attest
Governance over a directory you already run: provisioning from HR or directory events, periodic access reports, an audit trail. Not a campaign engine, and enough for many auditors.
Effort 2
Months — campaigns over a catalogue
Certification campaigns, access requests and approvals across the applications your identity provider already connects to. The realistic middle, and where most estates should aim.
Effort 3
Quarters — a modelled programme
Role design, segregation-of-duties rules, SAP and mainframe connectors, privileged accounts inside the same campaign. Deep, defensible, and usually needing a partner.
The gap
Machine identities
Service accounts, API consumers, pipeline credentials and agent tokens: no manager owns them, no HR event ends them, and they outnumber your people. Every product here certifies humans; the credentials belong in a vault.
The reviewer test
Ask these before the administrator demo, in this order.
The India layer
What the regulators actually say — and who reports in that shape.
Governance scales by entitlements and reviewers, not by identities alone. The bill follows the per-identity list; the programme follows how many people must make decisions.
The gap definition is the constraint
Put this in your PoC
Run one manual access review in a spreadsheet. What made it painful is the requirement; anything else is a feature you will not use.
Reviewer fatigue and connectors are the constraint
Put this in your PoC
Ask a vendor for a campaign completion rate from a reference at your size, and what percentage of decisions were 'approve all'.
Modelling and evidence are the constraint
Put this in your PoC
Count identities without a human owner. If nobody can name an owner for a service account, no certification campaign will ever cover it.
Okta, CyberArk, One Identity and ManageEngine document large estates; Securden, ARCON Converged Identity and ARCON Security Compliance Management are flagged unverified above 10,000 identities. Where a specific platform strains at your identity count: [TechBag to confirm].
The value is in connectors, roles, rules and campaign history — none of which is portable. Switching restarts the programme with the audit clock still running.
Connectors and mappings
Every application connection, attribute mapping and provisioning rule is rebuilt on the new platform, including the custom ones nobody documented.
Roles and rules
Business roles and segregation-of-duties rules were modelled for the old platform's engine. Re-modelling is the original design project, again.
Campaign history
Past certifications are your evidence that reviews happened. Export what the regulator's retention period requires before the contract ends — it rarely migrates.
The gap in coverage
Certification cycles run to a calendar the auditor knows. Time the switch so no cycle is missed; a skipped campaign is a finding regardless of the reason.
Connector rebuild, role re-modelling and evidence export for your estate: [TechBag to confirm] — TechBag scopes it from your connector inventory and audit retention rules.
What you may already hold, the products priced per identity at three estate sizes in USD and INR, and what the licence line leaves out — which, for governance, is nearly always larger than the licence.
Four places governance may already sit. Two are real, and one of them is on most Microsoft invoices.
If the reviews your auditor wants can come from a licence you already hold, we say so. It costs us a sale and saves you one.
Reported and published meters (INR for scale), worked at 500 / 5,000 / 25,000 identities per year. The implementation is the larger number and it is stated apart, below — a governance licence bought without an implementation budget is a shelf product.
The implementation — stated apart from the licence, because it is usually larger
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Connector configuration, role design, campaign setup, reviewer training and one full cycle before the output can be trusted — weeks, months or quarters by class, and at the deep end the services line commonly rivals the licence. Your figure: [TechBag to confirm].
The application holding your real risk is frequently the one with no connector. Custom development, testing and maintenance of that integration are in no licence and on every project plan.
Every cycle costs hundreds of reviewer-hours across the business, plus a coordinator chasing completion. It recurs quarterly or half-yearly, forever — and it is the cost that decides whether the programme survives year two.
Documented behaviour and programme outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the second campaign.
Role design projects that never finish
A committee spent three quarters designing business roles for a moving organisation. Mine roles from what people actually hold, ship something, then refine.
Certification campaigns rubber-stamped because reviewers have no context
Managers approved lists of entitlement names they did not recognise, on a deadline. The audit trail is perfect and the control is fictional — ask to see the reviewer's screen.
Connectors missing for the applications that hold the risk
The catalogue covered mainstream SaaS; the core banking system and the ERP were manual spreadsheets. Governance reaches exactly as far as its connectors.
Leaver automation that removes access but leaves the account
The account was disabled in the directory and remained live in three applications and one VPN. Removal must be verified per system, not assumed from the directory.
Buying IGA when the actual gap was joiner-mover-leaver in HR
A months-long governance programme for a problem that needed HR to trigger provisioning. Name the gap precisely before shopping.
Evidence that does not survive the auditor's second question
The report showed the review happened; nobody could show that the revocations were actually executed. Decision and removal are two different records.
Machine identities left outside every campaign
Service accounts and pipeline credentials had no owner, no HR event and no reviewer. They outnumber the humans, and they are not in the campaign.
A programme that stops after the first cycle
The first campaign was resourced as a project and the second was nobody's job. Budget the recurring reviewer hours, or the control lapses quietly.
Vendor-neutral. No gated content.