Platform Model
Breadth of native coverage
Single platform converging IAM + IGA + PAM + CIEM + ISPM + IVIP. One contract, one data layer, one vendor. No module fragmentation across product lines.
4-in-1 Native Platform
IGA-first platform. PAM and CIEM are not listed as native pillars on their website. Customers must procure separate products and integrate them independently.
PAM / CIEM Not Native
PAM Coverage
Privileged access management
Native PAM module: credential vaulting, session recording, just-in-time access, and privileged account discovery all governed within the same platform as IGA.
Native PAM
No native PAM listed on product pages. Privileged access management requires a separate third-party tool, creating a governance gap between IGA and PAM data.
Requires Separate PAM Tool
NHI and AI Agent Security
Non-human identity governance
Service accounts, bots, and AI agents governed under the same framework as human identities. Automated discovery and deprovisioning of orphaned credentials.
Native NHI Governance
Machine Identity Security is a listed pillar but it operates as a separate module with its own interface, not unified with IGA lifecycle policies.
Separate Module
Deployment Options
Flexibility of deployment
On-premise, private cloud, public cloud, and hybrid. Agentless-first architecture. Supports legacy system integration without requiring rip-and-replace.
Maximum Flexibility
Cloud-native SaaS platform. On-premise deployments require additional configuration and professional services. No public guidance on hybrid deployment complexity.
Cloud-First, PS Required for Hybrid
Time to Value
Speed to first outcome
5-5-5 Rapid Deployment Program: 5 apps connected in 5 weeks for $5K. A low-risk, fixed-price entry point that delivers immediate value.
5-5-5 Fast Start
No deployment timeline or time-to-value commitment published on their website. Implementations are typically 6-18 months with heavy professional services involvement.
No Published Timeline
Connector Count
Pre-built integrations
250+ pre-built connectors across cloud, SaaS, on-premise, legacy systems, and custom apps. Covers IAM, IGA, PAM, and CIEM targets. Connector SLAs are defined and published.
250+ Connectors
"Hundreds of connectors" no specific count published on their website. Connector quality, maintenance SLAs, and coverage scope are not disclosed publicly.
Count Not Published
Vendor Independence
Ecosystem neutrality
Purpose-built independent identity security company. Roadmap driven entirely by identity security outcomes. No parent platform dependencies or ecosystem lock-in.
Fully Independent
Independent identity company but historically reliant on large professional services partners for complex deployments, creating indirect vendor dependency.
PS Partner Dependency
IGA Capabilities
Governance depth
Full IGA module: AI-assisted User Access Reviews, role mining, Separation of Duties, access request workflows, and audit-ready compliance reporting. Continuous monitoring.
Full IGA Module
Core IGA strength access certifications, role management, and policy enforcement. Strong for large enterprises but requires significant PS investment to operationalize.
Strong IGA, High PS Cost
Compliance Frameworks
Regulatory coverage
Pre-built reports for SOX, HIPAA, PCI-DSS, GDPR, and SOC 2. Continuous monitoring ensures audit readiness at all times, not just at review cycles.
Pre-Built Compliance Reports
Compliance reporting available but report customization and audit-ready output often require professional services engagement and additional licensing.
PS Engagement Often Required
AI Capabilities
Intelligence layer
Generative + Agentic AI Assistant: AI-powered User Access Reviews, role mining, SoD analysis, anomaly detection, and natural language policy queries. AI is embedded across all modules.
Generative + Agentic AI
AI-powered app onboarding and adaptive identity claims primarily focused on provisioning automation. Broader AI capabilities not yet published across all governance workflows.
Provisioning AI Only