Top Tools / August 7, 2026
StartupStash

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages, public pricing, and recent product changes. A second editor reviews the piece before it goes live. We also run a directory of startup tools. A paid listing does not buy a place on a shortlist.

Best Enterprise IGA Platforms in 2026

Identity governance starts with knowing who has access to what, then controlling how access changes when someone joins, changes role, or leaves. Mature IGA also checks segregation-of-duties conflicts and runs access certifications. AI agents add a new identity type, but they do not replace those core governance jobs. Skip a step and the agent add-on is a demo, not the product.

Start with the access lifecycle you already need to control. If transfers leave old roles behind, fix joiner-mover-leaver workflows first. If auditors cannot prove who approved access, prioritize certifications and policy controls. Add agent governance only after those foundations work. A runtime kill switch is not a certification campaign. A sovereign tenant is not a hybrid connector pack. Non-human identities now outnumber people in most estates, and Gartner’s February 2026 cybersecurity trends note named IAM adaptation to AI agents as one of six defining shifts. Access is still a grant you can revoke at 2am. If the product cannot show that, the campaign is theater.

If the audit is the emergency, start with SailPoint Identity Security Cloud. If agents are already calling APIs you cannot see, start with Saviynt and ask for Zuma Access in the POC. If residency is a hard gate, Omada. If the core systems still run on-prem, One Identity Manager 10.0. The method is on How we review tools.

What usually goes wrong when buying IGA

Most quotes in this category fail for the same few reasons. The fix is operational, not a new acronym.

Problem Solution
Joiner-mover-leaver cannot move a contractor the same day Confirm JML can create, change, and kill the role in one workflow
An SoD collision across SAP and Salesforce never fires Ask to see a segregation-of-duties example that crosses those systems
On-prem is a slide, not generally available Write whether the runtime is already generally available
The list price is IGA-adjacent, not the IGA seat Use the public IGA rate when one exists. Otherwise treat it as quote-only

How we evaluated IGA platforms

We compared the platforms on whether a transfer kills the old role the same day, whether an SoD rule fires before approval across SAP and Salesforce, whether an orphan agent can be revoked at 2am, and whether any price is public. Connector-count slides did not move a ranking. Identity-provider add-ons and on-prem siblings sit in What we left out because they sit next door, not on those questions.

TL;DR: The Four Compared

Service Best for What to check
SailPoint Audit-scale SaaS IGA, then agents on the same certification calendar
DeploymentIdentity Security Cloud is SaaS only. IdentityIQ is the on-prem line
Agent productAgentic Fabric generally available 4 Aug 2026. Existing customers upgrade to Agentic Business or Agentic Business Plus
PriceQuote-only. Suites page allots five non-human identities per human on Agentic Business - confirm the ratio on the quote
Saviynt Cloud-app IGA when runtime control of agents is a day-one requirement
DeploymentEnterprise Identity Cloud. Privileged access on the same fabric
Agent productZuma Access is intent-aware runtime authorization, launched 28 Jul 2026
PriceQuote-only. AWS Marketplace lists Identity Cloud and related modules from $100,000 per 12-month contract
Omada Opinionated certifications plus a sovereign tenant if residency requires it
DeploymentFeature parity between on-prem Omada Identity and Identity Cloud. Identity Sovereign for buyers who cannot use multi-tenant SaaS
Agent productAgent Governance is preview. Product page targets technical preview in Q4 2026 and production in H1 2027
PriceQuote-only. Microsoft Marketplace lists the SaaS offer without public rates
One Identity Hybrid or on-prem estates that are not ready for SaaS-only IGA
DeploymentOn-prem Identity Manager, or On Demand Starling Edition as hosted
Agent productAgents modeled as non-human identities. Runtime MCP enforcement is still being built
PriceQuote-only. Subscription and, in some deals, perpetual. On Demand is a transactable, quote-based offer on Microsoft Marketplace

SailPoint

SailPoint

SailPoint Identity Security Cloud is the large-enterprise IGA SaaS: lifecycle, access requests, usage-informed certifications, and embedded SoD. The company returned to public markets on 13 Feb 2025 (Nasdaq: SAIL). IdentityIQ remains the on-prem line. Identity Security Cloud is SaaS only.

On 4 Aug 2026 SailPoint Agentic Fabric reached general availability, standalone or inside the Identity Security suite (Agentic Business / Agentic Business Plus). Lightweight sensors find hidden AI agents, credentials, and MCP servers. Governance treats those agents as identities with a human owner. Protection includes inline prompt security and a kill switch. The Entro Security close on 29 Jun 2026 adds secrets and non-human-identity scanning. Entro still ships as a standalone while native integration continues.

Best for: Complex enterprises with heavy audit exposure, SAP or multi-SaaS estates, and a need to put agents on the same certification calendar as people.

What you get:

  • Event-driven provisioning and deprovisioning across a wide connector set.
  • Usage-informed certification campaigns with AI reviewer recommendations.
  • SoD modeling with pre-approval conflict checks on ERP and SaaS.
  • Agentic Fabric generally available (4 Aug 2026), plus Entro for secrets and machine identities.

Why we like it: Auditors already know this product. The 2026 work closes the machine-identity gap reviewers used to write into every RFP as a risk.

Limits:

  • Implementation is a program. Custom rules usually mean a services partner.
  • Entro is not fully native yet. Ask for the integration timeline.
  • SaaS only on Identity Security Cloud. Customer-controlled infrastructure is IdentityIQ or another vendor.

Price: Quote-only, by identity count and package. No list rate. The suites page allots five non-human identities per human identity on Agentic Business. It still says that 5:1 ratio was subject to change prior to general availability, and that it shall not fall below 5:1 upon GA. Agentic Fabric went GA on 4 Aug. Confirm the ratio on the quote. Public-sector buyers can check FedRAMP authorization on the marketplace.

Saviynt

Saviynt

Saviynt is cloud-and-application IGA with privileged access on the same fabric. On 28 Jul 2026 it said it had passed $300 million ARR, with bookings up more than 80% and 96% retention, and launched Zuma, an AI identity security platform. Zuma Insights discovers agents, LLMs, AI apps, and other non-human identities. Zuma Access is intent-aware runtime authorization on the action the agent is trying to take. Zuma Governance is ownership, lifecycle, reviews, and a kill switch for orphaned agents. Saviynt cites millions of service accounts and more than 5,000 agent API calls per second as the runtime layer’s scale.

Identity Security for AI shipped 24 Mar 2026. The Agent Access Gateway, expanded in June with intent-aware authorization, is the control that sits in the path. Named references have included Hertz and The Auto Club Group. Zuma is available now with a trial on the launch page.

Best for: Organizations that need cloud-app IGA and want runtime agent control as a first-class product in 2026.

What you get:

  • Automated joiner-mover-leaver and risk-based access reviews tuned for cloud applications.
  • Zuma Insights / Access / Governance for AI agents and non-human identities (28 Jul 2026).
  • Agent Access Gateway for runtime, intent-aware authorization.
  • Converged IGA plus privileged access on one identity data fabric.

Why we like it: If the RFP question is “what can this agent do right now,” this is the product writing that sentence in the product, not only in the deck.

Limits:

  • Support speed and roadmap predictability show up in peer reviews.
  • Total cost at scale is a watch item. Rushed deployments accumulate technical debt.
  • Zuma is new. Ask for production references on the specific agent features you will buy.

Price: Quote-only, typically private offers. AWS Marketplace lists Identity Cloud, Application Access Governance, External Identity & Risk Management, Privilege Access Management, Just-in-Time Access, and Identity Security Posture Management from $100,000 per 12-month contract. The listing also says each dimension is priced per user. That is still a contract line, not a self-serve seat.

Omada

Omada

Omada Identity Cloud is configurable SaaS IGA with a strong role and certification core. Founded in 2000. KuppingerCole named it an Overall Leader in the 2026 IGA Leadership Compass (27 May 2026), also a leader in Product, Innovation, and Market. The company sells full feature parity between on-prem Omada Identity and Identity Cloud, plus Identity Sovereign for buyers who cannot use multi-tenant SaaS.

Omada Agent Governance (announced 15 Jun 2026) assigns a business sponsor and a technical owner to each agent, maps what the agent can reach against what it has used, and scores risk to NIST AI RMF, the EU AI Act, ISO 42001, OWASP, and MITRE ATLAS. It is built to run beside an existing IGA, including someone else’s, and publish governed agents back as a source. It can also run alone. Omada’s own product page targets a technical preview in Q4 2026 and production in H1 2027. Those are plans. Do not buy Agent Governance as if it were generally available today.

Best for: Mid-to-large regulated enterprises that want low-code certifications and role mining, with a sovereign tenant if the data-residency rule requires it.

What you get:

  • Provisioning and certification workflows without custom code for the core path.
  • Role management, role mining, and access insights.
  • Audit-oriented reporting beyond dashboards.
  • Agent Governance in preview, and Identity Sovereign for residency-bound buyers.

Why we like it: Reviewers keep citing cleaner certifications and less auditor back-and-forth. The sovereign option is a real differentiator when multi-tenant SaaS is the blocker, not a preference.

Limits:

  • Agent Governance is not in production yet. H1 2027 is the current target.
  • Reporting UX and heavy customization constraints show up in comparisons.
  • Some on-prem connectors need extra work. Professional services quality varies by partner.

Price: Quote-only, typically by identity count and tier. Microsoft Marketplace lists the SaaS offer without public rates.

One Identity

One Identity

One Identity Manager is the hybrid and on-prem IGA of record on this list. The On Demand Starling Edition is the same governance scope as a hosted service. Version 10.0 shipped 16 Jan 2026: risk-based governance, identity threat detection and response, a browser admin UI that does not need the desktop console, and AI-assisted reporting through a customer-controlled LLM so auditors can ask questions in English instead of SQL. Automated remediation (disable an account, launch a targeted attestation) sits on the On Demand path.

AI agents are modeled as non-human identities inside the existing data model (owner, lifecycle, attestation). Runtime MCP enforcement is something One Identity says it is building. Saviynt’s runtime layer is already generally available. That gap is the decision, not a footnote.

Best for: Enterprises with a heavy on-prem or hybrid footprint, deep RBAC, or a regulator that is not ready for SaaS-only IGA.

What you get:

  • Lifecycle automation across legacy and modern targets.
  • Granular RBAC and SoD suited to deep org hierarchies.
  • Enterprise-scale attestation spanning cloud and on-prem in one campaign.
  • Natural-language query and automated remediation on On Demand / 10.0.

Why we like it: You can keep IGA next to the systems that will not move this year, then take On Demand when the rest of the estate is ready. That timeline is a buying reason.

Limits:

  • Implementation and learning curve are the consistent review themes.
  • Agent-specific runtime controls are thinner than the cloud IGA names here. Demo the non-human-identity path you care about.
  • Heavy customization makes upgrades expensive. Budget for that on top of licenses.

Price: Quote-only. Subscription and, in some deals, perpetual. The On Demand edition is on Microsoft Marketplace as a transactable, quote-based offer, with no public list rate.

Can it stay on-prem, and is agent runtime already GA?

This grid plots two questions. Across is where IGA can run: a hybrid or sovereign option on the left, multi-tenant SaaS only on the right. Up is the 2026 agent product: runtime authorization that is generally available at the top, certifications and preview modules at the bottom.

Runtime GAHybrid / sovereignNone on this list
Runtime GASaaS onlyZuma Access in the path
Certs / previewHybrid / sovereignStay next to the estate
Certs / previewSaaS onlyAudit IGA, agents as identities

Placement is from product language: Identity Security Cloud is SaaS; Identity Sovereign and Identity Manager stay next to the estate; Zuma Access is generally available runtime; Agentic Fabric is GA governance, not a runtime MCP gate; Agent Governance is preview. This is a map of the products, not a ranking.

Pricing and usage costs compared

Service Agent product today What the quote still hides
SailPoint Agentic Fabric GA (4 Aug 2026). Agents as identities with a human owner Existing Identity Security Cloud customers upgrade to Agentic Business or Plus. Confirm the 5:1 non-human allotment and whether unused allotment rolls
Saviynt Zuma Access is runtime authorization in the path AWS Marketplace lists modules from $100,000 / 12 months and prices each dimension per user. Ask which modules you are actually buying
Omada Agent Governance is preview. Production target H1 2027 The module can run beside someone else’s IGA. That is not the same as a kill switch you can operate this quarter
One Identity Agents modeled as non-human identities in 10.0 Runtime MCP enforcement is still being built. Demo the revoke path, not the object model

What we left out

They sit next door because they lack a standalone IGA you can bake off, a transfer-and-SoD path you can demo, or an agent revoke that is more than a slide.

  • Microsoft Entra ID Governance - the right mention when the estate already lives in Entra. It is not a standalone IGA bake-off for SAP plus Salesforce plus a 2am orphan-agent revoke.
  • Okta Identity Governance - an IGA add-on on an identity provider you already bought. Different hole than a certification-and-SoD platform.
  • SailPoint IdentityIQ - the on-prem sibling. This shortlist is the cloud IGA buy except where hybrid is the requirement, and that seat is One Identity Manager.

Questions before you sign an IGA contract

Get these three in writing. A quote that cannot is still buying a slide.

  1. Does a transfer kill the old role the same day? Move a contractor. If joiner-mover-leaver misses the SAP account, the proof failed.
  2. Does SoD fire before approval, across systems? Propose a grant that should collide with Salesforce. A quarterly report is too late.
  3. Can you revoke an orphan agent at 2am? Show an AI agent with no human owner. If that grant cannot die tonight, the agent add-on is not the product yet.

Which IGA platform should you pick

Audit is the emergency: SailPoint, and confirm the Agentic Business upgrade plus the 5:1 non-human allotment. Agents already calling APIs you cannot see: Saviynt, and ask for Zuma Access in the POC. Residency or a sovereign tenant is the gate: Omada, and treat Agent Governance as preview. Core systems still on-prem: One Identity Manager 10.0. Then run the transfer, the SoD fail, and the orphan agent before anyone talks connector counts.

Frequently asked questions

Is an agent governance add-on a substitute for certifications and SoD?

No. Joiner-mover-leaver, segregation of duties, and a campaign an auditor will defend are still the product. Agent features sit on top of that path. A preview module with an H1 2027 production target does not replace a transfer that has to work this quarter.

Do any of these four publish a list rate?

No. All four are quote-only. Saviynt’s AWS Marketplace listing shows Identity Cloud and related modules from $100,000 per 12-month contract, with each dimension also described as priced per user. SailPoint’s suites page discusses a 5:1 non-human allotment, not a dollar seat. Omada and One Identity appear on Microsoft Marketplace without public rates.

Can we keep Identity Security Cloud and add Agentic Fabric later?

Existing Identity Security Cloud customers need an upgrade to Agentic Business or Agentic Business Plus. Confirm the 5:1 non-human allotment on the quote, and whether unused allotment rolls at renewal. Agentic Fabric went generally available on 4 August 2026, so treat the suites-page 5:1 language as something to confirm on the order, not a pre-GA caveat.



List your product on Startup Stash

A listing is not a paid rank on this page.
Get listed

About the author

How we review tools

Written by

StartupStash

StartupStash

Editorial team

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages and public prices before it goes live.

Reviewed by

Manaal

Manaal

Content Manager, Startup Stash

Manaal is Content Manager at Startup Stash. She reviews the shortlist, the priced claims, and the sourcing before a Top Tools piece goes live.

Best Enterprise IGA Platforms in...
StartupStash

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages, public pricing, and recent product changes. A second editor reviews the piece before it goes live. We also run a directory of startup tools. A paid listing does not buy a place on a shortlist.