The KuppingerCole Leadership Compass on Access Governance & Intelligence maps a maturing, crowded market where organizations increasingly want stand-alone access governance, often because identity provisioning already exists or is delivered as a managed service while governance remains in-house for tighter control. Access governance is positioned as an IAM risk-management discipline that enables business involvement in managing entitlements, certifications, reporting, and segregation-of-duties (SoD) controls, while access intelligence adds analytics and machine learning to support role design, automated reviews, anomaly detection, and process optimization. Core questions are who has access, who used it and why, and who granted it.
A complete access governance approach is defined as role management (including role mining and simulations), continuous attestation/recertification, auditing and analysis, access request management with workflows and reconciliation, SoD enforcement, and increasingly the inclusion of privileged users through tight integration with privilege management. The document also highlights the rise of entitlement and access governance (EAG) and data access governance for platforms like SAP and Windows file servers, plus the importance of integrating with GRC tools for compliance visibility even though GRC tools alone are insufficient.
The evaluation focuses on predominantly on-premises or MSP-hosted products (excluding vendor-operated IDaaS). Vendor selection is emphasized as requiring requirements analysis and proof of concept beyond the Compass. In overall leadership, SailPoint leads, followed closely by IBM, CA Technologies, and Oracle, with a strong second cluster including EmpowerID, Hitachi-ID, Micro Focus, Omada, One Identity, RSA, SAP, and Saviynt. The report provides correlated views across product, innovation, and market leadership to identify “market champions,” overperformers, and highly capable but regionally constrained vendors.
See All Locations
See All Locations