DRAFT — NOT FOR PUBLICATION — Requires founder approval before any distribution
Founding-partner program now open · start a scoped proof →
SidantiX Blog · Competitive landscape

The Week IGA Woke Up

By SidantiX Team · August 2026

TL;DR: Saviynt launched Zuma. SailPoint acquired Entro. Both moves are significant and both confirm the direction we've been building toward. But neither addresses the structural gaps that matter most: cryptographic proof of governance decisions, runtime-immutable safety invariants, EU AI Act conformity, or deterministic natural-language querying. Those aren't features you bolt on. They're architecture decisions you either made at day one or you didn't.


Saviynt Zuma: a credible refresh, built on familiar assumptions

Saviynt has been a real competitor for years. Their cloud-native architecture, their application access governance, their CPAM integration — these are genuine strengths. Zuma, launched July 28, is clearly their next-generation bid: modernized UX, expanded automation, and what they're describing as AI-driven identity intelligence.

Credit where it's due: Saviynt recognized earlier than most incumbents that IGA needed to move beyond static role models. Zuma reflects that. It's a serious platform refresh from a team that understands enterprise identity.

What Zuma doesn't address is the evidence problem. Every governance decision in an enterprise IGA — every access grant, every certification, every revocation — should produce a cryptographically verifiable receipt. Not a log entry. Not an audit trail in a database an admin can edit. An ECDSA-signed receipt, hash-chained into an evidence pack that auditors can verify offline without trusting the vendor's infrastructure.

Zuma also doesn't address AI agent governance as a first-class primitive. Their AI story is about copilots and assistants — AI helping humans make decisions. That's 2024 thinking. The 2026 question is: who governs the AI agents themselves? Who authorizes which tools an agent can invoke at runtime? Who ensures the agent's safety invariants can't be disabled by an admin with the right credentials?

Those are architecture questions, not feature questions. You don't add them in a point release.

SailPoint + Entro: the right acquisition, half the picture

SailPoint acquiring Entro makes strategic sense. Non-human identity — service accounts, API keys, machine credentials, secrets sprawl — is the fastest-growing attack surface in enterprise IT. Entro built a credible NHI discovery and lifecycle product. SailPoint needed that capability. The acquisition fills a real gap in their portfolio.

But NHI discovery is table stakes. Knowing what non-human identities exist is necessary. Knowing what they did, proving that every action was authorized, and being able to revoke access with cryptographic finality — that's the harder problem.

At SidantiX, non-human identity governance has been in the core architecture since the first commit. Not bolted on. Not acquired. Every NHI — every service account, every API key, every AI agent — goes through the same governance pipeline as a human user: birthright provisioning, certification campaigns, access reviews, and closed-loop revocation. Five steps, one hash chain: signal, evaluate, revoke, verify, seal.

SailPoint's acquisition gives them NHI visibility. It doesn't give them NHI governance with verifiable proof. Those are different products.

What they still can't do

I spent years building identity governance. I know what enterprise IGA platforms are good at, and I know where the structural ceilings are. Here's what no competitor — Saviynt, SailPoint, Okta, Microsoft, or anyone else — currently ships:

IQL — Identity Query Language. A user types "Who has admin access to production databases?" and gets an instant, deterministic answer. Not a chatbot guess. Not an LLM hallucination wrapped in a friendly UI. IQL translates natural language into SQL, executes it against the governance data model, and returns auditable, reproducible results. Same question, same data, same answer, every time. The query itself is logged as evidence.

MCP governance. AI agents are here. They use tools. They invoke APIs. They make decisions. SidantiX provides first-class tool-call authorization at runtime through the Model Context Protocol. Every tool invocation is policy-evaluated before execution, not after. This isn't "AI copilot for IGA." This is IGA for AI.

EU AI Act conformity. Article 9 of the EU AI Act requires risk classification, human oversight mechanisms, and audit documentation for high-risk AI systems. Our EU AI Act module provides conformity assessment documentation, risk classification per Annex III, and the human oversight hooks that auditors actually ask for. No other IGA platform ships this today.

Machine Constitution. Runtime-immutable safety invariants, cryptographically signed, verified at process startup. No admin can disable them. No configuration change can bypass them. No attacker with valid credentials can turn them off. The only way to modify them is through a signed manifest deployed through your release pipeline. We published the open spec — MIT license, reference implementation included.

Cryptographic proof. Every governance decision — grant, certify, revoke, deny — produces an ECDSA-signed receipt. Receipts are hash-chained into evidence packs. Auditors download the pack and verify it offline with a standalone tool. No vendor trust required. The math is the proof.

Closed-loop revoke. Signal → evaluate → revoke → verify → seal. Not "we sent a revocation request and hope the target system processed it." We verify the revocation took effect and seal the evidence. Five steps, one hash chain, tamper-evident end to end.

The framing

I don't think Saviynt or SailPoint are bad platforms. They're credible, battle-tested, and they serve real customers well. What I think is that they were built for a different era — an era where the hardest identity problem was "which humans have access to which applications." That era is ending.

The new era is: humans, machines, and AI agents, governed uniformly, with cryptographic proof on every decision, immutable safety invariants that no operator can disable, and regulatory conformity that's structural rather than aspirational.

That's what we've been building. This week, the industry started catching up to the problem statement. The architecture gap remains.


About the author: SidantiX is founded by an identity governance veteran with over two decades of experience building identity governance platforms deployed at some of the world's largest enterprises. SidantiX answers the question: what would IGA look like if you started from cryptographic proof and AI agent governance on day one?

See it yourself. We don't ask you to believe the claims — we ask you to verify them. Request a scoped proof-of-concept and we'll run your scenarios against real governance decisions with verifiable evidence.

← All posts Request a scoped proof →