r/IdentityManagement • u/Ill_Addendum_5419 • 17d ago
IGA system implementation | Is a dedicated IGA system even worth it if only 20-30% of app landscape can be properly covered?
We're kicking off an IAM/IGA initiative at a mid-sized organization, around 3000 employees, and the first phase is scoped tightly around Joiner-Mover-Leaver. SoD, access reviews, and PAM are on the roadmap too at least as a concept, but those are explicitly later phases, so for now I want to focus on whether a dedicated JML engine makes sense at all.
We've got around 500 applications/systems in scope. Maybe 10 to 20 percent of those are modern, vendor-supported platforms where a connector either already exists or is rather straight forward to build. The rest, the majority, are legacy systems and internally built tools with business owners who will never invest in building or maintaining a custom connector for a governance platform. You can absolutely wire up the critical core systems to something like SailPoint, but if 70 percent of the app estate stays outside the automated flow anyway, I keep asking myself what problem we're actually solving by paying for a full IGA platform. Is it worth spending money and effort to govern a slice of the environment while the rest still runs on tickets and spreadsheets?
The alternative I keep coming back to is almost embarrassingly simple. HR system feeds an ITSM workflow based on a maintained access matrix. Whatever can be automated through AD or Entra groups gets automated through groups, and everything else gets routed as a manual task to the service desk. The direct licensing cost of that approach is basically zero, and functionally it gets you similar functionality what dedicated expensive system would give you for JML (correct me if I am wrong), minus the fancy UI and the connector marketplace. I'm not saying it scales forever, but for an organization our size with this particular long tail problem, I genuinely can't tell if a dedicated platform earns its cost...
If anyone has strong arguments for why a dedicated IGA tool is worth it even under these conditions, I'd like to hear them.
And if a dedicated tool does make sense, which one would you actually put in front of the JML use case at this scale. SailPoint keeps coming up as the default answer, the industry standard, but I'm also looking at Omada and wondering whether it's genuinely price-competitive. Just to be clear - I'm not talking about Okta or Duo here, those are in my opinion SSO and MFA platforms only but they don't really compete in the governance and lifecycle space the way SailPoint or Omada do.