Cloud Identity Governance (CIG)
Cloud Identity Governance platforms provide security and identity teams with a unified, continuous view of who has access to what across cloud providers, SaaS applications, and identity stores, and whether that access is appropriate. Instead of spreadsheet-driven access reviews and one-off IAM audits, CIG tools continuously ingest entitlements, groups, and roles to surface toxic combinations, privilege creep, and access that no longer matches a user’s role. Traditional IGA was built around on-prem directories and a small set of core apps. Cloud Identity Governance extends that model to multi-cloud and SaaS environments where access is spread across IAM roles, SaaS tenants, and ephemeral resources. Legacy IGA platforms remain strong at workflow (joiner/mover/leaver, approvals, attestations) but often struggle with cloud entitlements such as thousands of granular permissions, Kubernetes roles, and SaaS-specific privilege models. CIG platforms specialise in discovering and normalising these entitlements, analysing risk, and feeding decisions back into IGA or ITSM for approvals and lifecycle.
Vendor shortlist
11 listed- VisitApono
Apono provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreView details → - VisitBritive
Britive provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreComplianceSOC 2 Type IIISO 27001HIPAAPCI DSSGDPRView details → - VisitClutch Security
NHI‑centric identity governance. Discovers service accounts, tokens, and AI agents; automates lifecycle and reviews; detects stale or over‑privileged NHIs; and enforces least privilege and compliance from creation to decommissioning.
Not providedDiscovery and ownership correlation for NHIsLifecycle management with policy engineDetection of stale/orphaned/over‑privileged NHIsAccess reviews and compliance supportPosture and risk management for machine access+3 moreView details → - VisitConductorOne
ConductorOne provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreComplianceSOC 2 Type IIView details → - Visit
OpalOpal provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreComplianceSOC 2View details → - Visit
SaviyntConverged cloud IGA with strong machine identity governance. Provides unified visibility of keys, certs, bots, and service accounts; automates lifecycle, reviews, and revocation; and applies risk‑based controls and SoD to enforce least privilege across cloud and SaaS.
Not providedUnified visibility of machine identitiesLifecycle automation (issue, renew, revoke)Risk‑based access and certificationsSoD enforcement and audit reportingOwner assignment and succession policies+3 moreComplianceSOC 2 Type IIISO 27001ISO 27017FedRAMPPCI DSSView details → - Visit
SecurEndsSecurEnds provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreView details → - Visit
StrongDMStrongDM provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreComplianceSOC 2View details → - Visit
TeleportTeleport provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreComplianceSOC 2 Type IIISO 27001HIPAAView details → - Visit
VezaVeza provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreComplianceSOC 2 Type IIView details → - Visit
ZluriZluri provides cloud identity governance with automated provisioning, access reviews, and JIT access. It discovers human and machine identities, right‑sizes privileges, enforces least privilege, and produces audit‑ready evidence across cloud and SaaS.
Not providedAutomated provisioning and deprovisioningAccess reviews and certification workflowsJust-in-time and just-enough accessZero standing privilege enforcementSegregation of duties and policy rules+4 moreView details →
What we evaluate
- Coverage & depth of the core use case
- Deployment model, integrations, and time to value
- Detection quality and false-positive posture
- Ecosystem: SIEM, SOAR, and identity plumbing
- Pricing transparency and total cost of ownership
- Vendor traction, roadmap, and support experience