By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: JosysPublished September 2, 2026

TL;DR: SaaS governance, identity workflows, and AI-aware oversight are converging into one control plane, according to Josys, which says it reached #1 in G2’s Momentum Grid for SaaS Management Platforms for the fourth straight cycle, added four badges, and entered G2’s IAM category as customer reviews pushed it across 93 reports and 26 awards. The signal for practitioners is that these capabilities are increasingly being managed together in a single control plane.


At a glance

What this is: This is Josys’ recap of its G2 Fall 2026 results, highlighting a #1 Momentum Grid position for SaaS Management Platforms, a first-time IAM category entry, and growing customer review traction.

Why it matters: It matters because IAM teams are being pushed to govern SaaS sprawl, offboarding, and non-human access through fewer control planes, not more disconnected tools.

By the numbers:

👉 Read Josys’ G2 Fall 2026 ranking recap for SaaS management and IAM


Context

The governance gap here is not about feature count. It is about whether identity teams can manage SaaS access, offboarding, and bot and AI agent visibility in one operating model rather than bouncing between separate tools for discovery, remediation, and review. For SaaS Management Platforms, that convergence is now the product story that matters to IAM leaders.

Josys is using its G2 results to argue that customers are rewarding tighter linkage between identity data, access control, and lifecycle workflows. That framing is relevant to NHI, human IAM, and emerging autonomous identities because the operational problem is the same: access has to be discovered, governed, and revoked before it becomes shadow risk.


Key questions

Q: How should teams govern SaaS access when bots and AI agents are also active?

A: Treat bots and AI agents as governed identities, not exceptions inside the SaaS stack. Assign ownership, lifecycle rules, and revocation paths for each non-human actor, then make sure review workflows can surface them separately from employee access. If the platform cannot distinguish those actors, governance is incomplete.

Q: What breaks when SaaS discovery is not linked to deprovisioning?

A: Discovery without deprovisioning creates visibility without closure. Teams can identify apps and still leave orphaned users, shared access, and stale permissions in place. That means the organisation learns what exists but cannot actually remove unnecessary access, which is where the real security value is lost.

Q: When does SaaS license management become a governance problem rather than a cost issue?

A: It becomes a governance issue when teams cannot see which apps are in use, who holds access, or whether licenses match actual account activity. At that point, the organisation risks shadow IT, wasted spend, and audit gaps. Effective governance ties application discovery, entitlement assignment, and cost tracking into one operating model.

Q: How can security teams tell whether privileged access reviews are actually working?

A: They are working when every privileged entitlement is inventoried, every decision is traceable, and revoked access is removed from all connected systems without delay. If the organisation can only show approvals but not downstream revocation, the review is administrative recordkeeping rather than governance. Proof of removal is the best maturity signal.


Technical breakdown

SaaS management platforms now sit inside the identity control stack

A SaaS management platform is no longer just an inventory layer. In practice, it becomes a control point for discovery, provisioning, deprovisioning, license optimisation, and audit evidence across connected applications. That makes it adjacent to IAM and IGA, especially when app access is tied to identity provider data and role mapping. The technical value is in reducing drift between what the IdP says, what the app grants, and what the business still needs. When that drift is visible, teams can act on stale access earlier.

Practical implication: Practitioners should evaluate whether SaaS management is feeding identity governance decisions or merely reporting on them after the fact.

Bot and AI agent visibility changes the scope of SaaS governance

Once bots and AI agents are treated as identities touching enterprise applications, governance stops being human-only. The article points to systems that surface bots and AI agents alongside employee access, which is operationally important because machine actors can generate permissions, tokens, and activity patterns that evade conventional review cadences. This is an NHI problem, even when the platform market labels it as SaaS governance. The challenge is not only who has access, but what non-human actors are active, where they were granted access, and whether their privileges are lifecycle-managed.

Practical implication: Identity teams should require non-human visibility in SaaS governance workflows, not leave bot and agent access to separate operational silos.

Access reviews are only useful when they produce revocation and audit evidence

The article describes access reviews moving from manual work to structured surveys with exportable audit trails. That matters because review activity by itself is not governance. The technical test is whether the process produces an enforceable decision, a revocation path, and evidence that can be reused in audit, risk, and compliance workflows. Where access reviews stay disconnected from lifecycle enforcement, they become documentation exercises. Where they connect to deprovisioning and policy, they become a real control.

Practical implication: Teams should test whether review outcomes automatically trigger access removal, not just generate a report for later follow-up.


NHI Mgmt Group analysis

SaaS governance is becoming an identity control plane problem, not a license administration problem. The article describes visibility, onboarding, offboarding, and review workflows in one platform narrative, which is where the market is heading. For IAM and IGA teams, that means SaaS management is increasingly evaluated on its ability to reduce identity drift, not just optimise spend. The practitioner conclusion is that governance and lifecycle enforcement now define the category more than app inventory does.

Identity governance has to include non-human actors once bots and AI agents touch enterprise applications. Josys’ customer commentary explicitly mentions bots and AI agents, which is a meaningful signal even if the product framing stays broad. Non-human access expands the review surface because activity can be continuous, delegated, and harder to map back to a single human owner. The implication is that SaaS governance programmes now need a documented position on NHI visibility and lifecycle ownership.

Customer ratings are not a control, but they are a market signal about where buyer pain is concentrated. A first-time IAM category entry alongside recurring SaaS management recognition suggests that practitioners are trying to collapse identity workflow fragmentation. That does not validate the vendor, but it does show that buyers are looking for a single operational path across discovery, access, and revocation. The practitioner conclusion is to re-check whether your current toolchain still forces those functions apart.

Access review maturity now depends on whether review output is machine-actionable. Structured surveys and exportable audit trails are only valuable if they translate into actual entitlement changes. The governance failure mode is review theatre, where attestations accumulate without removing stale access or reconciling exceptions. The implication for identity teams is that review design should be measured by remediation closure, not participation rates.

Named concept: identity visibility debt. When SaaS sprawl, human access, and non-human activity are managed in different places, organisations accumulate hidden access risk even when each system appears individually controlled. That debt surfaces later as orphaned accounts, stale entitlements, and weak audit evidence. The practitioner conclusion is to treat cross-system visibility as a governance backlog, not a dashboard feature.

From our research:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
  • For a broader view of breach patterns, see 52 NHI Breaches Analysis for the failure modes that follow weak lifecycle control.

What this signals

SaaS governance is moving toward identity control consolidation, where discovery, access, and lifecycle actions need to sit closer together. That shift matters because fragmented tooling creates blind spots for both employees and non-human actors, especially when offboarding and review decisions are still handled in separate systems.

Identity visibility debt: when SaaS access, app roles, and non-human activity are scattered across tools, teams inherit hidden risk that looks manageable until a review, audit, or incident forces reconciliation. Practitioners should expect more pressure to prove machine-actionable governance rather than manual oversight.

The next phase of platform evaluation will focus less on dashboards and more on whether the control plane can enforce outcomes across human and non-human identities. Teams that still separate SaaS administration from IAM and NHI governance will find the operating model harder to defend.


For practitioners

  • Map SaaS governance to identity lifecycle outcomes Check whether every discovered application is linked to an enforceable provisioning and deprovisioning path, not just a visibility record. Use the review process to verify that access changes propagate back into the source of truth.
  • Add non-human identities to SaaS access reviews Require the review workflow to flag service accounts, bots, and AI agents where they touch SaaS applications. Separate ownership, approval, and revocation logic for these actors so they are not hidden inside employee-centric certification processes.
  • Test whether review outputs drive revocation Measure how many certified entitlements are actually removed within the same workflow cycle. If the process ends at attestation, the control is producing evidence but not reducing exposure.
  • Reconcile role mapping with app-level permissions Confirm that RBAC mappings in the governance layer match what the application actually grants. Where app roles drift from business roles, the platform may report coverage while privilege creep continues underneath.

Key takeaways

  • Josys’ G2 performance is best read as a market signal that SaaS governance is being pulled closer to IAM and lifecycle enforcement.
  • The most operationally relevant detail is the growing expectation that non-human actors and access reviews belong in the same governance conversation.
  • Identity teams should judge this category by whether it produces enforceable revocation and audit evidence, not by visibility alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-06Non-human visibility and lifecycle control are central to the article's NHI references.
Use NHI-06 to check that bots, service accounts, and AI agents are inventoried and lifecycle-managed.
NIST CSF 2.0PR.AC-1The article centres on controlling and reviewing access across SaaS environments.
Map SaaS governance to PR.AC-1 and verify access is provisioned, reviewed, and revoked consistently.
NIST SP 800-53 Rev 5AC-2Account management governs provisioning, review, and deprovisioning described in the post.
Apply AC-2 to ensure SaaS entitlement changes are tied to lifecycle events and review outcomes.
NIST Zero Trust (SP 800-207)The article aligns with continuous verification and reduced standing access in SaaS governance.
Use Zero Trust principles to reduce standing access and validate identity before SaaS entitlement changes.

Use Zero Trust principles to reduce standing access and validate identity before SaaS entitlement changes.


Key terms

  • SaaS Management Platform: A SaaS management platform is a visibility and optimisation layer for cloud software use. It helps teams discover applications, track utilisation, and understand spend patterns, but it does not by itself enforce access policy, revoke permissions, or manage identity lifecycle state.
  • Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Identity visibility debt: The gap that appears when an organisation can list its assets but cannot reliably link them to owners, entitlements, or activity. It creates a false sense of control because inventory looks complete while access relationships remain hidden, stale, or unreviewed.

What's in the full article

Josys' full post covers the operational detail this analysis intentionally leaves for the source:

  • The full G2 badge breakdown across SaaS Management Platforms and IAM category reports.
  • Customer review excerpts that explain why IT teams and MSPs rated the platform highly.
  • The platform's own description of how identity, governance, and automation are positioned together.

👉 Josys’ full post includes the report-period badge changes, review themes, and category placement details.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org