By NHI Mgmt Group Editorial TeamBased on Zluri: “Top 10 Kayako Alternatives & Competitors in 2026” (December 24, 2025)

TL;DR: Kayako alternatives are being framed around ticketing, automation, and reporting, but the underlying pattern is access governance: employee app requests, approval workflows, and app visibility determine how safely identities are provisioned, according to Zluri’s review. The real issue is whether ITSM-style workflows can control lifecycle, approvals, and SaaS sprawl without turning access into another ticket queue.


At a glance

What this is: This is a vendor analysis of Kayako alternatives that argues the real comparison point in ITSM is identity governance, especially how app requests, approvals, and visibility shape safe provisioning.

Why it matters: It matters because IAM and IGA teams should not treat service desk workflows as a substitute for governed access lifecycle controls, especially where SaaS sprawl and shadow IT are in play.


Context

Kayako is presented as a help desk and ITSM platform, but the article’s deeper point is about governance boundaries. Ticketing, approvals, reporting, and self-service are useful only when they are connected to controlled access decisions and clear ownership of app entitlement.

For identity practitioners, the important question is not whether a service desk can route requests efficiently. It is whether that workflow can support app visibility, approval quality, and lifecycle governance across SaaS access without turning entitlement management into a ticketing backlog.


Key questions

Q: What breaks when ITSM tools are used as the only access request control?

A: The workflow still records requests, but it cannot judge entitlement scope, license fit, time limits, or SoD conflicts. That means access can be approved quickly while still being wrong, which leads to over-permissioning, orphaned access, and weak audit evidence. Service desks can move the ticket, but they cannot prove the access was appropriate.

Q: How should security teams govern SaaS app requests without creating a ticket backlog?

A: They should curate a request catalogue, define approval rules up front, and reserve manual review for higher-risk apps or exceptions. That keeps the workflow efficient while preserving policy control over who can request what, under which conditions, and with what ownership trail.

Q: Why do app visibility controls matter in employee self-service portals?

A: Because visibility determines the set of access paths employees can even attempt. If the catalogue is not filtered by risk, compliance, and business ownership, self-service becomes an open-ended access market rather than a governed entitlement process.

Q: How do identity teams connect app requests to joiner-mover-leaver governance?

A: By treating requests as lifecycle events, not one-off tickets. Each approved request should map to an owner, a business reason, and a review or removal trigger tied to role changes and offboarding, so access does not outlive the need for it.


Technical breakdown

Why ITSM workflows do not equal identity governance

ITSM platforms manage requests, incidents, and notifications, but identity governance manages who can receive access, under what conditions, and for how long. A ticket can record the request, yet it does not by itself prove entitlement validity, enforce segregation of duties, or offboard access when an employee changes role. In SaaS-heavy environments, that gap matters because the request path can become the de facto control layer even when the actual access decision belongs elsewhere.

Practical implication: Treat the service desk as a workflow front end, not the system of record for entitlement governance.

App visibility and approval logic in SaaS access

The article’s most relevant mechanism is selective app visibility inside an employee app store model. That approach changes the control surface from open request intake to curated entitlement choices, where risk score, compliance requirements, and approval logic shape what can be requested. This is less about convenience than about narrowing the set of possible access paths so that requesters see only what the organisation is prepared to govern.

Practical implication: Curate requestable apps by risk and ownership, then force approval logic to follow the entitlement policy, not the other way around.

How ticketless access changes the governance model

A ticketless request model reduces administrative friction, but it also moves governance upstream. Instead of relying on long ticket chains, the organisation must decide which apps are pre-approved, which need review, and which should be blocked or routed for procurement. That means the real control point becomes the catalogue and its policy metadata, not the support queue. If those policy decisions are weak, automation merely accelerates bad access decisions.

Practical implication: Define policy at the catalogue level so automation speeds governed access rather than uncontrolled provisioning.


Threat narrative

Attacker objective: The objective is not a single exploit but uncontrolled access expansion, where weak governance lets more users obtain more SaaS access than policy would allow.

  1. Entry begins when employees submit app requests through a service desk or self-service workflow that looks operational but actually opens an access pathway.
  2. Escalation occurs when approvals are driven by convenience rather than entitlement policy, allowing access to be granted without enough context on risk or business need.
  3. Impact is SaaS sprawl, shadow IT, and inconsistent access governance, because the organisation has automated request handling without fully governing the resulting entitlements.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.
  • Caesars Entertainment breach 2023: Social engineering of an IT support vendor let attackers copy Caesars loyalty database; about $15 million was reportedly paid.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

ITSM is being asked to do identity governance work it was never designed to do: The article shows a familiar market pattern in which request routing, approvals, and reporting are treated as access control. That works only until someone has to prove entitlement validity, enforce role boundaries, or revoke stale access across SaaS sprawl. The practitioner conclusion is that request workflow and identity governance are separate disciplines, even when they share the same user interface.

App visibility is the real control surface in SaaS request models: Curating what employees can request is more important than making the request flow faster. Once visibility is tied to threat level, risk score, and compliance requirement, the catalogue becomes a policy instrument rather than a convenience feature. The field should stop treating self-service as a UX story and start treating it as an entitlement policy problem.

Ticketless access only works when policy is already mature: Automation can reduce friction, but it also removes the natural delay that often exposes weak approvals. If the underlying catalogue, ownership model, and approval criteria are vague, the system will provision faster and govern less well. The practitioner lesson is that speed without entitlement discipline simply scales the governance gap.

Identity governance for ITSM is now a lifecycle problem, not a service-desk problem: Requests, approvals, procurement, and visibility all touch joiner-mover-leaver decisions across SaaS. That means the real control question is whether the organisation can govern app access from request through offboarding without depending on ticket volume as the main safeguard. The conclusion is that lifecycle ownership must sit above the help desk layer.

Access request sprawl is becoming its own governance debt: The article implicitly describes a new control debt where every extra app request path increases the policy surface that must be maintained. That debt accumulates when request flows outpace entitlement review, ownership mapping, and auditability. The practitioner implication is to measure request paths as governance assets, not just support workflows.

What this signals

Request workflows are becoming entitlement policy engines: The practical shift in this article is that service desk tooling is no longer just an intake layer. Once app visibility, approval rules, and procurement routing decide what can be requested, the governance burden moves into catalogue design and ownership mapping. Teams should review whether their request process already contains the policy decisions they think live elsewhere.

Ticketless access can improve experience without improving control: Faster request handling is useful only if the underlying approval model is mature. Where app catalogues are broad and ownership is unclear, automation will simply provision risk more quickly. The programme question is whether request velocity is being measured ahead of entitlement quality.

SaaS sprawl changes the shape of lifecycle management: The article points to a world where joiner, mover, and leaver decisions increasingly begin inside self-service request flows. That means offboarding, recertification, and access review cannot be bolted on after the fact. They have to be designed into the same process that grants the access in the first place.


For practitioners

  • Separate request handling from entitlement governance Keep the service desk focused on intake and case management, while access policy, approval authority, and entitlement ownership remain defined in the identity programme.
  • Curate requestable apps by risk and ownership Limit the app catalogue to software with clear business ownership, documented approval criteria, and explicit risk thresholds before it can be requested.
  • Use approval metadata to drive provisioning decisions Capture risk score, compliance requirement, and business justification in the request workflow so approvers are not making decisions with incomplete context.
  • Map requests to lifecycle events Tie employee app requests to joiner, mover, and leaver processes so granted access can be reviewed and removed when role or employment status changes.
  • Measure governance quality, not just ticket speed Track approval accuracy, exception rates, and stale access findings alongside resolution time so faster routing does not mask weaker access control.

Key takeaways

  • The article’s core message is that help desk workflows do not replace identity governance when access to SaaS apps is at stake.
  • Its strongest operational signal is the use of curated visibility and approval logic to shape which applications can be requested and provisioned.
  • The control lesson is that access requests should be tied to lifecycle ownership, risk thresholds, and entitlement review, not only to ticket resolution.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIRequest flows can over-provision SaaS access when approval logic is weak.
NHI-01 — Improper OffboardingThe article’s lifecycle framing depends on removing access when roles change or end.
Recommendation — Restrict request catalogues and approvals so SaaS access cannot exceed policy-defined need. Tie access removal to leaver events so SaaS entitlements do not survive role changes.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeITSM request models must still enforce least privilege at the entitlement layer.
Recommendation — Apply least privilege to app requests so approvals grant only the minimum needed access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on governing authorisations across SaaS request workflows.
Recommendation — Define and review access permissions and authorizations before any self-service provisioning occurs.
CIS Controls v8CIS-5 — Account ManagementRequest, approval, and offboarding processes all depend on account governance.
Recommendation — Maintain account lifecycle controls so provisioning and removal stay aligned with business need.

Key terms

  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Employee App Store: An employee app store is a governed self-service channel for requesting approved applications and access. Its value comes from policy enforcement, traceability, and approval logic, not from convenience alone, because it can reduce shadow IT only when requests are tied to current role and risk.
  • Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.
  • Entitlement: An entitlement is the permission set that defines what a non-human identity can do after it authenticates. It is usually expressed through roles, policies or access assignments, and unmanaged entitlements are a common reason machine identities become over-privileged over time.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org