TL;DR: 2024 ARR rose more than 35%, NRR reached 111%, and subscription revenue made up 88% of total revenue, while Saviynt positioned its cloud-native identity security platform as the answer to legacy IAM limits, according to Saviynt. The governance question is not platform enthusiasm but whether converged identity tooling can keep pace with NHI sprawl, audit pressure, and emerging AI-driven access patterns.
At a glance
What this is: Saviynt frames 2025 as a convergence moment for identity security, backed by growth metrics and a push toward a cloud-native platform model.
Why it matters: IAM, IGA, PAM, and NHI teams need to assess whether platform consolidation improves governance coverage or simply repackages long-standing visibility and lifecycle gaps.
By the numbers:
- Year-end 2024 ARR was up over 35% year-over-year.
- New SaaS ACV bookings were approximately $60 million, up more than 35% year-over-year.
- Contracted gross retention rate exceeded 95%, or 98% when excluding downsell.
- Net revenue retention increased from 104% to 111%.
👉 Read Saviynt's blog post on its 2025 identity security momentum
Context
Identity security platforms are increasingly being judged on whether they can unify governance across human users, service accounts, and emerging AI-driven access patterns. The core issue is not whether a platform is cloud-native, but whether it can reduce fragmentation across identity lifecycle, privileged access, and audit workflows.
This article is framed as a momentum update, but the operational question for practitioners is different: does convergence actually close governance gaps, or does it simply move them into a larger platform boundary? For teams managing NHIs, human IAM, and autonomous access pathways, that distinction determines whether consolidation improves control or just changes the packaging.
The article also points to a wider market shift away from point tools and toward broader identity security suites. That shift is typical of the current market, but the value for practitioners depends on evidence of lifecycle coverage, visibility, and enforceable policy across identity types rather than claims of platform completeness.
Key questions
Q: How should security teams evaluate identity security platforms when NHI governance is in scope?
A: They should look for coverage across discovery, ownership, lifecycle control, access review, and remediation for both human and non-human identities. The key test is whether the platform can support policy decisions and evidence collection across service accounts, secrets, and entitlements without forcing separate workflows for each identity type.
Q: Why do legacy IAM controls struggle with AI-driven environments?
A: Legacy IAM was built for relatively stable identities and slower review cycles. AI-driven systems change context quickly, chain actions, and make decisions at machine speed, which makes periodic certification and static roles too slow to contain risk. Continuous evaluation is now the practical requirement.
Q: What do security teams get wrong about IAM platform consolidation?
A: They often assume more catalog breadth means better governance. In practice, overlapping modules can increase integration burden, dilute ownership, and preserve partial implementations. A larger platform stack does not fix fragmented identity data or unclear accountability, so teams should evaluate control reliability, not vendor breadth.
Q: How do organisations know whether an identity security platform is actually improving control?
A: They should measure whether offboarding is faster, credential rotation is more complete, and service account visibility is better after adoption. If those outcomes do not improve, the platform may have simplified administration without materially changing risk.
Technical breakdown
Why converged identity security platforms are gaining traction
A converged identity security platform tries to unify governance, entitlement management, privileged access, and compliance oversight across multiple identity types. The technical appeal is operational: fewer integrations, less duplicated policy logic, and a single place to see access state. But convergence only helps if the platform can normalize identity objects consistently across applications, directories, cloud services, and machine identities. Without that normalization, a single pane of glass becomes a reporting layer rather than a control plane.
Practical implication: map which identity classes are actually governed end to end before assuming platform consolidation will reduce risk.
Why legacy IAM tools struggle with NHI and AI-driven access
Legacy identity tools were designed around durable human accounts, predictable joiner-mover-leaver events, and review cycles that assume access persists long enough to be certified. NHI workloads and AI-assisted systems change that model because credentials can be embedded in code, distributed through pipelines, or used by systems that create and consume access dynamically. That creates visibility and lifecycle problems that traditional IAM and IGA designs do not automatically solve.
Practical implication: test whether your controls can distinguish human, NHI, and emerging agentic access before treating them as one governance population.
What ai-centric identity security changes at the policy layer
An ai-centric identity security model suggests policy evaluation must expand beyond user-centric entitlements to include workload context, secret handling, and runtime access patterns. The technical challenge is not just authentication, but continuous authorization state across systems that do not behave like users. In practice, that means governance logic has to account for issued credentials, service dependencies, and exceptions that can outlive the original business process that created them.
Practical implication: build policy reviews around runtime identity behaviour, not only around static entitlement inventories.
NHI Mgmt Group analysis
Platform convergence is now an identity governance story, not just a tooling story. When vendors emphasize cloud-native convergence, the real question for practitioners is whether one control plane can actually govern three different identity populations: humans, NHIs, and autonomous systems. The value proposition changes from feature accumulation to governance coherence. That means the market will increasingly reward platforms that prove lifecycle control and access visibility across identity types, not just breadth of modules.
Legacy identity assumptions break first at the NHI layer. The assumption that access is assigned to durable accounts and reviewed on human timescales was designed for stable, person-centric identity. That assumption fails when credentials are embedded in code, consumed by workloads, or distributed across service-to-service flows. The implication is not merely more inventory, but a different governance model for identities that do not wait for review cycles.
Converged identity platforms only matter if they reduce blind spots in offboarding and privilege scope. NHIMG’s own research shows that only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them. That is the practical benchmark against which convergence should be judged. If a platform cannot shrink those operational gaps, it has not changed the security model in a meaningful way.
The market is moving toward identity security as infrastructure, not as a set of point controls. That shift can help teams if it simplifies governance across directories, cloud services, secrets, and privilege workflows. But it can also mask incomplete coverage if buyers confuse breadth with enforcement. Practitioners should treat platform consolidation as a governance design decision and demand proof of control outcomes, not just product scope.
From our research:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
- For the lifecycle and rotation angle, see Ultimate Guide to NHIs and the broader Top 10 NHI Issues analysis.
What this signals
Identity platform consolidation will only matter if it tightens control over non-human identity lifecycle. The market is moving toward broader identity suites, but practitioners should judge them by whether they reduce secret sprawl, improve service account visibility, and close offboarding gaps. With 97% of NHIs carrying excessive privileges according to the Ultimate Guide to NHIs, governance failure is more often about control quality than tool count.
Convergence should be evaluated as an operational simplification test. If a platform cannot reduce the number of places where identity state must be maintained, it will not reduce risk. That makes lifecycle control, entitlement scope, and revocation speed the practical measures that matter to IAM and IGA teams.
The next procurement cycle will likely reward platforms that can prove coverage across human, workload, and agent-adjacent access paths. Teams should expect harder questions about ownership, policy enforcement, and evidence of revocation, because governance buyers are now comparing outcomes, not just architecture.
For practitioners
- Map governance coverage by actor type Separate human identities, service accounts, API keys, certificates, and AI-adjacent access paths into distinct governance populations before evaluating platform consolidation. A converged tool is only useful if it can show which controls apply to each population and where lifecycle ownership breaks down.
- Test offboarding and revocation workflows end to end Walk an API key, service account, and privileged workload credential through joiner-mover-leaver, revocation, and rotation paths to see whether the platform can actually close access. Use the Ultimate Guide to NHIs as a baseline for what lifecycle coverage should look like.
- Challenge single-pane-of-glass claims with audit evidence Ask for evidence of visibility into service accounts, stale credentials, and privilege scope rather than relying on dashboard unification. The question is whether the platform can enforce policy across identity types, not whether it can display them in one console.
- Re-evaluate AI-centric governance assumptions If the platform is being positioned for AI-driven identity security, verify whether it handles runtime access patterns, secret handling, and workload context as separate governance concerns. AI adjacency alone does not mean the system can govern autonomous or semi-autonomous access safely.
Key takeaways
- Saviynt’s 2025 message is really about identity platform convergence, with governance breadth becoming the competitive narrative.
- The operational test for practitioners is whether a converged platform improves visibility, offboarding, and privilege control across human and non-human identities.
- Platform consolidation only changes risk if it closes lifecycle gaps and reduces the persistence of excessive access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centers on lifecycle and governance gaps for non-human identities. |
| NIST CSF 2.0 | PR.AC-4 | Identity and access management controls are the article's core governance theme. |
| NIST Zero Trust (SP 800-207) | 5.4 | The post stresses zero-trust identity governance across human and non-human access. |
| NIST SP 800-53 Rev 5 | IA-5 | Credential lifecycle management is central to the article's NHI discussion. |
Map platform capabilities to PR.AC-4 and verify least-privilege enforcement across identity types.
Key terms
- Platform-based identity security: A governance model that unifies multiple identity security functions into one control approach. The goal is to reduce gaps created by disconnected tools, so policy, visibility, and enforcement can work together across privileged access and mixed identity estates.
- Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
- Service account visibility: The ability to discover, attribute, and review non-human accounts across an environment. For NHI governance, visibility includes owner mapping, permission history, and lifecycle state so that access is not left to drift in legacy or private systems.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- Platform positioning, product scope, and partner ecosystem references that explain how Saviynt is packaging its identity security strategy.
- The specific 2025 feature themes and roadmap signals that are only summarised here at a strategic level.
- Customer and market framing around why organisations are shifting from legacy providers to converged identity platforms.
- The company performance narrative behind ARR, bookings, retention, and profitability claims.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org