TL;DR: Pathlock was featured as an Overall Leader in KuppingerCole Analysts AG’s 2026 Leadership Compass for Business Application Risk Management, which evaluates how vendors manage entitlements and enforce SoD policies across heterogeneous enterprise applications such as SAP, Salesforce, Workday, Oracle, and Microsoft Dynamics. The practical shift is that IGA programmes must govern access across business application estates, not just directory-centric identity controls.
Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “Pathlock Recognized as an Overall Leader in the 2026 KuppingerCole Leadership Compass for Business Application Risk Management”.
Key questions
Q: How should teams govern access across multiple sites and business units?
A: Use one lifecycle model for all sites, then vary access by role, location and relationship.
Q: Why do segregation of duties controls break down in hybrid and multi-application environments?
A: They break down because access governance is often built around one system at a time, while real users and service identities operate across several platforms.
Q: What are the signs that business application IGA is too fragmented?
A: Common signs include inconsistent entitlement inventories, manual evidence gathering, delayed certification cycles, and SoD exceptions that are discovered only during audit preparation.
Practitioner guidance
- Map entitlement coverage across business applications Inventory where roles, permissions, and privilege assignments actually live across SAP, Salesforce, Workday, Oracle, Microsoft Dynamics, and other core systems.
- Define SoD rules at the business process level Translate segregation conflicts into business-process terms so the same control can evaluate combinations of entitlements across multiple applications instead of only within one product.
- Validate connector depth before standardising governance Check whether each application integration captures the entitlement and transactional fields needed for audit evidence, not just basic user records.
Bottom line: Business application risk management now depends on cross-system visibility into entitlements and SoD conflicts, not just directory-linked access control.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Business application risk management has become a cross-system IGA problem, not an application-by-application exercise. The report’s central signal is that entitlements now need to be governed across heterogeneous business platforms, because risk emerges in the joins between systems rather than inside any single app. That shifts programme design away from isolated access control toward federated entitlement visibility and policy consistency across the business stack.
A question worth separating out:
Q: How do IAM and IGA teams decide whether to prioritise cross-system coverage?
A: Prioritise the applications that carry the highest entitlement risk and the most important business transactions, then expand coverage where control gaps or audit pain are greatest. If critical workflows span multiple platforms, cross-system governance should be treated as a programme baseline, not a later enhancement.
👉 Read our full editorial: Business application risk management now centers on cross-system IGA