Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

G2 momentum and IAM category entry: what it means for teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: SaaS governance, identity workflows, and AI-aware oversight are converging into one control plane, according to Josys, which says it reached #1 in G2’s Momentum Grid for SaaS Management Platforms for the fourth straight cycle, added four badges, and entered G2’s IAM category as customer reviews pushed it across 93 reports and 26 awards. The signal for practitioners is that these capabilities are increasingly being managed together in a single control plane.

NHIMG editorial — based on content published by Josys: G2 Fall 2026 ranking recap for SaaS management and IAM

By the numbers:

Questions worth separating out

Q: How should teams govern SaaS access when bots and AI agents are also active?

A: Treat bots and AI agents as governed identities, not exceptions inside the SaaS stack.

Q: What breaks when SaaS discovery is not linked to deprovisioning?

A: Discovery without deprovisioning creates visibility without closure.

Q: When does SaaS license management become a governance problem rather than a cost issue?

A: It becomes a governance issue when teams cannot see which apps are in use, who holds access, or whether licenses match actual account activity.

Practitioner guidance

  • Map SaaS governance to identity lifecycle outcomes Check whether every discovered application is linked to an enforceable provisioning and deprovisioning path, not just a visibility record.
  • Add non-human identities to SaaS access reviews Require the review workflow to flag service accounts, bots, and AI agents where they touch SaaS applications.
  • Test whether review outputs drive revocation Measure how many certified entitlements are actually removed within the same workflow cycle.

What's in the full article

Josys' full post covers the operational detail this analysis intentionally leaves for the source:

  • The full G2 badge breakdown across SaaS Management Platforms and IAM category reports.
  • Customer review excerpts that explain why IT teams and MSPs rated the platform highly.
  • The platform's own description of how identity, governance, and automation are positioned together.

👉 Read Josys’ G2 Fall 2026 ranking recap for SaaS management and IAM →

G2 momentum and IAM category entry: what it means for teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

SaaS governance is becoming an identity control plane problem, not a license administration problem. The article describes visibility, onboarding, offboarding, and review workflows in one platform narrative, which is where the market is heading. For IAM and IGA teams, that means SaaS management is increasingly evaluated on its ability to reduce identity drift, not just optimise spend. The practitioner conclusion is that governance and lifecycle enforcement now define the category more than app inventory does.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.

A question worth separating out:

Q: How can security teams tell whether privileged access reviews are actually working?

A: They are working when every privileged entitlement is inventoried, every decision is traceable, and revoked access is removed from all connected systems without delay. If the organisation can only show approvals but not downstream revocation, the review is administrative recordkeeping rather than governance. Proof of removal is the best maturity signal.

👉 Read our full editorial: G2 rankings show Josys gaining ground in identity governance



   
ReplyQuote
Share: