TL;DR: 2024 ARR rose more than 35%, NRR reached 111%, and subscription revenue made up 88% of total revenue, while Saviynt positioned its cloud-native identity security platform as the answer to legacy IAM limits, according to Saviynt. The governance question is not platform enthusiasm but whether converged identity tooling can keep pace with NHI sprawl, audit pressure, and emerging AI-driven access patterns.
NHIMG editorial — based on content published by Saviynt: Leading the Identity Security Transformation: Saviynt’s Momentum into 2025
By the numbers:
- Year-end 2024 ARR was up over 35% year-over-year.
- New SaaS ACV bookings were approximately $60 million, up more than 35% year-over-year.
- Contracted gross retention rate exceeded 95%, or 98% when excluding downsell.
Questions worth separating out
Q: How should security teams evaluate identity security platforms when NHI governance is in scope?
A: They should look for coverage across discovery, ownership, lifecycle control, access review, and remediation for both human and non-human identities.
Q: Why do legacy IAM controls struggle with AI-driven environments?
A: Legacy IAM was built for relatively stable identities and slower review cycles.
Q: What do security teams get wrong about IAM platform consolidation?
A: They often assume more catalog breadth means better governance.
Practitioner guidance
- Map governance coverage by actor type Separate human identities, service accounts, API keys, certificates, and AI-adjacent access paths into distinct governance populations before evaluating platform consolidation.
- Test offboarding and revocation workflows end to end Walk an API key, service account, and privileged workload credential through joiner-mover-leaver, revocation, and rotation paths to see whether the platform can actually close access.
- Challenge single-pane-of-glass claims with audit evidence Ask for evidence of visibility into service accounts, stale credentials, and privilege scope rather than relying on dashboard unification.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- Platform positioning, product scope, and partner ecosystem references that explain how Saviynt is packaging its identity security strategy.
- The specific 2025 feature themes and roadmap signals that are only summarised here at a strategic level.
- Customer and market framing around why organisations are shifting from legacy providers to converged identity platforms.
- The company performance narrative behind ARR, bookings, retention, and profitability claims.
👉 Read Saviynt's blog post on its 2025 identity security momentum →
Identity platform consolidation in 2025: what does it mean for IAM teams?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Platform convergence is now an identity governance story, not just a tooling story. When vendors emphasize cloud-native convergence, the real question for practitioners is whether one control plane can actually govern three different identity populations: humans, NHIs, and autonomous systems. The value proposition changes from feature accumulation to governance coherence. That means the market will increasingly reward platforms that prove lifecycle control and access visibility across identity types, not just breadth of modules.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: How do organisations know whether an identity security platform is actually improving control?
A: They should measure whether offboarding is faster, credential rotation is more complete, and service account visibility is better after adoption. If those outcomes do not improve, the platform may have simplified administration without materially changing risk.
👉 Read our full editorial: Saviynt’s 2025 momentum signals a broader identity platform shift