Overview
A trusted global leader in data, analytics, and technology.
Industry
Financial and information services
Saviynt Identity Cloud Capabilities:
Turning to Saviynt’s Cloud-Native Platform to Enable Secure Innovation
Tasked with stewarding massive amounts of sensitive financial information from consumers and businesses around the world, this industry-leading analytics firm had already invested heavily in modernizing its security infrastructure. To enable further innovation and accelerate AI adoption, the organization set out upon a large-scale cloud transformation journey. However, identity security team members soon realized that their legacy on-premises identity management tools weren’t ready for the business’s tech-forward future. They turned to Saviynt’s unified platform to drive efficiencies, eliminate standing privileges, and prepare to secure AI agents and applications.
Moving Beyond Legacy IGA
When the company embarked upon a sweeping cloud transformation project to spur business growth, enable innovation, and reduce operating costs, it quickly became clear its existing identity security ecosystem wasn’t ready for that future. The legacy tool stack was complex and fragmented, incorporating multiple vendors’ solutions, including an on-premises implementation of SailPoint IdentityIQ (IIQ) for identity governance and administration (IGA).
The organization had already implemented Saviynt’s IGA and Privileged Access Management (PAM) solutions for the portion of its cloud infrastructure that housed data belonging to federal agencies. When that project began, SailPoint’s cloud products were not FedRAMP-authorized, so the company had needed a new identity security partner to support its expansion into the federal sector. It also needed a solution that could govern identities across Google Cloud Platform (GCP) applications and infrastructure, since GCP was—and remains—the company’s primary cloud provider. Saviynt was chosen.
We evaluated a number of IGA products when we were looking for a FedRAMP-authorized solution. A challenge we faced was that most of the products on the market were not Google-centric, and we were a GCP shop at the time. What differentiated Saviynt was that they were willing to partner with us to come up with a solution that could deliver the functionalities we needed in a GCP environment. We worked very closely with Saviynt’s product team and developed a strong connection. Saviynt has been a very good partner to us.
Three years later, with the cloud migration in progress, the security team decided to build upon the strength of its existing relationship with Saviynt by expanding the IGA implementation into the rest of the company’s commercial environment. As they began shutting down legacy mainframes and decommissioning data centers, they could see that they needed a cloud-native solution capable of enforcing just-in-time (JIT) access policies so that standing privileges could be eliminated. Saviynt offered these capabilities, while SailPoint IIQ did not.
By adopting a converged platform solution, the identity security team was able to eliminate the cost and effort associated with managing multiple IGA tools side by side. A major enterprise needs an entire team of specialists to support each additional solution that’s introduced, so eliminating tools yields significant savings in cases like this one.
The identity and security team took a phased approach to implementation, first onboarding core applications such as Workday and Active Directory into Saviynt, then migrating applications with custom connectors, and finally moving databases into Saviynt before retiring SailPoint IIQ. Along the way, they undertook a large-scale cleanup project, identifying applications and databases that were no longer in use and decommissioning them. In total, they were able to eliminate between 500 and 600 orphaned applications, reducing cyber risk as well as costs.
An Intelligent Platform that Can Secure All Identities in the AI Era
With Saviynt’s cloud-native, AI-powered platform solution, this leading financial services firm has been able to simplify its identity security infrastructure. By eliminating on-premises servers, the company has reduced operational overhead and improved reliability and uptime. Adding automation further streamlined administration. After the move from SailPoint IIQ to Saviynt, the number of labor-hours needed for identity security program management decreased by 35 to 50%.
Even though identity governance is now more efficient, the security team now enjoys greater visibility and control. With Saviynt, they’ve been able to eliminate standing privileges across their cloud environment and have fully implemented JIT access.
With IIQ, we had to develop all of the connectors ourselves, but with Saviynt, it’s much easier. Bringing new applications onto the platform is now mostly plug-and-play, and even for large self-hosted databases and custom apps, we’ve built a templated onboarding process where the work involved is minimal.
Reporting is also greatly improved. “The daily health check reports that Saviynt offers are much better than what SailPoint had,” he says. “With the intelligence features in Saviynt, it’s very easy to create queries that tell us exactly what we need to know about our identity security environment.
The identity security team is using Saviynt’s built-in intelligence to help them manage certifications and approvals. AI can now handle routine approvals, whereas before, teams needed to manually review thousands of requests.
The AI features that Saviynt has recently rolled out have greatly helped with our security posture overall. We’re actively engaged with the Saviynt team to find additional use cases, and those conversations are very valuable for us. We appreciate the team’s understanding of what’s going on in the industry.
Leveraging AI wherever possible is a key business priority for the organization. Their identity security team plans to work with Saviynt to build access controls that protect model context protocol (MCP) servers and generative AI systems. They’re also looking to secure sensitive data with governance for AI agents as their AI maturity continues to grow.
We recently rolled out our first AI agent for customers. This brings new security challenges, because there are new risks that data could be exposed if AI agents access it. Governing the access that agents have is really important, so it’s really beneficial that we have a platform that can help support the security of those agents, and their access to services. Building this out is one of our most important goals for the next six months.
Partnering with Saviynt to Achieve Industry-Leading Identity Security
Corporate leadership believes that the road to business growth runs through the cloud. The firm plans to leverage its investments in a cloud-native data fabric and AI to drive faster product innovation and expand its analytics offerings. Its business is built on handling sensitive corporate and consumer credit data, so maintaining an industry-leading identity security program is vital for earning trust. The partnership with Saviynt will remain critical for achieving these objectives.
Already, the organization is securing more than 1,000 applications and 23,000 human identities with Saviynt’s unified platform, but the company will continue to build on this foundation. The identity security team is investigating additional use cases for AI, such as automatically granting emailed approvals, and intelligent identity security posture management (ISPM). As AI’s capabilities grow, they’re hoping that they’ll be able to further automate JIT provisioning, as well.
Impact
Eliminated costs and risks associated with 500-600 orphaned applications
Secured 23,000 human and 20,000 non-human identities with the Saviynt platform
Reduced labor-hours spent on identity governance by 35-50%
Achieved FedRAMP Moderate authorization
I would say our entire engagement with Saviynt has been amazing. When we went through rough times, Saviynt was there for us. We still have someone from Saviynt coming to our office once a week to look at our current challenges, advise us, and propose solutions. That support has always been there, and it’s really taken the engagement to the next level.



