About Persistent Systems
A 32-year-old global software and technology services company delivering AI-first solutions across industries and partnering closely with the world’s leading hyperscalers.
Industry
Headquarters
Delivering 80% Reduction in SoD Violations and Continuous Audit Readiness Across 27,000 Identities
Persistent Systems is a trusted digital engineering and enterprise modernization partner with over 35 years of software engineering leadership, serving clients across industries including banking, healthcare, life sciences, and software & hi-tech. The company offers a broad portfolio of services spanning AI, cloud and infrastructure, data and analytics, software product engineering, and CX transformation, operating across 18 countries. The Pune-based global software and technology services company has over 27,000 employees and partners with the world’s leading hyperscalers, building products with them, selling to them, and selling alongside them.
Sanjiv Kumar Shrivastava, Head of Enterprise Information Systems, Apps & Data, and the AI COE at Persistent Systems saw the opportunity to modernize their application access governance strategy to keep up with the pace of business and maintain the rate of innovation they were delivering to customers. Three core principles drive all initiatives at Persistent: Be Digitally Inclusive, AI-First, and Secure by Design.
Today you do segregation of duty for humans. Tomorrow your agent will have all the rights and privileges you have. How do you do segregation of duties among agents? That is going to be very critical for us and for the industry — and Saviynt already has a product and proper vision around that.
The Opportunity
Modernizing Application Access Governance for a Scaling Enterprise
Persistent Systems is a hybrid organization with roughly 70% of systems running on SaaS. Their application landscape is diverse and anchored by Oracle as the core system of record. Oracle has become the backbone of their business managing their front end, revenue operations, as well as their employee’s lifecycles. Their ‘Order to Cash’ sales motion includes the process of creating a sales lead in Salesforce, through pricing, project creation, project accounting, and delivery.
Their ‘Hire to Retire’ employee lifecycle includes the onboarding of new hires through the applicant tracking system and seeing them through job changes and termination. Access governance sits on top of Oracle, and is what Shrivastava describes as the company’s protective layer and connective tissue.
The dependency on humans to grant, change and disable access to applications was cumbersome. There were also no segregation-of-duties providing the right checks and balances over access. Users were over provisioned as a result and without the centralized visibility these blind spots put the company at risk.
Audits took months and teams were in a year long audit prep cycle because by the time one wrapped up, it was time to prepare for the next one. Shrivastava shared, “A lot of midnight oil was burnt to reduce audit issues.”
As applications, identities, and AI-driven workflows expand, Persistent recognized that governance could no longer be managed through isolated controls and periodic reviews. The company needed a continuous, business-aligned model that treats identity as the control plane for managing access risk across a rapidly evolving enterprise.
As a fast growing company, we needed a platform that was designed for our business requirements and would allow us to scale. Manual, time consuming application governance left us in continual audit mode fighting to prove compliance.
The Solution
Replacing Fragmented, Manual Application Access Governance
Before Saviynt, Oracle access at Persistent was managed through a combination of Oracle’s in-built controls, a custom role-privilege management system, and a separate ITSM ticketing tool. Access provisioning was semi-automated at best, with much time spent hopping back and forth between request and grant. Joiner-mover-leaver activity (people joining a project, moving across projects, or leaving the organization) was heavily human-driven, and the periodic audits required to keep Persistent compliant involved Excel-driven analysis, third-party reviews, and significant time, effort, and money.
Before Saviynt, application access was fragmented, manual, and a lot of human effort, with limited centralized visibility. There was no audit issue, but there was a lot of midnight oil burning to ensure that.
Identity is a thread that runs through nearly every audit. Persistent has adopted Information Technology General Controls (ITGC) and Internal Control over Financial Reporting (ICFR) principles as part of their regular auditing practices. The team needed unified, end-to-end visibility into the identity lifecycle and the ability to enforce segregation of duties (SoD) by design, not after the fact.
AI-First Solution That Scales With the Business
Persistent evaluated multiple identity platforms. While many vendors offered the core governance capabilities Persistent required, the decision ultimately came down to which platform could best support the company's long-term vision. Persistent needed more than compliance automation. They needed a modern governance model that could scale with the business and use identity as the control plane for governing access across an increasingly complex mix of applications, identities, and AI-driven workflows.
With that goal in mind, the team evaluated vendors based on how completely each platform addressed the controls their auditors care about and how effectively the provider could partner with them through implementation.
Saviynt stood out on both fronts. The platform was already aligned to ITGC and ICFR requirements, with identity control aspects baked in by design, and Saviynt’s readiness to extend the same governance model to non-human identities matched Persistent’s AI-first roadmap. Equally important, Saviynt was willing to work with Persistent to understand their business first and partner to deploy the platform to address their business requirements.
The change management aspect of application access governance rollouts requires somebody who can understand the business problem, not just say, ‘the product is like that, take it or leave it.’ Saviynt was aligned to our thought process and our vision — that was as important as any feature.
The decision ultimately came down to three priorities: strengthening compliance, improving operational efficiency, and gaining end-to-end visibility. Persistent needed a continuous governance model with identity serving as the control plane for managing access across human and non-human identities as the business continued to scale.
Accelerated Go-live
Shrivastava had aggressive implementation goals for Saviynt Identity Security Platform including its Application Access Governance capabilities. The implementation was a true joint effort across Persistent, Saviynt’s-recommended implementation partner[6] , and Saviynt’s services team.Strong executive sponsorship drove positive change management internally.
Persistent split the work into two sprints. Phase 1 was hyper-focused on a slice of the financial module including its procure to pay and invoicing to harden the platform, prove out the engineering integrations, and stabilize the workflows. The team mapped roles to Persistent’s Charter of Delegated Authority (CODA), the internal model that defines who is authorized to approve what at each level of the organization. With Phase 1 stable, Phase 2 took on real momentum, covering the rest of the Oracle ecosystem and addressing a historical inventory of 2,000+ roles that needed cleanup before go-live. By the end of the project, 27,000 active users, 6,000 roles, and approximately 900,000 data security entitlements had been onboarded onto the Saviynt platform.
Tech can do what tech can do, but with the business partnership, it was like a catalyst. The way the business team came forward and supported this initiative to go live in record time is very uncommon.
The Results
Continuous Compliance, Continuous Audit
With Saviynt Application Access Governance in production, SoD checks now happen before access is granted rather than after the fact. The CODA-driven workflow kicks in automatically: it checks whether the requestor already has conflicting access, routes elevated requests to the right approval level, and tracks the full lifecycle (joiner, mover, and leaver) without human intervention in the loop. What used to be a quarterly audit is now a continuous control embedded in every transaction.
The audit team has felt the difference most directly. What previously took 10–15 days of work each quarter, pulling in two to three people from IT and three to four people from the business, is now a report Persistent’s internal audit team can pull on demand, without needing to reach out to IT at all.
The proof of the pudding was the audit. What used to take months of Excel file churning, pivots, and VLOOKUPs is now a simple report from Saviynt. I’m hoping identity will become the least important point in the audit going forward.
Persistent is tracking outcomes against the metrics that matter most to the business rather than counting button clicks. By those measures, the team estimates a 70–80% reduction in SoD violations on a conservative basis, and expects that number to climb after another quarter or two of operation. Access-related tickets, along with the time and effort to handle them, are down by 30–50% conservatively. The cost of being compliant, in Sanjiv’s words, is now negligible.
Just as important is what the model enables culturally. Governance has shifted left: issues are caught at the point of provisioning rather than as audit findings months later. Identity ownership has moved from IT alone into a shared accountability with the business (Finance, Procurement, and HR each take responsibility for the roles their people hold) because the platform finally gives them a workable seat at the table.
Agentic Identity Governance and Non-Human Identities
Persistent's identity program is already extending beyond Phase 1. As governance expands to additional business-critical applications, Persistent also sees an opportunity to identify and reduce access risks that span systems, business processes, and identity types rather than evaluating risk within individual applications alone. As applications, automation, and AI-driven workflows continue to grow, Persistent sees identity as the control plane for enforcing policy, reducing risk, and maintaining visibility across the enterprise.
The next phase of the journey includes extending governance beyond human users to service accounts, machine identities, and AI agents. Persistent sees AI agents as fundamentally different from traditional workforce identities. While human users are often granted broad access to perform a range of responsibilities, applying the same model to AI agents can introduce significant risk. As agentic workflows become more common, governance must move beyond static provisioning and role assignments toward more dynamic authorization models that determine what actions an agent can perform in a given context. For Persistent, extending segregation-of-duties principles and authorization controls to AI agents will be a critical part of governing the next generation of enterprise identities.
Today you do segregation of duty for humans. Tomorrow your agent will have all the rights and privileges you have. How do you do segregation of duties among agents? That is going to be very critical for us and for the industry — and Saviynt already has a product and proper vision around that.
For Persistent Systems, the move to Saviynt has reframed application access governance from a quarterly scramble into a continuous, business-owned discipline, one ready to scale with the company’s growth and with the AI-driven future its leadership is already building toward.
The next phase of the journey includes extending governance beyond human users to service accounts, machine identities, and AI agents. Persistent sees AI agents as fundamentally different from traditional workforce identities. While human users are often granted broad access to perform a range of responsibilities, applying the same model to AI agents can introduce significant risk. As agentic workflows become more common, governance must move beyond static provisioning and role assignments toward more dynamic authorization models that determine what actions an agent can perform in a given context. For Persistent, extending segregation-of-duties principles and authorization controls to AI agents will be a critical part of governing the next generation of enterprise identities.
70-80%
Reduced SoD violations
across Oracle HCM, Finance, and Procurement
30–50%
Cut access-related tickets, time, and effort
7 week
Go live
Onboarded 27,000 users, 6,000 roles, and 900,000 data security entitlements




