The Mid-Market IGA Buying Guide: Why Enterprise Suites Are Overkill (and What to Buy Instead)

Enterprise IGA suites are built for 10,000-employee banks with dedicated IAM teams. If you're 500-5,000 employees with a lean IT team, here's what actually matters - and what to avoid.

8 min read · Last updated June 2026

You have 800 employees, 60-plus SaaS apps, and one IT generalist who also owns the helpdesk queue. Your auditor just asked for evidence of quarterly access reviews. You Google "IGA platform" and land on SailPoint, Saviynt, and a Gartner Magic Quadrant built for Fortune 500 procurement teams.

This guide is not for them. It's for you.

Here's the honest version: most IGA content is written for organizations with dedicated IAM engineers, multi-year implementation budgets, and the patience for a 12-month rollout. If that's not you - and for most 500-5,000 employee companies, it isn't - you need a different shortlist and different buying criteria.


Why Enterprise IGA Is the Wrong Starting Point

Enterprise IGA platforms like SailPoint and Saviynt were architected for a specific customer: large regulated enterprises with complex on-premises infrastructure, dedicated identity engineering teams, and governance programs that span mainframes, ERP systems, and thousands of custom connectors.

Both are designed primarily for enterprise organizations with dedicated IAM teams. That's not a criticism - it's a design choice. The problem is that mid-market buyers keep ending up in their sales cycles anyway, because the analyst coverage and SEO footprint make them look like the default answer.

The numbers tell the real story. Enterprise IGA - SailPoint, Saviynt, One Identity Manager - is built for organizations with thousands of users, complex on-prem infrastructure, and dedicated identity engineering teams. Implementation cycles run 12 to 18 months. Ongoing maintenance requires specialized skills. The power is real, but so is the cost and complexity.

On the cost side, the gap is even wider than most buyers expect. Based on third-party procurement data and customer reports, mid-market enterprises typically pay $100,000-$500,000+ annually for SailPoint, with professional services typically representing 30-60% of first-year total cost. Vendr's analysis of 30 verified SailPoint purchases shows the median annual contract value sits at $113,354, with deals ranging from $22,043 to $528,594. ([1])

And that's before you factor in the hidden costs. According to industry analysis, professional services costs for SailPoint implementations typically range from 2-3 times the license costs. Implementation is notoriously difficult, often taking over a year to reach maturity with professional service costs that can triple the initial software price. ([2])

The conclusion for sub-5,000 employee organizations is blunt: both SailPoint and Saviynt are designed for enterprise - the implementation overhead, ongoing maintenance requirements, and pricing frequently exceed what mid-market organizations need. ([3])

warning Warning

The enterprise IGA trap: If a vendor requires a professional services engagement before you can go live, charges per-connector fees on top of licensing, or quotes a 6–9 month deployment timeline as standard, you're looking at a tool designed for a team three times your size. Walk away and shortlist accordingly.


The SCIM Wall: Why "Modern IGA" Often Isn't Enough Either

So you skip the legacy giants and look at the newer, lighter tools - the ones marketed as "modern IGA" or "SSO-adjacent governance." Many of these are genuinely easier to deploy. But most hit a hard ceiling: they only govern apps that support SCIM.

SCIM (System for Cross-domain Identity Management) is the open standard that lets identity platforms automate account provisioning and deprovisioning. When it works, it's great. The catch is that SCIM access is frequently paywalled behind enterprise-tier SaaS plans. A recent analysis of 721 SaaS apps found that only 9 offered usable SCIM provisioning without forcing customers onto higher-priced enterprise plans - making SCIM effectively inaccessible for about 98.8% of those apps for mid-market buyers. ([4])

The practical result: most SSO and "modern IGA" tools automate the 20-40% of your stack with SCIM or APIs. The rest - niche SaaS, department-owned tools, OT/ICS, custom apps - remains manual. ([5])

Omdia research found that only 54% of available apps (SaaS, cloud infrastructure, on-prem) were adequately integrated with IGA. ([6]) That means nearly half your stack is ungoverned - and auditors don't care that SCIM wasn't available.

When 80% of an application portfolio is not connected to an IGA solution's governance or provisioning workflows, lifecycle risk compounds quickly. Departed employees may retain active accounts for days or weeks. Role changes may not trigger access reviews. Temporary access may never expire. Over time, orphaned accounts accumulate and audit trails fragment across systems that cannot be centrally reconciled. ([7])

This is the SCIM tax in action: you pay enterprise-tier SaaS prices just to unlock a provisioning protocol, and you still don't cover the long tail. For a lean team managing 60+ apps, that's not a governance strategy - it's a governance illusion.

Isometric diagram showing a mid-market IT team at a single desk with a laptop, connected by lines to a large cluster of SaaS app icons. About half the icons are lit up green (governed), the other half are dim grey (ungoverned), with a clear visual gap between the two groups. Clean, minimal style.

The Five Buying Criteria That Actually Matter at 500-5,000 Employees

Forget the enterprise RFP checklist. Here's what determines whether an IGA platform will actually work for a lean team.

1. App Coverage Breadth (Not Just SCIM Support)

The right question isn't "how many SCIM connectors do you have?" It's "what percentage of my actual app stack can you govern - including apps without SCIM or APIs?" Ask vendors to demo coverage for your specific long-tail apps: Notion, Figma, Linear, niche HR tools, internal portals. If the answer is "we'd need to build a custom connector," that's a red flag.

2. Time-to-Value (Days, Not Months)

Traditional IGA platforms like Saviynt can take six months or longer to implement, which delays the security and compliance benefits you bought the platform for in the first place. ([8]) For a mid-market team with an audit deadline in 90 days, that's a non-starter. Target platforms that can get you live in days, with first automations running in under a week.

3. Access Reviews Without a Specialist

Access certification campaigns are where most lean teams drown. The right platform should let a non-IAM-specialist - a department manager, a compliance lead - run a meaningful access review without needing to understand role mining or entitlement hierarchies. If the review workflow requires training, it won't get done.

4. Full Joiner-Mover-Leaver Automation

Onboarding and offboarding are the highest-frequency, highest-risk identity events. The platform needs to automate the full JML cycle across your entire app stack - not just the SCIM-friendly 30%. Benchmarks show organizations routinely waste 30-50% of SaaS budgets on unused or underused licenses. ([4]) Automated deprovisioning is the fix - but only if it reaches every app.

5. Predictable, Per-User Pricing

Opaque enterprise pricing - custom quotes, per-connector fees, module add-ons, professional services multipliers - is a budget risk you can't afford. Look for transparent per-user pricing with no hidden connector costs and no requirement to upgrade target apps to enterprise tiers just to enable governance.


Red Flags: Walk Away When You See These

block Caution

Red flags in an IGA vendor evaluation:

  • Requires a full-time admin to operate — if the vendor's own documentation assumes a dedicated IAM engineer, the platform isn't built for your team size.
  • Per-connector fees — paying extra for each integration compounds fast across a 60-app stack and creates perverse incentives to leave apps ungoverned.
  • 6–9 month standard deployment — this is an enterprise implementation timeline. Mid-market teams can't wait that long and shouldn't have to.
  • Professional services required to go live — if you can't self-serve the initial setup, you're buying a consulting engagement, not a product.
  • SCIM-only coverage — if the vendor can't govern apps without SCIM endpoints, you'll be back to spreadsheets for 60–80% of your stack.
  • Opaque pricing — if you can't get a per-user number without a sales call, assume the number is too high for your budget.

A Practical Shortlisting Framework

Before you book demos, run every candidate through this scorecard. Score each criterion 1-5 and weight by importance to your situation.

How to Use the Scorecard in Practice

Run this before your first demo, not after. It forces you to weight criteria against your actual situation - a company chasing SOC 2 in 60 days should weight time-to-value higher; one with a sprawling SaaS stack should weight coverage breadth highest.

Use the same scorecard for every vendor you evaluate. The discipline of scoring consistently exposes the gap between demo polish and real-world fit.


Where Different Vendors Actually Fit

To be direct about the landscape:

If you're a massive enterprise - big IAM team, multimillion-dollar budget, multi-year plan - legacy players still serve. But if you're managing identity for 200, 800, or 1,500 people with a handful of admins and a labyrinth of non-SCIM SaaS, you need different tools. ([9])

For the mid-market specifically:

  • SailPoint / Saviynt - right fit for large enterprises with dedicated IAM teams and complex on-prem environments. Wrong fit if you're under 5,000 employees without a staffed IAM function.
  • Okta Identity Governance / Microsoft Entra ID Governance - solid if you're all-in on one SSO ecosystem and your app stack is mostly SCIM-friendly. Coverage gaps appear fast once you hit the long tail.
  • ConductorOne / Lumos - faster to deploy than legacy platforms, good for workflow-centric access reviews. Still primarily SCIM-dependent for provisioning automation.
  • Iden - built specifically for the 50-2,000 employee, SaaS-heavy, lean-IT segment. Iden's universal connector technology reaches 175+ apps (and counting), including apps without SCIM or APIs, with new custom connectors delivered in approximately 48 hours. ([5]) Iden customers report 80% fewer access tickets, 120 hours saved per quarter on access reviews, and up to 30% SaaS spend reduction from license reclamation and avoiding SCIM-driven upgrades. ([9]) Deployments go live in approximately 24 hours, with no dedicated IAM admin required.
CriterionEnterprise IGA (SailPoint/Saviynt)SCIM-Only Modern IGAIden (Universal Coverage)
Deployment time6–18 months4–12 weeks~24 hours
App coverageBroad (with custom connectors)SCIM apps only (~20–40% of stack)175+ apps incl. non-SCIM
Dedicated admin required?YesOftenNo
Per-connector fees?CommonSometimesNo
Access reviews without specialist?DifficultModerateYes
Pricing transparencyOpaque / customModeratePer-user, predictable
Best fit10,000+ employees, IAM teamSCIM-heavy stacks, SSO-first500–2,000 employees, lean IT

The Honest Caveat

Iden is not the right answer for every mid-market company. If you have a heavily on-premises environment with mainframe dependencies, complex SAP SoD requirements, or a staffed IAM team ready to run a multi-year program, a legacy platform may still be the right call. The point isn't that enterprise IGA is bad - it's that it's wrong-sized for most companies in the 500-5,000 employee range.

The mistake to avoid is buying enterprise ceremony when you need operational coverage. A platform that governs 100% of your apps on day 30 beats one that promises to govern 100% of your apps after an 18-month rollout.


Your Next Step

If you're actively shortlisting, the scorecard above is your starting point. Run every vendor through it before you book a demo. Then ask each vendor three questions that separate real fit from sales theater:

  1. "Can you show me governance for [specific non-SCIM app in our stack] - live, not in a roadmap?"
  2. "What does a non-IAM-specialist need to do to run a quarterly access review?"
  3. "What's the all-in per-user cost, including connectors, professional services, and support?"

The answers will tell you more than any feature matrix.

For more context on the broader IAM landscape, see our 10 Best IAM Tools for Fast-Growing Teams in 2026 and Identity-First Security Architecture for Lean Teams.

Related reading