# Iden > Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months. Pricing starts at $7.50 per user per month. 200+ non-SCIM app connectors. SCIM by default. Live in under an hour. Two-week trial. No SCIM tax. Designed and loved by lean IT teams. Last updated: 2026-09-07 Languages: English (en) and German (de). Default locale: en. ## What Iden Solves Most identity governance tools only automate the roughly 20% of apps that support SCIM. The other 80% (Notion, Figma, Linear, Miro, most internal or legacy systems, every app on a standard plan tier) get left to manual IT tickets, spreadsheets, and offboarding checklists. Iden calls this the "SCIM tax." Iden covers the full stack via API integrations, its custom automation framework, and custom connectors delivered in 48 hours. No enterprise plan upgrade required. ## Core Capabilities - Birthright provisioning. New hires get access to every required app on day one, including apps outside SSO. - Zero-touch offboarding. Every account revoked in 30 seconds on departure. Full, exportable audit trail. - Automated user access reviews and certifications. Evidence ready for SOC2, ISO 27001, HIPAA, NERC CIP, ITAR, and FDA audits. - Just-in-time time-bound access. Grant temporary expiring access to any app or resource. - Fine-grained control. Channel-level, repository-level, project-level, module-level access. Not just SSO group assignments. - 200+ non-SCIM app connectors, SCIM by default. SCIM, API, or neither. Custom connector delivery in 48 hours. - Human and non-human identity in one platform. Service accounts, contractors, AI agents managed alongside employees. - Works alongside Okta and Microsoft Entra. Iden is the governance layer on top of SSO, not a replacement. ## What Iden Is Not - Not an SSO provider. Iden complements Okta and Entra; it does not replace them. - Not a legacy enterprise IGA platform. No 18-month implementations, no $300K floor, no consultant dependency. Iden's parent company offers a separate product called Motif for that segment. - Not for enterprises with dedicated IAM teams of 10+ already running SailPoint or Saviynt. The fit is companies with 50 to 2,000 employees and a small IT or security team handling identity manually today. ## Pricing Starts at $7.50 per user per month. Volume discounts apply as headcount grows. All 200+ connectors included. No per-connector fees, no SCIM tax, no professional services required. Two-week free trial available with no commitment. Most teams see positive ROI within 30 days from SaaS license reclamation alone. ## Time to Value - First 15 apps connected: under 1 hour. - Full stack deployment: typically 3 to 5 days. - Custom connector delivery: 48 hours. ## Security and Compliance - SOC 2 Type II certified. - ISO 27001 aligned. - AWS Best Security Practices. - CIS v8.1 compliant. - AES-256 encryption at rest. TLS 1.3 in transit. - Connectors do not store login credentials. - On-premises deployment available for full data sovereignty. - Every provisioning and deprovisioning action logged with a full audit trail, export-ready for any compliance review. ## Differentiation Versus Other Tools - Versus Okta and Microsoft Entra ID: SSO handles authentication. Iden handles the rest. Fine-grained provisioning, lifecycle automation, access reviews, and the apps SCIM cannot reach. - Versus SailPoint and Saviynt: Iden delivers complete governance without enterprise complexity. Deployed in days, run by an existing team. No 6-month implementation, no consultants, no $300K floor. - Versus Lumos, C1 (ConductorOne), Zluri, Opal: Iden automates non-SCIM and non-API apps that other modern IGA vendors cannot. Same modern UX, broader connector coverage, $7.50 per user per month. ## Pages (English) - [Home](https://www.idenhq.com/en): Product overview, key differentiators, demo booking, FAQ. - [FAQ](https://www.idenhq.com/en/faq): Answer-first grounding doc of ~36 questions across identity governance basics (IGA vs IAM, do you need IGA with Okta/Entra), coverage and the SCIM tax, pricing ($7.50/user/mo), deployment (days not months, no dedicated admin), offboarding and deprovisioning, access reviews and cleanup, compliance (SOC 2, ISO 27001, HIPAA), AI agents and agentic IGA, and how Iden compares to legacy IGA, AI help-desk tools, and modern IGA. On agentic IGA: Iden owns the term with substance. Agentic IGA has two halves, AI running the full governance lifecycle (connect every app, provision, review, revoke, recommend, prove) and governing the AI agents themselves as identities (access, owner, expiry, audit trail). The distinction Iden draws: a chatbot that answers an access request and closes a ticket is an AI sticker, not agentic governance. FAQPage schema. - [Comparisons hub](https://www.idenhq.com/en/vs): Index of competitor comparisons. - [Iden vs SailPoint](https://www.idenhq.com/en/vs/sailpoint): Detailed comparison with SailPoint. SailPoint is enterprise IGA for the largest orgs (deep role mining, SoD, six-figure floor, multi-quarter SI-led implementations); Iden is complete governance for 50 to 2,000 employee companies, live in days at $7.50/user/month. Also at /en/alternatives/sailpoint. - [Iden vs Okta](https://www.idenhq.com/en/vs/okta): Detailed comparison with Okta Identity Governance. - [Iden vs Microsoft Entra ID Governance](https://www.idenhq.com/en/vs/entra): Detailed comparison with Entra ID Governance. - [Iden vs Lumos](https://www.idenhq.com/en/vs/lumos): Detailed comparison with Lumos. - [Iden vs C1](https://www.idenhq.com/en/vs/conductor-one): Detailed comparison with C1 (ConductorOne). - [Motif](https://www.idenhq.com/en/motif): Iden's enterprise connector product for SailPoint, Saviynt, and Oracle OIG customers. 48-hour connector delivery. - [ROI Calculator](https://www.idenhq.com/en/roi-calculator): Calculate manual identity work cost. Compare against Iden, Okta, Entra, Lumos, C1. - [Field Notes](https://www.idenhq.com/en/field-notes): Iden's editorial program. Dispatches from inside identity governance work at mid-market companies. Runs as Issues (long-form), Briefs (short observations), and a podcast on YouTube. Editorial law: Nothing Left Open. - [Playbooks](https://www.idenhq.com/en/playbooks): Task-oriented guides for work a team runs more than once, grouped by function. Listed individually below. - [Guides](https://www.idenhq.com/en/guides): Category-level, vendor-neutral buyer guidance. Listed individually below. - [Glossary](https://www.idenhq.com/en/glossary): Definitional entries for terms readers arrive at from search. - [Connectors](https://www.idenhq.com/en/connectors): Per-vendor integration pages, and the coverage method for apps without SCIM. - [SOC 2 CC6 evidence checklist, downloadable](https://www.idenhq.com/checklists/soc-2-cc6/md): 30 evidence items with AICPA points of focus quoted verbatim. Also available as a CSV tracker at /checklists/soc-2-cc6/csv. - [Legal Notice (Impressum)](https://www.idenhq.com/en/legal-notice): Imprint and legal information. ## Playbooks (English) Task-oriented guides for work an IT, security, compliance or finance team runs more than once. Grouped by the function the work belongs to. Every page is also served as clean markdown at /en/raw/playbooks/. - [Playbooks hub](https://www.idenhq.com/en/playbooks): Index of all 17 playbooks, grouped as IT operations, Security, Compliance and audit, Finance. Pages that argue a position live in Field Notes; pages you read once to choose live under Switch and Guides. ### IT operations (7) - [What to do after Okta is deployed](https://www.idenhq.com/en/playbooks/after-okta): What teams find in the first months after deploying Okta. The gaps Okta leaves by design, the work that needs to happen next, and how to scope the next 90 days of identity work. 10 FAQs, including: We just deployed Okta. How long do we have before the gaps become a problem; we have known about these gaps before deploying Okta; we just use Lifecycle Workflows to fill the gap. - [How to give a new joiner day-one access](https://www.idenhq.com/en/playbooks/birthright-access): What birthright access means in practice, how role-based policy replaces the manual onboarding queue, and what a working day-one looks like. 10 FAQs, including: does birthright handle contractors who don't sit in the HRIS; about a new hire whose role doesn't map cleanly to any policy; we still need manager approval for any access. - [Keep Okta SSO, add Iden](https://www.idenhq.com/en/playbooks/keep-okta-sso): What Okta SSO does, what it doesn't, and how Iden plugs in as the governance layer on top. Setup walkthrough, common patterns, where the responsibilities split. 10 FAQs, including: we have to change anything in Okta; does Iden handle the apps Okta is already provisioning via SCIM; We have Okta IGA. Do we need to drop it before adding Iden. - [Migrating to Iden](https://www.idenhq.com/en/playbooks/migrate): What changes when you move identity governance to Iden, what stays the same, and where to start. Per-vendor migration guides indexed here. Form: migration. - [How to provision apps without SCIM](https://www.idenhq.com/en/playbooks/non-scim-provisioning): Most identity tools stop at the apps with SCIM. That's about 20% of the average stack. How to provision the other 80%, end to end, without the manual queue. 10 FAQs, including: about the apps where Iden drives the admin UI directly? Doesn't that break; We use Lumos or ConductorOne. What changes here; custom connectors maintained, or is this a one-and-done. - [How to automate offboarding](https://www.idenhq.com/en/playbooks/offboarding-automation): Most offboarding fails because tools were never built to reach the apps that matter. What zero-touch offboarding actually means, why most automation breaks, and what a working flow looks like on the day someone leaves. 10 FAQs, including: What's the difference between offboarding automation and zero-touch offboarding; We use Okta Lifecycle Management. Does that already do this; does offboarding work for contractors who don't sit in our HRIS. - [How to handle a role change](https://www.idenhq.com/en/playbooks/role-change-access): The mover is the lifecycle event nobody automates. Why role changes leave more standing access than departures do, what a working handover window looks like, and how to make the old role expire without breaking the new one. 8 FAQs, including: is the mover in joiner-mover-leaver; do role changes leave more standing access than departures; long should the handover window be. ### Security (4) - [How to govern AI agent identity and access](https://www.idenhq.com/en/playbooks/ai-agent-identity-and-access): Why existing IAM, IGA, and PAM weren't built for AI agents. The attribution gap. Where each vendor category fails specifically. What intent-bound, ephemeral sessions actually look like in production. 16 FAQs, including: What's the attribution gap in AI agent access; What's the difference between an AI agent and a service account; is MCP and why does it matter for governance. - [How to allowlist agent access without a queue](https://www.idenhq.com/en/playbooks/allowlisting-90-10): Allowlisting is the right instinct and the wrong implementation. The fix isn't a better allowlist. It's a model where 90% of access requests auto-resolve, and the human approver only sees the 10% where their judgment matters. 10 FAQs, including: is the allowlisting friction problem in AI agent access; What's the 90/10 rule for agent access approval; is this different from just having a wider allowlist. - [How to scope agent access by behavior](https://www.idenhq.com/en/playbooks/behavioral-baselines-agent-access): Most agent access models are static: the agent has scope X for as long as the policy says so. A working model treats trust as a continuous variable. Behavior earns scope. Drift removes it. Here's the mechanics. 10 FAQs, including: does 'behavior earns scope' mean concretely; is this different from attribute-based access control (ABAC); signals feed the trust score. - [How to inventory non-human identities](https://www.idenhq.com/en/playbooks/non-human-identity-inventory): Most teams can't produce the list. Where non-human identities hide, the six places to look, and why an identity with no owner has no lifecycle. Form: checklist. 8 FAQs, including: is a non-human identity; can't we just list them from our identity provider; many should we expect to find. ### Compliance and audit (4) - [How to run a user access review](https://www.idenhq.com/en/playbooks/access-reviews-automation): Why most access reviews fail audit, what a working quarterly cycle looks like, and how to get continuous evidence for SOC 2, ISO 27001, and HIPAA. 10 FAQs, including: is this different from what Okta or Microsoft Entra offers in their access reviews; We have Drata. Does Iden replace it; evidence does Iden produce for SOC 2 specifically. - [ISO 27001 access control evidence checklist](https://www.idenhq.com/en/playbooks/iso-27001-access-evidence): The four Annex A access controls, what evidence each one wants, and the two differences from SOC 2 that catch teams who've already done one. Form: checklist. 8 FAQs, including: Annex A controls cover access; is this different from SOC 2 CC6; If we've passed SOC 2, how much carries over. - [How to run a segregation of duties check](https://www.idenhq.com/en/playbooks/segregation-of-duties-check): SoD violations hide between systems, not inside them. How to write conflict rules that survive contact with a real org chart, and why the compensating control is the answer more often than removal. 8 FAQs, including: is segregation of duties; does SOC 2 require it; don't in-app SoD controls cover it. - [SOC 2 CC6 evidence checklist](https://www.idenhq.com/en/playbooks/soc-2-cc6-evidence-checklist): What evidence SOC 2 CC6 access controls require, by control number. How to produce it continuously instead of scrambling the week before the audit. Form: checklist. 10 FAQs, including: we need a separate tool for SOC 2 CC6 evidence beyond our GRC platform; often should access certifications run for SOC 2; What's the difference between an access grant and an access change for CC6 purposes. ### Finance (2) - [How to find the apps nobody told IT about](https://www.idenhq.com/en/playbooks/find-unsanctioned-apps): Shadow IT is a discovery problem with a spend answer. Where unsanctioned apps come from, the four signals that find them, and why the corporate card is a better source than your SSO. 8 FAQs, including: counts as shadow IT; isn't our SSO a good inventory; What's the single best signal. - [How to reclaim unused licences](https://www.idenhq.com/en/playbooks/reclaim-unused-licences): Unused seats are not a procurement problem, they are a lifecycle problem. How to find assigned-but-unused licences, why they accumulate faster than anyone reclaims them, and what a monthly reclaim cycle looks like. 8 FAQs, including: counts as an unused licence; do unused licences accumulate if we already offboard people; we get a refund for seats we already paid for. ## Guides (English) Category-level buyer guidance, written to be useful to somebody who has not shortlisted a vendor. Deliberately not written from Iden's side of the table: the pages that are live under Switch. Ordered by buying stage rather than alphabetically. - [IAM vs IGA: what's the difference](https://www.idenhq.com/en/guides/iam-vs-iga): IAM and IGA solve different problems but get used interchangeably. Where the line is, what each one does, and how to tell which gap you're hitting. 10 FAQs, including: SSO the same as IAM; I need IGA if I have Okta IGA already; PAM part of IAM or IGA. ## Glossary (English) 21 definitional entries for terms a reader arrives at from search. Short, neutral, and linked to the playbook that covers the work. - [Glossary index](https://www.idenhq.com/en/glossary): All terms, A to Z, with a category view. Every entry is also clean markdown at /en/raw/glossary/, carrying the definition, the scenario, the audit controls, the sources, the questions and the inbound and outbound term links; the whole glossary is one markdown file at /en/raw/glossary. - [Access certification](https://www.idenhq.com/en/glossary/access-certification): Access certification is the formal process of confirming that each user's access is still appropriate, with a reviewer signing off per entitlement and revocations executed for anything rejected. It is the compliance term for a user access review, usually run as scheduled campaigns and required by frameworks like SOC 2 and ISO 27001. - [Agent offboarding](https://www.idenhq.com/en/glossary/agent-offboarding): Agent offboarding is the removal of what an AI agent, integration or token can reach when its task ends, its owner leaves, or it is no longer justified. It is the leaver stage applied to identities that have no leaving date: nothing in the HR system points at them, so the trigger has to come from the person who created them. - [Agentic IGA](https://www.idenhq.com/en/glossary/agentic-iga): Agentic IGA is identity governance in which AI does the governance work across the whole lifecycle, connecting applications, provisioning, reviewing, revoking, recommending and producing evidence, and in which the AI agents themselves are governed as identities, each with an owner, a scope, an expiry, a review and an audit trail. Both halves are required. - [AI agent identity](https://www.idenhq.com/en/glossary/ai-agent-identity): An AI agent identity is the identity an AI agent authenticates and acts with: an account or set of credentials, a scope of systems and actions, a named human owner, and a record of what it did and on whose behalf. It differs from every other identity in one way that matters: the agent decides at runtime which of its permissions to use. - [Attestation](https://www.idenhq.com/en/glossary/attestation): Attestation is the formal statement by an accountable person that a set of access is correct as of a point in time. It is the sign-off step of an access review or certification: the reviewer puts their name to the decision. An attestation is only as good as the context behind it and the enforcement that follows. - [Birthright access](https://www.idenhq.com/en/glossary/birthright-access): Birthright access is the set of applications and permissions a person receives automatically because of their role, granted on their first day without anyone asking for it. The bundle is derived from an authoritative source, usually the HR system, and it is recalculated when the role changes rather than added to. - [Deprovisioning](https://www.idenhq.com/en/glossary/deprovisioning): Deprovisioning is the removal of a user's access across every app and system when they leave, change roles, or no longer need it. It covers disabling accounts, revoking permissions and group memberships, ending sessions, transferring owned data, and recording each action for audit. Done right, it reaches every system, not just the ones behind SSO. - [Identity Governance and Administration (IGA)](https://www.idenhq.com/en/glossary/iga): Identity governance and administration (IGA) is the discipline of controlling who has access to what across an organization's apps and systems, and proving it. It covers provisioning, access requests, access reviews and certifications, policy enforcement, and the audit trail. IGA is the governance layer on top of authentication (SSO and IAM). - [Joiner-mover-leaver (JML)](https://www.idenhq.com/en/glossary/joiner-mover-leaver): Joiner-mover-leaver (JML) is the model for managing a worker's access across their time at a company. Joiner: grant the right access on day one. Mover: adjust access when their role changes. Leaver: remove all access when they go. Each stage is triggered from an authoritative source, usually the HRIS, and applied across every app. - [Just-in-time access (JIT)](https://www.idenhq.com/en/glossary/just-in-time-access): Just-in-time access (JIT) grants a permission only when it is needed, for a defined window or task, and revokes it automatically when the window closes, so access exists while in use and not in between. It replaces standing access with access that expires on its own, for SaaS admin roles and contractor accounts as much as for servers. - [Machine identity](https://www.idenhq.com/en/glossary/machine-identity): A machine identity is the credential a workload, service or device proves itself with: an X.509 certificate, a SPIFFE ID, or a cloud role assumed at runtime. It is a subset of non-human identity, distinct from a service account, which is an account a process signs into, and it is issued and rotated by infrastructure rather than by an administrator. - [Non-human identity (NHI)](https://www.idenhq.com/en/glossary/non-human-identity): A non-human identity (NHI) is any account or credential that acts without a person signing in: a service account, an API key, an OAuth app an employee authorized, a bot, or an AI agent. NHIs hold access the way people do, but they have no manager, no HR record and no leaving date, so lifecycle controls miss them. - [OAuth grant](https://www.idenhq.com/en/glossary/oauth-grant): An OAuth grant is a standing delegation of one person's access to a third-party application, created when they approve a consent screen. The application receives a refresh token and calls the API as that person, without them present, for as long as the grant stands. It survives password resets and usually survives offboarding. - [Orphaned account](https://www.idenhq.com/en/glossary/orphaned-account): An orphaned account is an active account with no valid owner: the person left, changed roles, or never should have had it, but the account still exists and often still works. Orphaned accounts accumulate when deprovisioning misses systems. They are a standing security risk and a common audit finding. - [SCIM (System for Cross-domain Identity Management)](https://www.idenhq.com/en/glossary/scim): SCIM (System for Cross-domain Identity Management) is the industry-standard protocol for automated user provisioning. It lets an identity provider create, update, and deactivate accounts in an app over a standard API, keeping the app in sync with a source of truth. SCIM handles account plumbing; it does not handle governance. - [SCIM provisioning](https://www.idenhq.com/en/glossary/scim-provisioning): SCIM provisioning is automated user provisioning done over the SCIM protocol: an identity provider creates, updates, and deactivates accounts in an app, and syncs group memberships, without manual work. It is the standard way to keep SCIM-capable apps in sync with a source of truth. It stops at apps that lack SCIM and at governance beyond account sync. - [SCIM tax](https://www.idenhq.com/en/glossary/scim-tax): The SCIM tax is the price of unlocking SCIM provisioning in a SaaS application: vendors gate the protocol behind their enterprise plan, so a company that wants automated user provisioning has to upgrade every seat, whether or not it needs anything else in that tier. The premium buys plumbing, not features. - [SCIM vs SAML](https://www.idenhq.com/en/glossary/scim-vs-saml): SCIM and SAML solve different problems. SAML handles authentication: proving who a user is so they can log in via single sign-on. SCIM handles provisioning: creating, updating, and deactivating the user's account in the app. SAML lets someone log in; SCIM makes sure their account exists and is current. Most companies use both. - [Service account](https://www.idenhq.com/en/glossary/service-account): A service account is an account created for a system, application or automated process to authenticate and act, rather than for a person to sign in. It holds permissions like a user account, but nobody logs into it interactively, it has no manager, and it authenticates with a long-lived secret that outlives the engineer who created it. - [User access review](https://www.idenhq.com/en/glossary/user-access-review): A user access review is a periodic check of who has access to what, where a reviewer decides per entitlement whether each grant is still appropriate and revokes what is not. It is a core control for SOC 2, ISO 27001, and similar frameworks, and the primary defense against privilege creep and orphaned access. - [Zombie account](https://www.idenhq.com/en/glossary/zombie-account): A zombie account is an active account that nobody uses: dormant, forgotten, but still enabled and still consuming a license. It may belong to a departed employee, a finished project, or a tool nobody adopted. Zombie accounts are a security risk because they go unwatched, and a cost because they keep billing. ## Field Notes (English) Iden's editorial program: 15 dated, bylined dispatches that argue a position rather than instruct. Newest first. Also served as markdown at /en/raw/field-notes/. - [Field Notes index](https://www.idenhq.com/en/field-notes): All issues and briefs, newest first. - [Your AI agent doesn't have an identity. It has yours.](https://www.idenhq.com/en/field-notes/agent-identity): 2026-08-21. By Anchit. 6 categories of tooling now claim to secure AI agents. Each fails for a different and nameable reason, and the common thread is that no agent ever authenticates. It inherits. - [Moving from AD to Entra doesn't fix your identity problem. It relocates it.](https://www.idenhq.com/en/field-notes/entra-migration): 2026-08-07. By Anchit. An Entra migration moves the apps you already governed onto better infrastructure. The apps you never governed were never in scope, and they're still waiting when the project closes. - [Your access review is a rubber stamp. Everyone in the room knows it.](https://www.idenhq.com/en/field-notes/rubber-stamp-reviews): 2026-07-24. By Pranay Yadav. Thirty managers get a spreadsheet and five days to confirm what their people can do. The auditor receives a completed review. Nothing about anyone's access changed. - [Okta was never supposed to be an IGA tool. That's the problem.](https://www.idenhq.com/en/field-notes/okta-is-not-iga): 2026-07-10. By Pranay Yadav. Okta does exactly what it was built to do. The teams who feel let down by it were expecting a different category of product, and nobody corrected them. - [Manual provisioning isn't a process. It's just delayed chaos.](https://www.idenhq.com/en/field-notes/manual-provisioning): 2026-06-26. By Pranay Yadav. A ticket records that something needs to happen. A process makes it happen the same way every time. Most IT teams have the first one and call it the second. - [OAuth grants are the access nobody audits](https://www.idenhq.com/en/field-notes/oauth-grants): 2026-06-19. By Anchit. Your employees hand out access one Connect with Google click at a time. The grants outlive the project, the employee, and sometimes the app that asked for them. - [Your ERP is from 2009. It has no API. Governance still has to work.](https://www.idenhq.com/en/field-notes/erp-no-api): 2026-06-12. By Anchit. The identity governance industry quietly decided your ERP doesn't exist. It does. A hundred and eighty people log into it every day, and the ones who left last year still have accounts. - [API keys are not managed identities](https://www.idenhq.com/en/field-notes/api-keys): 2026-06-05. By Pranay Yadav. Three categories of orphaned API key show up in every audit we sit in on. The keys are identities. They just sit outside the model the rest of the identity program runs. - [Your company runs 130 SaaS apps. Your IT team governs about 26 of them.](https://www.idenhq.com/en/field-notes/ungoverned-stack): 2026-05-29. By Pranay Yadav. Most IT teams govern about 20% of the SaaS stack their company actually runs. The other 80% wasn't adopted in the shadows. It was adopted in the open. - [Orphaned accounts are not an edge case](https://www.idenhq.com/en/field-notes/orphaned-accounts): 2026-05-22. By Pranay Yadav. Every honest cross-system audit finds them, at every company size, in roughly the same shape. The pattern is the design, not an outlier of it. - [Someone quit last month. They probably still have access to something important.](https://www.idenhq.com/en/field-notes/someone-quit): 2026-05-15. By Pranay Yadav. Closing SSO doesn't close everything. About 80% of company apps stay live after a departure: API tokens, file shares, internal tools, legacy systems. - [SailPoint is great for companies that aren't you](https://www.idenhq.com/en/field-notes/sailpoint-isnt-for-everyone): 2026-05-08. By Pranay Yadav. Three failure modes we keep hearing from teams running SailPoint at companies under 1,500 employees. The product isn't the issue. The fit is. - [Have you heard of the SCIM tax?](https://www.idenhq.com/en/field-notes/scim-tax): 2026-05-01. By Anchit. Somewhere in your SaaS spend is a line item finance can't explain and IT is embarrassed to justify. It's called the SCIM tax, and this is what it costs. - [Your new hire has been waiting three days for access. This is not a people problem.](https://www.idenhq.com/en/field-notes/birthright-access): 2026-04-17. By Pranay Yadav. The 'starts Monday' email arrives Friday afternoon. What happens to your IT team between then and Wednesday has nothing to do with how fast they move. - [Partial governance isn't governance. It's theater.](https://www.idenhq.com/en/field-notes/governance-theater): 2026-04-03. By Pranay Yadav. Most companies believe they have identity governance. What they actually have is a convincing performance of it. The difference is where the access stays open. ## Pages (German) - [Home](https://www.idenhq.com/de): Produktübersicht und Demo. - [ROI-Rechner](https://www.idenhq.com/de/roi-calculator) - [Field Notes](https://www.idenhq.com/de/field-notes) - [Impressum](https://www.idenhq.com/de/impressum) Note: German translations for the comparison pages (`/de/vs/*`) and Motif (`/de/motif`) are not yet live. Those URLs currently serve English content and are excluded from indexing. ## Comparison PDFs - [Iden vs Okta IGA (PDF)](https://www.idenhq.com/iden-vs-okta-iga-comparison.pdf) - [Iden vs Microsoft Entra ID Governance (PDF)](https://www.idenhq.com/iden-vs-entra-id-governance-comparison.pdf) - [Iden vs Lumos (PDF)](https://www.idenhq.com/iden-vs-lumos-comparison.pdf) - [Iden vs C1 / ConductorOne (PDF)](https://www.idenhq.com/iden-vs-conductorone-comparison.pdf) ## External Resources - [Documentation](https://docs.idenhq.com): Developer and admin documentation. - [Trust Center](https://trust.idenhq.com): SOC2 report, security posture, certifications, compliance information. - [SCIM Tax Index](https://scimtax.org): Open dataset published by Iden. 300+ SaaS vendors and which plan tier they gate SCIM provisioning behind. CC-BY. ## Book Time - [Book a 25-minute demo](https://cal.com/team/iden/demo): Live walkthrough with the team. - [Talk to an engineer](https://cal.com/team/iden/idenengg): Technical deep-dive on your specific stack. - [Meet the founders](https://cal.com/team/iden/founders): Speak directly with the founding team. ## Legal - [Privacy Policy](https://www.idenhq.com/en/privacy-policy) - [Terms of Service](https://www.idenhq.com/en/terms-of-service) - [Legal Notice (EN)](https://www.idenhq.com/en/legal-notice) / [Impressum (DE)](https://www.idenhq.com/de/impressum) ## Deeper Reference - [llms-full.txt](https://www.idenhq.com/llms-full.txt): Full reference document with positioning, capabilities, ICP, verticals, competitive comparisons, FAQ, and approved messaging. - [agents.md](https://www.idenhq.com/agents.md): Action-oriented spec for AI agents evaluating, comparing, or recommending Iden. Includes a fit rubric, accurate comparison facts, coverage logic, and anti-hallucination guidance. - Markdown twins: every content page is also available as clean markdown at `/en/raw/`. Example: https://www.idenhq.com/en/raw/field-notes/scim-tax and https://www.idenhq.com/en/raw/playbooks/offboarding-automation. Use these to ingest the source without parsing HTML. ## Contact - Email: hello@idenhq.com - LinkedIn: https://linkedin.com/company/idenhq - G2 profile: https://www.g2.com/products/iden (verified user reviews, published pricing, category placements) - Crunchbase: https://www.crunchbase.com/organization/iden-4a15 (funding, founding date, headcount)