Live intel Wed · 09 Sep 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 15 Sponsored by — your logo here — Subscribers: 24,880
// Good morning, defenders.

Last issue we made a bold, falsifiable prediction about what CrowdStrike would announce at Fal.Con — built entirely on job postings rather than teasers — and then promised to grade ourselves in public. Good news for our credibility, mixed news for the concept of surprise: we mostly nailed it. Agentic Identity Provider is real, Continuous Identity extended everywhere we said it would, the endpoint-to-browser-to-cloud fabric shipped, supply-chain protection landed. We'll show our work below, including the one call we got wrong and the thing we completely missed. A prediction you don't grade is just a horoscope.

The rest of the week kept pace: Proofpoint circling Varonis for ~$5.4B, Saviynt closing a $255M investment that is much more interesting than the headline once you read the fine print — and a small filing in a UK companies registry that, read alongside that raise, tells a story nobody at Saviynt is telling out loud. Then our vendor assessment of Omada, the quietly excellent European IGA that almost nobody in America talks about and probably should. Let's get into it.

01

Market Movers

the week, distilled — & why it lands on your desk

M&A$5.4B

Proofpoint circles Varonis — Thoma Bravo builds a data-plus-human-risk giant

Reuters, Bloomberg and the WSJ all reported Proofpoint (Thoma Bravo-owned since a $12.3B take-private in 2021) is in advanced talks to acquire data-security firm Varonis, sending Varonis up ~10–13% to a market value near $5.4B. Nothing's signed and another bidder could still emerge, but the logic is clean: Proofpoint protects the human attack surface, Varonis protects and classifies the data behind it. Together that's a data-security-plus-human-risk platform — and, notably, another data-security consolidation right as data and identity keep converging (see: Cyera/Oasis, ServiceNow/Veza).

Why it matters: if you run Varonis for DSPM or data access governance, a change of control is now a live scenario — model it. And note the pattern: data security is consolidating on exactly the timeline identity security did, which means the "who can access what data" question keeps getting bought up into fewer, larger platforms.
Funding$255M

Saviynt's "$255M investment" is mostly a secondary — read the structure

Carrick Capital announced a $600M single-asset continuation vehicle for Saviynt on Aug 31, including a $255M new commitment — Carrick's largest-ever investment, led by Coller Capital with HSBC Asset Management co-leading. But read what it actually does. It "gave Carrick's existing limited partners the option to roll their equity into the continuation vehicle or realize an 11x gross multiple," and the new money "helped fund a tender offer that provided liquidity to Saviynt employees," completing the final close of the previously announced $700M Series B at the same ~$3B valuation.

Why it matters: this is not fresh growth capital hitting the balance sheet to build product. It's primarily a liquidity event — cashing out early Carrick LPs and letting employees sell — wrapped inside a Series B close. A continuation vehicle at a flat valuation is a fund telling its LPs "we're not selling this yet, take your money or stay in," which is a very different signal from a step-up growth round. Deep dive below.
Fal.ConAgentic IdP

CrowdStrike ships Agentic Identity Provider — our prediction, graded below

At Fal.Con (Sep 2), CrowdStrike introduced the Agentic Identity Provider in Falcon Next-Gen Identity Security, giving every AI agent a trusted identity tied to the human and workload behind it, with short-lived access, MFA requirements, and continuous authorization from the SGNL acquisition. It also extended modern privileged access across SaaS, endpoints, code repos and cloud; shipped software-supply-chain protection that blocks malicious package installs at the endpoint; unified NHI ownership and visibility; and brought the Falcon platform to Anthropic's Claude marketplace. Sentonas flagged "more exciting Agentic IdP announcements at Fal.Con Europe in November."

Why it matters: the identity control plane fight just got more real. CrowdStrike is now shipping an actual agent IdP — competing with the very concept Okta, Entra and the IGA vendors are building toward. We predicted almost exactly this in Issue 14; the scorecard is in the special segment.
Earnings·context-6%

CrowdStrike's stock fell during its own conference — a useful reality check

Even as CrowdStrike blanketed Fal.Con with launches, CRWD traded down roughly 6% across the event days. Nothing broke — the announcements were well received — but the market has grown selective about "AI security" narratives from companies already priced for perfection. It's a healthy reminder heading into the Saviynt and Idira valuation conversations this newsletter keeps having: momentum framing and enterprise value are not the same thing.

Why it matters: when even the category's strongest performer gets a skeptical read on an AI-security launch blitz, take every private vendor's "AI identity platform" valuation claim with a correspondingly larger grain of salt.
PartnershipsCLEAR

Identity verification and AI security keep fusing at the edges

Alongside the agent news, CrowdStrike brought CLEAR's verified human identity into the Falcon platform to help teams distinguish trusted users from potential threats — a notable move as deepfakes and synthetic identity make "is this a real human" a live security question, not just an onboarding one. It rhymes with the broader theme: the boundary between identity verification (proving who someone is) and identity security (governing what they can do) is blurring as agents and synthetic identities proliferate.

Why it matters: "verify the human" is becoming a runtime control, not a day-one check. If your help desk and high-risk workflows still rely on knowledge-based verification, the market is moving past you.
GovernanceZscaler

The ecosystem keeps wiring continuous identity into zero trust

CrowdStrike and Zscaler extended their partnership to bring Continuous Identity into zero-trust access, and CrowdStrike expanded its standards footprint via OpenID and IDPro. The through-line across the week: agent authorization is standardizing fast — SPIFFE, Shared Signals, CAEP — and the vendors are racing to be the ones whose enforcement point everyone else plugs into.

Why it matters: standards adoption is the quiet tell of a maturing category. Ask your vendors which of these they actually implement — an enforcement point that speaks Shared Signals and CAEP is worth more than one that doesn't, regardless of the demo.
02

The Reckoning

grading last issue's Fal.Con predictions against what actually shipped

Issue 14 · predicted Aug 31 · graded Sep 9
We read the job board. Here's how that went.

Last issue we argued that hiring is the one roadmap a company can't spin, and made six ranked, falsifiable predictions about Fal.Con. Fal.Con happened. A prediction you don't grade is a horoscope, so here's the honest scorecard — hits, the miss, and the thing we didn't see coming.

Predictions made
6Issue 14
Broadly correct
5of 6
Wrong / early
1the CIEM call
Didn't predict
2see below
The scorecard
GradeWhat we predicted (Issue 14)What actually shipped at Fal.Con
✓ HIT Continuous Identity reaches GA and becomes the identity headline; the "identity control plane for the agentic enterprise" (~80%) Agentic Identity Provider launched in Falcon Next-Gen Identity Security, explicitly billed as "the identity control plane for the agentic enterprise." Near word-for-word.
✓ HIT Continuous Identity extends zero-standing-privilege beyond AD/Entra into SaaS, code repos, cloud (~80%) CrowdStrike extended "modern privileged access across SaaS applications, endpoints, code repositories, and cloud infrastructure." Exactly the surfaces we named.
✓ HIT Charlotte AI / AgentWorks and AIDR advancements; "agentic SOC" as the narrative (~85%) Agentic SOC took center stage on Day 2; AIDR, cross-domain OverWatch hunting into Guardian, and autonomous investigation were core.
✓ HIT Endpoint → browser → cloud fabric, Falcon Secure Access featured (~75%) Falcon Secure Access (Seraphic) featured as the browser layer, unified with identity and cloud protection.
✓ HIT Unified NHI ownership, visibility and intelligence (~implied) Shipped: unified ownership, visibility and intelligence across non-human identities.
~ EARLY A cloud entitlement management / NHI governance product from the "new team… at its infancy" posting (~45%) No standalone CIEM product launched. The hiring signal was real but the product isn't GA — consistent with "at its infancy." We flagged 45%; the market said "not yet."
✗ MISSED Software-supply-chain protection: blocking malicious open-source package installs at the endpoint (XZ-style). We didn't call this.
✗ MISSED Falcon on the Anthropic Claude marketplace, and the CLEAR verified-human-identity integration. Didn't see either coming.
What we got right, and why the method worked

The core thesis held up well: the dedicated "Sr. Project Manager, Continuous Identity" posting was the tell, and it was accurate. Companies staff a program manager for a launch with a date, and the launch arrived on schedule with the exact positioning we quoted. The Tel Aviv browser-security cluster correctly predicted Falcon Secure Access featuring prominently. Reading the org chart beat reading the teasers.

The one that resolved our biggest question

In Issue 14 we told governance buyers to listen for four words from a product stage — governance, certification, entitlement, lifecycle — as the signal that CrowdStrike was moving into true IGA. None of them shipped as a certification or lifecycle product. Agentic IdP is authorization and enforcement, not access certification campaigns or joiner-mover-leaver provisioning. Our "adjacent, not direct" call on the IGA incumbents holds: CrowdStrike is squeezing the authorization and NHI layers hard, but it did not ship classic governance. SailPoint and Omada's core workflows remain uncontested — for now.

What we got wrong, and what we missed — honestly

The miss on the upside: we didn't predict software-supply-chain protection or the Anthropic marketplace deal. In hindsight the supply-chain move was foreseeable — the XZ compromise had made "malicious package at the endpoint" a live board-level worry — but there was no distinct hiring cluster pointing at it, which is exactly the limitation of a hiring-signal method: it catches what a company staffs a new team for, and misses what an existing team ships as an extension. The Claude marketplace deal was a distribution move, not a product, so it was never going to show up in engineering reqs.

The one we over-weighted: we put CIEM/entitlement management at 45% and it didn't ship as a product. The "new team at its infancy" language was real, but "at its infancy" turned out to mean exactly that — a team, not a launch. Lesson logged: a hiring post confirms intent and timeline-start, not ship date. We'll calibrate future "infancy" signals lower.

The net

Five of six broadly correct, the miss was a missing prediction rather than a wrong one, and the single most important strategic call — "adjacent, not direct" on IGA — resolved in our favor. We'll keep grading ourselves in public. It's the only way a prediction is worth printing, and it's a useful discipline against the thing this whole newsletter exists to fight: confident claims nobody ever checks.

03

Deep Dive

Saviynt's $255M, the departing director, and what a flat continuation vehicle signals

Reading the fine print
This wasn't a growth round. It was a liquidity event.

The headline said "$255M investment in Saviynt." The structure says something more specific — and, read alongside a small filing in a UK companies registry, more interesting. None of it is improper. All of it is worth understanding before you take a "hypergrowth" framing at face value.

CV size
~$600Mcontinuation vehicle
New capital
$255MCarrick's largest ever
Valuation
~$3Bflat vs. Dec 2025
Carrick LP return
11xgross · 10x net offered
What a single-asset continuation vehicle actually is

Strip the announcement to mechanics. Carrick has held Saviynt since leading its $35M Series A in 2018 — it was the company's only institutional investor until the Series B. Those 2018 dollars are now sitting on a reported ~11x gain, and Carrick's fund that holds them is aging. LPs in an eight-year-old fund want their money back.

A single-asset continuation vehicle solves that. Carrick raises a new ~$600M fund (led by Coller Capital and HSBC), moves the Saviynt stake into it, and offers its original LPs a choice: take the 11x now, or roll into the new vehicle. The $255M of "new capital" primarily funds that liquidity — cashing out exiting LPs and, via a tender offer, letting Saviynt employees sell some shares. Per dot.LA, it "was completed as part of the final close of Saviynt's previously announced $700M Series B," at the same ~$3B valuation.

The distinction that matters

Fresh primary capital goes onto the company's balance sheet to hire, build, and expand. Secondary capital changes whose name is on existing shares and puts cash in sellers' pockets. This transaction is predominantly the second kind. That is completely legitimate — employees deserve liquidity and funds have lifecycles — but "$255M investment in Saviynt" invites you to picture a war chest for product, and that is mostly not what this is.

The signal in a flat valuation

Here's the part worth sitting with. The continuation vehicle is priced at roughly $3B — the same valuation as the December 2025 Series B. Eight months, a $300M ARR milestone, an 80%-bookings-growth story, a major platform launch in Zuma… and the mark didn't move.

There are innocent readings — continuation vehicles are often priced conservatively to be defensible to new LPs, and a flat mark protects the incoming Coller/HSBC investors. But connect it to the arithmetic we ran in Issue 11: at ~$300M ARR, a $3B valuation is ~10x, which is supportable only if Saviynt sustains high-growth-tier revenue. A flat continuation mark eight months later is at minimum consistent with a company whose growth is solid but not accelerating the valuation — and a sponsor choosing "give LPs the option to cash out at 11x" over "raise a step-up primary round to fund the next leg" is making a revealed-preference statement about which of those was available.

Dec 2025 Series B valuation~$3.0B
Aug 2026 continuation vehicle~$3.0B (flat)
Implied multiple at ~$300M ARR~10x
Structuresecondary-heavy, not primary
A flat eight-month mark is not evidence of trouble — it is evidence the story didn't re-rate the price. For a company whose public messaging emphasizes momentum, that gap between narrative and mark is the thing worth noticing.
And then there's the filing nobody mentioned

On September 1, 2026 — the day after the Carrick announcement — the UK companies registry recorded a Form TM01 for SAVIYNT EUROPE LTD: "Termination of appointment of James Jackson as a director on 2026-08-31." A single director resignation at a regional subsidiary is, on its own, nothing. Directors rotate constantly, and we want to be very clear: we have no information about why this happened, and it may be entirely routine.

What makes it worth a careful mention is the timing. The departure is dated August 31 — the exact day of the continuation-vehicle close — and filed September 1. Governance changes at subsidiaries frequently cluster around transaction closings for mundane reasons: board reconstitutions, entity restructurings, and share-ownership changes routinely trigger director updates as a matter of corporate housekeeping. That is the most probable explanation and we'd bet on it.

Stated plainly, because this concerns a named individual

We are not suggesting anything improper, and we are not speculating about this person. We're noting a factual, public filing whose date lines up precisely with a transaction close, because in aggregate — a flat continuation mark, a secondary-heavy structure, and subsidiary governance changes at the closing date — the picture is of a company and sponsor tidying up and providing liquidity, not one raising fuel for a growth sprint. If your read on Saviynt has been shaped by the momentum framing, this is the counterweight. Nothing here is an allegation; all of it is on the public record.

What a buyer should take from this

None of this says Saviynt is a bad product or an unstable vendor. $300M ARR is real, 96% retention is real, and a sponsor willing to keep holding via a continuation vehicle is a form of conviction. What it says is narrower and more useful: discount the "hypergrowth" framing, and price the vendor on its fundamentals, not its press releases. A flat mark and a liquidity-driven raise are the financial equivalent of the "do your homework" verdict we gave Saviynt's product back in Issue 07. The two readings rhyme.

Practically: if you're mid-cycle with Saviynt, this changes nothing about your deployment — but it's a good reason to hold firm on pricing and to get the same upgrade-notification and roadmap commitments we've recommended all along. A vendor providing employee liquidity at a flat mark is a vendor with every incentive to protect revenue, which shows up at renewal.

SOURCING: Continuation-vehicle terms, $255M commitment, 11x/10x LP return, Coller/HSBC roles, and tender-offer/Series-B-close structure per Carrick Capital's press release (Aug 31 2026), PR Newswire, dot.LA, and PE Professional. December 2025 Series B ($700M, ~$3B, KKR-led) per Reuters and Tracxn. The valuation multiple is our arithmetic on disclosed ARR. The director termination is a public UK Companies House filing (Form TM01, SAVIYNT EUROPE LTD #10265536, effective 2026-08-31, filed 2026-09-01). We draw no conclusion about the reason for that departure, make no allegation of any kind about any individual, and note it solely as a dated public record adjacent in time to the transaction. Saviynt and Carrick were not contacted and did not review this analysis.
04

Vendor Spotlight

the pitch vs. the reality, synthesized from the people who run it

Omada
NASDAQ CPH: OMADA · Copenhagen · Omada Identity + Identity Cloud · pure-play enterprise IGA
VERDICT: QUIETLY EXCELLENT, DELIBERATELY NARROW
Product / Capability
8.4/10
Implementation Ease
6.8/10
Vendor Stability
7.6/10
Ecosystem Depth
5.6/10

The company & the record

Positioning founded 2000
IPO 2022 (CPH)
The pure-play IGA that stayed a pure-play IGA

While the American incumbents raced to become "identity security platforms" spanning PAM, NHI, ITDR and runtime, Copenhagen-based Omada did something almost contrarian: it stayed an identity governance and administration company and got very good at it. Full-featured, enterprise-grade, cloud-native IGA — identity lifecycle, access certification, role management, policy, and compliance — with a stated specialty in the regulatory regimes European enterprises actually live under (GDPR, NIS2). It's publicly traded on Nasdaq Copenhagen, which brings a level of financial transparency most of its private competitors don't offer.

Read: in a market obsessed with platform breadth, Omada is a bet on depth. For a buyer who wants governance done properly rather than governance bundled into something else, that focus is a feature, not a limitation.
Reviews Gartner PI
2026
4.6/5 across 218 Gartner Peer Insights reviews — and the ratings hold up

Omada carries a 4.6/5 aggregate across 218 verified Gartner Peer Insights reviews (44% five-star, 50% four-star, 0% one- or two-star — a genuinely unusual distribution), with 87% willing to recommend. The capability breakdown is telling: Scalability 4.5, Integration 4.5, Identity Life Cycle 4.5, Access Certification 4.3, Customization 4.2. The recurring praise is out-of-the-box connectors, a low-code/no-code administration model, and — repeatedly — the quality of the people. One banking director: "much better than the competition… they pushed very hard to get the product implemented on our timelines."

Read: a zero-percent bottom-rating share across 200+ reviews is rare and worth weighting. This is a product that, once deployed, its customers genuinely like — which is not something we could say about every vendor in this newsletter.
Gartner Peer Insights · Omada ↗
The real weakness customer-reported
The ecosystem is thin — and Omada's own reviewers say so

The most consistent criticism isn't about the product; it's about everything around it. Straight from Gartner reviews: "poor availability of implementation partners… closed user group, with less answers to questions… in the public internet there are no groups or entries in StackOverflow etc." Another, more affectionate but pointed: "The possibilities are endless — but only if you know how." A third describes needing three years and a third-party consultancy to learn the product's depth. The capability is there; finding people who can unlock it is the friction.

Read: this is the mirror image of CyberArk's problem in Issue 14. CyberArk has a huge partner ecosystem and a product so complex you need it; Omada has a cleaner product but a thin bench of people who know it deeply. Both end in the same place — budget for expertise — for opposite reasons.
Market context 2026
Boxed in on both sides — cloud-native challengers below, mega-platforms above

Independent buyer's guides now place Omada (SaaS + on-prem, 4.6) alongside a widening field: cloud-native challengers like Linx (5/5), Veza (4.8), Lumos (4.6) and Opal below it on modernity, and SailPoint (4.8) and Saviynt (4.8) above it on scale and mindshare. Omada's cleanest positioning is "GDPR/NIS2 compliance" and European enterprise — a real and defensible niche, but a niche. The agentic/NHI wave is a genuine strategic test: Omada must extend its governance model to non-human and agent identities without losing the focus that makes it good.

Read: Omada isn't going to win the platform war and isn't trying to. The question for a buyer is whether deep, well-liked, compliance-grade IGA from a focused vendor beats governance-as-a-feature from a giant. For a lot of European enterprises, it does.
SOURCING: Ratings and capability scores per Gartner Peer Insights (Omada Identity + Omada Identity Cloud, 218 aggregate verified reviews) as of Aug/Sep 2026. Reviewer quotes are drawn from published Gartner reviews. Competitive positioning per independent IGA buyer's guides. Corporate facts (Copenhagen HQ, Nasdaq Copenhagen listing) per public company information. Omada was not contacted and did not review this assessment. Note that vendor-published "voice of the customer" quotes on Omada's own site are selected by Omada; we weight the aggregate Gartner distribution above any curated testimonial.

The Pitch vs. The Reality

What Omada says
  • Full-featured, enterprise-grade, cloud-native IGA — governance done properly, not bundled
  • Best-in-class identity governance framework with a strong compliance (GDPR/NIS2) fit
  • Low-code/no-code administration; strong out-of-the-box connector portfolio
  • "Leading the future of IGA with AI" — extending governance to the agentic enterprise
What the evidence shows
  • The IGA core is genuinely strong — 4.6/5, 0% bottom ratings across 218 reviews
  • Scalability, integration and lifecycle all rate 4.5; this is a real enterprise product
  • The connector portfolio and no-code model are the most-praised concrete features
  • Implementation-partner availability is thin; the community is closed and small
  • The AI/agentic story is early — a strategic necessity Omada is still executing, not a proven strength

Community Pulse — synthesized signal

Gartner Peer Insights · aggregate 4.6/5 · 218 reviews
"Highly adaptable and scalable solution. Covers all our use cases without having to write and maintain any code."
— finance-industry reviewer. The distribution is the story: 44% five-star, 50% four-star, 6% three-star, 0% one- or two-star. Across 200+ verified enterprise reviews, essentially nobody rates it badly — a consistency signal that matters more than the headline average
consistently strong
The people signal recurring praise
"Omada and their technical team have been great partners throughout a challenging implementation. They pushed very hard to get the product implemented on our timelines." / "A company with a client-first mindset."
— banking and real-estate reviewers. Unusually for enterprise software, the vendor's people come up as often as the product. In a category where implementation makes or breaks the outcome, a well-regarded professional-services team is a genuine differentiator
strong service reputation
The ecosystem complaint the real gap
"Poor availability of implementation partners. Closed user group, with less answers to questions. In the public internet there are no groups or entries in StackOverflow etc — you can[not easily] find solutions for requirements."
— verified Gartner reviewer, quoted directly. This is the single most consistent criticism and it's structural: a smaller, European-centric vendor has a smaller SI bench and a quieter community than SailPoint or Saviynt. If you're in a region where Omada partners are scarce, factor that into your timeline
thin bench
The learning curve, honestly framed depth has a cost
"The possibilities are endless — but only if you know how. After working with the product for three years and getting help from a third-party vendor, we are learning more and more about the possibilities."
— a review that captures the trade-off precisely. The flexibility that power users love is the same flexibility that makes the product deep to master. This is a "grows with you" tool, not a "live in a sprint" tool — set expectations accordingly
deep, therefore demanding
Competitive position boxed, but defensible
"Best for GDPR/NIS2 compliance — SaaS + on-prem, 4.6/5."
— independent IGA buyer's guide placement. Below it on cloud-native modernity sit Linx, Veza, Lumos and Opal; above it on scale sit SailPoint and Saviynt. Omada's moat is European enterprise, regulatory depth, and a hybrid (SaaS + on-prem) footprint that the pure-cloud challengers can't match — a real niche, but a niche
a defensible niche
METHOD: Synthesized from Gartner Peer Insights (218 aggregate verified reviews across Omada Identity and Omada Identity Cloud), independent IGA buyer's guides, and public company information, as of Sep 2026. A note on the fourth axis. We replaced our usual sentiment score with Ecosystem Depth (5.6) because for Omada that is the decisive variable — the product scores well and the sentiment is strongly positive, so a generic sentiment number would overstate the ease of actually deploying it. The 5.6 reflects the consistently-reported thinness of implementation partners and community resources outside Omada's European core, not any weakness in the software. Product (8.4) reflects the strong, unusually consistent review distribution; Vendor Stability (7.6) reflects a profitable, publicly-listed focused vendor weighed against its modest scale next to the platform giants. This is one of our more positive spotlights, and the evidence supports it.

The Signal Read

Trajectory: the best IGA product most American buyers have never seriously evaluated. After fourteen issues of vendors whose problems ranged from stability to culture to valuation games, Omada is a slightly disorienting change of pace: a company whose biggest weakness is that not enough people know how to implement it. The product is genuinely strong — 4.6/5 with zero bottom-ratings across 218 reviews is a distribution we haven't seen from anyone else in this newsletter — and the consistent praise for its people is the kind of signal that predicts good deployment outcomes.

The focus is the whole thesis, and it cuts both ways. Omada didn't chase the platform-consolidation wave. It stayed an IGA company while SailPoint added NHI, Saviynt added Zuma, Okta added governance and CrowdStrike added everything. That discipline is why its core is so well-regarded — and it's also why Omada is boxed in: cloud-native challengers are more modern, the mega-platforms are broader, and the agentic/NHI wave is a real test of whether a focused governance vendor can extend into non-human identity without losing its edge. Omada's answer to that ("Leading the Future of IGA with AI") is still more slogan than proof.

The honest positioning: this is a European enterprise's best-fit IGA and an American enterprise's underrated option. If you operate under GDPR and NIS2, want hybrid SaaS-plus-on-prem deployment, and value governance done deeply over governance bundled cheaply, Omada should be on your shortlist and frequently isn't. The single caveat that determines your experience is partner availability — confirm you can staff the implementation, from Omada or a capable SI in your region, before you sign. Get that right and this is one of the lower-regret buys in the category.

Buy the story if…
  • You want deep, purpose-built enterprise IGA rather than governance bundled into a platform
  • You operate under GDPR/NIS2 — regulatory depth and EU data residency are genuine strengths
  • Your estate is hybrid; the SaaS-plus-on-prem footprint beats pure-cloud challengers here
  • Deployment quality matters to you and you value a well-regarded professional-services team
Do your homework on…
  • Partner availability in your region — this is the variable that most affects your outcome; confirm it first
  • Budget for the learning curve; the product is deep and the community is small and closed
  • Pressure-test the NHI/agentic roadmap specifically — it's a strategic necessity Omada is still proving
  • If you need a single platform spanning PAM, ITDR and runtime, Omada is deliberately not that — pair it or look elsewhere
05

The Stack

a category, tool, or idea worth knowing this week

Diligence technique

Ask one question of any funding announcement: primary or secondary?

This issue's Saviynt deep dive is the case study. "$255M investment" and "$255M to fund a tender offer so LPs and employees can cash out" are both true and wildly different. Primary capital builds product; secondary capital changes whose name is on the shares. When a vendor cites a raise as proof of momentum, ask which kind it was and whether the valuation stepped up. The pause before the answer is often more informative than the answer.

Prediction hygiene

Grade your own forecasts in public

We predicted CrowdStrike's Fal.Con slate from job postings last issue and graded ourselves this issue — five of six, one miss, calibration noted. The discipline matters beyond bragging rights: a forecast nobody checks is a horoscope, and an industry drowning in unchecked vendor claims should model the opposite behavior. Whatever you predict in a board deck — a vendor's trajectory, a category's direction — write down what would prove you wrong, and revisit it. It's the cheapest credibility you'll ever buy.

Buying discipline

The best product isn't always the loudest one

This issue's spotlight, Omada, has a 4.6/5 rating with zero bottom ratings across 218 reviews and is barely discussed in American identity circles. Meanwhile the loudest vendors in the category are the ones we've flagged for stability, culture, and valuation games. Marketing spend and product quality are not correlated — sometimes they're inversely correlated. Before you build a shortlist from the vendors you've heard of, check who the practitioners in the reviews actually rate.

06

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Separate the vendors you trust from the vendors you\'ve simply heard of

Your board and your CFO know the loud names — the ones with the biggest booths and the most LinkedIn badges. What they rarely hear is that some of those names are the ones this kind of analysis flags for culture problems, flat valuations, or shelfware, while quieter vendors quietly outscore them with actual customers. When you defend a shortlist, lead with practitioner evidence, not brand recognition. It reframes the conversation from "is this a safe name" to "is this the right tool," which is the conversation you actually want to be having.

"The vendor everyone has heard of and the vendor our peers actually rate highest are not always the same company. I\'d rather explain an unfamiliar name that works than a familiar one that becomes shelfware."
07

Overheard

a spicy anonymized take from the community this week

"Vendor told me their $255M raise proves the market believes in them. I asked if it was primary or secondary. Long pause. Then: 'It's a vote of confidence.' So, secondary."
— identity investor, on a diligence call · lightly paraphrased