Live intel Wed · 16 Sep 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 16 Sponsored by — your logo here — Subscribers: 25,720
// Good morning, defenders.

There is a game you can play with this week's identity-security press releases: cover the vendor logos, read the announcements aloud, and try to guess who said what. You will lose. SailPoint has a "Human Fabric" and an "Agentic Fabric." Okta has an "identity security fabric" and a "kill switch" for "shadow agents." Saviynt has Zuma, which — we'll get to this — looks and reads uncannily like SailPoint's product from four months ago. CrowdStrike has an "Agentic IdP." Everyone has "first-class identities," "runtime governance," and a "control plane." The words have stopped describing products and started describing each other.

So this issue we're doing something about it. We're launching The Buzzword Confusion Index — a new standing instrument on the site that tracks, week over week, exactly how much the market's language is fogging the windshield for the people writing the checks. It has a confusion score, a leaderboard of the guiltiest terms, and a vendor offender ranking. Consider it a public service. Around that: SailPoint's earnings (strong, with one honest asterisk on AI revenue), the Zuma pattern and why it's starting to look less like coincidence, Okta's latest blueprint, and the rest of the week. Let's get into it.

01

Market Movers

the week, distilled — & why it lands on your desk

Earnings+25%

SailPoint's Q2: $1.231B ARR, AI revenue finally shows up — with an asterisk

Reported Sep 9 (fiscal Q2'27): total ARR $1.231B, up 25%, SaaS ARR $847M up 36%, with SaaS now 97% of net new ARR and free cash flow of $37M. The headline for this newsletter's beat: AI-driven ARR crossed $70M against a fiscal-2027 target of just $10M, contributing more than 30% of net new ARR. Founder Mark McClain leaned into it, and CTO/product leadership has been loud on LinkedIn about "Agentic Fabric" and "Human Fabric" as the compounding engine. KuppingerCole's Overall Leader nod (Issue 13) got a victory lap on the call.

The asterisk is worth keeping. As DA Davidson noted, "AI ARR includes all ARR from customers who are consuming any Agentic Suites, Agentic Fabric, etc… the actual net-new ARR from AI/Agentic products is much lower." Revenue of ~$309M came in fractionally below Street expectations even as ARR beat, and management held full-year guidance flat — a "rev-rec timing," not demand, story per the company.

Why it matters: SailPoint is genuinely monetizing AI earlier than it guided, which is real and rare. But "AI ARR" is a generously drawn circle — any customer touching an agentic suite counts. When a vendor quotes you an AI-growth number, ask what's inside the definition. The gap between "$70M of AI ARR" and "$70M of net-new agentic product revenue" is the whole ballgame.
ProductZuma

Saviynt's Zuma looks a lot like SailPoint's Agentic Fabric — again

Saviynt is pushing Zuma, its AI identity security platform, hard this month. The trouble, covered in depth in this issue's deep dive: the positioning, structure, terminology, and even the product demo track SailPoint's Agentic Fabric (launched four months earlier) closely enough that it's become a talking point across the industry. Both launched from a Nasdaq stage. Both use near-identical "discover / govern / protect," "first-class identities," "you can't secure what you can't see" framing. And a CIO.com video walkthrough of Zuma that circulated earlier appears to have quietly come down.

Why it matters: pattern-matching is a buyer's job. When a vendor's flagship launch mirrors a competitor's this closely — and that vendor is also defending a trade-secret suit from Delinea — the resemblance stops being a curiosity and starts being a diligence item. Deep dive below.
ProductBlueprint

Okta ships "Okta for AI Agents" and a "kill switch" for shadow agents

Okta announced its "Blueprint for the Secure Agentic Enterprise" built around three questions — where are my agents, what can they connect to, what can they do — plus Okta for AI Agents to discover known and "shadow" agents, register them as first-class identities, and "instantly revoke access… the ultimate kill switch." Universal Directory now treats agents as a first-class identity category; all Identity Security Fabric capabilities (SSO, governance, provisioning) extend to agents; and Okta proposed "Cross-App Access" (XAA) as an open MCP extension. It also closed its Permiso acquisition on earnings day.

Why it matters: the capabilities are real and the open-standard work (XAA/MCP) is genuinely useful. But read the language: "fabric," "first-class identities," "shadow agents," "kill switch," "control plane" — it is nearly word-for-word what SailPoint, Saviynt and CrowdStrike are all saying. That convergence is the entire premise of this issue's new Buzzword Index.
Market91%

The Sea of Sameness is now measurable — and it reads 91%

We built a way to quantify what everyone feels. Across the eight major identity vendors, claim overlap on the core agentic-identity themes — discover agents, govern them as first-class identities, enforce at runtime, revoke fast — now runs about 91%. Nearly every vendor makes nearly every claim. The differentiation that used to live in the positioning has migrated entirely into the architecture and the proof, which is exactly where buyers now have to look.

Why it matters: if the marketing is 91% identical, the marketing is worthless as a shortlisting tool. Cut vendors on what they can demonstrate in your environment, not on what they claim in a keynote. The new Buzzword Index exists to make that discipline easier.
M&A$5.4B

Proofpoint / Varonis moves toward the finish line

Last issue's rumored deal firmed up: Proofpoint (Thoma Bravo) remains in advanced talks to acquire Varonis at a valuation near $5.4B, with reporting suggesting an announcement could land within weeks. It would be one of the largest software take-privates of the year and another data-security consolidation as data and identity keep merging — the same current that produced Cyera/Oasis and ServiceNow/Veza.

Why it matters: if you run Varonis, keep modeling the change-of-control scenario. And note the meta-pattern: the "who can access what data" question keeps getting bought up into fewer, larger platforms — good for integration, bad for negotiating leverage.
StandardsXAA

The quiet good news: agent-access standards are actually converging

Beneath the buzzword fog, real interoperability work is happening. Okta's Cross-App Access extends MCP; CrowdStrike leaned on SPIFFE, Shared Signals and CAEP at Fal.Con; the July MCP authorization spec mandates audience-bound tokens. For all the marketing sameness, the underlying plumbing is standardizing — which is genuinely good for buyers who don't want to be locked into one vendor's agent model.

Why it matters: this is the signal worth rewarding. A vendor implementing open agent-access standards is giving you exit options; one pushing a proprietary agent model is building a moat around your environment. Ask which one you're being sold.
02

New Standing Instrument

introducing The Buzzword Confusion Index

A new weekly feature · live on the site now
We built an instrument to measure the fog

For fifteen issues we've complained about the identity market's marketing language — the fabrics, the control planes, the fifteen vendors saying the same eight words. Complaining is easy. This week we're doing something more useful: measuring it, every week, on a public dashboard.

Confusion Score
78/100 · ↑ from 72
Claim overlap
91%"Sea of Sameness"
Terms tracked
24five categories
Vendors scored
8offender index
What it is

The Buzzword Confusion Index is a standing instrument — a live page on the site, updated every week — that tracks how badly the market's language is fogging the view for the people writing the checks. It's satirical in tone and rigorous in method, and it has four parts:

1. The Composite Confusion Score (0–100). How much noise the market is making this week, with week-over-week movement. This week it reads 78, up from 72 — driven by four sub-metrics: term velocity (how fast new coinages appear), sameness (how much vendor claims overlap), definition drift (how far a term has wandered from any fixed meaning), and AI-washing density.

2. The Buzzword Leaderboard. Roughly two dozen terms stack-ranked by "Confusion Contribution," across five categories — Architecture Metaphors, the AI-Agent Land Grab, Access & Privilege, Detection & Posture, and Zombie Buzzwords. Each term gets a plain-English gloss, a real on-record vendor quote, and a "what a buyer actually hears" translation.

3. The Sea of Sameness. A vendor-vs-theme grid showing, at a glance, how nearly every major vendor makes nearly every claim. This week it reads 91% overlap. It is the single most damning visual we've published.

4. The Vendor Buzzword Offender Index. Each of eight vendors — SailPoint, Okta, CyberArk, CrowdStrike, Palo Alto, MS Entra, Ping, Saviynt — scored 0–100 on buzzword reliance, with a podium and week-over-week ranks.

This week's read

Ping Identity tops the offender board at 89 ("Identity for AI," a "unified fabric for agentic trust," and identity as "the universal language of accountability" — in one breath). SailPoint sits at 85 for shipping two fabrics and rebranding the cloud. And Saviynt jumped five points to 76 on the strength of Zuma — which brings us to the deep dive.

Why it's not just a joke

The Index is funny on purpose, because the alternative — another earnest 2,000-word lament about marketing — changes nothing. But underneath the satire is a genuinely useful discipline for a CISO. When claim overlap runs at 91%, the marketing has zero shortlisting value, and every hour you spend comparing vendor positioning is an hour wasted. The Index is designed to make that obvious at a glance, and to push you toward the only questions that still discriminate: what can this vendor demonstrate, in my environment, that the other seven can't?

It's live on the site now, linked in the nav as Buzzword Index, and it updates every week. Quotes are on-record; the vendor scores are our editorial read, framed as such, not audited counts. Go break it.

Open the Buzzword Confusion Index →
03

Deep Dive

Zuma, Agentic Fabric, and a pattern that's getting harder to call coincidence

Pattern recognition
Once is chance. Twice is coincidence. Four times is a habit.

We have now documented, across several issues, a recurring resemblance between Saviynt's launches and SailPoint's. Individually, each instance is explainable. Together, they form a pattern a buyer should at least be aware of — especially given the legal cloud already hanging over the company.

The receipts, in order

Let's lay out what we've actually observed, issue by issue, because the case is cumulative rather than any single smoking gun.

WhereSailPoint did it firstSaviynt followed
Issue 11 — the launch Agentic Fabric launched May 11 from a Nasdaq stage Zuma launched Jul 28 — also from a Nasdaq stage, ten weeks later
Issue 11 — the words "You cannot secure what you cannot see"; discover / govern / protect; agents as "first-class identities" "You can't secure what you can't see"; discover / protect / manage; agents as "first-class, non-human identities"
Issue 11 — the platform claim "Delivered by our core SailPoint Platform" "Built on the same Saviynt Identity Security Data Fabric"
This issue — the demo Agentic Fabric product walkthrough, May Zuma walkthrough that observers say mirrors it in look, structure and flow
Ongoing — the lawsuit Delinea (not SailPoint) alleges trade-secret misappropriation via a former employee Saviynt is the defendant; motion to dismiss pending (Issue 07)
The disappearing CIO.com walkthrough

Here is the newest wrinkle, and we're reporting it carefully. A CIO.com video titled along the lines of "Watch how Saviynt stops AI agents from taking unauthorized actions" — a Zuma walkthrough — was circulating earlier. As of this writing, that URL no longer resolves to the video. We don't know why. Media companies unpublish content constantly, for reasons ranging from sponsorship terms to routine CMS housekeeping to editorial decisions, and none of those are nefarious.

What we're saying, and what we're not

We are not claiming the takedown is connected to the resemblance, to the lawsuit, or to anything at all. We have no information about why the page came down, and the most likely explanation is mundane. We note it only because a reader following this story would find the link dead, and we'd rather tell you that than have you wonder. A missing web page is not evidence of anything. It's a missing web page.

The honest counter-argument, which is real

We owe Saviynt the strongest version of its defense, because there is one. Categories genuinely do converge on shared language — we just built an entire Buzzword Index proving that every vendor sounds alike right now, so singling out one company for "sounding like the others" is, on its face, a little rich. "Discover / govern / protect" is close to an industry-standard triad. Launching from Nasdaq is what public and pre-IPO companies do. And Saviynt has a real ISPM heritage that predates any of this. A skeptic could fairly say we're pattern-matching noise into a narrative.

Here's why we think it clears that bar anyway. The Buzzword Index measures everyone converging on the same vocabulary. What we're describing with Saviynt is narrower and more specific: the same company repeatedly matching the same competitor's launch choices — venue, sequence, signature phrasing, and now demo structure — across multiple events. Vocabulary convergence is the whole market drifting together. This is one boat steering toward another, repeatedly. Those are different phenomena, and the second one is the one a buyer should file away.

What a buyer should actually do with this

Nothing dramatic. This is not "don't buy Saviynt" — we scored the product 7.0 in Issue 07 and nothing here changes the product. It's a diligence lens, and a narrow one: when you evaluate Zuma, ask what in it is genuinely Saviynt's own engineering versus what is newly named to match the category leader. Ask for the architecture, not the demo. Ask how the runtime authorization actually works, in technical detail, and compare the answer to what SailPoint tells you. If the resemblance is skin-deep marketing over real, distinct engineering, that's fine — lots of good products wear fashionable clothes. If the resemblance goes deeper than the vocabulary, you want to know before you sign, and so does your legal team given the Delinea matter still sitting unresolved.

SOURCING & CARE: Launch dates, venues and quoted positioning per SailPoint (May 11 2026) and Saviynt (Jul 28 2026) public materials, as documented in Issues 07 and 11. The Delinea v. Saviynt suit is a matter of public record; allegations are unproven and Saviynt has moved to dismiss. The CIO.com video's current unavailability was verified at time of writing; we draw no conclusion about the reason for it and explicitly disclaim any implication of causation — media unpublishing is routine. This segment presents observed resemblances and an explicit counter-argument; the inference a reader draws is their own. Saviynt was not contacted and did not review this analysis. Nothing here is an allegation of wrongdoing.
04

The Stack

a category, tool, or idea worth knowing this week

New tool for your shortlist

Use claim-overlap as a disqualifier, not a qualifier

The new Buzzword Index pegs vendor claim overlap at 91%. Flip that into a buying rule: if a capability appears in every vendor's deck, it cannot help you choose between them — cross it off your evaluation criteria entirely. "Governs agents as first-class identities" is now table stakes, not a differentiator. Spend your evaluation hours only on the claims that fewer than half the field can make, because those are the only ones with discriminating power.

Diligence technique

When two products look identical, compare the architecture, not the demo

This issue's Zuma deep dive is the case study. Demos are choreographed and marketing converges; neither tells you what's actually different under the hood. When two vendors' products look the same, make each one walk you through its runtime authorization in technical detail — how a decision is actually evaluated and enforced, live. Genuinely distinct engineering survives that conversation. Marketing-deep resemblance does not.

Metric to trust

Interrogate every "AI ARR" number

SailPoint's $70M "AI-driven ARR" beat its own target by 7x — genuinely impressive — but the definition counts any customer touching an agentic suite, so net-new agentic product revenue is materially lower. That's not unique to SailPoint; it's how every vendor will draw the circle. When a vendor quotes AI revenue, ask exactly what's inside the boundary. The honest ones will tell you; the answer separates real monetization from generous accounting.

05

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Ban buzzwords from your own evaluation

The market's language has collapsed into sameness — 91% claim overlap by our count. The fastest way to cut through it in your own shop is to refuse to let vendors grade themselves on it. When a team brings you a shortlist, make them describe each vendor's differentiation without using the words "fabric," "control plane," "first-class identity," or "runtime governance." What's left after you strip the shared vocabulary is the actual decision — and sometimes there's alarmingly little left.

"For this evaluation, no vendor gets credit for a claim that every other vendor also makes. Tell me what only this one can do, demonstrate it in our environment, and we'll score that."
06

Overheard

a spicy anonymized take from the community this week

"Sat through four agentic-identity briefings this week. Same fabric, same first-class identities, same kill switch, same control plane. I've started playing a private game where I guess the vendor before they say their name. I have never once been right."
— identity architect, Fortune 100 · overheard in a peer Slack, lightly paraphrased