There is a game you can play with this week's identity-security press releases: cover the vendor logos, read the announcements aloud, and try to guess who said what. You will lose. SailPoint has a "Human Fabric" and an "Agentic Fabric." Okta has an "identity security fabric" and a "kill switch" for "shadow agents." Saviynt has Zuma, which — we'll get to this — looks and reads uncannily like SailPoint's product from four months ago. CrowdStrike has an "Agentic IdP." Everyone has "first-class identities," "runtime governance," and a "control plane." The words have stopped describing products and started describing each other.
So this issue we're doing something about it. We're launching The Buzzword Confusion Index — a new standing instrument on the site that tracks, week over week, exactly how much the market's language is fogging the windshield for the people writing the checks. It has a confusion score, a leaderboard of the guiltiest terms, and a vendor offender ranking. Consider it a public service. Around that: SailPoint's earnings (strong, with one honest asterisk on AI revenue), the Zuma pattern and why it's starting to look less like coincidence, Okta's latest blueprint, and the rest of the week. Let's get into it.
the week, distilled — & why it lands on your desk
Reported Sep 9 (fiscal Q2'27): total ARR $1.231B, up 25%, SaaS ARR $847M up 36%, with SaaS now 97% of net new ARR and free cash flow of $37M. The headline for this newsletter's beat: AI-driven ARR crossed $70M against a fiscal-2027 target of just $10M, contributing more than 30% of net new ARR. Founder Mark McClain leaned into it, and CTO/product leadership has been loud on LinkedIn about "Agentic Fabric" and "Human Fabric" as the compounding engine. KuppingerCole's Overall Leader nod (Issue 13) got a victory lap on the call.
The asterisk is worth keeping. As DA Davidson noted, "AI ARR includes all ARR from customers who are consuming any Agentic Suites, Agentic Fabric, etc… the actual net-new ARR from AI/Agentic products is much lower." Revenue of ~$309M came in fractionally below Street expectations even as ARR beat, and management held full-year guidance flat — a "rev-rec timing," not demand, story per the company.
Saviynt is pushing Zuma, its AI identity security platform, hard this month. The trouble, covered in depth in this issue's deep dive: the positioning, structure, terminology, and even the product demo track SailPoint's Agentic Fabric (launched four months earlier) closely enough that it's become a talking point across the industry. Both launched from a Nasdaq stage. Both use near-identical "discover / govern / protect," "first-class identities," "you can't secure what you can't see" framing. And a CIO.com video walkthrough of Zuma that circulated earlier appears to have quietly come down.
Okta announced its "Blueprint for the Secure Agentic Enterprise" built around three questions — where are my agents, what can they connect to, what can they do — plus Okta for AI Agents to discover known and "shadow" agents, register them as first-class identities, and "instantly revoke access… the ultimate kill switch." Universal Directory now treats agents as a first-class identity category; all Identity Security Fabric capabilities (SSO, governance, provisioning) extend to agents; and Okta proposed "Cross-App Access" (XAA) as an open MCP extension. It also closed its Permiso acquisition on earnings day.
We built a way to quantify what everyone feels. Across the eight major identity vendors, claim overlap on the core agentic-identity themes — discover agents, govern them as first-class identities, enforce at runtime, revoke fast — now runs about 91%. Nearly every vendor makes nearly every claim. The differentiation that used to live in the positioning has migrated entirely into the architecture and the proof, which is exactly where buyers now have to look.
Last issue's rumored deal firmed up: Proofpoint (Thoma Bravo) remains in advanced talks to acquire Varonis at a valuation near $5.4B, with reporting suggesting an announcement could land within weeks. It would be one of the largest software take-privates of the year and another data-security consolidation as data and identity keep merging — the same current that produced Cyera/Oasis and ServiceNow/Veza.
Beneath the buzzword fog, real interoperability work is happening. Okta's Cross-App Access extends MCP; CrowdStrike leaned on SPIFFE, Shared Signals and CAEP at Fal.Con; the July MCP authorization spec mandates audience-bound tokens. For all the marketing sameness, the underlying plumbing is standardizing — which is genuinely good for buyers who don't want to be locked into one vendor's agent model.
introducing The Buzzword Confusion Index
For fifteen issues we've complained about the identity market's marketing language — the fabrics, the control planes, the fifteen vendors saying the same eight words. Complaining is easy. This week we're doing something more useful: measuring it, every week, on a public dashboard.
The Buzzword Confusion Index is a standing instrument — a live page on the site, updated every week — that tracks how badly the market's language is fogging the view for the people writing the checks. It's satirical in tone and rigorous in method, and it has four parts:
1. The Composite Confusion Score (0–100). How much noise the market is making this week, with week-over-week movement. This week it reads 78, up from 72 — driven by four sub-metrics: term velocity (how fast new coinages appear), sameness (how much vendor claims overlap), definition drift (how far a term has wandered from any fixed meaning), and AI-washing density.
2. The Buzzword Leaderboard. Roughly two dozen terms stack-ranked by "Confusion Contribution," across five categories — Architecture Metaphors, the AI-Agent Land Grab, Access & Privilege, Detection & Posture, and Zombie Buzzwords. Each term gets a plain-English gloss, a real on-record vendor quote, and a "what a buyer actually hears" translation.
3. The Sea of Sameness. A vendor-vs-theme grid showing, at a glance, how nearly every major vendor makes nearly every claim. This week it reads 91% overlap. It is the single most damning visual we've published.
4. The Vendor Buzzword Offender Index. Each of eight vendors — SailPoint, Okta, CyberArk, CrowdStrike, Palo Alto, MS Entra, Ping, Saviynt — scored 0–100 on buzzword reliance, with a podium and week-over-week ranks.
Ping Identity tops the offender board at 89 ("Identity for AI," a "unified fabric for agentic trust," and identity as "the universal language of accountability" — in one breath). SailPoint sits at 85 for shipping two fabrics and rebranding the cloud. And Saviynt jumped five points to 76 on the strength of Zuma — which brings us to the deep dive.
The Index is funny on purpose, because the alternative — another earnest 2,000-word lament about marketing — changes nothing. But underneath the satire is a genuinely useful discipline for a CISO. When claim overlap runs at 91%, the marketing has zero shortlisting value, and every hour you spend comparing vendor positioning is an hour wasted. The Index is designed to make that obvious at a glance, and to push you toward the only questions that still discriminate: what can this vendor demonstrate, in my environment, that the other seven can't?
It's live on the site now, linked in the nav as Buzzword Index, and it updates every week. Quotes are on-record; the vendor scores are our editorial read, framed as such, not audited counts. Go break it.
| Open the Buzzword Confusion Index → |
Zuma, Agentic Fabric, and a pattern that's getting harder to call coincidence
We have now documented, across several issues, a recurring resemblance between Saviynt's launches and SailPoint's. Individually, each instance is explainable. Together, they form a pattern a buyer should at least be aware of — especially given the legal cloud already hanging over the company.
Let's lay out what we've actually observed, issue by issue, because the case is cumulative rather than any single smoking gun.
| Where | SailPoint did it first | Saviynt followed |
|---|---|---|
| Issue 11 — the launch | Agentic Fabric launched May 11 from a Nasdaq stage | Zuma launched Jul 28 — also from a Nasdaq stage, ten weeks later |
| Issue 11 — the words | "You cannot secure what you cannot see"; discover / govern / protect; agents as "first-class identities" | "You can't secure what you can't see"; discover / protect / manage; agents as "first-class, non-human identities" |
| Issue 11 — the platform claim | "Delivered by our core SailPoint Platform" | "Built on the same Saviynt Identity Security Data Fabric" |
| This issue — the demo | Agentic Fabric product walkthrough, May | Zuma walkthrough that observers say mirrors it in look, structure and flow |
| Ongoing — the lawsuit | Delinea (not SailPoint) alleges trade-secret misappropriation via a former employee | Saviynt is the defendant; motion to dismiss pending (Issue 07) |
Here is the newest wrinkle, and we're reporting it carefully. A CIO.com video titled along the lines of "Watch how Saviynt stops AI agents from taking unauthorized actions" — a Zuma walkthrough — was circulating earlier. As of this writing, that URL no longer resolves to the video. We don't know why. Media companies unpublish content constantly, for reasons ranging from sponsorship terms to routine CMS housekeeping to editorial decisions, and none of those are nefarious.
We are not claiming the takedown is connected to the resemblance, to the lawsuit, or to anything at all. We have no information about why the page came down, and the most likely explanation is mundane. We note it only because a reader following this story would find the link dead, and we'd rather tell you that than have you wonder. A missing web page is not evidence of anything. It's a missing web page.
We owe Saviynt the strongest version of its defense, because there is one. Categories genuinely do converge on shared language — we just built an entire Buzzword Index proving that every vendor sounds alike right now, so singling out one company for "sounding like the others" is, on its face, a little rich. "Discover / govern / protect" is close to an industry-standard triad. Launching from Nasdaq is what public and pre-IPO companies do. And Saviynt has a real ISPM heritage that predates any of this. A skeptic could fairly say we're pattern-matching noise into a narrative.
Here's why we think it clears that bar anyway. The Buzzword Index measures everyone converging on the same vocabulary. What we're describing with Saviynt is narrower and more specific: the same company repeatedly matching the same competitor's launch choices — venue, sequence, signature phrasing, and now demo structure — across multiple events. Vocabulary convergence is the whole market drifting together. This is one boat steering toward another, repeatedly. Those are different phenomena, and the second one is the one a buyer should file away.
Nothing dramatic. This is not "don't buy Saviynt" — we scored the product 7.0 in Issue 07 and nothing here changes the product. It's a diligence lens, and a narrow one: when you evaluate Zuma, ask what in it is genuinely Saviynt's own engineering versus what is newly named to match the category leader. Ask for the architecture, not the demo. Ask how the runtime authorization actually works, in technical detail, and compare the answer to what SailPoint tells you. If the resemblance is skin-deep marketing over real, distinct engineering, that's fine — lots of good products wear fashionable clothes. If the resemblance goes deeper than the vocabulary, you want to know before you sign, and so does your legal team given the Delinea matter still sitting unresolved.
a category, tool, or idea worth knowing this week
The new Buzzword Index pegs vendor claim overlap at 91%. Flip that into a buying rule: if a capability appears in every vendor's deck, it cannot help you choose between them — cross it off your evaluation criteria entirely. "Governs agents as first-class identities" is now table stakes, not a differentiator. Spend your evaluation hours only on the claims that fewer than half the field can make, because those are the only ones with discriminating power.
This issue's Zuma deep dive is the case study. Demos are choreographed and marketing converges; neither tells you what's actually different under the hood. When two vendors' products look the same, make each one walk you through its runtime authorization in technical detail — how a decision is actually evaluated and enforced, live. Genuinely distinct engineering survives that conversation. Marketing-deep resemblance does not.
SailPoint's $70M "AI-driven ARR" beat its own target by 7x — genuinely impressive — but the definition counts any customer touching an agentic suite, so net-new agentic product revenue is materially lower. That's not unique to SailPoint; it's how every vendor will draw the circle. When a vendor quotes AI revenue, ask exactly what's inside the boundary. The honest ones will tell you; the answer separates real monetization from generous accounting.
one line to sound three moves ahead in your next exec meeting
The market's language has collapsed into sameness — 91% claim overlap by our count. The fastest way to cut through it in your own shop is to refuse to let vendors grade themselves on it. When a team brings you a shortlist, make them describe each vendor's differentiation without using the words "fabric," "control plane," "first-class identity," or "runtime governance." What's left after you strip the shared vocabulary is the actual decision — and sometimes there's alarmingly little left.
a spicy anonymized take from the community this week