Not a smaller SailPoint.
A different way of doing IGA.
The classical IGA playbook — a 12-month implementation project, a consulting team, a role-model workshop, then a big-bang go-live — fails mid-market organisations structurally, not incidentally. We rebuilt the playbook, not just the product. Here are the eight deliberate differences, plus an honest list of where the incumbents are still ahead.
The problem
First value at go-live — or on day one.
A 12-month implementation project, a consulting team, a role-model workshop, then a big-bang go-live. That playbook was built for Fortune-500 programmes — for a 2,000-person organisation it means paying for a year before seeing your own data. RapidValue doesn't assume a dedicated IAM team or a mandatory integrator programme — the guided product does the heavy lifting, and a partner accelerates where you want one.
Schematic — classic timeline per the programmes we ran ourselves at the incumbents; RapidValue timeline is the POC sequence on the homepage journey.
Eight deliberate differences
The playbook, rebuilt.
🛞 1 · Training wheels, not big-bang
Classical IGA flips provisioning on at go-live — after months of config, with maximum blast radius on day one. We invert it: connectors provision from the start, but every write queues for your batch approval until you remove the gate, per system. You watch the platform make the right calls before you let it act. Go-live is a gradient, not a cliff.
📊 2 · Your data on day one
We don't demo a sandbox with fictional employees. The POC connects your HR feed and one of your systems in the first session — role-mining proposals, risk scores and audit evidence come from your own environment the same afternoon. If the value isn't visible in your data, you shouldn't buy it.
🇪🇺 3 · Sovereignty by construction
Not a compliance slide — an architecture. The tier-3 agent runs in your VPC and resolves connector credentials locally: secrets never cross the wire to our control plane. Bring-your-own-vault points us at HashiCorp Vault, Azure Key Vault or AWS Secrets Manager instead — we store the reference, your vault keeps the value. EU-hosted, EU-owned, no US parent company. The full architecture →
🧾 4 · Evidence-first, always-on
Auditors don't trust screenshots of dashboards. Every reconciliation run produces snapshots with per-grant reasons ("expected via policy X" / "not expected — flagged"), the audit trail is cryptographically chained and database-immutable, and audit packs (SOX · ISO · HIPAA · GDPR) generate from live data — not from a quarterly evidence-gathering scramble.
🪞 5 · The platform governs itself
Who governs the governor? In RapidValue, the platform is its own connected system: your admins are identities, their platform roles are group memberships, every role assignment is a governed grant that shows up in reconciliation and access reviews like any other. No shadow admin layer — and guardrails ensure automation can never strip your last admin.
💬 6 · Business-readable, wizard-first
Role mining outputs plain-language proposals — "12 people in Finance
share this access" — not cluster IDs. Policies are built in a visual wizard
with a preview that names people, not just counts them: who starts matching,
who stops, and what that population actually gets. A policy that quietly
takes access away from ninety-three people should not read as
−93. Config that classically needs a consultant
dialect is a guided flow an admin walks through alone. The consulting
workshop is the product.
🧩 7 · One rule model — central defaults, local overrides
Who approves, who reviews, who owns, what may never combine — in classic IGA that logic is re-authored inside every workflow and drifts apart. Here every rule family — approval chains, review rules, ownership rules and SoD rules with compensating controls — is a named, reusable object with a workbench per topic: define it once as the default for its type, override only where a system or team genuinely differs, and universal fallbacks guarantee nothing ever routes to nobody.
🔁 8 · The test is what a change costs
Every IGA platform works on the day it goes live. The question nobody asks in the demo is what happens when the rules change, when the people change, and when the controlling never stops — because that is where these programmes actually die.
Our answer is one architectural choice: the platform converges, it does not react to events. Reconciliation pulls the world toward the model on a clock, so a missed message costs you a run instead of a gap. A leaver's account is disabled by the next run — no event to miss, no ticket to chase.
On top of that sit the things that keep the asking honest:
- A question that has been answered closes itself. We measured 24 of 192 open items asking something that was already settled. They now supersede themselves, with the reason on the trail.
- A decision follows its owner at the moment the owner changes — not at the next sync. And a task somebody already took over by hand stays put.
- The "object owner" role is derived, not assigned. Own something and you have it; own nothing and you do not. Nothing else grants it, and the API refuses a manual add.
- The asking is no longer a login habit. A review round announces itself, an overdue decision nudges its owner from a scheduled job, and the person who asked hears the outcome — approved, rejected with the reason, live. "Reminders are automatic" is a sweep here, not a sentence on a status page.
- An attestation can say no. "Do you still own this?" offers "no — it is X's now", and the handover moves the pending decisions at that moment. The only answer a yearly campaign used to accept was yes.
And underneath, 45 background jobs keep the model converged — each one reporting its own health, because a job that quietly stops running is itself a finding.
Side by side
What the difference looks like in practice.
← swipe to compare →
| Classic IGA platforms | RapidValue | |
|---|---|---|
| Time to first working POC | 4–8 weeks | 1 day |
| Who carries the implementation | A systems-integrator engagement alongside the licence | The guided product does the heavy lifting — a partner accelerates. Four starter packs ship the first afternoon's governance (birthright, JML, access review, SoD), installed inert so nothing fires before you have read it |
| Customer security review for trial | 2–4 weeks — a full vendor-access review | An afternoon (outbound-only agent, auditable source) |
| Where connector credentials live | Fixed by the deployment model you buy | Your choice per deployment: EU-managed vault, your own vault (BYOV), or your network (agent mode) |
| POC cleanup if not converting | Formal decommissioning | Remove the agent and export everything yourself; deletion is a governed offboarding we run on request — typed-confirm, never automatic |
| Role mining output | Cluster IDs and algorithm metrics | Business stories (cohort, intent, impact) — with the coverage number alongside |
| Compliance evidence at end of POC | "We'll discuss in scoping" | Privacy-safe take-home report |
Where we sit in your IAM landscape
We do governance. Deeply. And we're honest about the rest.
IGA — Identity Governance & Administration
Lifecycle, requests & approvals, roles & policies, reviews, SoD, reconciliation, audit evidence, identity analytics, NHI governance. This is the whole product.
PAM — Privileged Access
Break-glass emergency access (instant, auto-expiring, justified) and scheduled time-boxed elevation are two distinct pillars — plus privileged tagging and admin-account routing. We're no password vault or session recorder; pair with a dedicated PAM tool. The privileged story →
Access Management — SSO · MFA · IdP
Your IdP (Entra ID, or any OIDC or SAML 2.0 provider) keeps doing authentication. We govern what it grants — including sign-in to RapidValue itself through your own IdP.
Directories & HR
AD, Entra ID and LDAP stay your directories — we read, reconcile and provision them. Your HR system stays the source of truth for people — we consume it.
CIAM — Customer identity
Workforce and non-human identities are our scope. Customer login/registration flows belong to a CIAM product.
Endpoint / network security
We govern who may have access — EDR, firewalls and network segmentation are adjacent disciplines we happily coexist with.
The honest part
Where the incumbents are ahead.
If these are hard requirements for you today, we'd rather tell you now than after a POC. We chose our trade-offs deliberately for the EU mid-market — here's what sits on the other side of them.
🔌 Connector library size
The incumbents ship connector libraries in the hundreds; we ship 14 vendor templates — from Entra ID and Active Directory to Exchange Online, Google Workspace, Workday, AFAS, TOPdesk and Nmbrs — plus six generic engines (REST, SCIM 2.0, LDAP, SQL, SFTP-CSV and SMB/NTFS): 20 production connectors in total, of which SQL, SFTP-CSV and SMB read only. For mid-market estates that generic layer covers the long tail — but if you need a certified mainframe or SAP GRC connector today, the incumbents are ahead. The flip side: because every template is built on those generic engines, a new vendor template is days of work, not a product-roadmap quarter — we build them alongside onboarding customers, at no extra cost. The fourteenth is not ours: Nmbrs was contributed as a package against our template SDK, which is the proof that the long tail does not have to run through our roadmap.
🔐 Deep PAM
We tag privileged access, route it to admin accounts, and measure JIT coverage — but we are not a password vault or session recorder. If you need full PAM, pair us with a dedicated tool; SailPoint + CyberArk is a mature combo.
📈 Analyst coverage & 20-year references
We're not in a Forrester Wave and won't be for a while, and our focus is mid-market estates, not FTSE-100 with 50k+ identities. If procurement needs a magic quadrant, that's a real constraint — we compensate with a POC on your data in a day, which no quadrant can show you.
📱 Mobile app & marketplace
Approvals and review rounds reach you by mail now — one link, per tenant and off by default, and the decision itself still happens on a page that shows you the SoD warnings first. There is no native mobile app and no third-party extension marketplace; extensibility runs through config packs and the governed API.
The team
Built by people who have done this before.
We spent the past decade selling and implementing IGA at Omada Identity, Saviynt and SailPoint — across presales, architecture, alliances and enterprise sales in the Benelux and EMEA. And we kept seeing the same problem: great governance products that took six months before a customer could see their own data. RapidValue is our answer to that.
Serge Kerremans
Former Benelux Presales Lead at Omada Identity and co-lead for EMEA Strategic Alliances at Saviynt. 15+ years designing and delivering IGA programmes for Belgian and Dutch enterprise clients.
Mark Vermeulen
Former Senior Account Manager at SailPoint, Senior Director Technology Alliances EMEA at Saviynt and Regional Sales Director Benelux at Omada Identity. A decade of enterprise identity-security sales in the Benelux.
The test
Don't take the word "different" on faith.
Every claim on this page is demonstrable in a single POC session on your own data: the gated writes, the mining proposals, the recon evidence, the self-governing platform. Book the kickoff and judge it live.
Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.