$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
🧭 Our approach

Not a smaller SailPoint.
A different way of doing IGA.

The classical IGA playbook — a 12-month implementation project, a consulting team, a role-model workshop, then a big-bang go-live — fails mid-market organisations structurally, not incidentally. We rebuilt the playbook, not just the product. Here are the eight deliberate differences, plus an honest list of where the incumbents are still ahead.

The problem

First value at go-live — or on day one.

A 12-month implementation project, a consulting team, a role-model workshop, then a big-bang go-live. That playbook was built for Fortune-500 programmes — for a 2,000-person organisation it means paying for a year before seeing your own data. RapidValue doesn't assume a dedicated IAM team or a mandatory integrator programme — the guided product does the heavy lifting, and a partner accelerates where you want one.

month 0 3 6 9 12 CLASSIC IGA scoping & procurement implementation project (consultants on site) role workshop big-bang go-live first value: at go-live · maximum blast radius on day one RAPIDVALUE day 1: connect + see your data gradual go-live week 1: govern · writes stay gated per system until you release them

Schematic — classic timeline per the programmes we ran ourselves at the incumbents; RapidValue timeline is the POC sequence on the homepage journey.

Eight deliberate differences

The playbook, rebuilt.

🛞 1 · Training wheels, not big-bang

writes your gate target system observe → approve → release, per system

Classical IGA flips provisioning on at go-live — after months of config, with maximum blast radius on day one. We invert it: connectors provision from the start, but every write queues for your batch approval until you remove the gate, per system. You watch the platform make the right calls before you let it act. Go-live is a gradient, not a cliff.

📊 2 · Your data on day one

We don't demo a sandbox with fictional employees. The POC connects your HR feed and one of your systems in the first session — role-mining proposals, risk scores and audit evidence come from your own environment the same afternoon. If the value isn't visible in your data, you shouldn't buy it.

🇪🇺 3 · Sovereignty by construction

Not a compliance slide — an architecture. The tier-3 agent runs in your VPC and resolves connector credentials locally: secrets never cross the wire to our control plane. Bring-your-own-vault points us at HashiCorp Vault, Azure Key Vault or AWS Secrets Manager instead — we store the reference, your vault keeps the value. EU-hosted, EU-owned, no US parent company. The full architecture →

🧾 4 · Evidence-first, always-on

#8f2a #c41d #77b0 #e5c9 every record chained to its predecessor update/delete → rejected by the database itself

Auditors don't trust screenshots of dashboards. Every reconciliation run produces snapshots with per-grant reasons ("expected via policy X" / "not expected — flagged"), the audit trail is cryptographically chained and database-immutable, and audit packs (SOX · ISO · HIPAA · GDPR) generate from live data — not from a quarterly evidence-gathering scramble.

🪞 5 · The platform governs itself

platform your admins the platform is its own connected system admin rights = governed grants, reviewed like any other

Who governs the governor? In RapidValue, the platform is its own connected system: your admins are identities, their platform roles are group memberships, every role assignment is a governed grant that shows up in reconciliation and access reviews like any other. No shadow admin layer — and guardrails ensure automation can never strip your last admin.

💬 6 · Business-readable, wizard-first

Role mining outputs plain-language proposals — "12 people in Finance share this access" — not cluster IDs. Policies are built in a visual wizard with a preview that names people, not just counts them: who starts matching, who stops, and what that population actually gets. A policy that quietly takes access away from ninety-three people should not read as −93. Config that classically needs a consultant dialect is a guided flow an admin walks through alone. The consulting workshop is the product.

🧩 7 · One rule model — central defaults, local overrides

Who approves, who reviews, who owns, what may never combine — in classic IGA that logic is re-authored inside every workflow and drifts apart. Here every rule family — approval chains, review rules, ownership rules and SoD rules with compensating controls — is a named, reusable object with a workbench per topic: define it once as the default for its type, override only where a system or team genuinely differs, and universal fallbacks guarantee nothing ever routes to nobody.

🔁 8 · The test is what a change costs

Every IGA platform works on the day it goes live. The question nobody asks in the demo is what happens when the rules change, when the people change, and when the controlling never stops — because that is where these programmes actually die.

Our answer is one architectural choice: the platform converges, it does not react to events. Reconciliation pulls the world toward the model on a clock, so a missed message costs you a run instead of a gap. A leaver's account is disabled by the next run — no event to miss, no ticket to chase.

On top of that sit the things that keep the asking honest:

  • A question that has been answered closes itself. We measured 24 of 192 open items asking something that was already settled. They now supersede themselves, with the reason on the trail.
  • A decision follows its owner at the moment the owner changes — not at the next sync. And a task somebody already took over by hand stays put.
  • The "object owner" role is derived, not assigned. Own something and you have it; own nothing and you do not. Nothing else grants it, and the API refuses a manual add.
  • The asking is no longer a login habit. A review round announces itself, an overdue decision nudges its owner from a scheduled job, and the person who asked hears the outcome — approved, rejected with the reason, live. "Reminders are automatic" is a sweep here, not a sentence on a status page.
  • An attestation can say no. "Do you still own this?" offers "no — it is X's now", and the handover moves the pending decisions at that moment. The only answer a yearly campaign used to accept was yes.

And underneath, 45 background jobs keep the model converged — each one reporting its own health, because a job that quietly stops running is itself a finding.

Side by side

What the difference looks like in practice.

← swipe to compare →

Classic IGA platformsRapidValue
Time to first working POC4–8 weeks1 day
Who carries the implementationA systems-integrator engagement alongside the licenceThe guided product does the heavy lifting — a partner accelerates. Four starter packs ship the first afternoon's governance (birthright, JML, access review, SoD), installed inert so nothing fires before you have read it
Customer security review for trial2–4 weeks — a full vendor-access reviewAn afternoon (outbound-only agent, auditable source)
Where connector credentials liveFixed by the deployment model you buyYour choice per deployment: EU-managed vault, your own vault (BYOV), or your network (agent mode)
POC cleanup if not convertingFormal decommissioningRemove the agent and export everything yourself; deletion is a governed offboarding we run on request — typed-confirm, never automatic
Role mining outputCluster IDs and algorithm metricsBusiness stories (cohort, intent, impact) — with the coverage number alongside
Compliance evidence at end of POC"We'll discuss in scoping"Privacy-safe take-home report

Where we sit in your IAM landscape

We do governance. Deeply. And we're honest about the rest.

✓ our core

IGA — Identity Governance & Administration

Lifecycle, requests & approvals, roles & policies, reviews, SoD, reconciliation, audit evidence, identity analytics, NHI governance. This is the whole product.

◐ partial

PAM — Privileged Access

Break-glass emergency access (instant, auto-expiring, justified) and scheduled time-boxed elevation are two distinct pillars — plus privileged tagging and admin-account routing. We're no password vault or session recorder; pair with a dedicated PAM tool. The privileged story →

→ integrates

Access Management — SSO · MFA · IdP

Your IdP (Entra ID, or any OIDC or SAML 2.0 provider) keeps doing authentication. We govern what it grants — including sign-in to RapidValue itself through your own IdP.

→ integrates

Directories & HR

AD, Entra ID and LDAP stay your directories — we read, reconcile and provision them. Your HR system stays the source of truth for people — we consume it.

✕ not us

CIAM — Customer identity

Workforce and non-human identities are our scope. Customer login/registration flows belong to a CIAM product.

✕ not us

Endpoint / network security

We govern who may have access — EDR, firewalls and network segmentation are adjacent disciplines we happily coexist with.

The honest part

Where the incumbents are ahead.

If these are hard requirements for you today, we'd rather tell you now than after a POC. We chose our trade-offs deliberately for the EU mid-market — here's what sits on the other side of them.

🔌 Connector library size

The incumbents ship connector libraries in the hundreds; we ship 14 vendor templates — from Entra ID and Active Directory to Exchange Online, Google Workspace, Workday, AFAS, TOPdesk and Nmbrs — plus six generic engines (REST, SCIM 2.0, LDAP, SQL, SFTP-CSV and SMB/NTFS): 20 production connectors in total, of which SQL, SFTP-CSV and SMB read only. For mid-market estates that generic layer covers the long tail — but if you need a certified mainframe or SAP GRC connector today, the incumbents are ahead. The flip side: because every template is built on those generic engines, a new vendor template is days of work, not a product-roadmap quarter — we build them alongside onboarding customers, at no extra cost. The fourteenth is not ours: Nmbrs was contributed as a package against our template SDK, which is the proof that the long tail does not have to run through our roadmap.

🔐 Deep PAM

We tag privileged access, route it to admin accounts, and measure JIT coverage — but we are not a password vault or session recorder. If you need full PAM, pair us with a dedicated tool; SailPoint + CyberArk is a mature combo.

📈 Analyst coverage & 20-year references

We're not in a Forrester Wave and won't be for a while, and our focus is mid-market estates, not FTSE-100 with 50k+ identities. If procurement needs a magic quadrant, that's a real constraint — we compensate with a POC on your data in a day, which no quadrant can show you.

📱 Mobile app & marketplace

Approvals and review rounds reach you by mail now — one link, per tenant and off by default, and the decision itself still happens on a page that shows you the SoD warnings first. There is no native mobile app and no third-party extension marketplace; extensibility runs through config packs and the governed API.

The team

Built by people who have done this before.

We spent the past decade selling and implementing IGA at Omada Identity, Saviynt and SailPoint — across presales, architecture, alliances and enterprise sales in the Benelux and EMEA. And we kept seeing the same problem: great governance products that took six months before a customer could see their own data. RapidValue is our answer to that.

Serge Kerremans

Serge Kerremans

Co-founder · Product & Architecture

Former Benelux Presales Lead at Omada Identity and co-lead for EMEA Strategic Alliances at Saviynt. 15+ years designing and delivering IGA programmes for Belgian and Dutch enterprise clients.

Omada IdentitySaviynt EMEAIGA Architecture
Mark Vermeulen

Mark Vermeulen

Co-founder · Sales & Go-to-Market

Former Senior Account Manager at SailPoint, Senior Director Technology Alliances EMEA at Saviynt and Regional Sales Director Benelux at Omada Identity. A decade of enterprise identity-security sales in the Benelux.

SailPointSaviynt EMEAOmada Benelux

The test

Don't take the word "different" on faith.

Every claim on this page is demonstrable in a single POC session on your own data: the gated writes, the mining proposals, the recon evidence, the self-governing platform. Book the kickoff and judge it live.

Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.