Saviynt and AUSCERT discuss securing NHIs

Learn how to secure non-human identities, a critical vector for modern automated cyber threats.
30-Second TL;DR
What Changed
Roundtable discussion focused on Non-Human Identity (NHI) security
Why It Matters
Highlights the growing importance of managing machine identities and service accounts in modern security architectures.
What To Do Next
Review your organization's IAM policy to ensure non-human identities are governed with the same rigor as human users.
Key Points
- •Roundtable discussion focused on Non-Human Identity (NHI) security
- •Collaboration between Saviynt and AUSCERT
- •Industry event held at Kiyomi Japanese restaurant
Deep Insight
Background and context from public sources — not the original article. 25 sources cited.
Enhanced Key Takeaways
- •Saviynt's approach to Non-Human Identity (NHI) security involves a unified platform that provides real-time inventory, contextual insights, and risk-based evaluation for both human and non-human identities.
- •Non-Human Identities, encompassing service accounts, API tokens, bots, and AI agents, are rapidly proliferating and often outnumber human identities, presenting significant security challenges due to inherent visibility gaps and potential for over-permissioning.
- •AUSCERT, established in 1993, is a non-profit organization headquartered at The University of Queensland, dedicated to offering advice, education, and solutions for cybersecurity threats to its network of over 500 member organizations across Australasia.
- •Saviynt's Identity Security Posture Management (ISPM) for NHI extends established identity governance principles to non-human identities, aiming to proactively eliminate hidden risks and ensure clear, accountable ownership for these digital entities.
- •The Saviynt platform leverages AI-driven insights to enhance and automate critical security functions, including streamlining access reviews, accelerating provisioning processes, and supporting contextual decision-making for managing both human and non-human identities.
Competitor Analysis
- Saviynt
- Cloud-native IGA & PAM, converged identity security (human & non-human), AI-driven.
- SailPoint
- Enterprise-grade IGA, compliance, security, user lifecycle management.
- Okta
- Identity & Access Management (IAM), SSO, MFA, workforce identity.
- Microsoft Entra ID
- Microsoft ecosystem integration, conditional access, PIM, hybrid identity.
- CyberArk
- Privileged Access Management (PAM), securing privileged accounts, least privilege.
- Saviynt
- Strong focus, unified governance for human, non-human, and AI identities, real-time inventory, risk evaluation.
- SailPoint
- Focus on identity governance for human and machine identities, but less explicit emphasis on AI agents.
- Okta
- Primarily workforce IAM, less direct emphasis on comprehensive NHI governance.
- Microsoft Entra ID
- PIM for privileged identities, including some non-human, but not as broad as Saviynt's NHI focus.
- CyberArk
- Strong for privileged non-human identities (e.g., service accounts, secrets).
- Saviynt
- Cloud-native, SaaS.
- SailPoint
- Cloud governance, enterprise integration ecosystem.
- Okta
- Cloud-native.
- Microsoft Entra ID
- Cloud-based, hybrid identity support.
- CyberArk
- SaaS and on-premises options for PAM.
- Saviynt
- AI-driven insights for access reviews, provisioning, risk detection, AI agent security.
- SailPoint
- Advanced Analytics Engine.
- Okta
- Adaptive Authentication.
- Microsoft Entra ID
- Privileged Identity Management.
- CyberArk
- Focus on privilege protection.
- Saviynt
- Implementation and ongoing customization can drive up total cost of ownership for some customers.
- SailPoint
- High setup cost, long setup, specialized skills required.
- Okta
- Expensive at scale, complex legacy integrations, premium modules cost extra.
- Microsoft Entra ID
- Microsoft-centric, complex pricing.
- CyberArk
- Adds complexity unless PAM is a primary requirement.
| Feature/Aspect | Saviynt | SailPoint | Okta | Microsoft Entra ID | CyberArk |
|---|---|---|---|---|---|
| Primary Focus | Cloud-native IGA & PAM, converged identity security (human & non-human), AI-driven. | Enterprise-grade IGA, compliance, security, user lifecycle management. | Identity & Access Management (IAM), SSO, MFA, workforce identity. | Microsoft ecosystem integration, conditional access, PIM, hybrid identity. | Privileged Access Management (PAM), securing privileged accounts, least privilege. |
| NHI Security | Strong focus, unified governance for human, non-human, and AI identities, real-time inventory, risk evaluation. | Focus on identity governance for human and machine identities, but less explicit emphasis on AI agents. | Primarily workforce IAM, less direct emphasis on comprehensive NHI governance. | PIM for privileged identities, including some non-human, but not as broad as Saviynt's NHI focus. | Strong for privileged non-human identities (e.g., service accounts, secrets). |
| Deployment | Cloud-native, SaaS. | Cloud governance, enterprise integration ecosystem. | Cloud-native. | Cloud-based, hybrid identity support. | SaaS and on-premises options for PAM. |
| AI/ML Capabilities | AI-driven insights for access reviews, provisioning, risk detection, AI agent security. | Advanced Analytics Engine. | Adaptive Authentication. | Privileged Identity Management. | Focus on privilege protection. |
| Noted Drawbacks | Implementation and ongoing customization can drive up total cost of ownership for some customers. | High setup cost, long setup, specialized skills required. | Expensive at scale, complex legacy integrations, premium modules cost extra. | Microsoft-centric, complex pricing. | Adds complexity unless PAM is a primary requirement. |
Technical Deep Dive
- Saviynt Identity Cloud is a converged platform designed to unify Identity Governance and Administration (IGA), Privileged Access Management (PAM), and application Governance, Risk, and Compliance (GRC) capabilities.
- The platform's architecture is built on a scalable framework that ensures full data, network, and service isolation.
- It features automated discovery tools to inventory workloads, service accounts, and credentials across diverse IT environments.
- Saviynt leverages AI-driven insights to enhance risk detection, streamline access reviews, and automate remediation processes.
- The solution supports just-in-time (JIT) access, which minimizes standing privileges for both privileged and non-human accounts.
- It provides a unified view that maps each non-human identity to its human owner, business purpose, and applicable policy, ensuring comprehensive governance.
- The architecture allows for customers to bring their own (BYO) keys and vaults for enhanced encryption.
- A mature SaaS operational continuous integration and deployment (CI/CD) pipeline facilitates continuous improvements and rapid delivery of new features.
Future ImplicationsAI analysis grounded in cited sources
Timeline
- 2010Saviynt founded in El Segundo, California.
- 2011Launched the first Cloud IGA platform optimized for SAP environments.
- 2018Secured $40 million in Series A funding, expanding into Privileged Access Management (PAM) and Third-Party Access Governance.
- 2024Surpassed $200M ARR and introduced the Identity Cloud, managing over 50 million identities.
- 2025-10-29Announced general availability of Identity Security Posture Management for Non-Human Identities (ISPM for NHI).
- 2025-12-09Closed a $700 million Series B funding round, valuing the company at approximately $3 billion.
Sources (25)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events →
AI-curated news aggregator. All content rights belong to original publishers.
Original source: iTNews Australia ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
The weekly digest
One email a week. Unsubscribe anytime.