Saviynt is a major, innovative player, and its evolution makes visible exactly the question we are asking about the market. With Agent Access Gateway, the vendor adds a capability designed to control certain actions at runtime, in particular those of AI agents.
We follow this module attentively, but that does not mean we are convinced by the convergence goal itself. It is a very interesting architectural experiment to observe, and it immediately raises the question of trade-offs.
Organisations that historically choose Saviynt are looking for a SaaS IGA platform: modern, functionally rich, with a strong user experience and governance cockpit, centralised, able to give a broad view of identity and access. That is exactly the control-tower logic described above — historically, it is not the same constraint as an authorization engine designed to sit in an application's runtime.
An IGA can live with a rich web interface, complex processing, workflows, calls to a remote SaaS, synchronisations and asynchronous jobs. A runtime authorization engine sits on the critical path of a transaction: the application waits for its decision before moving on. Its latency budget must stay extremely low, almost imperceptible. There is no universal figure — it depends on the architecture — but a few hundred milliseconds that are perfectly acceptable in some SaaS interactions become potentially problematic when added to every application decision.
Ariovis position — August 2026
You choose a platform like Saviynt in part to get a clean, centralised SaaS control plane. But to make extremely fast decisions as close as possible to the applications, you may progressively have to push components back down into the infrastructure. That is exactly where our questions lie. Agent Access Gateway interests us above all because it makes visible the architectural trade-off the market will have to resolve. Today, Ariovis is more convinced by the complementarity of specialised technologies than by the search for a single platform able to absorb everything: an excellent IGA designed as a rich business control tower, and an excellent authorization engine designed from the start to decide fast in the runtime — rather than one platform forced to compromise on both architectures. This is our architects' conviction in August 2026, not a definitive truth: the market moves fast and we are watching Saviynt in particular to see how these constraints are actually resolved.
Netwrix Identity Manager
- Lifecycle
- Governance
- Roles
- Workflows
- Certifications
- Business understanding of identity
Axiomatics
- PDP
- Policies
- Context
- Fine-grained authorization
- Runtime decision
- Integration as close as possible to the PEPs
Today we would rather make two specialised architectures talk to each other extremely well than ask each of them to become the other.