Build vs Buy for Identity Governance: The Middle Option Teams Miss
Identity governance projects fail less from bad technology than from bad cost models. The real decision is not build versus buy; it is whether you can afford the middle option most teams never price: assembling governance from identity primitives, workflow, and controls you already run.
Nesqual Tech AI
The hidden cost is not licensing — it is the control plane you do not price
A Fortune 500 security team recently replaced a $1.2M annual identity governance suite after discovering that 38% of its spend went to connectors, customization, and admin work, not policy enforcement. The replacement was not a full rebuild or a clean SaaS swap; it was a hybrid control plane built from existing IdP, HR, ticketing, and SIEM tools.
That is the part most teams miss when they compare build versus buy for identity governance. They price licenses, then underestimate the operating model, the integration tax, and the exception handling that actually consumes the budget.
If your review cycles still take 11 days, your joiner-mover-leaver process still depends on CSV exports, or your auditors keep asking for evidence you can only produce manually, the decision is not simply build versus buy. The real choice is whether you want to own the control plane or rent it.
What identity governance really costs in 2026
Identity governance in 2026 is not just access reviews. It includes entitlement discovery, policy enforcement, segregation-of-duties checks, privileged access oversight, evidence collection, and lifecycle automation across SaaS, cloud, and on-prem systems.
The three cost buckets most teams undercount
- License or engineering cost: the obvious line item.
- Integration cost: connectors, schema mapping, event handling, and exception logic.
- Run cost: policy tuning, audit support, workflow maintenance, and false-positive cleanup.
A realistic mid-market deployment with 8,000 employees and 120 applications often looks like this:
- Commercial IGA suite: $180K to $420K/year in subscription fees.
- Professional services and implementation: $250K to $900K one-time.
- Internal admin and engineering time: 0.5 to 1.5 FTE ongoing.
- Audit and remediation overhead: 80 to 200 hours per quarter.
By contrast, a build approach using Microsoft Entra ID, Okta, SailPoint APIs, ServiceNow, and a workflow engine can reduce license spend but shift cost into engineering and operations. If you need 6 to 9 months to reach parity on access requests, certifications, and evidence export, the build path is only cheaper if your team can absorb that delay.
A simple pricing model you can use
Total Cost of Ownership (3 years)
= Platform licenses
+ Implementation
+ Integration maintenance
+ Security review and compliance evidence
+ Internal engineering time
+ Failure cost from delayed access or audit gaps
A team that ignores the last two lines usually picks the wrong option.
Build versus buy for identity governance: when each path wins
The build versus buy for identity governance decision should start with constraints, not ideology. If you have a stable app portfolio, strict compliance requirements, and a small number of high-value workflows, buying can be faster and safer. If you have a highly customized stack, strong platform engineering, and frequent policy changes, building can outperform on flexibility.
Buy when the problem is broad and the process is stable
Buy if you need:
- Access reviews across hundreds of apps.
- Out-of-the-box certifications and audit trails.
- Prebuilt connectors for SAP, Workday, ServiceNow, AWS, Azure, and Google Cloud.
- Vendor support for regulatory evidence and segregation-of-duties rules.
A global manufacturer with 14,000 employees and 260 applications can often cut review cycle time from 14 days to 4 days using a mature SaaS IGA platform. The same team may also reduce audit evidence prep from 60 hours to 12 hours per quarter.
The tradeoff is rigidity. Once your governance model depends on vendor-specific workflows, changing policy logic can take weeks and may require paid services.
Build when the problem is narrow and the stack is yours
Build if you need:
- Custom approval paths for engineering, finance, and contractors.
- Event-driven lifecycle changes tied to HR and IAM events.
- Fine-grained policy logic that changes monthly.
- Tight integration with internal data products or service catalogs.
A cloud-native SaaS company with 1,200 employees and 40 internal apps may build a governance layer on top of Entra ID, Okta, Jira Service Management, and a lightweight policy service. If their access request latency drops from 2 days to 20 minutes and their engineering team spends 8 hours per week maintaining the system, build can win.
The decision rule CTOs actually use
Use buy when the governance workflow is a commodity. Use build when the workflow is a differentiator. Use neither if you are still trying to govern identities with spreadsheets and approvals in email.
The middle option most teams never price: assemble, do not purchase
The middle option in build versus buy for identity governance is not a compromise. It is an architecture choice: assemble governance from identity primitives you already own, then add only the missing control services.
This usually means:
- IdP for authentication and group data.
- HRIS as the source of truth for joiner/mover/leaver events.
- Ticketing/workflow for approvals.
- Policy engine for rules.
- SIEM or data lake for evidence and monitoring.
- Lightweight custom services for app-specific exceptions.
Why this option is often cheaper
You avoid paying a vendor to repackage capabilities you already have. You also avoid building every connector and report from scratch.
A practical example:
- Entra ID handles identities and groups.
- Workday triggers lifecycle events.
- ServiceNow handles approvals and tickets.
- AWS IAM Access Analyzer and cloud-native logs feed evidence.
- A small policy service evaluates SoD and role rules.
In one enterprise rollout, this architecture reduced the number of manual access exceptions from 1,400 per quarter to 280, while keeping engineering ownership to 2 platform engineers and 1 compliance analyst.
The architecture pattern
HRIS -> Event Bus -> Policy Service -> Workflow/Ticketing -> Target Apps
| | | |
| | | +--> Evidence Store
| | +--> SoD / Role Rules
| +--> Lifecycle Events
+--> Source of Truth
What you must price in the middle option
Do not assume the middle option is free just because you already own the tools. Price these items:
- Policy authoring and review.
- Connector maintenance.
- Evidence normalization.
- Alert tuning and false-positive handling.
- On-call ownership for failed provisioning.
A good rule: if the assembled model needs more than 1.5 FTE to keep access requests, certifications, and evidence reliable, it is no longer the cheap option. At that point, compare it directly with a commercial suite.
A practical decision framework for 2026
The build versus buy for identity governance choice becomes easier when you score the environment, not the vendor demo.
Score these five factors from 1 to 5
- Application diversity: How many unique systems need governance?
- Policy volatility: How often do rules change?
- Integration depth: Do you need custom APIs, event streams, or just standard connectors?
- Audit pressure: How often do you need evidence, certifications, and exception reports?
- Platform maturity: Do you already run identity, workflow, and data plumbing at scale?
If your total is 18 or higher, buy is usually safer. If your total is 12 or lower and you have strong platform engineering, assemble or build becomes realistic.
A sample scoring table
Scenario: 6,000-user SaaS company
- App diversity: 2
- Policy volatility: 5
- Integration depth: 4
- Audit pressure: 2
- Platform maturity: 5
Total: 18 -> assemble or build, not full-suite buy
Benchmark targets to compare options
Use these 2026 operational targets:
- Access request approval latency: under 30 minutes for standard requests.
- Quarterly certification completion rate: 95% within 10 business days.
- Provisioning failure rate: under 2%.
- Evidence retrieval time for auditors: under 15 minutes.
- False-positive SoD alerts: under 10% after tuning.
If a vendor cannot show these numbers in a pilot with your data, the price is incomplete.
Common pitfalls that distort build versus buy for identity governance
The biggest mistakes are predictable, and expensive.
1. Comparing license cost to engineering cost only
A team at a healthcare provider chose a build path because the software quote was $310K/year. They later spent $420K in internal labor and 11 months before the first audit-ready certification run.
Avoid it: Model three-year total cost, including audit remediation and support time.
2. Buying a suite before mapping the exceptions
Many teams buy a platform and then discover that 30% of their access requests are exceptions that the product workflow cannot express cleanly.
Avoid it: Sample 100 real requests before buying. If more than 20 are edge cases, test the workflow first.
3. Building without an evidence strategy
If your custom system cannot produce immutable logs, reviewer attestations, and exportable reports, auditors will treat it as a liability.
Avoid it: Store policy decisions and approvals in append-only logs, then mirror them to a searchable evidence store.
4. Ignoring ownership after go-live
Identity governance fails when nobody owns policy drift.
Avoid it: Assign a named product owner, a policy owner, and an operational SLA. For example: provisioning failures triaged in 30 minutes, policy changes reviewed weekly, and access review templates refreshed quarterly.
What a good middle architecture looks like in practice
A strong assembled model is not a pile of scripts. It is a governed service with clear boundaries.
Reference implementation
identity_governance:
source_of_truth: Workday
directory: Microsoft Entra ID
workflow: ServiceNow
policy_engine: OPA
evidence_store: Snowflake
logging: Splunk
provisioning:
method: SCIM
retry_policy: exponential_backoff
max_attempts: 5
controls:
access_reviews: quarterly
sod_checks: pre_request_and_post_change
privileged_access: separate_approval_chain
Where the middle option performs best
- Fast-moving SaaS companies with frequent org changes.
- Enterprises with strong platform teams and standardized APIs.
- Regulated firms that need custom evidence but not custom UI.
- M&A-heavy organizations that must onboard apps quickly.
In these environments, the assembled approach can cut time-to-control by 40% to 60% versus a full build, while avoiding the rigid workflow tax of a monolithic suite.
Key Takeaways
- Price the control plane, not just the license, when evaluating build versus buy for identity governance.
- Buy when your workflows are standard, your audit burden is high, and you need fast connector coverage.
- Build when policy logic changes often and your platform team already owns identity, workflow, and logging.
- Always price the middle option: assembling governance from identity primitives, workflow tools, and policy services you already run.
- Use measurable targets: approval latency, certification completion, provisioning failure rate, and evidence retrieval time.
- If the assembled model needs more than 1.5 FTE to operate reliably, compare it directly with a commercial suite.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Written by
Nesqual Tech AI
Nesqual Tech
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI