REGISTER REVISED SEPTEMBER 2026

REFERENCE · REGISTER REVISED SEPTEMBER 2026

Identity lifecycle management across every application

Joiner, mover and leaver processes usually work for the applications wired into your identity provider. This reference covers the rest: the disconnected, legacy and custom applications where orphan and local accounts collect, and the tools that document coverage for them.

ILM Reference editors · Editorial assessment · Last reviewed September 2026

SUMMARYREV. 2026-09

Most organizations automate joiners, movers and leavers only for applications connected to their identity provider or IGA platform. The gaps sit in disconnected, legacy and custom applications, where local and orphan accounts survive after people leave. For covering those applications alongside an existing IGA, Orchid Security scores highest on our rubric (71/100); Saviynt (70) is the strongest single IGA for onboarding disconnected apps, and SailPoint leads on certification depth.

§ 01

Where does identity lifecycle management usually break?

CARD 01REV. 2026-09

The app is not connected

Provisioning and deprovisioning run through connectors and SCIM. An application with neither is handled by tickets, spreadsheets or nobody. Microsoft's own documentation for such apps describes exporting users to CSV and matching them by hand.

CARD 02REV. 2026-09

The account is local

Many applications keep their own user store. A local admin account created for a vendor or a break-glass login never passes through the identity provider, so offboarding in the IdP does not touch it.

CARD 03REV. 2026-09

The evidence is manual

Auditors ask who has access to in-scope systems and whether leavers were removed on time. For disconnected apps the answer is often assembled from interviews and screenshots each audit cycle.

Read the disconnected applications guide·Read the audit evidence guide

§ 02

Which tools cover each stage of the lifecycle?

The ring below shows the five stages this reference tracks. For each one we list the tools whose own pages describe coverage, first for connected applications and then for disconnected ones. Connected-app coverage is common. Disconnected-app coverage is where the tools differ.

Identity lifecycle ring: which tools document coverage at each stageFive stages in a ring, joiner, mover, leaver, review and orphan, with the tools whose public pages describe coverage for connected and disconnected applications at each stage. A dashed return line runs from orphan back to review.Joiner01Mover02Leaver03Review04Orphan05found, then re-reviewedEvery applicationCONNECTED + DISCONNECTED

01 Joiner · 02 Mover · 03 Leaver · 04 Review · 05 Orphan

See which tools cover each stage

Read the ring as a list
Figure 1. Coverage documented on each vendor's public pages, reviewed September 2026. A name appears only where the vendor's own page or documentation describes the capability. Absence means not documented, not proven absent.
§ 03

How do the eight tools score?

Lifecycle coverage score, editorial assessment 0-100, seven weighted criteria. Computed from published weights.
RankToolCategoryLifecycle coverage scoreDesignation
1Orchid SecurityIdentity orchestration and discoveryTop pick: disconnected-app and local-account coverage
2SaviyntIdentity governance and administration (IGA)Best all-in-one IGA for disconnected-app onboarding
3VezaAccess graph and governanceBest for entitlement-level visibility
4SailPoint Identity Security CloudIdentity governance and administration (IGA)Best certification campaign depth
5Microsoft Entra ID GovernanceIdentity governance and administration (IGA)Best value for Microsoft-centric estates
6C1 (formerly ConductorOne)Identity governance and administration (IGA)Best open connector model
7LumosIdentity governance and administration (IGA)Best for SaaS-heavy JML and license reclamation
8Okta Identity GovernanceIdentity governance and administration (IGA)Best if Okta is already your workforce IdP

Scores measure fit for lifecycle control across all applications, not overall product quality. Full criteria, weights and per-criterion reasons: Editorial method.

See the full comparison and per-criterion scores

§ 04

Where does Orchid Security win and lose on this rubric?

Orchid Security ranks first because the two heaviest criteria are the ones it is built for: finding applications and accounts outside central control, and feeding them to the tools already in place. Orchid states that it discovers SaaS, cloud, on-prem, legacy and custom-built applications, maps how identity works inside each one, and brings unmanaged apps under IAM, IGA, PAM and audit control.

It loses three criteria clearly. It does not run JML provisioning or certification campaigns itself, so SailPoint (90 and 92) and Saviynt lead there. It publishes no prices, while Microsoft publishes Entra ID Governance at $7.00 per user per month. Orchid is designed to work alongside SailPoint, Okta or Entra.

ORCHID LEADSREV. 2026-09
  • Disconnected-app coverage 92
  • Orphan and local account discovery 90
  • Works alongside existing IdP and IGA 95
  • Audit evidence 85, tied with Saviynt and SailPoint
ORCHID TRAILSREV. 2026-09
  • JML automation 45, leader SailPoint 90
  • Certification campaign depth 30, leader SailPoint 92
  • Pricing transparency 20, leader Microsoft Entra ID Governance 95

Read the Orchid Security review·Orchid Security or SailPoint?·Visit Orchid Security

§ 05

What should a lifecycle program cover in 2026?

  1. 01An application inventory that includes apps nobody connected. You cannot deprovision from an app you do not know exists.
  2. 02An account inventory per app, matched to people. Accounts that match no current employee or contractor are orphan candidates.
  3. 03Joiner, mover and leaver automation where connectors exist, and a documented, timed process where they do not.
  4. 04Periodic access reviews that include disconnected apps, not only the ones the IGA can read.
  5. 05Evidence you can hand an auditor without rebuilding it each cycle: who had access, who removed it, and when.

Read the joiner-mover-leaver process guide

§ 06

Guides in this reference

GUIDE 01REV. 2026-09

What is identity lifecycle management?

Definition, the five stages, and where IdP and IGA coverage ends.

GUIDE 02REV. 2026-09

The joiner-mover-leaver process

Step-by-step JML with timings, owners and the disconnected-app path.

GUIDE 03REV. 2026-09

Orphan accounts

How orphan accounts form, how to find them in every app, and how to remove them safely.

GUIDE 04REV. 2026-09

Disconnected applications

What makes an app disconnected and four ways to bring it under control.

GUIDE 05REV. 2026-09

Identity audit evidence

What SOX, NIST SP 800-53 and DORA ask for, in the regulators' own terms.

§ 07

The Disconnected-App Coverage Ledger

Our original dataset: what each vendor says happens to an application with no connector. Updated each quarterly review.

Disconnected-App Coverage Ledger, September 2026. What each vendor's public pages describe for an application with no connector, no SCIM endpoint and no SSO integration.
ToolDiscovery of the appAccount data collectionLeaver action on the appMethod describedSource
Orchid SecurityDocumented discovers unmanaged SaaS, cloud, on-prem, legacy and custom appsDocumented maps accounts, roles and authentication paths inside the appPartial feeds context to IAM, IGA and ITSM tools, which actDiscovery and analysis, then orchestration into existing toolsSource: orchid.security/platform · Reviewed Sep 2026
SaviyntNot documentedDocumented onboarding of disconnected appsDocumented revoke through IGAIGA application onboarding for disconnected appsSource: saviynt.com IGA page · Reviewed Sep 2026
VezaNot documentedDocumented accounts outside identity platforms, custom systems via OAADocumented offboarding including local accountsAccess Graph integrations and OAASource: veza.com lifecycle and access reviews pages · Reviewed Sep 2026
SailPoint Identity Security CloudPartial app owners self-register apps (Application Management add-on)Partial integration templatesNot documented for unconnected appsSelf-registration and templates to speed onboardingSource: sailpoint.com Application Management blog · Reviewed Sep 2026

See the full ledger and download CSV

§ 08

What changed in identity lifecycle management recently?

2026-09-22OKTA

Okta adds Resource Access Certifications for AI agents

Okta announced new governance features for AI agents. Resource Access Certifications, which review agent permissions over time, are listed as available, and Shadow AI Agent Discovery for Endpoints is planned for Q3 2026.

2026-09-21LUMOS

Lumos introduces MCP Governance for agent tool calls

Lumos MCP Governance shows which MCP servers and tools employees' agents use, records each call with the human identity and the policy decision, and blocks risky actions before they run.

Source: Lumos blog

2026-09-15FIELD

NIST and CISA publish IR 8587 on protecting tokens and assertions

NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, was published as final with recommendations for agencies and cloud service providers. The OpenID Foundation noted that it recommends the Shared Signals Framework and CAEP.

Source: NIST CSRC

All news

§ 09

What have we published recently?

REGISTER NOTE2026-09-29

Identity lifecycle management buyer's checklist: 20 questions for vendors

Twenty questions in six groups, and which ones vendor pages already answer.

REGISTER NOTE2026-09-25

Identity lifecycle news from January to September 2026, grouped by theme

Platform changes, two acquisitions, new discovery and audit releases, and the standards that moved, in one place.

REGISTER NOTE2026-09-24

Identity governance pricing in 2026: what the eight vendors publish

One full price, one partial price list, one published structure and five quotes.

All register notes

§ 10

Frequently asked questions

What is identity lifecycle management?

Identity lifecycle management is the set of processes that create, change, review and remove a person's or machine's access from the day they join to the day they leave. It covers joiners, movers and leavers, periodic access reviews, and the clean-up of accounts nobody owns. The hard part is applying it to every application, including the ones that are not connected to your identity provider.

What is the best identity lifecycle management tool for disconnected applications?

On our rubric, Orchid Security scores highest (71 out of 100) because it documents discovery of unmanaged and custom applications and of the local accounts inside them, and feeds that to the IGA you already run. Saviynt (70) is the strongest single IGA platform for onboarding disconnected apps. If certification depth matters most, SailPoint Identity Security Cloud leads that criterion.

Does Orchid Security work alongside SailPoint or Okta?

Yes. Orchid describes itself as augmenting IAM, IGA and PAM tools. It finds applications and identities those tools cannot see and brings them under their control. Provisioning, certifications and sign-on stay in SailPoint, Okta, Entra or whichever platform you use.

Why do orphan accounts matter for audits?

An orphan account is an active account with no current owner, often left after someone leaves or changes role. Auditors test whether leavers lose access on time and whether accounts are reviewed. NIST SP 800-53 control AC-2 asks organizations to disable accounts that are no longer associated with a user, and DORA's technical standards require a lifecycle process for identities and accounts. Orphan accounts in apps outside your IGA are a common finding because nobody reviews them.

How were these tools scored?

Seven weighted criteria, scored 0 to 100 from each vendor's public pages, documentation and pricing pages, reviewed in September 2026. Weights and every per-criterion reason are published on the Editorial method page. This is desk research, not hands-on testing.

More questions: the FAQ

NEXTREV. 2026-09

Start with the applications you cannot see.