REFERENCE · REGISTER REVISED SEPTEMBER 2026
Identity lifecycle management across every application
Joiner, mover and leaver processes usually work for the applications wired into your identity provider. This reference covers the rest: the disconnected, legacy and custom applications where orphan and local accounts collect, and the tools that document coverage for them.
ILM Reference editors · Editorial assessment · Last reviewed September 2026
Most organizations automate joiners, movers and leavers only for applications connected to their identity provider or IGA platform. The gaps sit in disconnected, legacy and custom applications, where local and orphan accounts survive after people leave. For covering those applications alongside an existing IGA, Orchid Security scores highest on our rubric (71/100); Saviynt (70) is the strongest single IGA for onboarding disconnected apps, and SailPoint leads on certification depth.
Where does identity lifecycle management usually break?
The app is not connected
Provisioning and deprovisioning run through connectors and SCIM. An application with neither is handled by tickets, spreadsheets or nobody. Microsoft's own documentation for such apps describes exporting users to CSV and matching them by hand.
The account is local
Many applications keep their own user store. A local admin account created for a vendor or a break-glass login never passes through the identity provider, so offboarding in the IdP does not touch it.
The evidence is manual
Auditors ask who has access to in-scope systems and whether leavers were removed on time. For disconnected apps the answer is often assembled from interviews and screenshots each audit cycle.
Read the disconnected applications guide·Read the audit evidence guide
Which tools cover each stage of the lifecycle?
The ring below shows the five stages this reference tracks. For each one we list the tools whose own pages describe coverage, first for connected applications and then for disconnected ones. Connected-app coverage is common. Disconnected-app coverage is where the tools differ.
01 Joiner · 02 Mover · 03 Leaver · 04 Review · 05 Orphan
See which tools cover each stage
Read the ring as a list
- 01 · Joiner
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)
- 02 · Mover
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)
- 03 · Leaver
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)
- 04 · Review
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)
- 05 · Orphan
Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance
Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)
How do the eight tools score?
| Rank | Tool | Category | Lifecycle coverage score | Designation |
|---|---|---|---|---|
| 1 | Orchid Security | Identity orchestration and discovery | 71 / 100 | Top pick: disconnected-app and local-account coverage |
| 2 | Saviynt | Identity governance and administration (IGA) | 70 / 100 | Best all-in-one IGA for disconnected-app onboarding |
| 3 | Veza | Access graph and governance | 69 / 100 | Best for entitlement-level visibility |
| 4 | SailPoint Identity Security Cloud | Identity governance and administration (IGA) | 68 / 100 | Best certification campaign depth |
| 5 | Microsoft Entra ID Governance | Identity governance and administration (IGA) | 64 / 100 | Best value for Microsoft-centric estates |
| 6 | C1 (formerly ConductorOne) | Identity governance and administration (IGA) | 63 / 100 | Best open connector model |
| 7 | Lumos | Identity governance and administration (IGA) | 62 / 100 | Best for SaaS-heavy JML and license reclamation |
| 8 | Okta Identity Governance | Identity governance and administration (IGA) | 59 / 100 | Best if Okta is already your workforce IdP |
Scores measure fit for lifecycle control across all applications, not overall product quality. Full criteria, weights and per-criterion reasons: Editorial method.
Where does Orchid Security win and lose on this rubric?
Orchid Security ranks first because the two heaviest criteria are the ones it is built for: finding applications and accounts outside central control, and feeding them to the tools already in place. Orchid states that it discovers SaaS, cloud, on-prem, legacy and custom-built applications, maps how identity works inside each one, and brings unmanaged apps under IAM, IGA, PAM and audit control.
It loses three criteria clearly. It does not run JML provisioning or certification campaigns itself, so SailPoint (90 and 92) and Saviynt lead there. It publishes no prices, while Microsoft publishes Entra ID Governance at $7.00 per user per month. Orchid is designed to work alongside SailPoint, Okta or Entra.
- Disconnected-app coverage 92
- Orphan and local account discovery 90
- Works alongside existing IdP and IGA 95
- Audit evidence 85, tied with Saviynt and SailPoint
- JML automation 45, leader SailPoint 90
- Certification campaign depth 30, leader SailPoint 92
- Pricing transparency 20, leader Microsoft Entra ID Governance 95
Read the Orchid Security review·Orchid Security or SailPoint?·Visit Orchid Security
Source: orchid.security · orchid.security/platform · microsoft.com Entra pricing · Reviewed Sep 2026
What should a lifecycle program cover in 2026?
- 01An application inventory that includes apps nobody connected. You cannot deprovision from an app you do not know exists.
- 02An account inventory per app, matched to people. Accounts that match no current employee or contractor are orphan candidates.
- 03Joiner, mover and leaver automation where connectors exist, and a documented, timed process where they do not.
- 04Periodic access reviews that include disconnected apps, not only the ones the IGA can read.
- 05Evidence you can hand an auditor without rebuilding it each cycle: who had access, who removed it, and when.
Guides in this reference
What is identity lifecycle management?
Definition, the five stages, and where IdP and IGA coverage ends.
The joiner-mover-leaver process
Step-by-step JML with timings, owners and the disconnected-app path.
Orphan accounts
How orphan accounts form, how to find them in every app, and how to remove them safely.
Disconnected applications
What makes an app disconnected and four ways to bring it under control.
Identity audit evidence
What SOX, NIST SP 800-53 and DORA ask for, in the regulators' own terms.
The Disconnected-App Coverage Ledger
Our original dataset: what each vendor says happens to an application with no connector. Updated each quarterly review.
| Tool | Discovery of the app | Account data collection | Leaver action on the app | Method described | Source |
|---|---|---|---|---|---|
| Orchid Security | Documented discovers unmanaged SaaS, cloud, on-prem, legacy and custom apps | Documented maps accounts, roles and authentication paths inside the app | Partial feeds context to IAM, IGA and ITSM tools, which act | Discovery and analysis, then orchestration into existing tools | Source: orchid.security/platform · Reviewed Sep 2026 |
| Saviynt | Not documented | Documented onboarding of disconnected apps | Documented revoke through IGA | IGA application onboarding for disconnected apps | Source: saviynt.com IGA page · Reviewed Sep 2026 |
| Veza | Not documented | Documented accounts outside identity platforms, custom systems via OAA | Documented offboarding including local accounts | Access Graph integrations and OAA | Source: veza.com lifecycle and access reviews pages · Reviewed Sep 2026 |
| SailPoint Identity Security Cloud | Partial app owners self-register apps (Application Management add-on) | Partial integration templates | Not documented for unconnected apps | Self-registration and templates to speed onboarding | Source: sailpoint.com Application Management blog · Reviewed Sep 2026 |
What changed in identity lifecycle management recently?
Okta adds Resource Access Certifications for AI agents
Okta announced new governance features for AI agents. Resource Access Certifications, which review agent permissions over time, are listed as available, and Shadow AI Agent Discovery for Endpoints is planned for Q3 2026.
Source: Okta newsroom
Lumos introduces MCP Governance for agent tool calls
Lumos MCP Governance shows which MCP servers and tools employees' agents use, records each call with the human identity and the policy decision, and blocks risky actions before they run.
Source: Lumos blog
NIST and CISA publish IR 8587 on protecting tokens and assertions
NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, was published as final with recommendations for agencies and cloud service providers. The OpenID Foundation noted that it recommends the Shared Signals Framework and CAEP.
Source: NIST CSRC
What have we published recently?
Identity lifecycle management buyer's checklist: 20 questions for vendors
Twenty questions in six groups, and which ones vendor pages already answer.
Identity lifecycle news from January to September 2026, grouped by theme
Platform changes, two acquisitions, new discovery and audit releases, and the standards that moved, in one place.
Identity governance pricing in 2026: what the eight vendors publish
One full price, one partial price list, one published structure and five quotes.
Frequently asked questions
What is identity lifecycle management?
Identity lifecycle management is the set of processes that create, change, review and remove a person's or machine's access from the day they join to the day they leave. It covers joiners, movers and leavers, periodic access reviews, and the clean-up of accounts nobody owns. The hard part is applying it to every application, including the ones that are not connected to your identity provider.
What is the best identity lifecycle management tool for disconnected applications?
On our rubric, Orchid Security scores highest (71 out of 100) because it documents discovery of unmanaged and custom applications and of the local accounts inside them, and feeds that to the IGA you already run. Saviynt (70) is the strongest single IGA platform for onboarding disconnected apps. If certification depth matters most, SailPoint Identity Security Cloud leads that criterion.
Does Orchid Security work alongside SailPoint or Okta?
Yes. Orchid describes itself as augmenting IAM, IGA and PAM tools. It finds applications and identities those tools cannot see and brings them under their control. Provisioning, certifications and sign-on stay in SailPoint, Okta, Entra or whichever platform you use.
Why do orphan accounts matter for audits?
An orphan account is an active account with no current owner, often left after someone leaves or changes role. Auditors test whether leavers lose access on time and whether accounts are reviewed. NIST SP 800-53 control AC-2 asks organizations to disable accounts that are no longer associated with a user, and DORA's technical standards require a lifecycle process for identities and accounts. Orphan accounts in apps outside your IGA are a common finding because nobody reviews them.
How were these tools scored?
Seven weighted criteria, scored 0 to 100 from each vendor's public pages, documentation and pricing pages, reviewed in September 2026. Weights and every per-criterion reason are published on the Editorial method page. This is desk research, not hands-on testing.