Security & Compliance

The Real TCO of Running IGA and SaaS Management as Separate Tools

Aditi Sharma
Director, Strategy & GTM
July 1, 2026
8 MIn read

Ready to secure your identity surface?

About the author

Aditi leads Go-to-Market (GTM) and Business Strategy at Zluri, where she helps mid-market organizations modernize their identity governance and access management practices. Prior to Zluri, she was a Management Consultant at McKinsey & Company advising large enterprises on digital transformation, and part of the enterprise software investment team at B Capital. She holds an engineering degree from IIT Kharagpur and an MBA from Harvard Business School.

When teams compare the cost of separate IGA and SaaS management tools against one converged platform, they compare invoices. But the invoices are the smallest and most visible line of the bill. The expensive parts are the ones that never appear on a purchase order: the human sync layer, the errors from drift, and the savings that never get the chance to happen.

The two disciplines depend on each other's answers, and when they run as separate tools, that dependency becomes a manual handoff with a person and a spreadsheet in the middle. We've covered the full comparison, what each side answers, how much they share, and where the seam breaks, in identity governance vs. SaaS management. This piece follows that seam to its financial conclusion: what does running them separately actually cost, in total, once you count everything?

The honest answer requires counting five categories of cost, and only the first one shows up in a procurement comparison.

The TCO at a glance

The first two rows are what procurement compares. The last three are where the money actually goes. Here's each of them.

Cost 1: The visible stack, doubled

Start with the obvious layer, because even it is bigger than the two license fees.

Running two platforms means two of everything operational:

  • Two implementations, each with its own setup, configuration effort, and ramp time
  • Two admin consoles for your team to learn, staff, and maintain
  • Two vendor relationships, two support contracts, two roadmaps to track
  • Two renewal negotiations a year, each defended separately to finance
  • Two training cycles every time the team changes

None of this is hidden, exactly. It's just rarely added up as one number, because the two tools sit in different budget lines owned by different teams, which is itself part of the problem: nobody sees the combined figure.

Cost 2: The integration you'll build, and keep rebuilding

Two tools that depend on each other's answers need a connection, so someone builds one: an API integration, a middleware job, a scheduled export-import.

The build is the cheap part. The ongoing cost is that the integration sits at the mercy of two vendors' release cycles. Either side changes an API, a field, or a data model, and the sync degrades, sometimes loudly, more often silently. Silent is worse: a sync that's been dropping records for six weeks doesn't announce itself, it just quietly widens the gap between the two inventories until someone asks a question that needs both and gets two different answers.

An integration between two vendors' products is a third product. It just doesn't come with a vendor, a roadmap, or anyone whose job is keeping it alive.

Cost 3: The human reconciliation layer

This is the line item that never appears in any budget, and it's usually the largest of the hidden ones.

When the platforms don't share a data model, a person becomes the data model. Someone on the IT or security team ends up doing, by hand, forever:

  • Noticing when the SMP discovers a new application, and manually adding it to the IGA's review scope
  • Cross-checking before every reclamation that revoking the license doesn't break a role policy or an active approval sitting in the other tool
  • Reconciling the two inventories periodically, chasing down why the SMP shows 100 apps and the IGA governs 30
  • Rebuilding the savings analysis manually at renewal time, exporting revocation logs from one tool and pricing them against contract data from the other

Price this honestly: a meaningful fraction of a skilled FTE, permanently, doing work that exists only because the two tools can't talk. And it's fragile in the way manual processes always are: it degrades when that person is busy, breaks when they leave, and was never anyone's actual job to begin with.

Cost 4: The errors that drift produces

The reconciliation layer, being human, misses things. Each miss has a price.

Stale review scopes become audit findings. Applications discovered in the SMP but never added to governance scope mean access reviews that were complete by the wrong definition of complete. The cost arrives later, as an audit finding, a remediation project, and in the worst case, an incident inside an app nobody was governing.

Blind reclamations become breakage and tickets. A license reclaimed on usage data alone, without governance context, occasionally revokes access someone legitimately needed. The cost is the outage, the ticket, the re-provisioning cycle, and the quieter long-term cost: after one bad reclaim, the team starts skipping reclamations entirely, which converts the error cost into permanent waste.

Disagreement erodes trust in both tools. When the two inventories give different answers, every downstream decision slows down, because someone has to figure out which system is right this time. Two sources of truth is a polite name for zero sources of truth.

Separate tools turn two allied teams into opponents. This is the friction cost nobody prices. When IT and security own one tool and finance owns the other, every disagreement between the systems becomes a disagreement between the teams: whose dashboard is right, whose budget covers the fix, whose priority wins when the reclaim finance wants collides with the policy security enforces. Each side defends its tool because its tool is its version of the truth. The same conversation on one platform is two teams reading one number and deciding together. On two platforms, it's a negotiation between departments, held quarterly, forever, and the relationship cost compounds alongside the reconciliation cost.

Cost 5: The savings that never get the chance to happen

The final category isn't a cost you pay. It's money you never receive, which finance experiences the same way.

We've broken down the three savings categories in detail in why Zluri's IGA ships with SaaS management; the TCO-relevant summary:

  • Revocation savings go unattributed. The IGA frees licenses at every offboarding, but without cost and contract data in the same platform, nobody can prove the number, so the governance program keeps getting defended at renewal as pure cost.
  • Downgrade savings never exist. Moving users from premium tiers to standard tiers requires usage data, pricing data, and a modify action in one workflow. Split across two tools, the opportunity is invisible to one and unactionable by the other.
  • Consolidation savings stay invisible. Redundant apps across departments and fragmented contracts for the same tool only show up in a portfolio-wide view of spend, ownership, and usage together, which neither tool alone ever assembles.

In a converged platform, these aren't just captured, they typically offset a meaningful share of the platform's own cost. In a separate stack, they're not merely unrealized. Most of them can't happen at all, because no tool in the stack holds all the data the action needs.

The comparison procurement should actually run

Put the five categories together and the honest TCO comparison looks nothing like a license-fee bake-off:

The separate stack doesn't just cost more. It costs more while delivering less, and hides most of the difference in places no purchase order ever goes.

Where we obviously stand, and why we'll say it anyway

We build both categories on one data model, IGA and SaaS management sharing a single discovery and inventory layer, so we're not neutral on this comparison. But the argument above doesn't depend on our product. It depends on arithmetic anyone can run on their own environment: price the reconciliation hours, count the apps in the SMP that never made it into review scope, ask finance whether they've ever seen a savings number attributed to a governance action. If the answers are "a lot," "dozens," and "never," the separate stack is already costing more than its invoices, and has been for a while.

Frequently Asked Questions

Isn't a converged platform just more expensive upfront than either single tool?

Compared to buying only one of the two capabilities, sometimes. Compared to buying both separately, which is the actual alternative for organizations that need both, the converged platform is typically cheaper even on visible spend, before counting the integration, reconciliation, and error costs that only exist in the separate stack. And the captured savings, license reclamation, tier downgrades, consolidation, offset a meaningful share of the platform cost in a way neither standalone tool can replicate.

We already own both tools. Does this math justify replacing them?

Run the arithmetic on your own environment first: hours spent reconciling inventories, the gap between apps the SMP sees and apps the IGA governs, incidents traceable to blind reclamations or stale review scopes, and savings you can actually attribute versus savings you assume. If the hidden categories are small, your integration and process discipline may genuinely be covering the seam. In most environments we've seen, the honest count changes the renewal conversation.

Can't good process discipline eliminate the reconciliation cost without changing platforms?

It can reduce it, and disciplined teams do. But process discipline is a recurring operational cost, not a fix: you're paying people to be the data model, indefinitely, and the process degrades exactly when it matters most, during busy periods, team transitions, and audits. A shared data model isn't better process. It's the removal of the thing the process existed to compensate for.

Which of the five cost categories is usually the biggest?

It varies by environment, but the missed savings category is most often the largest in absolute terms, because it compounds: every quarter of unattributed revocations, nonexistent downgrades, and invisible consolidation opportunities is money that was available and never collected. The reconciliation headcount is usually second, and it's the one teams most consistently underestimate because it was never assigned, it just accreted onto someone's job.

Does the team friction cost really belong in a TCO analysis?

It's the hardest category to put a number on, but it has real financial consequences: decisions that take three meetings instead of one, reclamations skipped because nobody wants the cross-team fight, and renewal cycles where each tool's owner defends their own line item instead of optimizing the combined spend. Organizations that have run both models consistently report the one-platform version of these conversations is faster and less adversarial, which is a productivity gain even if it never gets its own budget line.

Ready to secure your identity surface?