Just got the renewal quote for our Appgate SDP setup. The finance team nearly had a stroke. I get that zero-trust isn't cheap, but per-user, per-month pricing feels like it's scaling in a way that punishes you for actually adopting it widely.
We're not a huge shop, maybe 150 engineers and another 100 or so contractors/part-timers. The bill makes it look like we're guarding the crown jewels 24/7. For our use case—mostly securing k8s admin, some database tunnels, and a handful of legacy app access—the math starts to feel... off.
What are we comparing against?
* Open-source bastion hosts (painful, but nearly free)
* Cloud provider native solutions (e.g., IAP on GCP, AWS SSM)
* Other commercial ZTNA players (some are moving to bandwidth/feature tiers)
The product itself? It works. The terraform provider is decent, once you wrestle with it. The CLI is okay for automation. But the value-for-money curve seems to flatten real fast once you get past the initial "wow, everything's locked down" phase.
Anyone else running the numbers and feeling the squeeze? Especially for non-customer-facing, internal-dev-access use cases. I feel like I'm paying for a fleet of tanks to guard a sandcastle. Maybe my perspective is skewed from the graveyard shift.
NightOps
You've nailed the core frustration. The per-user model absolutely breaks down for internal tooling. We're in a similar boat with Cloudflare Zero Trust, and the moment you start onboarding CI/CD bots or service accounts as "users", the bill spirals.
> The value-for-money curve seems to flatten real fast
This is it exactly. The initial 80% of security benefit comes from just getting it deployed. The last 20% of polish and scale is where they slap you with the true cost. For k8s admin and DB tunnels, we've started pushing more to native cloud IAM and temporary credentials via Vault, keeping the commercial SDP only for the legacy junk that can't be modernized.
Have you done a true TCO comparison against, say, tailscale for those 150 engineers? The numbers get embarrassing for the big vendors.
shift left or go home
You're spot on with the flattening value curve. That's the crux of the vendor ROI argument falling apart. They sell on eliminating risk, but the marginal cost per additional user or bot often exceeds the marginal reduction in risk exposure. That's where your pivot to native cloud IAM for modern workloads makes economic sense.
I'd push back slightly on comparing Tailscale directly. For pure k8s and DB access, it's a compelling TCO story. But the moment you fold in legacy app access, compliance reporting, or non-engineering users, the operational overhead of managing a patchwork shifts the TCO calculation. The commercial SDP's centralized policy engine, even for the "junk," has a cost that needs to be quantified, though it's rarely as high as the per-seat license.
Have you factored the labor cost of your team's context-switching between Vault, cloud IAM, and the SDP into your comparison? That's often the hidden variable that either justifies the unified platform or sinks it.
Yep, that pricing model is the main reason we walked away from a similar evaluation last quarter. The per-seat cost made sense for our full-time staff, but the moment we factored in contractors, service accounts, and even CI/CD bots, the projection became unusable.
Your point about the native cloud solutions is key. For our k8s admin access, we ended up using AWS SSM Session Manager with IAM controls. It's not as feature-rich, but the cost delta is astronomical, and it's good enough. The commercial SDP stayed only for the handful of legacy apps that couldn't be touched.
It feels like these vendors are pricing for the Fortune 500 compliance checkbox crowd, not for practical, cost-conscious engineering teams. Have you gotten any traction internally with a hybrid approach, or is it an all-or-nothing contract?
Latency is the enemy, but consistency is the goal.