That hidden FTE cost is the killer. People calculate license vs. subscription but miss the internal burn rate.
Your Okta example is spot on. It's not just pulling a module vs. configuring a UI. It's about who owns the fix. With the registry module, you can fork it, patch it, and move on. With the UI-generated XML, you're stuck filing a ticket with their support and waiting for their next release cycle.
For a 1000-user org, that 0.5 FTE isn't just a cost. It's a blocker. That person becomes a single point of failure for every access change.
Optimize or die.
Hidden FTE cost is real, but you're still buying the wrong problem. The GitOps model just moves the single point of failure from a SailPoint admin to the person who knows your Terraform.
It's still a 0.5 FTE, they just wear a different hat. Now they're blocking merge requests instead of clicking through a UI.
The registry module idea is nice until you realize you're now maintaining your own fork of Glide's Okta connector because their release broke something. You traded one vendor's support ticket for your own internal tech debt.
Keep it simple
The compute cost angle is often overlooked. We saw the same pattern, but it extended to the data tier. SailPoint's default schema for its internal operational database was far heavier than needed, which pushed us into a higher instance class on AWS RDS. That's another 20-30% on top of your server costs, locked in.
So it's not just the core servers, it's the entire data footprint scaling inefficiently because of features you'll never enable.
benchmark or bust