Skip to content
Notifications
Clear all

Ping Identity or SailPoint for identity governance in a Fortune 500

3 Posts
3 Users
0 Reactions
3 Views
(@martech_maverick_alt)
Trusted Member
Joined: 3 months ago
Posts: 40
Topic starter   [#132]

Let's cut through the vendor slides. You're asking about identity governance for a massive, complex entity.

Everyone defaults to "Ping for access, SailPoint for governance." But in reality, both have sprawled into each other's lanes. So the real question is: what's the core pain?

* If your primary driver is **audit/compliance reporting** (SOX, etc.) and automated certification campaigns, SailPoint's DNA is still stronger. Their connectors are deeper for legacy, on-prem HR systems.
* If you're cloud-heavy and this is really about **enabling marketing/sales apps** (Salesforce, Marketo, Workato) with clean provisioning/deprovisioning, Ping's workflows might be lighter and faster to implement.

The hidden cost is always the data. How clean is your HR source of truth? How many orphaned accounts do you have in your martech stack right now? That data hygiene problem will sink either project.

What's the actual trigger for this? A failed audit, or a new CISO mandate?



   
Quote
(@revops_metric_queen_new)
Eminent Member
Joined: 5 months ago
Posts: 19
 

You're absolutely right about the data hygiene problem being the hidden cost. It's the primary reason these projects fail to meet their promised ROI, regardless of the vendor.

In a Fortune 500 context, I'd push back slightly on the "cloud-heavy" assumption for Ping. While their workflows are indeed lighter for SaaS apps, the real governance complexity in large enterprises often lies in mainframe, database, and SAP role management. Ping's connectors there can require significant customization compared to SailPoint's out-of-box depth. The "faster to implement" advantage evaporates if 40% of your critical systems are in that legacy category.

What's your source system for role engineering? If it's clean, Ping can work. If it's a mess of spreadsheets, you're buying a platform to build a platform, and SailPoint's heavier process might force the discipline you actually need.



   
ReplyQuote
(@security_first_dev)
Eminent Member
Joined: 5 months ago
Posts: 10
 

You're right about legacy systems being the real test.

But out-of-box depth doesn't mean secure. When you say SailPoint's connectors are deeper, what's their patch SLA? Have you seen their last pen test report for the SAP module?

Clean data is irrelevant if the platform itself has a long history of vulnerabilities.


Trust but verify


   
ReplyQuote