Skip to content
Notifications
Clear all

What identity management solution actually works for a fast-growing startup?

5 Posts
5 Users
0 Reactions
28 Views
(@ethanf)
Trusted Member
Joined: 3 months ago
Posts: 62
Topic starter   [#21194]

We've outgrown our initial setup (mostly manual user provisioning across a dozen SaaS apps). We're now around 150 people, hiring quickly, and the security/compliance team is starting to ask questions.

I've been tasked with evaluating identity management solutions. Ping Identity is on our shortlist, but I'm trying to understand what actually works at our stage.

For those who have implemented something like Ping in a similar high-growth environment:
* Did you start with a full suite or just one component (like SSO)?
* How did the operational overhead scale? Did you need a dedicated IAM person?
* Was the value immediate for end-users (reduced friction) or was it more of a backend/security win initially?

I'm particularly wary of solutions that require massive configuration or slow us down. Any real-world experiences on implementation complexity or unexpected costs would be helpful.



   
Quote
(@code_weaver_max)
Reputable Member
Joined: 4 months ago
Posts: 370
 

We implemented Ping at my last place around the same headcount. Started with just SSO and automated provisioning (SCIM) for our core apps like Gmail, Slack, and Salesforce. That's where you get the quick wins.

The operational overhead was non-trivial. You definitely don't need a *dedicated* IAM person at 150, but whoever owns it needs solid cycles for the initial config and connector tuning. The value was mixed: huge backend win for security/compliance and offboarding, but users only really felt it through the single sign-on convenience.

Unexpected complexity often came from apps with weird SAML implementations or custom attributes. My advice? Prioritize the apps where automated de-provisioning matters most for security - that's where the real ROI is. The rest can come later. Ping's solid, but the setup is a project, not a plug-and-play.


Prompt engineering is the new debugging


   
ReplyQuote
(@code_panda)
Reputable Member
Joined: 5 months ago
Posts: 294
 

We started with SSO and automated provisioning too, exactly like user186's path. It's the right call.

But I'd push back a bit on the "huge backend win" part being separate from user value. When we automated de-provisioning, we *immediately* cut down on "I can't get into X" tickets from new hires. The real win was frontloading that config pain so every future hire was zero-touch. The security/compliance team gets their audit logs, but our help desk saved 5-10 hours a week.

The hidden cost? Connector maintenance isn't a one-time thing. Every time a SaaS app changes its API or SAML fields, something breaks. You need to budget time quarterly just for that. Ping's solid, but no platform spares you from it.


Spreadsheets > marketing slides.


   
ReplyQuote
(@datadog_dave)
Honorable Member
Joined: 4 months ago
Posts: 494
 

We did SSO and provisioning first too. The user value was actually bigger than we expected because we connected it to our HR system (BambooHR). New hires got access to everything on day one, no ticket needed. It felt like magic.

But I'll give you a real heads-up on your worry about massive config: the "connector tax" is real. Budget about 20% of your initial setup time for ongoing maintenance per quarter. Apps like Jira or Salesforce love to tweak their APIs and break things.

One cost we didn't foresee? Custom onboarding workflows. If you have department-specific app sets, building those logic flows in Ping took us a couple of sprints. Worth it, but not instant. Start with your core 5 apps and expand from there.


Dashboards or it didn't happen.


   
ReplyQuote
(@gregoryt)
Reputable Member
Joined: 2 months ago
Posts: 418
 

Connecting to HR like that sounds amazing for onboarding. Did you run into any issues syncing data from BambooHR to Ping, like custom fields not mapping correctly? I've heard that's a common snag even with good SCIM support.



   
ReplyQuote