In December 2025, Saviynt raised $700 million at a $3 billion valuation from KKR to scale its converged identity platform that unifies Identity Governance and Administration (IGA), Privileged Access Management (PAM), and Application Access Governance into a single product. In 2026, Palo Alto Networks acquired CyberArk (the established PAM leader, which had itself acquired Zilla Security in 2025), consolidating identity into the broader Palo Alto security stack.

The identity stack just collapsed.

For most of the last decade, the Indian BFSI identity-management RFP scored three categories separately. IAM (Identity and Access Management) for workforce authentication, run typically on Okta, Microsoft Entra ID, or Ping Identity. IGA for compliance-aligned governance, lifecycle workflows, and access reviews, run on SailPoint or Saviynt. PAM for privileged account vaulting, session monitoring, and just-in-time access, run on CyberArk, BeyondTrust, or Delinea.

The three categories are converging into a single procurement decision. The 2022 RFP scoring three vendors against three feature matrices is being replaced by a 2026 RFP scoring one identity-fabric platform against an integrated functional bar. The Indian BFSI CISO whose three-vendor identity stack is up for renewal in 2026-2027 has to decide whether to consolidate, when to consolidate, and which fabric to consolidate on.

But first, some catch-up on infra this week.

🔍 IGA + IAM + PAM + Non-Human Identity = Identity Fabric

The identity-fabric concept emerged from Gartner's analyst frame in 2023-2024 and matured into a procurement category in 2026.

Four categories, one fabric.

The fabric framing treats identity as a single operating plane across four traditionally-separate categories.

IAM (workforce authentication) is the entry layer. SSO, MFA, conditional access, the user-to-application authentication primitives. Okta, Microsoft Entra ID, Ping Identity, and ForgeRock dominate this layer. For Indian BFSI, the M365 footprint usually pulls Entra ID forward by default; Okta is the strongest alternative for multi-cloud heterogeneous environments.

IGA (governance) is the compliance layer. Lifecycle workflows, access reviews, role mining, segregation of duties, audit reporting. SailPoint and Saviynt dominate this layer for large regulated enterprises. The procurement question is increasingly "which platform satisfies the regulator-grade audit-trail expectation with the lowest operational overhead."

PAM (privileged access) is the high-stakes layer. Vault for service-account credentials, session monitoring for administrative access, just-in-time elevation, secrets management for DevOps. CyberArk (now under Palo Alto Networks), BeyondTrust, and Delinea are the established names. Saviynt's converged platform adds PAM as a module rather than a separate vendor.

Non-human identity (NHI) is the new fourth layer. Service accounts, AI agents, API tokens, machine certificates, kubernetes service-account secrets. The category did not exist in the 2022 RFP. By 2026, the typical large Indian BFSI enterprise has 10-50 NHIs per human identity. Most security teams do not know how many exist, what they can access, or which ones are still active.

The fabric framing says these four layers should be governed by one platform, with one policy engine, one audit trail, and one operational team. The procurement question is which platform delivers all four credibly, not which vendor leads in each individual category.

For the Indian BFSI buyer working backward from a 2026 audit:

✔ Inventory identities by category. The IAM identity count is usually known. The IGA-governed identity count is usually documented. The PAM-vaulted identity count is usually small. The NHI count is usually unknown. Find the NHI count first.

✔ Map every identity to the data classes it can access. The audit committee needs the dependency graph, not the identity count.

✔ Document the segregation-of-duties posture across the four layers. The IGA platform usually owns this; verify the documentation is operational rather than theoretical.

✔ Test the privileged-access workflow under incident conditions. The PAM vault that requires a fresh ticket every time the SOC analyst needs production access during a midnight ransomware response is a vault that the SOC will route around.

How we plug in: Our Cyberdefense practice runs the identity-fabric assessment for Indian BFSI, manufacturing, pharma, and textile buyers. We do the four-layer inventory work, including the NHI discovery the security team rarely has visibility into. We map the identities to data classes, document the segregation of duties, and test the privileged-access workflow under realistic incident conditions.

🔐 Saviynt, SailPoint, Okta, and the Palo Alto Acquisition of CyberArk

The 2026 identity-fabric vendor landscape carries four serious shortlist names, with the caveat that the category is mid-consolidation.

Acquisition is the procurement risk.

Saviynt is the aggressive consolidation play. The December 2025 $700M raise at $3B valuation funds a converged IGA + PAM + Application Access Governance platform. Cloud-only architecture. Strong fit for the Indian BFSI buyer who wants to collapse three RFPs into one. The procurement caveat: Saviynt is still maturing on the PAM side compared to CyberArk's historical depth; pilots should validate the privileged-access workflow against existing CyberArk-grade expectations.

SailPoint remains the IGA market leader. Deep compliance automation, mature access-review workflows, the established choice for large regulated enterprises. The procurement question is whether SailPoint's IGA depth justifies running it as a separate vendor versus consolidating on a converged platform. For the Indian BFSI buyer with a mature SailPoint deployment, the renewal cycle is the moment to evaluate convergence versus continuity.

Okta is the multi-cloud workforce-IAM leader. Vendor-neutral identity provider, strong fit for heterogeneous cloud environments. The procurement caveat for Indian BFSI: Microsoft Entra ID is included in M365 E5 licensing the bank usually already has; Okta has to justify its premium on functionality the buyer cannot get from Entra ID. The case is real but specific.

CyberArk (now Palo Alto Networks) changed shape with the 2026 acquisition. The PAM functionality is the same; the procurement implications are different. The buyer signing a multi-year CyberArk contract is now signing inside the Palo Alto security platform, with the operational expectation of broader integration over the contract term. For the Indian BFSI buyer already running Palo Alto on the perimeter, SASE, and Cortex layers, the consolidation story is cleaner. For the buyer running heterogeneous security vendors, the question is whether CyberArk remains the right choice or whether the converged platform options are preferable.

The four-vendor read-out:

👉 Saviynt: aggressive convergence, cloud-only, strong if you want to collapse three RFPs.

👉 SailPoint: IGA depth leader, established compliance automation.

👉 Okta: multi-cloud workforce IAM, vendor-neutral.

👉 CyberArk: PAM leader inside Palo Alto, consolidation play.

The mid-consolidation reality is that any of these four could be acquired within the contract term. The Saviynt KKR investment may itself precede a 2028 strategic acquisition. The procurement memo for any 2026-2027 identity-fabric contract should include explicit clauses on what happens if the vendor is acquired during the term.

How we plug in: Our Complete IT Infrastructure Solution practice runs the identity-fabric vendor evaluation for Indian BFSI buyers. We sit on the buyer side of Saviynt, SailPoint, Okta, and CyberArk pilots, including the acquisition-risk clause-negotiation work that most procurement memos still skip.

📌 The Indian BFSI Identity Reality: 50,000 Workforce, 500,000 Customer, 5 Million NHI

The Indian BFSI identity estate is structurally different from the global average.

A typical Indian private-sector bank manages 50,000-plus workforce identities (branch staff, corporate office, contact-centre agents, contracted partners). The customer-identity count for the same bank runs in the millions, with the digital-banking and UPI footprint usually requiring real-time authentication at the API gateway. The non-human-identity count, once anyone bothers to inventory it, routinely exceeds the customer count: every microservice, every scheduled job, every integration partner, every AI agent, every kubernetes service account.

The procurement implications are operational:

✔ The IAM platform has to handle workforce, customer, and partner authentication at radically different scales. The unified identity provider that works for the 50,000 workforce identities probably struggles at the 5,000,000 customer authentication scale, and vice versa.

✔ The IGA platform has to govern the workforce-and-partner side with regulator-grade access reviews. The customer side has different governance requirements (consent management under DPDP, not access certification).

✔ The PAM platform has to handle service-account credentials for the IT estate and the data-platform admin credentials for the BFSI core. The privileged-access workflow has to align with RBI's incident-response expectations.

✔ The NHI layer is the gap. Most Indian BFSI estates have 10-50 NHIs per human identity. The total NHI count is in the millions for any meaningful bank. The fact that the security team cannot enumerate them is the procurement-side problem.

The Indian managed-services market provides the operational scaffold. TCS, Wipro, Infosys, and HCL run integrated identity-management services for Indian BFSI clients, typically with one of the four global vendors as the underlying platform. eSec Forte and Microland run regional offerings. For an Indian BFSI buyer wanting the labour-arbitrage advantage on the operational side and the global-vendor depth on the platform side, the hybrid model is standard.

The fresh procurement-side caveat post-CyberArk/PANW acquisition: the SI partner needs to demonstrate operational capability across the consolidated identity stack, not just on the individual products. The SI whose CyberArk team has not worked on a Palo Alto integration is the SI whose 2027 delivery will struggle.

How we plug in: Our Cyberdefense practice maps the Indian BFSI identity estate against the converged fabric platforms. The four-layer inventory, the NHI discovery, the SI-capability assessment, and the procurement-side risk negotiation are the parts of the conversation that the vendor's RFP response does not cover.

📋 DPDP, RBI, and the Identity Governance Documentation Bar

The Indian regulatory framework for identity governance tightened progressively from 2022 through 2026.

The DPDP framework expects consent-driven access for customer data, with documented purposes and lifecycle controls. The RBI Master Directions on Cyber Resilience expect documented privileged-access workflows with audit-grade evidence. The April 2026 authentication mandate expects dynamic-factor MFA at every digital-payment touchpoint. The CERT-In 6-hour reporting clock applies to any identity-system breach.

For the Indian BFSI buyer signing the 2026-2027 identity-fabric contract, three compliance-layer clauses worth getting right:

👉 What is the platform's audit-trail format for access reviews, and can the artefacts be exported to the RBI sector-regulator review template in a form the bank's audit committee can use directly?

👉 What is the consent-management posture for customer identities under DPDP? Most workforce-IAM platforms were not designed for the consent-management workflow; the integration story matters.

👉 What is the data-residency posture for identity telemetry, including access logs, session recordings, and audit-trail records? The platform's default cloud region may not be Indian-resident; the contract clause has to specify.

The compliance posture is the procurement frame, not a side conversation.

There is a fourth clause that procurement memos increasingly include in 2026: the audit-defensibility of the agentic-AI identity operations. As the major identity-fabric vendors add agentic-AI tooling for access-review automation, anomaly detection, and provisioning workflows, the regulator's question shifts from "did the platform do the right thing" to "can the bank prove the agentic-AI decision was correct, documented, and reviewed by a human at the appropriate threshold." The buyer that signs a 2026 identity-fabric contract without that clause is the buyer that has to renegotiate it during the next regulator review.

The compounding factor is the speed of the regulator-frame evolution. RBI's authentication mandate landed in April 2026. DPDP's full operational compliance is May 2027. The CERT-In direction has been in force since 2022 but the enforcement intensity has increased annually. The identity-fabric platform that the bank signs today has to satisfy not the 2026 regulator interpretation but the 2028 regulator interpretation, which is partially written but not yet final. The procurement-side strategy is to negotiate flexibility clauses that allow the bank to adjust the platform's configuration as the regulator frame matures, without triggering a full contract renegotiation each time.

How we plug in: Our Complete IT Infrastructure Solution practice reads the DPDP + RBI + CERT-In overlay against the identity-fabric vendor contract. The clauses that protect the buyer through the next regulator interpretation are the ones written before the renewal.

The Top 10 IGA Tools in 2026: Modern Identity Governance Buyer's Guide
Linx Security.
The cleanest 2026 IGA-vendor read with the Saviynt $700M funding context and the CyberArk consolidation backdrop.

10 Best IAM Solutions in 2026
CybersecurityNews.
The broader IAM-vendor landscape across workforce, customer, and partner identity.

ConductorOne Alternatives: Identity Security and Governance Platforms
Linx Security.
Useful for the convergence-vendor evaluation lens, with explicit framing of the CyberArk acquisition by Palo Alto.

Comparative Analysis of Top IAM Solutions
MajorKey Tech.
The procurement-side comparison framework worth reading before locking the RFP scoring rubric.

IAM Software Valuation Report Q1 2026
Windsor Drake.
The financial-and-valuation side read on the IAM consolidation, useful for the acquisition-risk assessment.

💡 My Take

For most of the last decade, the Indian BFSI identity-management procurement strategy was multi-vendor by default.

The IAM workforce platform was one vendor. The IGA governance platform was a second vendor. The PAM privileged-access platform was a third. The customer-identity platform was sometimes a fourth. Each platform owned its category. Each had its own contract, operational team, and integration debt.

That arrangement is finishing.

The fabric is the procurement frame.

The four categories converge in the operational reality, whether the buyer's RFP recognises it or not. The workforce IAM has to talk to the IGA for lifecycle and access review. The IGA has to talk to the PAM for privileged-access governance. The PAM has to talk to the IAM for authentication context. The customer IAM has to satisfy DPDP and the RBI authentication mandate. The NHI layer has to be governed by something. The four-vendor stack has integration debt at every boundary, and the integration debt accumulates faster than the individual platforms mature.

The convergence vendors (Saviynt, the converged-platform direction CyberArk follows under Palo Alto) are betting that the integration debt is the unmet customer need. The pure-play vendors (SailPoint on IGA, Okta on multi-cloud IAM) are betting that depth in each category still beats convergence breadth.

For the Indian BFSI CIO drafting the 2026-2027 identity-fabric RFP, both bets matter. The question is which bet aligns with the bank's actual operational reality.

The bank with a mature SailPoint IGA deployment, a working CyberArk PAM, an Okta or Entra IAM, and a documented customer-IAM probably keeps the multi-vendor stack and renegotiates each contract. The bank with three separate vendor stacks that have never properly integrated probably collapses to Saviynt or to the Palo Alto/CyberArk converged platform. The bank with no mature identity stack at all should not be evaluating the fabric question; it should be evaluating the workforce IAM as the floor and adding the IGA, PAM, and NHI layers on a phased plan over 24 months.

VEMIO™ exists because the operational reality of running an identity fabric across a multi-million-identity Indian BFSI estate needs an observability layer that the identity-platform's own console does not provide. The platform tells you which access reviews completed. The CISO needs to see across the workforce IAM, the customer IAM, the IGA reviews, the PAM session recordings, the NHI inventory, and the regulatory-reporting artefacts. All in one operator view, regardless of which vendor's platform sits underneath each layer.

The identity-fabric question is not whether convergence is right. It is whether convergence is right for this bank, this contract cycle, this regulatory window, and this operational maturity. The wrong answer to that question is permanent in a way that almost no other security procurement decision is, because identity sits underneath everything else. The buyer that gets the identity-fabric decision right buys five years of operational efficiency. The buyer that gets it wrong buys five years of integration debt.

Convergence is a procurement decision. Continuity is too.

Reply to this email with the one identity-category boundary you cannot currently audit across, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.

Until next time,

Ajay Salvi & the Vinay Enterprises team.