REGISTER REVISED SEPTEMBER 2026

Editorial method: how we score identity lifecycle management tools

ILM Reference editors · Editorial assessment · Last reviewed September 2026

SUMMARYREV. 2026-09

Each tool gets a 0-100 score on seven weighted criteria, based only on its public pages, documentation and pricing, reviewed in September 2026. Totals are computed from the published weights. The criteria each tool loses are shown on every comparison.

§ 01

What does the lifecycle coverage score measure?

Lifecycle coverage score (editorial assessment, 0-100). Measures how completely a tool, as described in its public material, covers joiner, mover, leaver, review and orphan-account control across all applications, including applications that are not connected to the identity provider or IGA platform. It is not a measure of overall product quality.

We weight coverage of disconnected applications and orphan accounts most heavily because that is the problem this reference is about. A buyer whose priority is certification campaigns or provisioning depth should re-read the per-criterion columns, where the ranking changes.

§ 02

What are the criteria and weights?

The seven criteria, their weights and what we look for in each. Weights sum to 100.
CriterionWeightWhat we look for
Disconnected-app coverage22Documented handling of applications with no connector, no SCIM and no SSO integration: discovery, onboarding, account data collection.
Orphan and local account discovery18Finding accounts with no owner, dormant accounts, and local or app-native accounts that sit outside the IdP.
JML automation15HR-triggered provisioning and deprovisioning, role-change handling, birthright access.
Certification campaign depth12Campaign types, reviewer routing, remediation of revoked access, AI-assisted review.
Audit evidence13Audit trails and exportable evidence mapped to SOX, PCI, HIPAA, NIS2 or similar.
Works alongside existing IdP and IGA12Adds value without replacing the identity provider or governance platform already in place.
Pricing transparency8A published price a buyer can model before a sales call.
§ 03

How is a total calculated?

Total = sum of (criterion score × weight) ÷ 100. Scores are whole numbers from 0 to 100. Totals are shown rounded to the nearest whole number and sorted by the exact value. Equal rounded totals are shown as ties. Nothing is hand-typed: the tables on this site are generated from one data file.

Orchid Security: 92×22 + 90×18 + 45×15 + 30×12 + 85×13 + 95×12 + 20×8
= 7,084 ÷ 100 = 70.84, shown as 71.
§ 04

What counts as evidence?

  • A capability counts only if the vendor's own product page, documentation, pricing page or official blog describes it. Each profile links the pages used.
  • Where a vendor does not publish something, we write 'Not published' or 'Not documented' and score conservatively. Absence of documentation is not proof that a capability is missing.
  • Regulatory requirements are summarized from the official texts: NIST SP 800-53 Rev. 5, Regulation (EU) 2022/2554 (DORA) and Commission Delegated Regulation (EU) 2024/1774, and PCAOB AS 2201.
  • We do not use user reviews, star ratings, analyst rankings or vendor-supplied benchmark numbers as score inputs.
§ 05

What are the limitations?

LIMITATIONSREV. 2026-09

Limitations. This is desk research from public sources only. We did not test the products, did not run them against our own applications, and did not interview vendors or customers. Vendor pages describe intended capability; real coverage depends on your applications and deployment. Pricing and packaging change often. Treat every score as a starting point for your own evaluation, and confirm details with the vendor.

§ 06

Why these eight tools?

We included tools whose public pages describe identity lifecycle work: joiner, mover and leaver automation, access reviews, or discovery of accounts outside central control. We reviewed Apono, Silverfort and Idira Identity Governance (Palo Alto Networks) and did not score them this edition, for the reasons given on the comparison page. Identity providers are covered only where they sell a governance product (Okta Identity Governance, Microsoft Entra ID Governance); this site does not compare identity providers or single sign-on.

§ 07

How often is this updated?

Every price and headline capability is re-checked each quarter. The register number and "Last reviewed" date on every page change when that happens. Register revised September 2026.

§ 08

How do I report an error?

Email editor@identitylifecyclemanagement.com with the page, the claim and a public source. We reply from that address and correct verified errors within ten business days.