Identity lifecycle management buyer's checklist: 20 questions for vendors
ILM Reference editors · Published 2026-09-29 · 3 minute read
Send vendors these twenty questions before a demo. They are grouped by coverage, lifecycle automation, access reviews, audit evidence, fit with your current tools and commercials. For each group we note what the public pages of the eight tools on this site already answer, so the questions focus on what is not published.
- § 01Coverage: which applications and accounts will it reach?
- § 02Lifecycle: how do joiners, movers and leavers work?
- § 03Access reviews: will certifications hold up?
- § 04Audit evidence: what can we hand an auditor?
- § 05Fit: will it work with what we already run?
- § 06Commercials: what will it cost?
- § 07Which answers should prompt a follow-up?
- § 08How should you use the answers?
Coverage: which applications and accounts will it reach?
- How does the tool handle an application with no connector, no SCIM endpoint and no SSO integration?
- Can it discover applications that are not in our inventory, and how?
- Does it find local accounts, service accounts and hardcoded credentials inside applications?
- What does it need installed or granted in each application to do that?
Public pages answer this unevenly. Saviynt names onboarding of disconnected applications; Orchid Security states discovery of unmanaged and custom applications; Microsoft Entra ID Governance documents a manual CSV process. The coverage ledger has the detail.
Lifecycle: how do joiners, movers and leavers work?
- Which HR systems trigger joiner, mover and leaver events, and how quickly?
- On a role change, how is the old role's access removed, and when?
- For leavers, is the account disabled or deleted, and can that differ by application?
- What happens in applications the tool cannot write to: a ticket, a task, or nothing?
Access reviews: will certifications hold up?
- Which campaign types are supported: manager, application owner, targeted, role?
- Can accounts from disconnected applications be loaded into a campaign?
- How are revoke decisions carried out and confirmed?
- How does the tool reduce rubber-stamping, for example by auto-certifying low-risk items?
Audit evidence: what can we hand an auditor?
- What evidence is exported, and is it mapped to SOX, PCI DSS, HIPAA, NIS2 or DORA?
- For each leaver, can it show the termination date and the date each account was disabled?
- How long is evidence retained, and can it be exported in a format our auditors accept?
Orchid Security and SailPoint Identity Security Cloud both describe evidence mapped to named frameworks. For the other tools, the pages we reviewed describe audit trails without a framework mapping, so ask.
Fit: will it work with what we already run?
- Does it replace our identity provider or IGA, or work alongside them? Which integrations exist today?
- Where is tenant data held, and is there a regional option such as an EU instance?
- What is the deployment model, and what network access does it need?
Commercials: what will it cost?
- What is the pricing unit, and how are contractors and non-human accounts counted?
- What is included, what is an add-on, and what is charged as services?
Only Microsoft Entra ID Governance publishes a full per-user price among the tools we score. The pricing note sets out what the others publish.
Which answers should prompt a follow-up?
- An answer about disconnected applications that describes only connectors. Ask what happens to the application that has none.
- A leaver answer that covers the directory account but not local accounts in the application.
- An evidence answer that is a screenshot of a dashboard. Ask for the export an auditor would receive.
- A pricing answer that gives a per-user figure without saying whether contractors and service accounts count as users.
None of these is disqualifying on its own. Each is a place where a proof of concept should test the claim instead of accepting it.
How should you use the answers?
Score the answers against the same criteria you would use for a shortlist. The calculator lets you set your own weights on the criteria this site uses, and the proof of concept note turns the most important answers into tests.
Sources
- Saviynt IGA
- Orchid Security
- Orchid Security, GRC and audit
- Microsoft Learn, apps that do not support provisioning
- SailPoint Identity Security Cloud
- C1 blog, C1 in Europe
- Microsoft Entra pricing
Reviewed Sep 2026