Not a smaller SailPoint.
A different way of doing IGA.
The classical IGA playbook — a 12-month implementation project, a consulting team, a role-model workshop, then a big-bang go-live — fails mid-market organisations structurally, not incidentally. We rebuilt the playbook, not just the product. Here are the seven deliberate differences, plus an honest list of where the incumbents are still ahead.
The problem
First value at go-live — or on day one.
A 12-month implementation project, a consulting team, a role-model workshop, then a big-bang go-live. That playbook was built for Fortune-500 programmes — for a 2,000-person organisation it means paying for a year before seeing your own data. RapidValue doesn't assume a dedicated IAM team or a mandatory integrator programme — the guided product does the heavy lifting, and a partner accelerates where you want one.
Schematic — classic timeline per the programmes we ran ourselves at the incumbents; RapidValue timeline is the POC sequence on the homepage journey.
Seven deliberate differences
The playbook, rebuilt.
🛞 1 · Training wheels, not big-bang
Classical IGA flips provisioning on at go-live — after months of config, with maximum blast radius on day one. We invert it: connectors provision from the start, but every write queues for your batch approval until you remove the gate, per system. You watch the platform make the right calls before you let it act. Go-live is a gradient, not a cliff.
📊 2 · Your data on day one
We don't demo a sandbox with fictional employees. The POC connects your HR feed and one of your systems in the first session — role-mining proposals, risk scores and audit evidence come from your own environment the same afternoon. If the value isn't visible in your data, you shouldn't buy it.
🇪🇺 3 · Sovereignty by construction
Not a compliance slide — an architecture. The tier-3 agent runs in your VPC and resolves connector credentials locally: secrets never cross the wire to our control plane. Bring-your-own-vault keeps even the encryption key in your KMS. EU-hosted, EU-owned, no US parent company. The full architecture →
🧾 4 · Evidence-first, always-on
Auditors don't trust screenshots of dashboards. Every reconciliation run produces snapshots with per-grant reasons ("expected via policy X" / "not expected — flagged"), the audit trail is cryptographically chained and database-immutable, and audit packs (SOX · ISO · HIPAA · GDPR) generate from live data — not from a quarterly evidence-gathering scramble.
🪞 5 · The platform governs itself
Who governs the governor? In RapidValue, the platform is its own connected system: your admins are identities, their platform roles are group memberships, every role assignment is a governed grant that shows up in reconciliation and access reviews like any other. No shadow admin layer — and guardrails ensure automation can never strip your last admin.
💬 6 · Business-readable, wizard-first
Role mining outputs plain-language proposals — "12 people in Finance share this access" — not cluster IDs. Policies are built in a visual wizard with a live blast-radius preview. Config that classically needs a consultant dialect is a guided flow an admin walks through alone. The consulting workshop is the product.
🧩 7 · One rule model — central defaults, local overrides
Who approves, who reviews, who owns, what may never combine — in classic IGA that logic is re-authored inside every workflow and drifts apart. Here every rule family — approval chains, review rules, ownership rules and SoD rules with compensating controls — is a named, reusable object with a workbench per topic: define it once as the default for its type, override only where a system or team genuinely differs, and universal fallbacks guarantee nothing ever routes to nobody.
Side by side
What the difference looks like in practice.
← swipe to compare →
| Classic IGA platforms | RapidValue | |
|---|---|---|
| Time to first working POC | 4–8 weeks | 1 day |
| Who carries the implementation | A systems-integrator engagement alongside the licence | The guided product does the heavy lifting — a partner accelerates |
| Customer security review for trial | 2–4 weeks (vendor reaches into AD) | An afternoon (outbound-only agent, auditable source) |
| Where connector credentials live | Vendor's SaaS (sent over the wire) | Your choice per deployment: EU-managed vault, your own vault (BYOV), or your network (agent mode) |
| POC cleanup if not converting | Formal decommissioning | Remove the agent and export everything yourself; deletion is a governed offboarding we run on request — typed-confirm, never automatic |
| Role mining output | Algorithm metrics (coverage %) | Business stories (cohort, intent, impact) |
| Compliance evidence at end of POC | "We'll discuss in scoping" | Privacy-safe take-home report |
Where we sit in your IAM landscape
We do governance. Deeply. And we're honest about the rest.
IGA — Identity Governance & Administration
Lifecycle, requests & approvals, roles & policies, reviews, SoD, reconciliation, audit evidence, identity analytics, NHI governance. This is the whole product.
PAM — Privileged Access
Break-glass emergency access (instant, auto-expiring, justified) and scheduled time-boxed elevation are two distinct pillars — plus privileged tagging and admin-account routing. We're no password vault or session recorder; pair with a dedicated PAM tool. The privileged story →
Access Management — SSO · MFA · IdP
Your IdP (Entra ID, or any OIDC provider) keeps doing authentication. We govern what it grants — including sign-in to RapidValue itself through your own IdP.
Directories & HR
AD, Entra ID and LDAP stay your directories — we read, reconcile and provision them. Your HR system stays the source of truth for people — we consume it.
CIAM — Customer identity
Workforce and non-human identities are our scope. Customer login/registration flows belong to a CIAM product.
Endpoint / network security
We govern who may have access — EDR, firewalls and network segmentation are adjacent disciplines we happily coexist with.
The honest part
Where the incumbents are ahead.
If these are hard requirements for you today, we'd rather tell you now than after a POC. We chose our trade-offs deliberately for the EU mid-market — here's what sits on the other side of them.
🔌 Connector library size
SailPoint advertises 200+ out-of-box connectors; we ship 11 vendor templates — from Entra ID and Google Workspace to AFAS and TOPdesk — plus generic REST, SCIM 2.0, LDAP, SQL and SFTP-CSV engines: 17 production connectors in total. For mid-market estates that generic layer covers the long tail — but if you need a certified mainframe or SAP GRC connector today, the incumbents are ahead. The flip side: because every template is built on those generic engines, a new vendor template is days of work, not a product-roadmap quarter — we build them alongside onboarding customers, at no extra cost.
🔐 Deep PAM
We tag privileged access, route it to admin accounts, and measure JIT coverage — but we are not a password vault or session recorder. If you need full PAM, pair us with a dedicated tool; SailPoint + CyberArk is a mature combo.
📈 Analyst coverage & 20-year references
We're not in a Forrester Wave and won't be for a while, and our focus is mid-market estates, not FTSE-100 with 50k+ identities. If procurement needs a magic quadrant, that's a real constraint — we compensate with a POC on your data in a day, which no quadrant can show you.
📱 Mobile app & marketplace
Approvals work fine in the responsive web UI, but there's no native mobile app and no third-party extension marketplace. Extensibility runs through config packs and the governed API instead.
The team
Built by people who have done this before.
We spent the past decade selling and implementing IGA at Omada Identity, Saviynt and SailPoint — across presales, architecture, alliances and enterprise sales in the Benelux and EMEA. And we kept seeing the same problem: great governance products that took six months before a customer could see their own data. RapidValue is our answer to that.
Serge Kerremans
Former Benelux Presales Lead at Omada Identity and co-lead for EMEA Strategic Alliances at Saviynt. 15+ years designing and delivering IGA programmes for Belgian and Dutch enterprise clients.
Mark Vermeulen
Former Senior Account Manager at SailPoint, Senior Director Technology Alliances EMEA at Saviynt and Regional Sales Director Benelux at Omada Identity. A decade of enterprise identity-security sales in the Benelux.
The test
Don't take the word "different" on faith.
Every claim on this page is demonstrable in a single POC session on your own data: the gated writes, the mining proposals, the recon evidence, the self-governing platform. Book the kickoff and judge it live.