<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.2.2">Jekyll</generator><link href="https://www.toriihq.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://www.toriihq.com/" rel="alternate" type="text/html" /><updated>2026-07-27T21:11:41+00:00</updated><id>https://www.toriihq.com/feed.xml</id><title type="html">Torii — SaaS Management Platform</title><subtitle>Find hidden apps, cut SaaS waste, and automate the rest</subtitle><entry><title type="html">Connect Torii to Claude, ChatGPT, and Other AI Assistants with Hosted MCP</title><link href="https://www.toriihq.com/blog/introducing-model-context-protocol-in-torii" rel="alternate" type="text/html" title="Connect Torii to Claude, ChatGPT, and Other AI Assistants with Hosted MCP" /><published>2026-05-05T00:00:00+00:00</published><updated>2026-05-05T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/introducing-model-context-protocol-in-torii</id><content type="html" xml:base="https://www.toriihq.com/blog/introducing-model-context-protocol-in-torii"><![CDATA[<p>Every day, IT teams move between spreadsheets, dashboards, tickets, and emails to answer simple questions:</p>

<p>Which apps are underused?<br />Which contracts are coming up for renewal?<br />Who owns this app?<br />Did this offboarding workflow finish?<br />What changed in our SaaS stack last week?</p>

<p>That work takes time because the context lives in different places.</p>

<p>Torii’s hosted <a href="/blog/what-is-model-context-protocol-mcp">Model Context Protocol (MCP)</a> server gives AI assistants a secure way to access your Torii data directly. Connect tools like Claude, ChatGPT, Cursor, and other MCP-compatible clients to Torii, and your assistant can query apps, users, contracts, workflows, audit logs, transactions, and more.</p>

<p>The best part: Torii MCP uses your existing Torii account permissions. Your assistant can only access the data and actions available to you.</p>

<h2 class="wp-block-heading">How it Works</h2>

<p>MCP is an open standard that lets AI tools connect to external [systems](/blog/hierarchical-way-to-connect-core-systems-and-saas-tools) through a shared interface. Instead of building one-off integrations for every AI tool, MCP gives compatible assistants a common way to talk to systems like Torii.</p>

<p>For Torii users, that means SaaS insights that once required the UI, manual reporting, or custom API work can now be surfaced directly in the AI tools your team already uses.</p>

<p>With Torii MCP, your assistant can help you access information like:</p>

<ul class="wp-block-list">
<li>User details</li>

<li>Contract details</li>

<li>Audit log history</li>

<li>Application details</li>

<li>Workflow activity</li>

<li>Transactions</li>

<li>SaaS costs</li>

<li>Renewal data</li>

<li>App ownership</li>

<li>And more</li>
</ul>

<p>Depending on your permissions, your assistant may also be able to take supported actions in Torii, such as searching apps, matching app records, creating contracts, updating users, or running workflows.</p>

<h2 class="wp-block-heading">Hosted MCP, No Local Setup Required</h2>

<p>Torii’s MCP server is now hosted, so you can connect your AI assistant directly to Torii without installing packages, running a local server, or managing API keys.</p>

<p>Connect your MCP-compatible client to Torii’s hosted MCP server:</p>

<pre class="wp-block-code"><code>https:&#47;&#47;api.toriihq.com/mcp</code></pre>

<p>From there, sign in with your Torii account and approve the connection. Torii uses OAuth and your existing Torii role permissions, so your assistant only gets the access you already have inside Torii.</p>

<p>Torii’s hosted MCP server can work with AI clients that support remote MCP servers with OAuth, including tools like Claude, ChatGPT, Claude Code, Cursor, Windsurf, Zed, Cline, Continue, and custom apps built with official MCP SDKs.</p>

<h2 class="wp-block-heading">Torii MCP in Action</h2>

<p>Below, see how a few prompts reveal offboarding status, ownership gaps, and replacement recommendations in seconds.</p>

<script src="https://fast.wistia.com/player.js" async=""></script>
<script src="https://fast.wistia.com/embed/3yp2lny6zk.js" async="" type="module"></script>
<style>wistia-player[media-id='3yp2lny6zk']:not(:defined) { background: center / contain no-repeat url('https://fast.wistia.com/embed/medias/3yp2lny6zk/swatch'); display: block; filter: blur(5px); padding-top:87.08%; }</style>
<wistia-player media-id="3yp2lny6zk" aspect="1.1483253588516746"></wistia-player>

<p>With just a few prompts in Claude, the user learns that:</p>

<ul class="wp-block-list">
<li>Six employees are currently in an offboarding workflow, and only one — Melba Donnelly — has not been deleted yet.</li>

<li>Melba is still the app owner for Box.</li>

<li>Claude can pull a list of active Box users, analyze usage, and suggest four candidates to take over ownership.</li>
</ul>

<p>That is a simple example, but it shows the larger value: IT teams can move from question to answer without manually checking multiple screens, exporting data, or building a report first.</p>

<h2 class="wp-block-heading">What You Can Ask</h2>

<p>Once connected, your AI assistant can help answer questions like:</p>

<ul class="wp-block-list">
<li>Which apps have more than 100 users?</li>

<li>Which contracts are renewing in the next 60 days?</li>

<li>Which apps have the most unused licenses?</li>

<li>Who owns this app?</li>

<li>Which users have access to this app?</li>

<li>What workflows ran in the last seven days?</li>

<li>Which apps were added last month?</li>

<li>What changed in our SaaS stack this week?</li>
</ul>

<p>You can also use Torii MCP to dig deeper. For example, you might ask your assistant to find apps with high spend and low usage, identify contracts that need attention, or review recent workflow activity before a meeting.</p>

<h2 class="wp-block-heading">Why It Matters</h2>

<p>AI is only useful when it has the right context.</p>

<p>For SaaS management, that context lives in Torii: your apps, users, contracts, costs, workflows, ownership data, and audit history. Torii MCP brings that context into the AI tools your team already uses, so you can ask better questions and get faster answers.</p>

<p>That helps IT, procurement, finance, security, and operations teams:</p>

<ul class="wp-block-list">
<li>Reduce manual reporting</li>

<li>Find SaaS risks faster</li>

<li>Spot cost-saving opportunities</li>

<li>Understand ownership and access</li>

<li>Review workflow activity</li>

<li>Prepare for renewals</li>

<li>Make decisions with fresher data</li>
</ul>

<p>Instead of asking your team to jump between systems, Torii MCP lets them start with a question and move straight toward the answer.</p>

<h2 class="wp-block-heading">How to Get Started</h2>

<p>Ready to connect your AI assistant to Torii?</p>

<p>Use Torii’s hosted MCP server:</p>

<pre class="wp-block-code"><code>https:&#47;&#47;api.toriihq.com/mcp</code></pre>

<p>For step-by-step setup instructions, see the support guide: <a href="https://support.toriihq.com/hc/en-us/articles/49894290637467-Connecting-AI-Assistants-to-Torii-with-MCP"><strong>Connecting AI Assistants to Torii with MCP</strong>.</a></p>

<p>Want to learn more about the standard behind it? Read the <a href="https://modelcontextprotocol.io/specification/"><strong>Model Context Protocol specifications</strong>.</a></p>

<p>Torii MCP helps your team bring live SaaS context into the AI tools they already use, so they can move faster, reduce manual work, and manage software with more confidence.</p>

<h2 class="wp-block-heading">Prefer a Local MCP Setup?</h2>

<p>Torii’s hosted MCP server is the recommended setup for most users because it does not require local installation, API key management, or running your own server.</p>

<p>For teams that prefer a local setup, Torii also offers a local MCP server package that can run on your machine and connect to Torii through your API key.</p>

<p>Install the package:</p>

<!-- Bash install command -->
<pre class="line-numbers"><code class="language-bash">npm install @toriihq/torii-mcp</code></pre>

<p>You’ll need:</p>

<ul class="wp-block-list">
<li>A Torii API key</li>

<li>Node.js</li>

<li>Yarn package manager</li>
</ul>

<p>A local setup may be useful if your team wants more control over how the MCP server runs, needs to test MCP behavior in a development environment, or is connecting through a client that does not support hosted remote MCP servers yet.</p>

<p>For most users, we recommend starting with the hosted MCP server:</p>

<p><a href="https://api.toriihq.com/mcp">https://api.toriihq.com/mcp</a></p>

<p>For local setup instructions, visit Torii’s npm repository or contact your Torii Customer Support Representative.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Connect Claude, ChatGPT, and other AI assistants to Torii with hosted MCP—query apps, users, contracts, and workflows using your existing permissions.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/introducing-model-context-protocol-in-torii.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/introducing-model-context-protocol-in-torii.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">What’s Behind Grammarly’s 3x Enterprise Growth? Three Years of Usage Data Has Answers</title><link href="https://www.toriihq.com/blog/grammarly-enterprise-growth-analysis" rel="alternate" type="text/html" title="What’s Behind Grammarly’s 3x Enterprise Growth? Three Years of Usage Data Has Answers" /><published>2026-03-27T00:00:00+00:00</published><updated>2026-03-27T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/grammarly-enterprise-growth-analysis</id><content type="html" xml:base="https://www.toriihq.com/blog/grammarly-enterprise-growth-analysis"><![CDATA[<p>Torii tracks SaaS usage across enterprise customers worldwide. One trend has been hard to ignore: Grammarly's footprint has grown roughly 3x in three years.</p>

<p>In January 2023, Grammarly appeared in just 17% of customer environments. By January 2026, it had jumped to 47%. The growth wasn't steady — it came in three distinct waves, each driven by something specific Grammarly did.</p>

<p>Here's what the data looks like, and what was happening at Grammarly each time the line jumped.</p>

<table style="border-collapse:collapse;width:100%;font-family:sans-serif;font-size:13px;border:1px solid #e0e0e0;">
  <thead>
    <tr style="background:#f5f5f5;">
      <th style="padding:8px 12px;text-align:left;border-bottom:2px solid #ccc;">Period</th>
      <th style="padding:8px 12px;text-align:center;border-bottom:2px solid #ccc;">Adoption Index</th>
      <th style="padding:8px 12px;text-align:left;border-bottom:2px solid #ccc;">Notable Change</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Jan 2023</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">17%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Baseline</td>
    </tr>
    <tr style="background:#fafafa;">
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Feb–Mar 2024</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">22% → 31%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;"><strong>Spike 1: +6 points in one month</strong></td>
    </tr>
    <tr>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Dec 2024 → Jan 2025</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">30% → 38%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;"><strong>Spike 2: +7 points and never dropped back</strong></td>
    </tr>
    <tr style="background:#fafafa;">
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Sep–Oct 2025</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">41% → 46%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;"><strong>Spike 3: +5 points as Grammarly became Superhuman</strong></td>
    </tr>
    <tr>
      <td style="padding:8px 12px;">Jan 2026</td>
      <td style="padding:8px 12px;text-align:center;">47%</td>
      <td style="padding:8px 12px;">Peak to date</td>
    </tr>
  </tbody>
</table>

<figure class="wp-block-image size-full"><img width="1424" height="752" src="/assets/images/blog/wp/2026/03/grammarly-enterprise-growth-analysis-body-1.webp" alt="SaaS usage dashboard showing Grammarly adoption growth over time with bar chart and app list" class="wp-image-10638" /></figure>

<h2 class="wp-block-heading">Spike 1 (Feb–Mar 2024): Grammarly stopped being a spell-checker</h2>

<p>On March 26, 2024, Grammarly launched Strategic Suggestions — AI-powered recommendations that went beyond fixing grammar to advising on audience, tone, and persuasion. The same week, it shipped App Actions, letting users trigger tasks in tools like Asana and Google Calendar from within Grammarly. For the first time, the product could make a real case to IT and procurement as a productivity platform, not a writing add-on.</p>

<p>Fast Company added fuel. Its 2024 Most Innovative Companies list (published March 19) named Grammarly in the AI category and cited some striking ROI numbers: one healthcare customer reported 28x ROI, and Grammarly claimed average savings of $5,000 per employee per year. That kind of coverage circulates in the procurement channels where enterprise software decisions get made.</p>

<h2 class="wp-block-heading">Spike 2 (Dec 2024–Jan 2025): A new CEO, a new company</h2>

<p>On December 17, 2024, Grammarly announced it was acquiring Coda — a collaborative workspace product competing with Notion and Google Docs — and that Coda's co-founder Shishir Mehrotra would become Grammarly's new CEO. The message was explicit: Grammarly was no longer a writing tool; it was building an AI productivity suite for enterprise teams.</p>

<p>That announcement closed a pipeline that had been building since October. Two months earlier, Grammarly had landed on the AWS Marketplace, giving companies with existing AWS commitments a way to apply cloud credits toward Grammarly Business — a procurement shortcut that removes significant friction. In the same October window, Grammarly launched Billing Groups, ServiceNow integration, and group-level security controls: the exact features IT admins need before they can deploy something organization-wide.</p>

<p>The jump from 30% in December to 38% in January reflects deals that probably started in Q4, enabled by the AWS listing and admin tooling, then accelerated by the Coda news.</p>

<h2 class="wp-block-heading">Spike 3 (Sep–Oct 2025): The Superhuman rebrand</h2>

<p>On July 1, 2025, Grammarly acquired Superhuman — the AI email client valued at roughly $825 million. Three months later, on October 29, Grammarly rebranded the entire company as "Superhuman" and launched the Superhuman Suite: four unified products (Grammarly writing, Coda workspace, Superhuman email, and a new AI agent platform called Superhuman Go). The rebrand landed across TechCrunch, Fast Company, Built In, and others simultaneously.</p>

<p>Usage in our dataset went from 35% in August to 41% in September and 46% in October. September also brought a Forbes Cloud 100 placement at #11 — the kind of analyst recognition that validates a platform to IT procurement teams evaluating AI investments. A $1 billion non-dilutive funding round announced in May, earmarked for sales and marketing scale, almost certainly put more reps in front of enterprise buyers during this window.</p>

<figure class="wp-block-image size-full"><img width="1424" height="752" src="/assets/images/blog/wp/2026/03/grammarly-enterprise-growth-analysis-body-2.webp" alt="IT admin dashboard showing SaaS app discovery with sanctioned, under review, and shadow IT status badges alongside an app approval workflow" class="wp-image-10639" /></figure>

<h2 class="wp-block-heading">What this means for IT teams managing SaaS</h2>

<p>Each of these spikes followed the same pattern: Grammarly expanded what the product does, and enterprise adoption followed. That creates a specific challenge for IT.</p>

<p>In 2023, most companies probably had Grammarly as an employee-purchased tool — a $12/month browser extension people expensed without telling IT. By 2026, the product has become a full AI productivity suite with admin controls, data governance features, and enterprise licensing that IT should be part of evaluating and managing.</p>

<p>If you're not tracking which tools are gaining momentum in your organization, you'll find out about the enterprise version of Grammarly (or Superhuman, now) after someone in marketing has already signed a contract. The best position is to see the adoption curve before the renewal conversation happens.</p>

<p>Torii surfaces that kind of usage data automatically — which apps employees are using, which ones are growing, and which ones have grown to the point where IT needs a seat at the table. <strong><a href="/request-a-demo">Book a demo to see how it works.</a></strong></p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/articles/oauth-google-workspace-risk">How to Detect OAuth Risks in Google Workspace and Who\u2019s Behind Them in 2026</a></li>
  <li><a href="/blog/log-analysis">What is a Log Analysis?</a></li>
  <li><a href="/blog/spend-analysis">What is Spend Analysis?</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[What’s Behind Grammarly’s 3x Enterprise Growth? Three Years of Usage Data from Torii Has Answers]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/grammarly-enterprise-growth-analysis.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/grammarly-enterprise-growth-analysis.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">HubSpot Is Closing the Gap on Salesforce: Two Years of Real CRM Data</title><link href="https://www.toriihq.com/blog/hubspot-vs-salesforce-crm-adoption" rel="alternate" type="text/html" title="HubSpot Is Closing the Gap on Salesforce: Two Years of Real CRM Data" /><published>2026-03-27T00:00:00+00:00</published><updated>2026-03-27T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/hubspot-vs-salesforce-crm-adoption</id><content type="html" xml:base="https://www.toriihq.com/blog/hubspot-vs-salesforce-crm-adoption"><![CDATA[<p>Salesforce still leads by a wide margin among the companies we track, and that's not changing anytime soon. But absolute numbers only tell part of the story. When you look at penetration rates over two [years](/blog/grammarly-enterprise-growth-analysis), the picture shifts considerably.</p>

<p>Two years ago, 87% of active Torii customers had Salesforce in their stack. Today that sits at 60%. HubSpot moved in the opposite direction, climbing from 23% to 35% over the same stretch. The ratio between the two dropped from 3.8x to 1.7x — a meaningful shift in 24 months that has less to do with Salesforce losing accounts and more to do with where new companies are starting when they come to market.</p>

<table style="border-collapse:collapse;width:100%;border:1px solid #e0e0e0;font-family:sans-serif;font-size:14px;margin-bottom:8px;">
  <thead>
    <tr style="background:#0D1B6E;color:#fff;">
      <th style="padding:10px 14px;text-align:left;border:1px solid #0a1660;">Period</th>
      <th style="padding:10px 14px;text-align:center;border:1px solid #0a1660;">Salesforce penetration</th>
      <th style="padding:10px 14px;text-align:center;border:1px solid #0a1660;">HubSpot penetration</th>
      <th style="padding:10px 14px;text-align:center;border:1px solid #0a1660;">SF:HS ratio</th>
    </tr>
  </thead>
  <tbody>
    <tr style="background:#fff;">
      <td style="padding:9px 14px;border:1px solid #e0e0e0;">Feb 2024</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">87%</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">23%</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">3.8x</td>
    </tr>
    <tr style="background:#f9f9f9;">
      <td style="padding:9px 14px;border:1px solid #e0e0e0;">Feb 2025</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">66%</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">32%</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">2.1x</td>
    </tr>
    <tr style="background:#fff;">
      <td style="padding:9px 14px;border:1px solid #e0e0e0;">Feb 2026</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">60%</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">35%</td>
      <td style="padding:9px 14px;border:1px solid #e0e0e0;text-align:center;">1.7x</td>
    </tr>
  </tbody>
</table>
<p style="font-size:0.8em;color:#888;margin-top:4px;">Source: Torii customer [data](/blog/data-localization). Penetration = share of active Torii customers using each platform that month.</p>

<h2 class="wp-block-heading">The numbers: where things stand today</h2>

<p>In February 2026, Salesforce was active at 60% of companies in Torii's customer base, compared to 35% for HubSpot. Those percentages don't tell the full story on their own, because the base itself has been growing fast.</p>

<p>Torii's active customer base nearly doubled between early 2024 and early 2026. The companies joining the platform more recently are less likely to have Salesforce as their primary CRM than earlier cohorts were. New entrants are choosing HubSpot at a noticeably higher rate, and that dynamic is what's pulling the penetration gap closed. It's not Salesforce churn — it's new business going elsewhere.</p>

<h2 class="wp-block-heading">HubSpot's rise: penetration, not just headcount</h2>

<p>HubSpot's penetration among Torii customers went from 23% in February 2024 to 32% a year later, then 35% by February 2026. The growth is real, and there are specific product moves that explain it.</p>

<p>In December 2023, HubSpot completed its acquisition of Clearbit for roughly $150 million, adding firmographic and technographic data across 20+ million companies. That data was folded into the platform as Breeze Intelligence at INBOUND 2024 in September 2024, giving HubSpot a data enrichment capability that previously required enterprise-tier tools. HubSpot's full-year 2024 revenue grew 21% year-over-year to $2.63 billion, roughly double Salesforce's 11% growth rate over the same period.</p>

<p>The customer count followed a similar trajectory, closing 2024 with 247,939 total customers, up 21% from the year prior. Those customers still skew smaller than Salesforce's enterprise book of business, but the mid-market overlap is growing, and both companies know it. Salesforce noticed the shift early enough to respond: in February 2024, it launched Marketing Cloud Growth Edition, a product explicitly targeting companies with fewer than 200 employees — the segment where HubSpot has historically been strongest.</p>

<figure class="wp-block-image size-full"><img width="1200" height="633" src="/assets/images/blog/wp/2026/03/hubspot-vs-salesforce-crm-adoption-body-1.webp" alt="Rising bar chart visualization representing HubSpot's growing CRM adoption rate from 2024 to 2026" class="wp-image-10656" /></figure>

<h2 class="wp-block-heading">Salesforce's response — and where it's holding</h2>

<p>Salesforce is not losing existing customers — but it is losing new ones. Torii's customer base more than doubled over this period, and Salesforce only captured about a third of those new accounts. That's what a starting point of 87% penetration looks like when the market grows faster than you do: the absolute count goes up, but your share of new business tells the real story.</p>

<p>The penetration drop from 87% to 60% is a function of base growth, not platform loss. Salesforce's per-customer revenue remains far higher than HubSpot's, and its enterprise positioning stayed intact through this period. Alongside Marketing Cloud Growth Edition, Salesforce launched Agentforce in late 2024, its AI agent platform aimed at automating complex workflows for large organizations. The 2024 Gartner Magic Quadrant for Sales Force Automation still rated Salesforce's AI stack as more mature than HubSpot's for enterprise use cases.</p>

<p>What Salesforce is actually losing is not its existing accounts. It's new business at the margin, where companies that might have defaulted to Salesforce five years ago are now starting with HubSpot first and finding less reason to switch later.</p>

<figure class="wp-block-image size-full"><img width="1200" height="633" src="/assets/images/blog/wp/2026/03/hubspot-vs-salesforce-crm-adoption-body-2.webp" alt="Two converging parallel tracks representing Salesforce and HubSpot market penetration closing over time" class="wp-image-10657" /></figure>

<h2 class="wp-block-heading">What SaaS managers should watch</h2>

<p>Both platforms follow a consistent seasonal pattern across the full two-year window: usage dips in July and December, with peaks in October and February. This tracks broader business cycles rather than anything CRM-specific. For SaaS and IT teams, that seasonality is useful. The dip months are the right time to pull utilization reports, compare licensed users against active ones, and flag contracts up for renewal in Q4.</p>

<p>The bigger operational question for SaaS managers is dual-CRM environments. As HubSpot moves upmarket and both platforms expand their feature overlap, the risk of running Salesforce and HubSpot in parallel grows significantly. Sales teams on one platform, marketing on another, no shared source of truth on customer data. Torii data shows a meaningful share of customers actively using both tools simultaneously, which creates redundancy in spend, fragmentation across go-to-market teams, and a governance headache around user access and license assignments.</p>

<p>The CRM question used to be simple: Salesforce for organizations that needed scale, HubSpot for teams that wanted speed. That distinction is blurring. Managing the overlap well, whether that means consolidating to one platform or governing two deliberately, has become a real SaaS management task that doesn't get any easier as both platforms grow.</p>

<p>If your organization runs both platforms, a quarterly license review timed to the July or December usage dips can surface real savings before renewals land. <strong><a href="/request-a-demo">See how Torii helps teams manage multi-CRM environments.</a></strong></p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Salesforce still leads, but two years of adoption data from Torii customers shows HubSpot's penetration has grown from 23% to 35% while Salesforce's dropped from 87% to 60%.]]></summary></entry><entry><title type="html">Introducing the Torii CLI</title><link href="https://www.toriihq.com/blog/introducing-torii-cli" rel="alternate" type="text/html" title="Introducing the Torii CLI" /><published>2026-03-17T00:00:00+00:00</published><updated>2026-03-17T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/introducing-torii-cli</id><content type="html" xml:base="https://www.toriihq.com/blog/introducing-torii-cli"><![CDATA[<p>Your SaaS data shouldn't live behind a dashboard you have to click through every time you need an answer. With the Torii CLI, it doesn't have to.</p>

<p>The <a href="https://developers.toriihq.com/docs/torii-cli">Torii CLI</a> is an OpenAPI-driven command line interface that lets you explore the Torii API, inspect schemas, and run API calls directly from your terminal. Every command is auto-generated from the live OpenAPI spec, so it stays in sync with the latest API capabilities without manual updates.</p>

<p>If you're writing automation scripts, building data pipelines, or connecting Torii to AI agents, this is your starting point.</p>

<h2 class="wp-block-heading">Why a CLI?</h2>

<p>Point-and-click interfaces work for exploring. But when you need to pull license data into a report, trigger a workflow from a script, or pipe SaaS usage stats into another tool, a CLI is faster and more composable. Every response comes back as structured JSON, so it works out of the box with <code>jq</code>, shell scripts, and automation frameworks.</p>

<p>The Torii CLI is built for:</p>

<ul class="wp-block-list">
<li><strong>Automation scripts</strong> — schedule recurring data pulls or trigger actions on a cron</li>

<li><strong>Data extraction pipelines</strong> — export application, user, and contract data for analysis</li>

<li><strong>AI and agent integrations</strong> — feed Torii data into LLMs, Claude Code, or custom agents</li>

<li><strong>Interactive exploration</strong> — browse available endpoints and test calls before writing code</li>
</ul>

<h2 class="wp-block-heading">Getting Started</h2>

<p>Install globally via npm, or run it directly with npx if you just want to try it out.</p>

<pre class="line-numbers"><code class="language-bash"># Install globally
npm install -g torii-cli

# Or run without installing
npx torii-cli discovery</code></pre>

<p>Before running commands, set your API key as an environment variable:</p>

<pre class="line-numbers"><code class="language-bash">export TORII_API_KEY="your-api-key"</code></pre>

<p>That's it. You're ready to query your Torii instance from the command line.</p>

<h2 class="wp-block-heading">How It Works</h2>

<p>The CLI dynamically fetches the OpenAPI specification from the Torii API. This means you don't need to memorize endpoints or check documentation every time the API changes. Run the <code>discovery</code> command to see every available operation:</p>

<pre class="line-numbers"><code class="language-bash"># List all available API operations
torii-cli discovery</code></pre>

<p>This returns a JSON list of every endpoint, generated directly from the spec. From there, you can run any operation. For example, to pull your top 10 applications:</p>

<pre class="line-numbers"><code class="language-bash"># List your first 10 applications
torii-cli apps list --size 10</code></pre>

<p>All responses are structured JSON, which makes it easy to pipe into other tools or parse in scripts.</p>

<h2 class="wp-block-heading">Pairing Torii CLI with AI Agents</h2>

<p>One of the most practical uses for the Torii CLI is connecting your SaaS data to AI-powered tools. Because the CLI returns structured JSON and supports the same operations as the API, it works well as a data source for LLMs and coding agents.</p>

<p>Here's what that looks like in practice. Below, a user asks Claude Code how many people in their company are using ChatGPT, Gemini, and Claude. Claude queries the Torii API to pull real usage data and return an answer in seconds.</p>

<figure class="wp-block-image size-full"><img width="800" height="278" src="/assets/images/blog/wp/2026/03/cli-1.webp" alt="Claude Code querying Torii data to show how many employees use ChatGPT, Gemini, and Claude" class="wp-image-10626" /></figure>

<p>Instead of logging into a dashboard, filtering by app category, and exporting a spreadsheet, the user gets an answer through a natural language prompt. The CLI (and the broader Torii API) makes this kind of integration straightforward.</p>

<p>This pattern applies to more than just usage questions. You can build agents that flag expiring contracts, identify orphaned accounts, surface license optimization opportunities, or generate compliance reports, all powered by the same API the CLI uses.</p>

<h2 class="wp-block-heading">What You Can Do With It</h2>

<p>The CLI gives you access to the same data and actions available through the Torii platform. A few examples:</p>

<ul class="wp-block-list">
<li><strong>Pull application inventory</strong> — list all discovered apps, filter by category, and export for audits</li>

<li><strong>Query user data</strong> — check who has access to what, identify inactive accounts, and track usage</li>

<li><strong>Monitor contracts and spend</strong> — surface renewal dates, license counts, and cost data</li>

<li><strong>Feed data into CI/CD or reporting tools</strong> — pipe JSON output into dashboards, Slack alerts, or ticketing systems</li>

<li><strong>Build custom automations</strong> — combine CLI calls with cron jobs, shell scripts, or orchestration tools</li>
</ul>

<h2 class="wp-block-heading">Get Started</h2>

<p>The Torii CLI is available now on <a href="https://www.npmjs.com/package/torii-cli">npm</a>. Install it, set your API key, and start querying your SaaS data from the terminal.</p>

<p>For full documentation, visit the <a href="https://developers.toriihq.com/docs/torii-cli">Torii Developer Docs</a>.</p>

<p>Already a Torii customer? Reach out to your Customer Success representative to get your API key and start building.</p>

<p><strong><a href="/request-a-demo">Book a demo</a></strong> to see how Torii helps teams manage SaaS with automation, visibility, and developer-friendly tools.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Introducing the Torii CLI: an OpenAPI-driven command line tool to explore the Torii API, run calls, and pipe SaaS data into scripts and AI agents.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/introducing-torii-cli.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/introducing-torii-cli.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">How to Track AI Costs in 2026</title><link href="https://www.toriihq.com/blog/how-to-track-ai-costs" rel="alternate" type="text/html" title="How to Track AI Costs in 2026" /><published>2026-03-10T00:00:00+00:00</published><updated>2026-03-10T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/how-to-track-ai-costs</id><content type="html" xml:base="https://www.toriihq.com/blog/how-to-track-ai-costs"><![CDATA[<p>Most SaaS costs fit a predictable pattern. You sign a contract, assign seats, pay the invoice. But AI spending doesn't always work that way. Hidden behind seemingly low costs (only $20 for Claude/month!) are usage caps, often with little warning when your allocated usage tips into incremental PAYG token-based costs. </p>

<p>Then you have shadow AI usage and tool overlap, leading to cost optimization questions like, "We use Google Workspace, which has Gemini built in. Why also pay for ChatGPT?" or "Why are we paying so much for Cursor when we could just use Claude Code instead?"
</p>

<p>The good news: it's possible to track AI costs in 2026 down to the cent, as well as easily identify overlapping AI tools. This guide breaks down how to track AI costs in 2026: what to measure, how to do it manually, and how platforms like Torii give you a real-time view across your entire AI stack.</p>

<h2 class="wp-block-heading">Why is AI Spending Harder to Control Than SaaS?</h2>

<p>Traditional SaaS follows a predictable model: pay $X per month, or per seat per month. In either model, predicting costs is easy (it'll be the same cost unless you add more people). AI tools have upended this with their focus on 'token-based' pricing and generally opaque insights into usage.</p>

<p>Usage-based pricing is of course not new. Tools like Stripe (commission %), Twilio (PAYG usage), and Hubspot (cost per marketing contact) have used them for years. Not to mention Google Cloud and AWS's cloud compute costs. But these are much more predictable than AI token pricing, and the norm for SaaS is still monthly/yearly pre-set commitments.</p>

<p>Meanwhile, AI tool usage is...confusing? Odd? Misleading? Just take a look at this <a href="https://developers.openai.com/api/docs/pricing">API pricing breakdown</a> from OpenAI.</p>

<p>Understanding costs here is a nightmare. What model are you using? Are we caching or not? Is this batch, flex, or standard? How do I track how many tokens any given message contains? At least with standard request-based PAYG pricing you know that 1 request = 1 request to pay for.</p>

<figure class="wp-block-image size-full"><img width="1000" height="609" src="/assets/images/blog/wp/2026/03/openai_costs.webp" alt="OpenAI API pricing breakdown showing token costs by model" class="wp-image-10391" /></figure>

<p>On top of that, you have <a href="/articles/shadow-ai">shadow AI</a>. Employees are signing up for their favorite new AI tools, even though they may overlap significantly with tools your company already pays for. Then, of course, people may be signing up for ChatGPT themselves when a team plan would be much more economical.</p>

<p>The costs can compound quickly. A 100-person engineering team could be running Cursor, GitHub Copilot, and Claude Code simultaneously, each doing roughly the same thing. At standard pricing, that's anywhere from $70,000 to $130,000 per year in coding AI alone.</p>

<p>This differs from traditional SaaS because normally it's easy to identify overlaps. If you're working with Box.com, it may feel weird to also work in Dropbox for some projects, since they are effectively the same tool. Gemini and MidJourney, on the other hand, may not feel that way. Yet, with the speed of AI innovation, the difference between AI tools is shrinking. Maybe you paid for Gemini Nano Banana because it was the best image generator, then switched to MidJourney the next month because it seemed better, and so on - until you just decide to keep paying for both. (Or, you were using MidJourney not knowing Gemini was also a great image generator).</p>

<div style="background:#fff7ed;border-left:4px solid #f97316;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>The math adds up fast:</strong></p>
  <p style="margin:0;">A 100-person dev team paying for Cursor ($48K/year), Copilot ($46.8K/year), and ChatGPT Team ($36K/year) could be spending over $130K annually on tools with significant feature overlap.</p>
</div>

<h2 class="wp-block-heading">How Do I Track AI Costs Manually?</h2>

<p>The manual approach to AI cost tracking is where most companies begin. For small companies, it's relatively simple: you log into each tool's billing dashboard separately (the OpenAI usage page, the Copilot admin console, Cursor Teams billing), pull the numbers, and paste them into a spreadsheet. Then you cross-reference expense reports to catch anything employees bought on their own.</p>

<p>This approach works passably when you have two or three tools and one person keeping the spreadsheet current. It doesn't hold up as your AI stack grows.</p>

<p>The core limitation with manual tracking comes down to visibility lag between spending and awareness. Each billing dashboard gives you a static snapshot from a single vendor. You have no cross-tool view of what an individual employee is spending across their whole AI stack. You can't see that one developer has active subscriptions to Cursor, Claude Pro, and ChatGPT running at the same time.</p>

<p>A second blind spot with manual tracking is that it tells you nothing about license utilization. A billing dashboard shows what you're paying, not what's being used. You can have 50 Copilot seats and only 20 active users, and the invoice looks the same regardless. Finding that waste requires comparing the bill against actual login data, which most AI tool billing dashboards don't surface.</p>

<div style="background:#fff7ed;border-left:4px solid #f97316;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>Where manual tracking breaks down:</strong></p>
  <p style="margin:0;">Expense reimbursements are often the first time IT learns about a new AI tool, and it may take months before IT even notices. By the time you notice the charge, the subscription has been running for weeks.</p>
</div>

<h2 class="wp-block-heading">How Can I Track Costs with Torii?</h2>

<p>Torii is an AI Management Platform that replaces the per-tool billing dashboard approach with a single consolidated view. Torii's AI Apps Spend dashboard pulls all your AI tool costs into one place: total spend by tool, last 30 days vs. last 12 months, user counts, and license utilization.</p>

<figure class="wp-block-image size-full"><img width="1000" height="389" src="/assets/images/blog/wp/2026/03/dashboard1.webp" alt="Torii AI Apps Spend dashboard showing AI tool costs and license utilization" class="wp-image-10392" /></figure>

<p>That last column is where the real value shows up. If Lovable is sitting at 38% license utilization, that means 62% of the seats you're paying for aren't actively used. That's not easily visible within Lovable alone. In Torii, it surfaces right next to the cost number so you can act on it immediately.</p>

<p>Additionally, the spend-over-time chart surfaces growth trends that a manual spreadsheet would never flag in time. Cursor spend jumping from roughly $1,400 per month to over $5,400 in two months is a signal worth investigating: is the team growing, or are a handful of power users burning through credits on a premium model? Seeing the trend is the first step to asking the right question.</p>

<figure class="wp-block-image size-full"><img width="1000" height="352" src="/assets/images/blog/wp/2026/03/dashboard2.webp" alt="Torii AI spend over time chart showing monthly AI tool costs by vendor" class="wp-image-10393" /></figure>

<div style="background:#ecfdf5;border-left:4px solid #10b981;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>What Torii surfaces that billing pages don't:</strong></p>
  <p style="margin:0;">License utilization by tool, spend trends over time, and cross-tool cost comparisons in one view, without logging into a single vendor dashboard.</p>
</div>

<h2 class="wp-block-heading">How Do I Cut My AI Costs?</h2>

<p>Seeing your AI spend is the starting point, not the finish line. Once you have a consolidated view, four actions consistently move the number down.</p>

<p><strong>Reclaim idle seats.</strong> For AI tools with seat-based pricing, any AI license that hasn't been accessed in 90 days is waste. License reclamation at this threshold can <a href="/articles/reduce-saas-costs">cut AI tool costs</a> by 20-35% in organizations that haven't been actively managing it. Set a policy, automate the reclaim, and redirect those seat costs elsewhere.</p>

<p><strong>Identify tool overlap.</strong> Once you can see every AI tool in use, consolidation decisions become obvious. If multiple teams are each paying for a coding assistant, pick one standard. If you have three separate <a href="/articles/llm-shadow-ai-risk">LLM subscriptions</a> doing similar work, consolidate. A tool like Torii can help surface those duplicate tools easily.</p>

<p><strong>Rightsize tiers.</strong> Actual usage data removes the guesswork from tier and contract decisions. If 60% of your Copilot users are only accessing basic features, downgrade those seats. Annual contracts save 10-20% over monthly billing for tools you're committed to keeping long-term.</p>

<p><strong>Set ongoing guardrails.</strong> Treat AI spend like cloud compute: allocated per team, monitored monthly, with budget alerts at 80% of the limit. Require new AI tool requests to pass a lightweight approval that checks for overlap with existing tools. The goal isn't to slow down adoption. It's to stop paying for the same capability twice.</p>

<p><strong>Monitor outliers.</strong> If a certain tool or user is causing costs to climb, why is that? Perhaps there is wayward automation running, or an expensive model is being used when a more cost-efficient one would suffice. Review and set guidelines on model and token usage.</p>

<div style="background:#f5f3ff;border-left:4px solid #8b5cf6;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>Quick wins after your first AI spend audit:</strong></p>
  <p style="margin:0;">Reclaim seats inactive for 90+ days, consolidate overlapping coding AI tools, and set monthly budget alerts per team. These three steps alone can recover 20-35% of AI spend without cutting tools people actually use.</p>
</div>

<p>AI tool adoption isn't slowing down, and neither is the spending that comes with it. Enterprise AI-native app spend grew 108% year-over-year in 2025, and with more tools hitting the market every month, the overlap problem will only compound. The companies that stay ahead of it are the ones that treat AI spend the same way they treat cloud compute: tracked by team, reviewed regularly, and tied to actual outcomes.</p>

<p>The path forward isn't complicated. Know what you have, know what's being used, and build a repeatable process to act on that data. Whether you start with a manual audit or a platform like Torii that consolidates everything into one view, the goal is the same: visibility that lets you make decisions before you get surprised by a five-figure invoice.</p>

<p><strong><a href="/request-a-demo">See how Torii tracks your AI spend across every tool. Book a demo.</a></strong></p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/articles/toxic-combination-saas">What Is a Toxic Combination in SaaS in 2026?</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[AI spending is growing fast and getting hard to control. Here's how to track AI costs across your stack in 2026, from manual methods to automated platforms.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/how-to-track-ai-costs.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/how-to-track-ai-costs.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Enterprise IGA Blueprint</title><link href="https://www.toriihq.com/blog/the-enterprise-iga-blueprint" rel="alternate" type="text/html" title="The Enterprise IGA Blueprint" /><published>2025-09-22T00:00:00+00:00</published><updated>2025-09-22T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/the-enterprise-iga-blueprint</id><content type="html" xml:base="https://www.toriihq.com/blog/the-enterprise-iga-blueprint"><![CDATA[<p class="has-medium-font-size">A board-ready framework to reduce identity risk, pass audits, and prove ROI in 2–3 quarters.</p>

<h2 class="wp-block-heading">Executive Summary</h2>

<p>Identity Governance &amp; Administration (IGA) is no longer a back-office task. It is a board-level responsibility. Identity is now central to enterprise risk, regulatory compliance, and shareholder value.</p>

<p>The pressure is mounting from every direction:</p>

<ul class="wp-block-list">
<li>Breach reality: Ransomware features in 44% of breaches, the human element is present in nearly 60%, and third-party exposure has doubled to 30%.</li>

<li>Financial impact: The average breach costs $4.4M, while most organizations hit by AI-related incidents lacked basic access controls.</li>

<li>Regulatory heat: Boards face direct accountability under DORA (resilience and third-party oversight), NIS2 (expanded obligations with active enforcement), and the SEC cyber rule (4-day disclosure of material incidents).</li>

<li>Business reality: Enterprises now run an average of 1,850 SaaS apps. Machine identities outnumber humans 82:1, and AI systems are emerging as new “users” with access needs of their own.</li>
</ul>

<p>The good news is that IGA delivers results quickly.&nbsp;</p>

<p>This blueprint gives boards, executives, and audit committees the tools to turn identity governance into a measurable, board-sanctioned program. Specifically, it will:</p>

<ul class="wp-block-list">
<li>Outline clear accountability: Show exactly who should own which responsibilities—from board and committee oversight, to executive sponsorship, to daily operations through an IGA council.</li>

<li>Provide a reference architecture: A vendor-agnostic model of the essential layers of IGA (sources, control plane, Zero Trust, PAM, ITDR, AI guardrails, reporting) that boards can use to judge maturity.</li>

<li>Define a board-ready KPI framework: A concise set of metrics and targets mapped directly to regulatory requirements, so progress can be tracked quarter by quarter.</li>

<li>Map controls to standards: Demonstrate how IGA outcomes align with NIST CSF 2.0, DORA, NIS2, and SEC rules—simplifying reporting and audit prep.</li>

<li>Deliver a 180-day SaaS sprawl plan: A phased approach to bring <a href="/blog/what-is-shadow-it" title="shadow IT">shadow IT</a>, vendors, and machine identities under governance, with quick wins in the first 30 days.</li>

<li>Show the ROI case: Translate governance outcomes into financial language—license reclamation, audit efficiency, and avoided breach losses—so CFOs and boards can clearly see value.</li>
</ul>

<p>The takeaway is simple: IGA is the control plane for digital risk. It enables boards to prove compliance, reduce exposure, and demonstrate financial value—turning identity from a hidden liability into a governed asset.</p>

<h2 class="wp-block-heading">IGA is a Board-Level Concern</h2>

<p>For years, identity was treated as a back-office function. It was something that IT, SecOps, and vendor management dealt with. But today, that era is over.</p>

<p>Identity is a board-level concern because it directly impacts enterprise risk, regulatory compliance, and shareholder value.&nbsp;</p>

<p>The facts are clear: stolen or misused credentials are still the easiest way for attackers to get in to the organization.&nbsp;</p>

<p>According to&nbsp; <a href="https://www.verizon.com/business/resources/infographics/2025-dbir-infographic.pdf">Verizon’s DBIR 2025</a> reports:</p>

<ul class="wp-block-list">
<li>Ransomware was involved in 44% of breaches</li>

<li>The human element was present in ~60%</li>

<li>Third-party involvement doubled year over year to 30%</li>
</ul>

<p><a href="https://www.ibm.com/reports/data-breach">&nbsp;IBM’s 2025 study</a> pins the average cost of a breach at $4.4M.</p>

<p>Additionally, they highlight a massive AI oversight gap. Among the orgs reporting an AI-realted security incident, 97% lacked proper AI access controls.</p>

<p>As financial impacts grow, regulatory leashes tighten.</p>

<p>In Europe, DORA now requires boards of financial institutions to prove resilience across their ICT and vendor ecosystems. NIS2 is expanding the obligations across industries, and the commission is already escalating against 23 lagging states. In the US, the SEC cyber&nbsp; disclosure rule now forces boards to disclose material incidents within four business days.</p>

<p>Each of these rgulations asks the same question of the board: Can you prove, right now, that you know who (or what) has access to what?</p>

<p>Along with the financial and&nbsp; regulatory risk, there is the business reality.&nbsp;</p>

<p>Organizations use:</p>

<ul class="wp-block-list">
<li>More applications than ever, with enterprises often leveraging over <a href="/reports/saas-benchmark-annual-report-2026">1,800 apps</a></li>

<li>Machine identities, <a href="https://www.cyberark.com/threat-landscape/?prevItm=690762184&amp;prevCol=6824667&amp;ts=11872">outnumbering human identities 82 to 1</a> </li>

<li>More AI solutions than ever before</li>
</ul>

<p>The takeaway is simple: IGA is the control system for digital risk, the foundation of zero trust, and the evidence trail that boards need for regulators and investors. Without it, companies risk breaches, regulatory fines, missed disclosures, and loss of market trust. However, there is also an opportunity. With an IGA architecture in place, boards gain measurable resilience, faster audits, and the ability to show ROI in just a few quarters.</p>

<p>In this piece, we’ll build out a reference architecture for your IGA Blueprint. This guide is vendor agnostic, instead it outlines the key building blocks and the relationships between them.</p>

<h2 class="wp-block-heading">Reference Architecture: The Core Layers of IGA </h2>

<p>If IGA is indeed a board-level concern, the next logical step is to show the board what a good outcome looks like. That is the purpose of a reference architecture, it is a blueprint of the essential layers that every enterprise needs in place to govern identity effectively.</p>

<p>These layers are non-negotiable building blocks of modern identity governance. Different organizations might use different language to describe some of the business functions included, but the processes and outcomes should be similar. Each layer addresses real-world weaknesses that attackers exp[loit and regulators scrutinize. Together, they form the control plane that allows boards and executives to both reduce risk and prove compliance.</p>

<h3 class="wp-block-heading">The Core Layers of IGA</h3>

<ul class="wp-block-list">
<li><strong>Identity Sources &amp; Context: </strong>The “source of truth” for who people are, who vendors are, and what machines or AI agents exist. Without authoritative sources, everything else falls apart.<br /></li>

<li><strong>IGA as the Control Plane: </strong>Where governance actually happens: automating joiner/mover/leaver processes, approving or denying access requests, enforcing segregation-of-duties rules, and running certifications. This is the heartbeat of the architecture.<br /></li>

<li><strong>Zero Trust Enforcement: </strong>Access is never granted by default. Instead, users must prove themselves continuously via SSO, MFA, device posture, and least-privilege rules, every time they connect.<br /></li>

<li><strong>ITDR (Identity Threat Detection &amp; Response): </strong>Because policies aren’t enough, ITDR provides the ability to detect stolen tokens, anomalous logins, or suspicious privilege escalation and shut it down fast.<br /></li>

<li><strong>Privileged Access Management (PAM): </strong>Admin accounts are the master keys to the kingdom. PAM ensures they’re controlled, time-boxed, monitored, and rotated whether human or machine.<br /></li>

<li><strong>Third-Party &amp; Supplier Access: </strong>Many of today’s breaches start with a vendor. Extending IGA controls to suppliers ensures that partners play by the same rules and that offboarding happens the moment a contract ends.<br /></li>

<li><strong>AI Identity &amp; Data Guardrails: </strong>As AI systems become active participants in workflows, they must be governed as identities too. Who can they access? What can they see? How are their API keys rotated?<br /></li>

<li><strong>Evidence &amp; Reporting: </strong>You need proof. Audit trails, attestation reports, and clear metrics that map directly to DORA, NIS2, and SEC requirements. This is what lets the board sleep at night.</li>
</ul>

<p>We’ve laid out the core layers of the reference architecture, these building blocks make up an enterprise-grade identity governance program. But layers on a diagram won’t move the board. Now it’s time to establish KPIs and targets that you can measure against.</p>

<h2 class="wp-block-heading">Board-Ready KPIs and Targets (90-Day to 3-Quarter Trajectory)</h2>

<p>What directors, audit committees, and CFOs need is a scoreboard: a small set of measurable outcomes that prove whether the architecture is working and whether the investment is paying off.&nbsp;</p>

<p>In this section, we’ll lock down KPIs and targets so you can see and prove your progress.</p>

<p>Think of these as your CEO/CFO-safe metrics. They’re clear, auditable, and can be tied directly to regulatory requirements or financial returns. They also have the advantage of being time-bound: progress can be demonstrated in as little as three quarters.&nbsp;</p>

<p>We’ll break these KPIs into five groups.</p>

<h3 class="wp-block-heading">Identity Hygiene &amp; Lifecycle</h3>

<ul class="wp-block-list">
<li>Orphaned accounts (both human and non-human): Accounts without owners are a breach waiting to happen.
<ul class="wp-block-list">
<li>Target: Reduce known orphaned accounts by 80% in 2 quarters.</li>

<li>Tip: Reconcile IdP/IGA directories against HRIS and the vendor master/NHI registry. Prioritize by: app criticality, privilege level, data sensitivity, and last login.</li>
</ul>
</li>

<li>Time-to-deprovision (JML): When someone leaves, or a vendor contract ends, access should disappear immediately.
<ul class="wp-block-list">
<li>Target: ≤ 4 hours for SaaS; ≤ 24 hours for infrastructure.</li>

<li>Tip: Start the clock at the HR “termination effective” timestamp; stop it when tokens/sessions are revoked. Automate HRIS → IGA → SSO/SCIM, add a one-click “kill switch,” and run monthly mystery-user tests.</li>
</ul>
</li>

<li>% apps under SSO + SCIM-based lifecycle: Coverage is control; if it’s not behind SSO and SCIM, it’s hard to govern.
<ul class="wp-block-list">
<li>Target: 80% coverage; prioritize the top 50 apps by risk/use.</li>

<li>Tip: Build an app register (criticality, user count, SSO/SCIM support, owner). Migrate in waves (top 25, next 25, long tail). Require SSO/SCIM in new-app intake and vendor contracts.</li>
</ul>
</li>

<li>Service/NHI with owner + rotation policy: Bots and keys are identities too; unowned secrets become permanent backdoors.
<ul class="wp-block-list">
<li>Target: 95% have an accountable owner; secrets MTTR ≤ 7 days (vs. DBIR’s 94-day median).</li>

<li>Tip: Discover NHIs via cloud IAM, CI/CD, and secrets scanners. Require Owner and Purpose fields for any token/key. Enforce TTLs and auto-rotation; break builds on expired/unknown secrets. Weekly reports: “NHIs without owner” and “secrets &gt;7 days after exposure.”</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">Governance &amp; Assurance</h3>

<ul class="wp-block-list">
<li>% access under review: Certifications keep real-world access aligned with policy.
<ul class="wp-block-list">
<li>Target: ≥ 95% on schedule (quarterly for critical apps; semiannual for the rest).</li>

<li>Tip: Scope by risk tier. Show delta-only changes to reviewers. Auto-revoke non-responses after X days with advance reminders; escalate misses to the app owner’s VP.</li>
</ul>
</li>

<li>SoD violations (opened vs. closed) + age: Toxic combinations enable fraud; the point is how fast you burn down the backlog.
<ul class="wp-block-list">
<li>Target: ≥ 85% closed within 30 days.</li>

<li>Tip: Seed SoD rules from Finance (P2P/O2C/GL) and Cloud Ops (deploy vs. approve). Triage by monetary/material risk and privilege level. Track oldest open and repeat offenders; require compensating controls or removal.</li>
</ul>
</li>

<li>Exception debt (temporary access): “Temporary” tends to become permanent unless engineered to expire.
<ul class="wp-block-list">
<li>Target: ≥ 98% auto-expire on time.</li>

<li>Tip: Default expiry (e.g., 7 days) for all exceptions; disallow no-end-date grants. Monthly leadership report: exceptions &gt;30 days. Treat break-glass the same, time-boxed, recorded, reviewed.</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">Risk &amp; Detection</h3>

<ul class="wp-block-list">
<li>Privileged accounts with phishing-resistant MFA: Admins hold the master keys; weak MFA isn’t acceptable.
<ul class="wp-block-list">
<li>Target: 100% coverage.</li>

<li>Tip: Inventory privileged roles (cloud/domain admins, root, CI/CD, finance superusers). Enforce WebAuthn/FIDO2 or platform authenticators; block SMS/voice for these roles. Maintain a short, dated exceptions list with remediation owners.</li>
</ul>
</li>

<li>High-risk identity alerts MTTR (ITDR): Time-to-contain drives breach impact; automation wins.
<ul class="wp-block-list">
<li>Target: ≤ 1 hour to containment.</li>

<li>Tip: Pre-define “high risk” (token theft, impossible travel + privilege, lateral movement to crown-jewel apps). Auto-contain (kill sessions, revoke tokens, force reset). Measure start (alert create) and stop (containment evidence). Run a monthly game day.</li>
</ul>
</li>

<li>Third-party/vendor identities governed: Vendors are part of your attack surface, and often the easiest path in.
<ul class="wp-block-list">
<li>Target: ≥ 90% via IGA/SSO/PAM; inactive vendor access = 0.</li>

<li>Tip: Integrate vendor master with IGA. Make IdP-only onboarding a contract term. Require named vendor managers who attest access quarterly. Auto-disable on contract end or 30 days of inactivity.</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">Regulatory Readiness</h3>

<ul class="wp-block-list">
<li>DORA/NIS2 control attestations: You can’t comply without evidence; mapping controls avoids audit surprises.
<ul class="wp-block-list">
<li>Target: Controls mapped and evidenced across third-party risk, incident playbooks, and continuity.</li>

<li>Tip: Build a control-mapping matrix: <em>Reg requirement → Control owner → Evidence source → Test cadence</em>. Store proofs in an “evidence locker” with timestamps. Do quarterly mini-audits instead of annual scrambles.</li>
</ul>
</li>

<li>SEC 8-K readiness (4 business days): If identity failure triggers a material incident, the clock starts immediately.
<ul class="wp-block-list">
<li>Target: Able to determine materiality and draft disclosure within 4 business days; tabletop tested.</li>

<li>Tip: Define a materiality rubric, escalation tree (CISO–GC–CFO–IR), and pre-approved templates. Time the tabletop from detection → decision → draft and stage identity evidence (logs, revokes, certifications).</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">ROI &amp; Efficiency</h3>

<ul class="wp-block-list">
<li>License reclamation via deprovisioning: Every orphaned seat is wasted spend; deprovisioning helps fund IGA.
<ul class="wp-block-list">
<li>Target: Report gross savings/quarter; make the number visible to Finance.</li>

<li>Tip: Focus on the top 10 apps by spend. Link revokes to seat removal (not just disabling). Publish a monthly “savings realized” report and forecast next-quarter savings from today’s pipeline.</li>
</ul>
</li>

<li>Access request cycle time: Faster access improves productivity, without increasing risk when guardrails are solid.
<ul class="wp-block-list">
<li>Target: Reduce median hours; show productivity regained.</li>

<li>Tip: Offer pre-approved catalog roles for low-risk access with auto-approval. Route only sensitive requests to multi-step approvals. Instrument median by app and owner; spotlight bottlenecks.</li>
</ul>
</li>

<li>Audit prep time: Continuous evidence shrinks effort and findings.
<ul class="wp-block-list">
<li>Target: Fewer hours vs. last cycle; fewer exceptions/findings.</li>

<li>Tip: Move to continuous evidence collection. Keep “audit-ready packs” per control (policy, config, sample, attestation). Give auditors read-only access to standard exports; track hours saved YoY.</li>
</ul>
</li>
</ul>

<p>This a comprehensive list of KPIs and Targets moving forward. The best way to operationalize this quickly is to pick the right denominators (i.e. top 50 apps by risk/spend + all privileged/NHI + all vendors), set a weekly burn-down goal for backlog KPIs (i.e. orphaned, SoD, exceptions), and automate timestamps for time-to-deprovision, mean time to respond/recover, and reviews (access certifications).&nbsp;</p>

<p>A lot of organizations estimate numbers, but they aren’t measuring them. But, regulators and auditors don’t want your gut feel, they want system logs. Ensure that you are always measuring and making progress on those numbers.&nbsp;</p>

<h2 class="wp-block-heading">Operating Model &amp; Governance</h2>

<p>A blueprint and a set of KPIs is only half the job. The other half is making sure the right people own the right parts of the system. This is where your operating model is critical.&nbsp;</p>

<p>Think of it as an accountability map:</p>

<ul class="wp-block-list">
<li>Who sets the rules</li>

<li>Who enforces the rules</li>

<li>Who provides the oversight</li>
</ul>

<h3 class="wp-block-heading">The Board and Committees</h3>

<p>The board and its audit/risk committee own the highest level of responsibility. They don’t manage the day-to-day minutia, but they do keep track of progress on a longer time horizon.&nbsp;</p>

<p>Board and Audit/Risk Committee Responsibilities:</p>

<ul class="wp-block-list">
<li>Set the organization’s risk appetite for identity and access.</li>

<li>Review KPI dashboards quarterly just as they do for financials</li>

<li>Oversee compliance with regulatory regimes such as the SEC cyber disclosure, DORA, and NIS2</li>
</ul>

<p>Their job is to ask tough questions in response to what they see. As KPIs start to roll in and conversations with regulators proceed, the board must keep focus on what matters.</p>

<p><em>“How many orphaned accounts remain?”</em></p>

<p><em>“Are we within SLA for vendor offboarding?”</em></p>

<p><em>“Can we prove it if regulators call?”</em></p>

<p>Often, the most importan thing they can do at this level is say <em>“Prove it to me before I have to prove it to someone else.”</em></p>

<h3 class="wp-block-heading">The Executive Triad (CISO, CIO, CFO)</h3>

<p>The executive triad consists of the CISO (accountable), CIO (co-owner), and CFO (controls). Together, these three roles create the charter, policy, and funding for identity governance.&nbsp;</p>

<ul class="wp-block-list">
<li><strong>CISO:</strong> Ultimately responsible for IGA control effectiveness and for reporting the results to the board</li>

<li><strong>CIO: </strong>Shares ownership, particularly around integration with infrastructure and the application portfolio</li>

<li><strong>CFO: </strong>Responsible for cost controls, ROI measurement, and financial compliance</li>
</ul>

<h3 class="wp-block-heading">The IGA Council</h3>

<p>Now we are at the level of daily execution. Your IGA council is a cross-functional team. A group that meets regularly (bi-weekly or monthly) to keep everyone in lockstep throughout the organmization. The IGA council should include representatives from:&nbsp;</p>

<ul class="wp-block-list">
<li>Security</li>

<li>IT/Identity Operations</li>

<li>HR</li>

<li>Procurement</li>

<li>Legal</li>

<li>Application Owners</li>
</ul>

<p>The council is responsible for the practical elements like the Segregation of Duties catalog, the Joiner/Mover/Leaver SLAs, and Vendor Access Policies. Their work ensures that there is allingment across functions so no single team carries the full burder <em>or </em>stalls the entire initiative.&nbsp;</p>

<p>In Summary:&nbsp;</p>

<ul class="wp-block-list">
<li><strong>Board:</strong> Approves the risk appetite and receives regular attestations.</li>

<li><strong>CISO:</strong> Accountable for IGA controls being effective and reported.</li>

<li><strong>IT Ops/Identity Team:</strong> Responsible for lifecycle automation, connectors, SCIM integration, and operational execution.</li>

<li><strong>App Owners:</strong> Approve or deny access, maintain SoD policies, and attest to who should have access.</li>

<li><strong>Procurement/Vendor Management:</strong> Ensure contracts include identity requirements and that offboarding happens automatically when agreements end.</li>
</ul>

<h2 class="wp-block-heading">Controls Blueprint: Tying IGA to Frameworks and Regulations</h2>

<p>Now that we’ve established the architecture and operating model, the next question a board or regulator will ask is, “How do these controls line up with recognized frameworks or laws?”</p>

<p>To answer that, we will now map your IGA program to relevant frameworks and regulations. This step is important because it shows that your initiative is anchored to external standards, it’s not simply a homegrown series of ideas.&nbsp;</p>

<h3 class="wp-block-heading">NIST Cybersecurity Framework 2.0&nbsp;</h3>

<p><a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">NIST CSF 2.0</a> is one of the most known and respected playbooks for cybersecurity governance in the U.S. and abroad. From the framework, there are two areas especially relevant to identity.</p>

<ul class="wp-block-list">
<li><strong>PR.AA (Identity Mgmt, Authn &amp; Access Control):</strong> From page 19 of the CSF 2.0, this section expects that organizations will manage identity lifecycles, enforce MFA, apply least privilege, vault and rotate credentials, prevent toxic access combinations, and conduct periodic access certifications. In other words, this is the day-to-day work of IGA. These are tasks for which the IGA council should focus to achieve. </li>

<li><strong>GV (Govern): </strong> The “<a href="https://csf.tools/reference/nist-cybersecurity-framework/v2-0/gv/">Govern</a>” function is new in CSF 2.0 and makes identity governance explicitly a board responsibility. It expects boards to set risk appetite, assign roles and responsibilities, manage supply-chain identity exposure, and track metrics for continuous improvement. This is the board’s call for direct accountability.</li>
</ul>

<h3 class="wp-block-heading">DORA (Digital Operational Resilience Act)</h3>

<p>Effective in Europe’s financial sector since January 2025, DORA requires companies to prove they can withstand ICT and third-party disruptions. For identity, that means demonstrating:</p>

<ul class="wp-block-list">
<li>Strong vendor access controls</li>

<li>Rapid revocation of third-party accounts</li>

<li>Tested incident playbooks and continuity plans</li>
</ul>

<h3 class="wp-block-heading">NIS2 Directive</h3>

<p>NIS2 expands obligations well beyond finance, making identity and least privilege first-class controls across industries like healthcare, energy, and digital services. Boards need to show they’ve assessed supply-chain risks and put governance in place for all third-party and privileged access.</p>

<h3 class="wp-block-heading">SEC Cyber Disclosure Rule</h3>

<p>In the U.S., public companies must disclose material cyber incidents within <strong>four business days</strong>. This raises identity governance from a “back office” activity to a board reporting requirement. If an identity or access failure leads to a breach, the board must be able to demonstrate:</p>

<ul class="wp-block-list">
<li>They had visibility into identity risks</li>

<li>They had tested playbooks for escalation and disclosure</li>

<li>They can provide evidence of access governance at the time of the incident</li>
</ul>

<h3 class="wp-block-heading">Why This Matters</h3>

<p>By explicitly mapping your IGA controls to NIST CSF and overlaying DORA, NIS2, and SEC requirements, you create a single story for auditors, regulators, and the board. Instead of a patchwork of policies, you can show:</p>

<ul class="wp-block-list">
<li>This control aligns with NIST.</li>

<li>This same control satisfies DORA/NIS2/SEC requirements.</li>

<li>Here’s the evidence (audit logs, certifications, revocations).</li>
</ul>

<p>This reduces redundancy, simplifies reporting, and ensures the board can answer the toughest regulatory question: <em>“Can you prove who had access, when, and why?”</em></p>

<h2 class="wp-block-heading">Build the SoD/Access Policy Backbone</h2>

<p>Once the architecture and governance model are in place, the next priority is to <strong>codify access rules</strong>; what combinations are allowed, what must be blocked, and how often they’re checked. This is your Segregation of Duties (SoD) and access policy backbone.</p>

<p>The SoD/Access Policy Backbone is a structured set of rules and guardrails that define who can do what across critical applications. It ensures no one person (or account) has too much unchecked power.&nbsp;</p>

<p>Think of it like any other task. You want a separation of duties to ensure accountability and accuracy. You want different people creating a vendor <em>and</em> approving payments, or pushing code <em>and</em> approving its release.&nbsp;</p>

<h3 class="wp-block-heading">Core Components</h3>

<p>The backbone of any effective identity governance program is built on a small set of <strong>practical components</strong>. These define <em>where to focus</em>, <em>what rules to enforce</em>, <em>how exceptions are handled</em>, and <em>how often access is checked</em>. Keeping this simple but structured makes it easier for teams to execute and for boards to oversee.</p>

<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Component</strong></td><td><strong>What It Is</strong></td><td><strong>Who’s Responsible</strong></td><td><strong>Example</strong></td></tr><tr><td><strong>Critical Apps Inventory</strong></td><td>Identify the 50 most important applications by data sensitivity and business impact (“blast radius”). Each must have a clear owner.</td><td>App Owners (with oversight from IT/IGA Council)</td><td>Salesforce, Workday, AWS, Jira; each tagged with owner and risk rating.</td></tr><tr><td><strong>SoD Library</strong></td><td>A set of prebuilt rules that block toxic combinations of access. Seeded from audit findings and real incidents.</td><td>IGA Council + App Owners</td><td>Finance: “Create vendor” + “Approve payment.” Engineering: “Deploy code” + “Approve release.”</td></tr><tr><td><strong>Access Request &amp; Emergency Access Patterns</strong></td><td>Standardize how users request access and how emergency (“break-glass”) access is granted. Ensure all are time-boxed, logged, and auto-expire.</td><td>IT Ops/Identity Team</td><td>A developer requests temporary DB admin rights; system auto-revokes after 24 hours.</td></tr><tr><td><strong>Certification Cadence</strong></td><td>Risk-based access reviews. High-risk apps reviewed quarterly; lower-risk apps semiannually. Auto-revoke if reviewers don’t respond.</td><td>App Owners (audited by Compliance)</td><td>Quarterly review in Workday; semiannual review in Jira. Non-responses trigger auto-removal of access.</td></tr></tbody></table></figure>

<p>This backbone turns abstract “least privilege” into tangible, enforceable rules. It gives the board confidence that fraud opportunities are minimized, regulators evidence that toxic combinations are managed, and business leaders assurance that emergency access is possible without leaving permanent backdoors.</p>

<h2 class="wp-block-heading">SaaS Sprawl Taming Plan (Fast Wins That Scale)</h2>

<p>SaaS sprawl is no longer measured in the dozens or even the hundreds. Torii’s research shows enterprise organizations run an average of ~<a href="/reports/saas-benchmark-annual-report-2026">1,850 apps</a>, far higher than the ~100–275 apps reported by <a href="https://www.okta.com/reports/businesses-at-work/">Okta</a>. For boards and executives, this is more than just a cost problem, it’s a governance and compliance challenge.&nbsp;</p>

<p>Every new app brings new identities, new entitlements, and new opportunities for oversight failures.</p>

<p>The good news: taming SaaS sprawl doesn’t require boiling the ocean. A phased, 180-day plan delivers fast wins, scales to enterprise portfolios, and works for mid-market companies with leaner teams.</p>

<h3 class="wp-block-heading">Phase 1 (0–30 days): Get Control of the Obvious</h3>

<ul class="wp-block-list">
<li><strong>SSO coverage for top 25 apps.</strong> Bring your most-used, highest-risk apps under single sign-on, and enable SCIM where available.</li>

<li><strong>Stop shadow IT invites.</strong> Put a hard stop on direct app invitations; enforce identity-provider onboarding only.</li>

<li><strong>Automate deprovisioning.</strong> Tie HR terminations and vendor contract ends directly to automated revokes. This closes the biggest “back door” first.</li>
</ul>

<p><em>Who owns it:</em> IT Ops/Identity team executes; App Owners and HR ensure onboarding/offboarding events are properly triggered.</p>

<h3 class="wp-block-heading">Phase 2 (30–90 days): Address Hidden Risks</h3>

<ul class="wp-block-list">
<li><strong>Service account census.</strong> Inventory all non-human accounts, assign owners, and rotate high-risk secrets.</li>

<li><strong>Certify access for top-risk apps.</strong> Run your first round of certifications on the most critical applications. Purge orphaned accounts and close aging SoD violations.</li>

<li><strong>Normalize exception handling.</strong> Ensure temporary access is time-boxed, logged, and auto-expiring.</li>
</ul>

<p><em>Who owns it:</em> IGA Council oversees; App Owners validate; Internal Audit monitors exception debt.</p>

<h3 class="wp-block-heading">Phase 3 (90–180 days): Scale and Mature</h3>

<ul class="wp-block-list">
<li><strong>Expand coverage.</strong> Push SSO/SCIM to cover ~80% of the portfolio, not just the top 25 apps.</li>

<li><strong>App-level SoD.</strong> Implement segregation-of-duties policies directly in SaaS apps that support it.</li>

<li><strong>Vendor portals.</strong> Bring supplier-facing access into the same IGA, SSO, and PAM flows as employees.</li>

<li><strong>Test response.</strong> Add ITDR detections across IdP/IGA/PAM, then run a red-team tabletop focused on identity misuse (we’ll cover more on IDTR in the next section).</li>

<li><strong>Refresh KPIs.</strong> Update the board-level KPI dashboard, set new targets, and establish next-year benchmarks based on progress.</li>
</ul>

<p><em>Who owns it:</em> CIO sponsors; CISO validates ITDR readiness; Board reviews new KPI trends.</p>

<h3 class="wp-block-heading">Why This Matters</h3>

<p>For enterprises, the scale (1,850 apps on average) makes SaaS governance a board-visible risk. For mid-market firms, fast growth means sprawl sneaks up faster than expected. This plan delivers:</p>

<ul class="wp-block-list">
<li><strong>Quick wins in the first month</strong> (orphaned accounts gone, SSO on critical apps).</li>

<li><strong>Risk reduction in the first quarter</strong> (service accounts, certifications, vendor offboarding).</li>

<li><strong>Mature governance by six months</strong> (broad coverage, tested detection, refreshed KPIs).<br /></li>
</ul>

<h2 class="wp-block-heading">ITDR Complements IGA (How They Work Together)</h2>

<p>Even the best access policies can’t stop every attack. That’s why <strong>Identity Threat Detection &amp; Response (ITDR)</strong> has become a critical partner to IGA. The two are designed to work hand-in-hand:</p>

<ul class="wp-block-list">
<li><strong>IGA prevents</strong> issues by ensuring the right people have the right access at the right time.</li>

<li><strong>ITDR detects and responds</strong> when accounts, tokens, or policies are misused despite those guardrails.</li>
</ul>

<p>Together, they close the loop: prevention on the front end, detection and containment on the back end.</p>

<h3 class="wp-block-heading">Playbook Intersections (Examples)</h3>

<ul class="wp-block-list">
<li><strong>Suspicious impossible travel</strong><strong><br /></strong> If a login shows up in two countries within minutes, ITDR auto-challenges the session. If it’s confirmed malicious, <strong>IGA policy</strong> revokes access while <strong>ITDR</strong> invalidates sessions and rotates tokens.</li>

<li><strong>Privilege escalation outside policy</strong><strong><br /></strong> When a user suddenly gains admin rights outside approved channels, <strong>PAM</strong> cuts the session, <strong>IGA</strong> generates an exception ticket, and <strong>ITDR</strong> alerts the SOC while storing evidence for audit.</li>

<li><strong>Leaked secret detected</strong><strong><br /></strong> If a secret (API key, token, password) shows up in a repo or monitoring feed, <strong>ITDR</strong> raises a high-severity alert. Then <strong>IGA/PAM</strong> rotate and re-issue credentials, forcing the owner to attest, targeting a mean-time-to-remediation of ≤ 7 days, compared to the DBIR’s 94-day median.<br /></li>
</ul>

<h3 class="wp-block-heading">Why This Matters</h3>

<p>For boards and executives, the key takeaway is that IGA and ITDR aren’t competing tools frameworks, they’re complementary layers of defense. IGA minimizes the number of doors into the enterprise; ITDR ensures that when a door is picked, the alarm rings and the lock is changed immediately.</p>

<p>This combination is what allows organizations to not only reduce breach likelihood but also meet audit and regulatory expectations for continuous monitoring and rapid response.<br /></p>

<h2 class="wp-block-heading">Executive ROI Model (Make Finance Love This)</h2>

<p>Identity governance only resonates at the board level if it’s framed in terms of <strong>financial outcomes</strong>. For directors and CFOs, the question is simple: <em>“What’s the return on this investment?”</em> The answer comes in two parts:<br />1. Hard savings you can measure today<br />2. Risk-adjusted benefits that protect against tomorrow’s losses.</p>

<h3 class="wp-block-heading">Hard Savings</h3>

<ul class="wp-block-list">
<li><strong>License reclamation through timely deprovisioning.</strong> Every orphaned seat costs money. By reclaiming SaaS licenses when users leave, you save directly: <em>number of seats × monthly license cost × reclaimed seats.</em> Finance teams see this as bottom-line savings.</li>

<li><strong>Audit prep reduction.</strong> Automated evidence collection and continuous certifications cut the hours spent on audit prep. Multiply saved hours by blended staff rates, then add in the reduced fines and fewer exceptions. That’s efficiency in dollars.</li>

<li><strong>Fewer privilege tickets.</strong> With cataloged roles and auto-approval guardrails, IT spends less time on access requests. The savings come in both reduced ticket volume and faster productivity for end users.<br /></li>
</ul>

<h3 class="wp-block-heading">Risk-Adjusted Benefits</h3>

<ul class="wp-block-list">
<li><strong>Expected Loss Avoided.</strong> The formula: <em>(Reduction in breach likelihood) × ($4.4M global average cost, per IBM)</em>. Regionalize where possible. Even modest improvements in likelihood reduction translate into millions of dollars in avoided loss.</li>

<li><strong>Ransomware containment and non-payment posture.</strong> Verizon’s 2025 DBIR shows that most organizations now decline to pay ransom. That makes <strong>response speed</strong> critical. Containing identity-driven ransomware quickly avoids secondary costs: PR damage, legal fees, downtime, and lost customer trust.<br /></li>
</ul>

<h3 class="wp-block-heading">Time-to-Value</h3>

<p>Boards don’t want ROI that takes years to materialize. Identity governance delivers visible results in <strong>2–3 quarters</strong> if you focus on the right KPIs:</p>

<ul class="wp-block-list">
<li>Orphaned accounts down</li>

<li>Time-to-deprovision reduced</li>

<li>SSO/SCIM coverage up</li>

<li>SoD backlog reduced</li>
</ul>

<p>Each of these can be tracked quarter by quarter, giving executives clear evidence that the program is paying off.</p>

<h3 class="wp-block-heading">Why Finance Should Care</h3>

<ul class="wp-block-list">
<li><strong>Direct savings</strong> (licenses, audit prep) show up in the P&amp;L quickly.</li>

<li><strong>Risk-adjusted benefits</strong> protect against catastrophic losses that could wipe out annual earnings.</li>

<li><strong>Faster time-to-value</strong> means this isn’t a long-term “trust us” program, it’s measurable progress within the board’s reporting cycle.<br /></li>
</ul>

<h2 class="wp-block-heading">Conclusion: From IT Project to Boardroom Priority</h2>

<p>Identity Governance &amp; Administration can no longer be treated as a back-office IT exercise. The data is clear: identity failures drive the majority of breaches, regulators on both sides of the Atlantic are raising the bar, and SaaS portfolios have exploded into the thousands of apps. What once felt like a technical detail is now a board-level governance issue, with financial, regulatory, and reputational consequences.</p>

<p>The blueprint we’ve laid out shows how to take control. It starts with a reference architecture that unifies prevention and detection. It moves through board-ready KPIs that let directors measure progress the same way they measure financials. It establishes a governance model with clear accountability, ties directly to NIST CSF 2.0 and regulatory overlays, and translates into fast wins against SaaS sprawl. Finally, it delivers a finance-ready ROI story that connects identity governance to both hard savings and avoided losses.</p>

<p>For boards, the next step isn’t whether to invest in IGA, it’s how quickly to elevate it into the governance agenda. For executives, the challenge is execution: embedding identity controls into everyday operations, measuring results quarter by quarter, and keeping oversight tight as the business grows.</p>

<p>The takeaway is simple: identity is the new control plane for digital business risk. Treating it as such not only reduces breach likelihood, but also positions the organization to meet regulatory demands, satisfy auditors, and protect shareholder value.</p>

<h2 class="wp-block-heading">Appendix</h2>

<h3 class="wp-block-heading">Glossary of Critical Terms for the Enterprise IGA Blueprint</h3>

<p><strong>Access Certification (Access Review)</strong></p>

<p>A periodic attestation by managers/owners to confirm users still need their current access; removals and exceptions are recorded as audit evidence.</p>

<p><strong>Access Request Catalog (Catalog Roles)</strong></p>

<p>A menu of pre-approved role bundles that users can request; low-risk items auto-approve within guardrails to reduce ticket load.</p>

<p><strong>ABAC (Attribute-Based Access Control)</strong></p>

<p>Authorization based on user/app/resource attributes (e.g., department, device posture), often layered with RBAC.</p>

<p><strong>AD / Active Directory (incl. Entra ID)</strong></p>

<p>Microsoft’s directory platforms that store identities, groups, and policies and act as core identity stores for many enterprises.</p>

<p><strong>AI Identity &amp; Data Guardrails</strong></p>

<p>Policies that treat AI systems/agents as identities—governing what data they can access, which plugins/APIs they can use, and how their secrets are managed.</p>

<p><strong>API Key / Token</strong></p>

<p>A credential used by software and services (non-human identities) to authenticate to systems; must be issued, rotated, and revoked like user passwords.</p>

<p><strong>App Owner</strong></p>

<p>The accountable person for an application’s access policies, approvals, SoD rules, and certifications.</p>

<p><strong>Audit Evidence / Evidence Locker</strong></p>

<p>Time-stamped artifacts (logs, exports, screenshots, tickets, attestations) stored systematically to prove controls are operating.</p>

<p><strong>Audit-Ready Pack</strong></p>

<p>A pre-assembled set of policy, configuration, samples, and evidence for a specific control, prepared for auditors/regulators.</p>

<p><strong>Auto-Revoke (Non-Response)</strong></p>

<p>A rule that removes access if a reviewer does not complete a certification by the deadline.</p>

<p><strong>Blast Radius (Business Impact)</strong></p>

<p>The potential harm if a system or identity is compromised (financial, regulatory, operational); used to prioritize “top 50” critical apps.</p>

<p><strong>Break-Glass (Emergency Access)</strong></p>

<p>A tightly time-boxed, logged, and monitored elevation path used in emergencies; must auto-expire and be reviewed afterward.</p>

<p><strong>CMDB (Configuration Management Database)</strong></p>

<p>A repository of infrastructure/services metadata that helps discover machines, service accounts, and ownership.</p>

<p><strong>Compensating Control</strong></p>

<p>An alternate control that reduces risk when a preferred control (e.g., removing a SoD violation) is temporarily infeasible.</p>

<p><strong>Credential Vaulting / Secret Vault</strong></p>

<p>Secure storage for passwords, keys, and certificates, typically managed by PAM; supports rotation and access auditing.</p>

<p><strong>CSF (NIST Cybersecurity Framework) 2.0</strong></p>

<p>A widely used framework; this guide maps IGA to <strong>PR.AA</strong> (Identity/Access outcomes) and <strong>GV</strong> (Govern).</p>

<p><strong>Deprovisioning (Termination Revocation)</strong></p>

<p>Automated removal of accounts/entitlements when people leave or vendors/contracts end; measured as <strong>TTD</strong>.</p>

<p><strong>Device Posture</strong></p>

<p>Security state of a device (OS version, disk encryption, EDR present) used in Zero Trust access decisions.</p>

<p><strong>Disclosure (SEC 8-K Item 1.05)</strong></p>

<p>U.S. requirement to disclose material cyber incidents within four business days of determining materiality.</p>

<p><strong>DORA (Digital Operational Resilience Act)</strong></p>

<p>EU regulation for financial entities focusing on ICT/third-party resilience; requires strong vendor access governance and tested response.</p>

<p><strong>Entitlement / Permission</strong></p>

<p>A discrete right in an application (e.g., “Billing Admin,” “Export Data”) that should be role- or policy-managed.</p>

<p><strong>Exception / Exception Debt</strong></p>

<p>Temporary access granted outside standard policy; becomes “debt” if not time-boxed and auto-expired.</p>

<p><strong>Expected Loss Avoided (ELA)</strong></p>

<p>Risk ROI metric: <em>(Reduction in breach likelihood) × (Average breach cost)</em>; used to quantify the financial impact of IGA.</p>

<p><strong>FIDO2 / WebAuthn (Phishing-Resistant MFA)</strong></p>

<p>Modern authentication standards using hardware or platform authenticators resistant to credential-phishing attacks.</p>

<p><strong>Form 8-K (Material Cyber Incident)</strong></p>

<p>The SEC filing used to disclose material cyber events; requires timely, evidence-backed decisioning on materiality.</p>

<p><strong>Govern (NIST CSF 2.0 GV)</strong></p>

<p>Framework function assigning board-level accountability for risk appetite, roles/responsibilities, supply-chain oversight, and metrics.</p>

<p><strong>HRIS (Human Resources Information System)</strong></p>

<p>The source of truth for workforce lifecycle events (hire, transfer, termination) that trigger provisioning/deprovisioning.</p>

<p><strong>IAM (Identity &amp; Access Management)</strong></p>

<p>Operational systems that authenticate and authorize users (IdP, directories, SSO, MFA); IGA governs policy on top of IAM.</p>

<p><strong>IGA (Identity Governance &amp; Administration)</strong></p>

<p>The policy/control plane that governs <strong>who</strong> gets <strong>what</strong> access, <strong>why</strong>, <strong>when</strong>, and <strong>for how long</strong>, with auditability (JML, requests, approvals, SoD, certifications).</p>

<p><strong>IGA Council</strong></p>

<p>Cross-functional working group (Security, IT, HR, Procurement, Legal, App Owners) that runs the program: SoD library, JML SLAs, vendor policy.</p>

<p><strong>IdP (Identity Provider)</strong></p>

<p>The service that authenticates users and issues assertions/tokens for SSO (e.g., Okta, Entra ID, Ping).</p>

<p><strong>Impossible Travel</strong></p>

<p>A detection signal where successive logins from distant locations cannot be legitimate given the elapsed time.</p>

<p><strong>ITDR (Identity Threat Detection &amp; Response)</strong></p>

<p>Detection/response focused on identity systems and usage (token theft, anomalous privilege, lateral movement), with automated containment.</p>

<p><strong>JEA / JIT (Just-Enough / Just-In-Time)</strong></p>

<p>Least-privilege patterns that grant only the specific rights needed, and only for the time needed—often enforced through PAM.</p>

<p><strong>JML (Joiner / Mover / Leaver)</strong></p>

<p>Lifecycle processes that create, modify, and remove access based on HR or vendor events; must be automated and auditable.</p>

<p><strong>KPI (Key Performance Indicator)</strong></p>

<p>An outcome metric used to manage performance (e.g., orphaned accounts ↓80%, TTD ≤4h/24h).</p>

<p><strong>KRI (Key Risk Indicator)</strong></p>

<p>A forward-looking signal of risk (e.g., % privileged accounts without phishing-resistant MFA).</p>

<p><strong>Least Privilege</strong></p>

<p>Granting only the minimum access necessary to perform a task; cornerstone of Zero Trust and SoD.</p>

<p><strong>Machine Identity (Non-Human Identity, NHI)</strong></p>

<p>Service accounts, workloads, bots, CI/CD and API credentials that require ownership, rotation, and certification.</p>

<p><strong>Materiality (Cyber Incidents)</strong></p>

<p>A determination of whether an incident is important to investors; triggers SEC disclosure timelines.</p>

<p><strong>MFA (Multi-Factor Authentication)</strong></p>

<p>Authentication that requires two or more factors; <strong>phishing-resistant MFA</strong> (FIDO2/WebAuthn) is preferred for privileged access.</p>

<p><strong>MTTR (Mean Time to Respond/Recover)</strong></p>

<p>Average time from alert to containment/recovery for identity incidents; measured from system logs.</p>

<p><strong>NIS2 (EU Directive)</strong></p>

<p>EU directive expanding cyber obligations and enforcement across sectors; includes supply-chain and access governance expectations.</p>

<p><strong>NIST CSF 2.0 PR.AA</strong></p>

<p>Outcomes category covering identity management, authentication, access control, SoD, credential rotation, certifications.</p>

<p><strong>OAuth 2.0 / OIDC (OpenID Connect)</strong></p>

<p>Standards for delegated authorization and federated authentication, commonly used for modern SSO.</p>

<p><strong>Offboarding (Vendor / Workforce)</strong></p>

<p>The process of revoking all access and reclaiming licenses at contract end or termination; must be automated and evidenced.</p>

<p><strong>Orphaned Account</strong></p>

<p>An account without an active owner (often after turnover or vendor churn); a high-risk hygiene defect and core KPI.</p>

<p><strong>PAM (Privileged Access Management)</strong></p>

<p>Controls for high-risk/admin access: session brokering/recording, JIT elevation, vaulting and rotation for human and machine credentials.</p>

<p><strong>PBAC (Policy-Based Access Control)</strong></p>

<p>Authorization using policies that evaluate context (risk, device, location) at decision time.</p>

<p><strong>Phishing-Resistant MFA</strong></p>

<p>MFA that resists credential phishing and man-in-the-middle attacks (e.g., FIDO2/WebAuthn, platform passkeys).</p>

<p><strong>Privilege Escalation (Outside Policy)</strong></p>

<p>A user or service gaining higher privileges through unsanctioned paths; should trigger PAM cut-off and ITDR alert.</p>

<p><strong>Provisioning / Reconciliation</strong></p>

<p>Provisioning: creating accounts/entitlements from IGA to apps. Reconciliation: pulling actual app entitlements back to detect drift.</p>

<p><strong>RBAC (Role-Based Access Control)</strong></p>

<p>Authorization based on roles that bundle entitlements by job function; often combined with ABAC.</p>

<p><strong>RACI (Responsible, Accountable, Consulted, Informed)</strong></p>

<p>A responsibility model clarifying who owns what across board, executives, council, and operations.</p>

<p><strong>Risk Appetite (Identity)</strong></p>

<p>The level of identity/access risk the board is willing to accept, used to set targets and thresholds.</p>

<p><strong>ROI (Return on Investment)</strong></p>

<p>Financial returns from IGA: hard savings (licenses, audit hours) and risk-adjusted benefits (Expected Loss Avoided).</p>

<p><strong>SCIM (System for Cross-domain Identity Management)</strong></p>

<p>Open standard that automates account provisioning/deprovisioning across SaaS applications.</p>

<p><strong>SaaS Sprawl</strong></p>

<p>Rapid growth of applications and identities (often &gt;1,800 in enterprises) that strains governance, offboarding, and SoD control.</p>

<p><strong>SAML (Security Assertion Markup Language)</strong></p>

<p>A federation standard used for SSO, especially with legacy or enterprise apps.</p>

<p><strong>SEC Cyber Disclosure Rule</strong></p>

<p>U.S. rule requiring timely disclosure of material cyber incidents and governance reporting; pushes identity oversight to the board.</p>

<p><strong>Secret / Secret Rotation</strong></p>

<p>Any credential (password, token, key) used by humans or services; rotation is the scheduled or event-driven replacement of that secret.</p>

<p><strong>Secrets MTTR</strong></p>

<p>Time from detection of leaked/compromised secrets to rotation/reissue; target ≤7 days.</p>

<p><strong>Service Account</strong></p>

<p>A non-human account used by applications or automation; must have a named owner, purpose, and rotation policy.</p>

<p><strong>Shadow IT</strong></p>

<p>Systems acquired or used outside official IT/IGA processes (e.g., direct SaaS invites); increases risk and audit scope.</p>

<p><strong>SoD (Segregation of Duties)</strong></p>

<p>Policies preventing toxic combinations of access (e.g., create vendor + approve payment) to reduce fraud/error.</p>

<p><strong>SoD Library</strong></p>

<p>A documented set of toxic-combo rules across finance, engineering, cloud ops, and data domains, seeded by audits and incidents.</p>

<p><strong>SSO (Single Sign-On)</strong></p>

<p>One identity to access many apps via federation (SAML/OIDC); enables centralized policy and telemetry.</p>

<p><strong>Supplier / Third-Party Access</strong></p>

<p>Governed access for non-employees (vendors, partners, contractors) that must follow the same IGA/PAM rules and automated offboarding.</p>

<p><strong>Tabletop Exercise (Identity/Disclosure)</strong></p>

<p>A rehearsal of incident detection, materiality decisioning, and disclosure—validates playbooks and timing (e.g., SEC 4-day rule).</p>

<p><strong>Target Coverage (e.g., SSO/SCIM ≥80%)</strong></p>

<p>A measurable adoption goal that prioritizes the highest-risk or highest-use apps first, then scales to the long tail.</p>

<p><strong>Threat Telemetry (Identity)</strong></p>

<p>Signals from IdP, IGA, PAM, and SIEM used by ITDR to detect anomalies (impossible travel, token theft, privilege surge).</p>

<p><strong>Time-to-Deprovision (TTD)</strong></p>

<p>Elapsed time from HR/vendor termination event to last access revoked; measured from system timestamps.</p>

<p><strong>Time-to-Value (TTV)</strong></p>

<p>Window (often 2–3 quarters) to show KPI improvements (e.g., orphans ↓, TTD ↓, SSO/SCIM ↑, SoD backlog ↓).</p>

<p><strong>Token Invalidation / Session Kill</strong></p>

<p>Automated response that terminates active sessions and revokes tokens after suspected compromise.</p>

<p><strong>Top 50 Critical Apps</strong></p>

<p>The prioritized application set (by blast radius and data sensitivity) used for initial control rollout, certifications, and SSO/SCIM onboarding.</p>

<p><strong>Vendor Master</strong></p>

<p>System of record for suppliers/contractors used to trigger onboarding/offboarding and to scope third-party certifications.</p>

<p><strong>WebAuthn / Passkeys</strong></p>

<p>Standards enabling passwordless or phishing-resistant authentication using device-bound or roaming authenticators.</p>

<p><strong>Zero Trust (ZTA)</strong></p>

<p>“Never trust, always verify” architecture: continuous, context-aware access decisions (identity, device, risk) with no implicit network trust.</p>

<h3 class="wp-block-heading">Resources &amp; Further Reading</h3>

<h4 class="wp-block-heading">Breach &amp; Threat Landscape</h4>

<ul class="wp-block-list">
<li><strong>Verizon 2025 Data Breach Investigations Report (DBIR) — Executive summary (PDF)</strong><strong><br /></strong><a href="https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf">https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf<br /></a>Key stats on ransomware prevalence, human element, 3rd-party involvement, and leaked secrets remediation timelines.</li>

<li><strong>Verizon 2025 DBIR (full hub)</strong><strong><br /></strong><a href="https://www.verizon.com/business/resources/reports/dbir/">https://www.verizon.com/business/resources/reports/dbir/<br /></a>Landing page with links to the full report, snapshots, and visuals.</li>

<li><strong>DBIR Highlights Infographic (PDF)</strong><strong><br /></strong><a href="https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary-infographic.pdf">https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary-infographic.pdf<br /></a>Quick scan of the year’s key trends.</li>

<li><strong>IBM Cost of a Data Breach 2025 (Main Report Page)</strong><strong><br /></strong><a href="https://www.ibm.com/reports/data-breach">https://www.ibm.com/reports/data-breach<br /></a>Summarizes global average breach cost ($4.44M) and AI oversight gaps (97% lacked AI access controls; 63% lacked AI governance policies).</li>

<li><strong>IBM Press Release (AI-specific findings)</strong><strong><br /></strong><a href="https://newsroom.ibm.com/2025-07-16-IBM-Report-Cybersecurity-AI">https://newsroom.ibm.com/2025-07-16-IBM-Report-Cybersecurity-AI<br /></a>Highlights AI-related security risks from the 2025 study.</li>
</ul>

<h4 class="wp-block-heading">Frameworks &amp; Standards</h4>

<ul class="wp-block-list">
<li><strong>NIST Cybersecurity Framework 2.0 (Full Document)</strong><strong><br /></strong><a href="https://www.nist.gov/cyberframework">https://www.nist.gov/cyberframework<br /></a>Authoritative reference for governance and identity outcomes.</li>

<li><strong>NIST CSF 2.0 — PR.AA (Identity Mgmt, Authentication &amp; Access Control)</strong><strong><br /></strong><a href="https://csf.tools/reference/nist-cybersecurity-framework/v2-0/pr/aa/">https://csf.tools/reference/nist-cybersecurity-framework/v2-0/pr/aa/<br /></a>Category page to map IGA controls.</li>

<li><strong>NIST CSF 2.0 — Govern (GV) Function</strong><strong><br /></strong><a href="https://csf.tools/reference/nist-cybersecurity-framework/v2-0/gv/">https://csf.tools/reference/nist-cybersecurity-framework/v2-0/gv/<br /></a>Board-level governance expectations and outcomes.</li>

<li><strong>NIST CSF 2.0 FAQs</strong><strong><br /></strong><a href="https://www.nist.gov/cyberframework/faqs">https://www.nist.gov/cyberframework/faqs<br /></a>Helpful clarifications for board/Audit &amp; Risk discussions.</li>
</ul>

<h4 class="wp-block-heading">Regulations &amp; Oversight</h4>

<ul class="wp-block-list">
<li><strong>DORA (Digital Operational Resilience Act) — EIOPA Overview</strong><strong><br /></strong><a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en">https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en<br /></a>What’s in scope and what boards must evidence; in force since Jan 17, 2025.</li>

<li><strong>NIS2 — European Commission Press Release</strong><strong><br /></strong><a href="https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive">https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive<br /></a>EC opened infringement procedures against 23 Member States for missed transposition.</li>

<li><strong>SEC Cybersecurity Disclosure Final Rule (Release No. 33-11216)</strong><strong><br /></strong><a href="https://www.sec.gov/files/rules/final/2023/33-11216.pdf">https://www.sec.gov/files/rules/final/2023/33-11216.pdf<br /></a>The source of the 4-business-day incident disclosure requirement (Item 1.05).</li>

<li><strong>SEC Fact Sheet — Public Company Cybersecurity Disclosures</strong><strong><br /></strong><a href="https://www.sec.gov/files/33-11216-fact-sheet.pdf">https://www.sec.gov/files/33-11216-fact-sheet.pdf<br /></a>Plain-English summary for directors and GC/IR.</li>
</ul>

<h4 class="wp-block-heading">Identity Threat Detection &amp; Response (ITDR)</h4>

<ul class="wp-block-list">
<li><strong>Microsoft: Identity Threat Detection &amp; Response (Overview)</strong><strong><br /></strong><a href="https://www.microsoft.com/en-us/security/business/solutions/identity-threat-detection-response">https://www.microsoft.com/en-us/security/business/solutions/identity-threat-detection-response<br /></a>High-level overview of ITDR.</li>

<li><strong>Microsoft Learn — Defender for Identity: ITDR Dashboard</strong><strong><br /></strong><a href="https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-daily">https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-daily<br /></a>How teams operationalize detections and MTTR.</li>

<li><strong>Microsoft Learn — What is Defender for Identity?</strong><strong><br /></strong><a href="https://learn.microsoft.com/en-us/defender-for-identity/what-is">https://learn.microsoft.com/en-us/defender-for-identity/what-is<br /></a>Productized ITDR capabilities and scope.</li>
</ul>

<h4 class="wp-block-heading">SaaS Sprawl &amp; App Portfolios</h4>

<ul class="wp-block-list">
<li><strong>Okta: Businesses at Work 2025</strong><strong><br /></strong><a href="https://www.okta.com/reports/businesses-at-work/">https://www.okta.com/reports/businesses-at-work/<br /></a>App usage trends and average app counts by org size.</li>

<li><strong>Zylo: 2025 SaaS Management Index</strong><strong><br /></strong><a href="https://zylo.com/resources/guides/saas-management-index-2025/">https://zylo.com/resources/guides/saas-management-index-2025/<br /></a>Portfolio size, category growth, and license utilization benchmarks.</li>

<li><strong>Torii Research (2025)</strong> <em>(internal)</em><em><br /></em>Enterprise portfolios average ~1,850 apps. Contact Torii for methodology and briefing deck.</li>
</ul>

<h4 class="wp-block-heading">Machine / Non-Human Identities</h4>

<p><strong>CyberArk 2025 Identity Security Landscape</strong><strong><br /></strong><a href="https://www.cyberark.com/resources/analyst-research/2025-identity-security-landscape">https://www.cyberark.com/resources/analyst-research/2025-identity-security-landscape<br /></a>Source of the “machine identities outnumber humans 82:1” statistic.</p>

<p></p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[The Enterprise IGA Blueprint: a board-ready framework with reference architecture, KPIs, and a 180-day plan to reduce identity risk and prove ROI.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/the-enterprise-iga-blueprint.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/the-enterprise-iga-blueprint.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Heading to Oktane? Here’s Every Networking Event</title><link href="https://www.toriihq.com/blog/heading-to-oktane-heres-every-networking-event" rel="alternate" type="text/html" title="Heading to Oktane? Here’s Every Networking Event" /><published>2025-09-19T00:00:00+00:00</published><updated>2025-09-19T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/heading-to-oktane-heres-every-networking-event</id><content type="html" xml:base="https://www.toriihq.com/blog/heading-to-oktane-heres-every-networking-event"><![CDATA[<p>Note: This year's [Oktane](/blog/is-oktane-worth-your-time-and-money) is being held at the&nbsp;Caesars Forum in Las Vegas, Nevada, from September 24-26, 2025.</p>

<p>The best moments at Oktane rarely happen on a slide. They occur in the in-between: the coffee line, a quick chat on the expo floor, a dinner table where notes turn into next steps.</p>

<p>If you’re heading to Las Vegas, plan as deliberately for your conversations as you do for your sessions. Who do you want to meet? What problems are you trying to solve? A bit of intention turns “nice to meet you” into “let’s ship this.”</p>

<p>To help, we put together a simple guide that maps the most useful meetups and mixers around the conference. Use it to stack your evenings with high-signal chats, compare notes with peers, and come home with contacts and commitments you’ll actually use.</p>

<table style="border-collapse:collapse;width:100%;border:1px solid #ccc;font-family:sans-serif;font-size:12px;">
  <thead>
    <tr style="background:#f7f7f7;">
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">Date</th>
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">Time (PT)</th>
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">Event</th>
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">Type</th>
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">Location</th>
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">Details</th>
      <th style="text-align:left;padding:8px;border:1px solid #ccc;">More</th>
    </tr>
  </thead>
  <tbody>

    <!-- Sep 24 -->
    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">5:30–7:30 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Torii [Networking](/blog/networking-equipment) Reception</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#059669;font-weight:600;">Reception</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Booth S8, Expo Floor</td>
      <td style="padding:8px;border:1px solid #ccc;">Visit Torii at Booth S8 for Plinko, daily Star Wars LEGO raffles, and great conversations over drinks.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFh43qn9qW8wLKSR6lZ3prW1MDjX97GWnkRW15m9C48SMSMHN3zhcGJmxrV9W3cgb4W8-89JQW61qZ1l7316TMW55y9zS5ZNsxyW9lwxg11T6T0DW548rDh5QNG-2W2hymBz6pXDcQW2RdMqG5ML410W5Q4KvV4FTbQJW72GZn-1cT7NhW1G0C9n890hkwW5hXdQM60LMjgW1k3xgW4djJllW5w9Kfb5D50cmW1wS6SY2Fwv6dW1jpXD61_kdzbW5PW0Qp5KPt1FN7mjdy_9LqlPW9cCN193QSyxlW79f6m8699TC5W36HZKz147R9xN71zX-4j6nv4W2S2hbM21K3PNN3Qt7L_PrRwSW6fxDVZ6k9vxmW6XjfgT7F_03qf4sJKHs04" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">2:45–5:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Smallstep Happy Hour</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#d97706;font-weight:600;">Happy Hour</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Booth S2, Expo Floor</td>
      <td style="padding:8px;border:1px solid #ccc;">Casual expo-floor happy hour by Smallstep. Swing by for drinks and quick chats between sessions.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFgP3qn9qW7Y8-PT6lZ3nDW5rBk8h2jvLhJW3SlHNn4590C1W9hwm9_7p9xWKW1xND2g5dpsWPW424Pt_7fjDGpVWPSHF3gBqbmW4-X5J22m3lyFW8CMbHT1BnqmLW1WNdYN88cCHZW921v4M8vcPHMW4mQFy-2NGry5W4drnQ395BmSbW8xf0j0903RzSW1Cwf1X2J_jBZW2vx7B277BXBnW4d28Fv1B1r29W1SBXLN2LmmKnW6Yb7F-2qF34WN6SM89vSr4LLW96JMX35V5xcsW6p9WF22Bcjh3W23Xcj55k6SXFVms2nq193Gq5N1VXvVl4SCYRW7lnmHP3mHJ-6W4m0LyC60ZcDxf2XH9WR04" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">6:00–10:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Whiteboard Venture Partners: Cybersecurity Leader Networking Dinner</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#b91c1c;font-weight:600;">Dinner</span></td>
      <td style="padding:8px;border:1px solid #ccc;">MGM Grand, Las Vegas</td>
      <td style="padding:8px;border:1px solid #ccc;">Exclusive dinner for CISOs and cybersecurity executives.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFfC5nXHCW5BWr2F6lZ3l0W3fdQJQ73Wy-7W6z3KyZ9gFNVdW7r3g405zYfFKW6pvNZL9gQdNmW5vFWhS67hwrsW751szG44wCSgW7kT9ST5jt3JTW23D4Sk8zQV_cW1TvcVS1H9QlmW6YL-075VZvrxVYzKxZ1VyJQbW73BCQL4hKH--Vtr9-C4Kd70HVQtrWR8DlsTtW5JX34Z91bhngW3dW74v4wf6QLVXn0pZ5WK7vFW6qKMg55t6sKbW4RjjLW5tk0LqW647J9N4BSl0TW4_dh826-6NbBMHgRWCn308VW4jLd9V3YkWNjW4q4YTg8KdmcmW5vz9Gk4RRRbpW25DjvK3pbCJwN2L8x7jT12f1W8ggSQD8wNB7KW5wPyGy8Z0gcBW4zTGg711P7VzW4V3cZs5BQ8VjW1CJZcS3mDCvLW8GXVgq5HHQTcN8Mkjj8cYRCXf52tv7604" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">6:00–10:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>WhiteSky &amp; Partners: Cybersecurity Leader Networking Dinner</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#b91c1c;font-weight:600;">Dinner</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Forum Shops at Caesars</td>
      <td style="padding:8px;border:1px solid #ccc;">Flagship dinner for CISOs: roundtables, industry insights, and new connections.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFgv3qn9qW7lCdLW6lZ3l6W19fGCQ7GHwdtW7DDSLP8Pkv8kW268gfx7MfPfkW50S4bf1cp0PqW9d2fgP8G3wMqW17N32W2-jVRHW6TRz0r4bgqfMW26gx9l9b8CSYW4nW_wh5ScYYgW60YkpZ6MxscqW50v0Wf2vJbxDW6_K5Kh8Qx7DXW8NYRWV2PJPtvVWG9rG6GVj7wW8xqgjG4MMdfXW448wfR5mjD4KW8fZgdR4JKKzFVX0BYz8DJycFW7m6jmS6qW5ppW5snv4F5QfJZ8N3fx4Z49WpRKW8BMMHC8LvTJJW6Mw1L-5RdtJhN1WkJ6Xqj2hGf3vSK0W04" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">6:30 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Tines &amp; Alchemy Dinner</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#b91c1c;font-weight:600;">Dinner</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Scarpetta, The Cosmopolitan</td>
      <td style="padding:8px;border:1px solid #ccc;">Relaxed, upscale dinner with fellow industry leaders.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFhn3qn9qW95jsWP6lZ3mcW5GxG7k2p27wnW5cZBmB1YL0n-W3RYFgm13hn-jW8Xpc6d545qhVW5qtSbY7f56JWN4p8jWqLWvRWW5TS3CJ3cR9D5W8zVrnW9gQQcpW2Kz0bP8pccCkW1dGXxL1TgHQqW5qT-tn7StVSbW8mdfTV1gCpFcW8JNGlz5XtP2CW73KQLr2NRLVJW8mfc_s5ncpBdN4rsQQ0WkPVGW6zMmMP9jjJcHW6YyG0q8bPfnyW5qCgK642N28LW8T7k5t2vBGQGW7ypX4N90MZ6JW8Z7l0k1wRFLFW8G1YLN5v0_8hW6v7ClV5qfbSqW8v3nZl3QBRSkW6pfsF94_bxNGW4vlntl2s7lypVd6tQT1n3yG3W7mKkRF2XvDnZW211sHX88cw2gdVdZK004" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">7:00–9:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Sift: Peter Luger Steak House Dinner</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#b91c1c;font-weight:600;">Dinner</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Peter Luger Steak House, Caesars Palace</td>
      <td style="padding:8px;border:1px solid #ccc;">Private dinner and networking with the Sift executive team; open to attendees.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFgP3qn9qW7Y8-PT6lZ3p-W3NR7mF4h37f9W6-lxBf2150sHW4HjCdC5KGmjDV_V51G7M4QGzW5K_vtd4803SfW1Bg0f56VdNrCW3B67rK1vPJxWW7wl6Kt4GKBSHV3sZvB8hLMmxW2lzk4z47txmdW1zqFcT2-syg5W2SDfpP24g4bpW8h3MNt6bhByyW4bzPRD2t9j09W8NTpQV4FYSyJW32tptr8mQdknW7tD35r5VRmyVW6b1r2N4m0TxxW2Z-4mW4Nq2C8W5kPjVd480_-sV9RH-f50ksL4W1c8NWQ4XkZ5YW3Y0QFw1mXKLfW2WKzdy1NfDvfW59h9vH6t_NV6W92hBJp55Lfxyf62NH8804" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>
    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 24, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">8:00–10:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Verosint, Evotek, and IDMWorks Dinner</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#b91c1c;font-weight:600;">Dinner</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Momofuku, 3708 Las Vegas Blvd S</td>
      <td style="padding:8px;border:1px solid #ccc;">Connect with peers, enjoy great food and drinks, and exchange ideas with identity &amp; security leaders.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFgv3qn9qW7lCdLW6lZ3kHW16zsKT3xk8xQW9fRqRX1mp8D5W86kySx3SVzs0W281lCb8JKMNGW1JmScH8M6MhmW1P_Kdv7llhp_VqXktH1mT2YNN720jljh3qKbVp98qv1mHfpBW69xvkN58ZRX0W7ys3LC88TQ4RW4Xsgm88QWPv3W47ZRYK2d9wtHW2-kDsG3XN64TW7MSl-Q8sTVF5N3tgjdbY3hDWW1SG20X6nppggW707hz16b1DY8W366MQq4m45XDW58Y6pc4KcN-DW6S95nb45L27tW25MWFv3x58qWW3-Ynn_2b4dZ9W6Vj5Hf8dNzQvf10f4Cs04" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <!-- Sep 25 -->
    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 25, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">4:30–6:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Okta Workflows Community Meetup</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#1d4ed8;font-weight:600;">Meetup</span></td>
      <td style="padding:8px;border:1px solid #ccc;">AmeriCAN Beer &amp; Cocktails</td>
      <td style="padding:8px;border:1px solid #ccc;">Community-driven meetup dedicated to Okta Workflows. Grab a beer and talk automation with fellow builders.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFh43qn9qW8wLKSR6lZ3nNW3wbhnB8KN0hfW4qCmSD7rcFmmW2p6G5c7x2kxxW6vs2Cl8JtdqKW8K76G69cbFPHW48dJ-67cV1GcW1SL_VV32Wjl2V45C1D6FSBTnW4LJNYP7XqBR5W2bKQry3N1xtpW2gbwJq5jpxnRW8QbVm35LXKyhW1Rc-CW1HZbZnW2G_gZ67VHDjpW2rb30r4tNHPpMpf7tDZqmT3W1qSljR1XM28FVVw29Z2npkJ2W6XXj-C1Z0MMNW2P1gDG7yxmRxW7LGGkd76QQsvW6YcrYy3psx9LW4YlNpw4wByTdW4N2KKT9c_bcgW1VT0PF5PDg_sW2zD3Sd38YcN7W6FDcSg8pD50_W7fdBw12Pm5gtf5Htqx804" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 25, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">5:30–9:00 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Ravenna Supper Club at NOBU Hotel</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#b91c1c;font-weight:600;">Dinner</span></td>
      <td style="padding:8px;border:1px solid #ccc;">NOBU Hotel, Las Vegas</td>
      <td style="padding:8px;border:1px solid #ccc;">Great food, good drinks, and a chance to connect with top industry peers in a premium setting.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFgv3qn9qW7lCdLW6lZ3kYW6NJg9122c-S9W2j9M6s5wY1svW7CGhdX97tGLyW3YQzr65pNpC3W94BscK8LXkpmW512n792xHhx6W6qPQz77GS0t4W1Gv9qb4vJKf4W6rbky359VVm6W70fzx347X02FN5MJq62tsZF5W8ghrc-2xX03CW7bmCC2963QPwW5KBCn452yx64W6xnJSJ1DL8sqW7PWpxY7xKV8qW7dbKyr2f5VQbW5Mdk2J8ZzTsQW75ZRC14XWm__W6Fj0-Q8xNB9lW2DvsDW6jKtfvW3KbPRs3LLq-3W6HzwtR2BRCJMW2J2G792C7yhPf5p6xns04" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

    <tr>
      <td style="padding:8px;border:1px solid #ccc;">Sep 25, 2025</td>
      <td style="padding:8px;border:1px solid #ccc;">5:30–7:30 PM</td>
      <td style="padding:8px;border:1px solid #ccc;"><strong>Carahsoft Networking Reception</strong></td>
      <td style="padding:8px;border:1px solid #ccc;"><span style="color:#059669;font-weight:600;">Reception</span></td>
      <td style="padding:8px;border:1px solid #ccc;">Vista Cocktail Lounge, Caesars Palace</td>
      <td style="padding:8px;border:1px solid #ccc;">Expect a crowd of IT decision-makers, vendors, and public-sector leaders at the Vista Lounge.</td>
      <td style="padding:8px;border:1px solid #ccc;">
        <a href="https://cw4Pq04.na1.hubspotlinks.com/Ctc/S+113/cw4Pq04/VWz58B8-xrXxW8m2yRF5X4m1JW4-ljtc5CCHNlN4WpFhn3qn9qW95jsWP6lZ3lQW8_qq-P8LKQfSW93_sbX57cnyTW5BKjXx8knVkLW7cC7qD7nfmp4W2THLzZ5S1DH1N4Yq8Z9NVB1RW3tS9s47gsLhYW1N1vHC1gTPHBN2K9v8fXwVXsW2pvGRG2JBVJKW6FsLty1g0SQPW2tphkR26B4V1N28f3-7HzQdDW7gjGmy4xdsRXVwL92c4dCF8gW7wtvg73fk9l1W7FXNqy2CYY29W6hJdT82MXrCKW5hjqwL7xR_x5VBS0j35jS3tgW6K9rcw7g6ClXW6SWTfy1xHhZyW6LW-w64zBCWlW3SYNwg60jq_tVV6R1q1M5d8RW9cmK5G7zmLMdW8xzw9w9bh_YmW3mSfrP4V2jL1N6kzk26tS5dMW6Zr6Sf2K8yg4f2BF68s04" target="_blank" rel="noopener">Learn more</a>
      </td>
    </tr>

  </tbody>
</table>

<p>And while you're at Oktane, be sure to swing by <strong>Torii at Booth S8</strong> for a quick demo and a real conversation about cutting SaaS waste, tightening access, and cleaning up renewals. We’ll be there with practical ideas (and yes, daily Star Wars LEGO raffles).</p>

<p>See you at Oktane 👋</p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/blog/30-of-licenses-are-idle-here-s-how-to-fix-it">30% of Licenses Are Idle—Here’’s How to Fix It</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Heading to Oktane 2025 in Las Vegas? Here's every networking event, reception, and mixer around the conference—mapped by date, time, and location.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/heading-to-oktane-heres-every-networking-event.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/heading-to-oktane-heres-every-networking-event.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Future of IGA in a Sprawling World</title><link href="https://www.toriihq.com/blog/the-future-of-iga-in-a-sprawling-world" rel="alternate" type="text/html" title="The Future of IGA in a Sprawling World" /><published>2025-09-16T00:00:00+00:00</published><updated>2025-09-16T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/the-future-of-iga-in-a-sprawling-world</id><content type="html" xml:base="https://www.toriihq.com/blog/the-future-of-iga-in-a-sprawling-world"><![CDATA[<p>Are you tracking identities, or just accounts?</p>

<p>Identity, application, and access sprawl all stem from the same problem: we can only control what we can see. It’s a familiar challenge, and it’s why we founded Torii in 2017.</p>

<p>Visibility built on purchase orders and official onboarding overlooked shadow apps, emerging AI tools, and the actual ways people work. That’s why Torii was built differently from other platforms. Rather than relying solely on the SSO to tell the story, we sifted through the shadow apps at the edges of a company’s ecosystem—the tools that dominated usage while remaining invisible to IT, procurement, and SecOps.</p>

<p>And it worked.</p>

<p>We uncovered orphaned accounts, role creep, and idle licenses that had been completely hidden from SecOps.</p>

<p>We know this because our discovery numbers revealed that most tools were drastically underestimating the reality. Per Okta in 2024: <em>“The average number of apps deployed by organizations… we’re seeing a jump to 93 this year. Large companies with ≥ 2000 employees lead the way, with an impressive average of 231 apps each.” </em>- <a href="https://www.okta.com/sites/default/files/2024-04/Okta-2024_Businesses_at_Work.pdf">source</a></p>

<p>By contrast, our <a href="/reports/saas-benchmark-annual-report-2026">SaaS Benchmarks Annual Report</a> found an average of 668 apps (7x Okta’s estimate), with large organizations (2,000–5,000 employees) averaging 1,474 apps.</p>

<p>This discrepancy isn’t an accident; it’s a testament to the importance of discovery based on usage, not just sanctioned approvals.</p>

<p>That’s long been the limitation of IGA vendors: they start with policies and approvals, but policies can only govern what’s visible. Torii began with discovery because we knew blind spots were the greatest risk. Years later, that focus has proven correct: in a SaaS-driven world, governance built on visibility and automation is the only way to keep pace with the rapid rate of change.</p>

<p><strong>The Next Acceleration</strong></p>

<p>Today, identity management is more complex than ever. AI agents are multiplying machine identities (non-human identities, or NHIs) at an alarming rate. Service accounts, API keys, and bots now outnumber humans <strong>80:1</strong>. And if you can’t spot them, you can’t govern them — and you can’t offboard them. In this world, visibility isn’t “nice to have.” It’s step zero.</p>

<p>I’ve spoken with countless security leaders who feel the pain of the legacy IGA dilemma. One CISO put it bluntly:</p>

<p><em>“I always have to rerun my quarterly reviews. Every time. We keep finding apps the IGA never knew existed. I can’t delegate sign-off when I don’t trust the inventory list, so my team babysits the process, and onboarding time suffers. We don’t need more forms. We need a higher standard of discovery.”</em></p>

<p>At Torii, we’re dedicating our discovery engine to enhancing visibility and control across identity, governance, and access.</p>

<p><strong>The Future State of Identity</strong></p>

<p>The next wave of identity governance won’t be built on forms, approvals, or quarterly attestations. It will be built on:</p>

<ul class="wp-block-list">
<li>Automatic data ingestion</li>

<li>Real-time <a href="/blog/what-is-shadow-it" title="shadow IT">shadow IT</a> discovery</li>

<li>Cross-system automation</li>

<li>Predictive and prescriptive analytics</li>
</ul>

<p>In this world, every identity—human and machine—must be visible the moment it comes into existence. Governance must be continuous and cross-platform, and machine identities must be treated with the same rigor as human ones.</p>

<p>Legacy IGA platforms are still playing catch-up. They provide permissions and insights based on SSO logs, rather than predicting actions and preventing threats in the face of continuously sprawling identities.</p>

<p><strong>Wholistic Visibility, Automated Control</strong></p>

<p>At the end of the day, visibility without control is useless, and control without visibility is blind. The future isn’t about adding another dashboard or checkbox. It’s about uniting both halves of the equation: seeing everything and acting with confidence.</p>

<p>The rise of AI and non-human identities has made this shift unavoidable. You can’t govern what you can’t see, and you can’t prove what you can’t automate. That’s why we’re building the first platform where discovery and governance live side by side.</p>

<p>That’s what we’ve built at Torii — and what we’ll continue to build — because your team deserves a tool that can keep up with your organization, no matter what the future holds.</p>

<p></p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;Chris Shuptrine&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/blog-chris.webp&quot;}</name></author><summary type="html"><![CDATA[The future of IGA: why identity governance must start with usage-based discovery as AI agents and machine identities outnumber humans 80 to 1.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/the-future-of-iga-in-a-sprawling-world.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/the-future-of-iga-in-a-sprawling-world.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">It’s Time to Measure Real Usage: Introducing Torii Research</title><link href="https://www.toriihq.com/blog/its-time-to-measure-real-usage-introducing-torii-research" rel="alternate" type="text/html" title="It’s Time to Measure Real Usage: Introducing Torii Research" /><published>2025-08-27T00:00:00+00:00</published><updated>2025-08-27T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/its-time-to-measure-real-usage-introducing-torii-research</id><content type="html" xml:base="https://www.toriihq.com/blog/its-time-to-measure-real-usage-introducing-torii-research"><![CDATA[<p>Real usage, not opinions.</p>

<p>If you make decisions about software—whether you’re in IT, finance, procurement, ops, or security—you don’t need more hype. You need a clear read on what people actually use inside real companies. That’s why we built <strong>Torii Research</strong>.</p>

<p>Check out <a href="https://www.toriiresearch.com">toriiresearch.com</a></p>

<p>Starting today, we publish monthly, live rankings of workplace apps based on anonymized usage across hundreds of organizations. </p>

<p>No surveys. No vendor spin. Just signals you can trust.</p>

<h2 class="wp-block-heading"><strong>Why Torii Research?</strong></h2>

<p>Buying software today is noisy. Vendors promote. Surveys lag. Opinions conflict. Meanwhile, your stack changes week to week, and “shadow” tools appear before anyone files a ticket.</p>

<p>Torii Research cuts through the noise. We show adoption patterns as they happen, so teams can:</p>

<ul class="wp-block-list">
<li>Spot apps that are spreading fast (and decide whether to lean in or rein them in).</li>

<li>Compare categories month over month to see what’s rising or slowing.</li>

<li>Prep renewals and evaluations with evidence, not guesswork.</li>
</ul>

<h3 class="wp-block-heading"><strong>What we publish each month</strong></h3>

<p>Under the App Adoption Index umbrella, you’ll find four reports:</p>

<ul class="wp-block-list">
<li><strong>Adoption Index Report</strong>: This monthly report ranks the top 20 applications every month as measured by the number of orgs adopting the application. Each app is compared against a 12-month rolling average, so you see who’s truly outperforming the trend—not just having a one-off spike.</li>
</ul>

<figure class="wp-block-image size-large"><img width="1024" height="538" src="/assets/images/blog/wp/2025/08/github-adoption-report-1024x538.webp" alt="Github adoption report" class="wp-image-9843" /></figure>

<ul class="wp-block-list">
<li><strong>Viral App Radar Report</strong>: This is an annual report that shows the fastest-growing apps inside companies. We combine the number of organizations that have the app, its growth rate within each organization, and a shadow-IT factor into a single score. Details live on the Methodology page. </li>
</ul>

<figure class="wp-block-image size-large"><img width="1024" height="538" src="/assets/images/blog/wp/2025/08/deepseek-viral-app-report-1024x538.webp" alt="Deepseek viral app report" class="wp-image-9842" /></figure>

<ul class="wp-block-list">
<li><strong>AI Breakout Report</strong>: The AI tools gaining real traction now. Expect churn here—new entrants appear often as teams try fresh models, agents, and workflows.</li>
</ul>

<figure class="wp-block-image size-large"><img width="1024" height="538" src="/assets/images/blog/wp/2025/08/granola-ai-app-report-1024x538.webp" alt="Granola ai app report" class="wp-image-9844" /></figure>

<ul class="wp-block-list">
<li><strong><a href="/blog/what-is-shadow-it" title="Shadow IT">Shadow IT</a> Index Report</strong>: Which tools are most often discovered outside sanctioned SSO/procurement flows. We normalize for well-known staples (e.g., AWS, Slack) so the ranking highlights true outliers, not detection quirks.</li>
</ul>

<figure class="wp-block-image size-large"><img width="1024" height="538" src="/assets/images/blog/wp/2025/08/tldv-shadow-it-report-1024x538.webp" alt="Tldv shadow it report" class="wp-image-9845" /></figure>

<p></p>

<h2 class="wp-block-heading">Aggregated, Anonymized, and Real-World</h2>

<p><strong>Anonymized by design.</strong> Our analyses use de-identified, aggregated data only. No customer, account, user, or organization is ever identified or linkable in what we analyze or publish.</p>

<p><strong>No account association—ever.</strong> Nothing in the Index ties usage back to any specific customer environment. We publish aggregate ranks, counts, and percentages, not customer- or user-level records.</p>

<p><strong>Real usage, not surveys.</strong> Signals come from anonymized workplace activity across hundreds of stacks, giving a clearer read than opinions or vendor claims.</p>

<p><strong>Rolling context.</strong> Where possible, we benchmark results against a 12-month rolling average to separate durable trends from one-off spikes.</p>

<p>Read the details: <a href="https://toriiresearch.com/methodology"><strong>Methodology &amp; FAQ</strong></a>.</p>

<h3 class="wp-block-heading"><strong>Who this helps</strong></h3>

<ul class="wp-block-list">
<li><strong>IT &amp; Security:</strong> See what’s entering the stack before it becomes risk.</li>

<li><strong>Finance &amp; Procurement:</strong> Prioritize renewals and negotiations with adoption facts.</li>

<li><strong>Ops &amp; Team Leads:</strong> Understand what your people actually use to get work done.</li>
</ul>

<h3 class="wp-block-heading"><strong>What to look for this month</strong></h3>

<p>We’re kicking off with a broad view across categories—adoption, virality, shadow IT, and AI. If you’re tracking AI specifically, watch the AI Breakout Report for fresh entrants and fast movers; new names can show up quickly as teams experiment and operationalize workflows.</p>

<h2 class="wp-block-heading"><strong>What’s next</strong></h2>

<p>We publish new rankings the first week of every month. Each drop includes highlights, charts, and links back to the full dataset and methodology.</p>

<ul class="wp-block-list">
<li>Explore the live Index: <strong><a href="https://www.toriiresearch.com">toriiresearch.com</a></strong></li>

<li>Get the monthly drop in your inbox: <strong>Subscribe on the site</strong></li>

<li>Press or research partner? Contact John Baker (john.baker@toriihq.com) to talk about early embargo access. </li>
</ul>

<p>Torii Research exists for one reason: to make SaaS decisions clearer with real usage not opinions. Let’s measure what matters.</p>

<p></p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/blog/introducing-torii-cli">Introducing the Torii CLI</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Introducing Torii Research: monthly, live rankings of workplace apps based on anonymized usage across hundreds of organizations—no surveys, no spin.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/its-time-to-measure-real-usage-introducing-torii-research.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/its-time-to-measure-real-usage-introducing-torii-research.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Evolution of SaaS Management: Torii’s Path as a Gartner® Recognized Leader</title><link href="https://www.toriihq.com/blog/the-evolution-of-saas-management-toriis-path-as-a-gartner-recognized-leader" rel="alternate" type="text/html" title="The Evolution of SaaS Management: Torii’s Path as a Gartner® Recognized Leader" /><published>2025-08-04T00:00:00+00:00</published><updated>2025-08-04T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/the-evolution-of-saas-management-toriis-path-as-a-gartner-recognized-leader</id><content type="html" xml:base="https://www.toriihq.com/blog/the-evolution-of-saas-management-toriis-path-as-a-gartner-recognized-leader"><![CDATA[<p><em>Torii CEO and Co-Founder Uri Haramati reflects on the company’s journey from a niche startup to becoming recognized as a Leader in the 2025 Gartner Magic Quadrant™ for SaaS Management Platforms. <a href="/reports/gartner-magic-quadrant-for-saas-management-platforms?utm_source=website&amp;utm_medium=&amp;utm_medium=cta&amp;utm_content=">Get a complimentary copy of the report today</a></em>.</p>

<p>Torii was born from a problem. Software was shifting to the cloud, and companies were not ready for the transition. The growth of SaaS meant that employees were adding new apps at record speed without the approval of procurement. These unsanctioned apps (<a href="/blog/what-is-shadow-it" title="shadow IT">shadow IT</a>) were adding tasks to already overworked IT teams. Onboarding, offboarding, spend management, and more, these legacy processes broke down under the weight of SaaS “busywork.” That’s why Torii was born. To address the problem at the heart of everything—unmanaged applications.&nbsp;</p>

<p>I experienced the headaches firsthand. My background in leadership and entrepreneurship meant that I was always testing new apps and dealing with the consequences, especially with a lean team. The systemic issues were painful, and manual management was impossible. That was when I realized that the only way out of the mess was through a unifying technology, one software designed to allow IT to see, manage, and automate all the software in their ecosystem. That was when I resolved to build Torii.</p>

<h2 class="wp-block-heading">Why “SaaS Management” mattered</h2>

<p>In 2016, my co-founders, Tal and Uri, and I spent weeks discussing the symptoms of managing SaaS.&nbsp;</p>

<ul class="wp-block-list">
<li>Wasted money</li>

<li>Security risks</li>

<li>Broken operations</li>

<li>Bad employee experience</li>
</ul>

<p>The issue was that different teams within an organization had different priorities, and we had to decide if we would focus on a subset of issues or stick to our original vision of “one software to manage all software.” We weren’t the only team working on this either. Many vendors, some which are still around, were also trying to tackle the problem of SaaS Management by addressing specific symptoms.&nbsp;</p>

<figure class="wp-block-image"><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcT47TT8YVcckrth71a_J_vclE0ob0D6SilxP7tM2ufZEOwZAKLahZzPVSc4z0iCAcvbrMZzFhotE5MY4t9-CtaZ_0m5msIWfldIGlEZaAkrE7Jb2NnZ3JshYF04fMwqF07JcQERb7rDUuXsNHI3mUKnRon?key=Wv9Fd32_5f8Ih_LLnQpAgw" alt="AD 4nXcT47TT8YVcckrth71a J vclE0ob0D6SilxP7tM2ufZEOwZAKLahZzPVSc4z0iCAcvbrMZzFhotE5MY4t9 CtaZ 0m5msIWfldIGlEZaAkrE7Jb2NnZ3JshYF04fMwqF07JcQERb7rDUuXsNHI3mUKnRon?key=Wv9Fd32 5f8Ih LLnQpAgw" /></figure>

<p><em>A Slack exchange between me and my co-founders about how to pitch the idea of Torii to investors. This was when we started to identify SaaS Management as the “north star” of the solution.&nbsp;</em></p>

<p>After hundreds of conversations with IT leaders, founders, and technologists—we doubled down on SaaS Management. That decision felt risky at the time. We were focusing on unmanaged apps, a problem that many organizations weren’t aware of instead of the more obvious symptoms of spend and security.&nbsp;</p>

<p>I thought about it like this. If I were a doctor and someone came into my office complaining of a series of symptoms that all sprung up at the same time—what would be my duty? I could prescribe a host of medicines to address each individual symptom <em>or </em>I could do the hard work of finding the underlying source of the symptoms. In our mind, this was the only way to proceed. But, this meant that we had to build our platform on a foundation of accurate data and robust automation and in order for that to work, we needed to focus on organizations with a large number of cloud apps.&nbsp;</p>

<h2 class="wp-block-heading">From nice to have to necessity</h2>

<p>In 2020, everything turned upside down. The pandemic struck, putting us on lockdown, and challenging companies to rethink what the workplace was. As knowledge workers stayed home, companies started adding more and more SaaS apps to their ecosystem and overnight, cloud apps went from “nice to have” to a necessity. As SaaS became the new default form of software, the management of those apps became necessary as well. Companies pushed legacy processes around budgets, procurement, and security to the side as they focused on survival at any cost. Even today, we are still dealing with the consequences of that era, organizations are still rationalizing their apps, license seats, and contracts.&nbsp;</p>

<p>As these changes rippled through the modern workplace, I&amp;O leaders began to look for insight and guidance about the implementation of a <a href="/blog/saas-management-platform" title="SaaS Management Platform">SaaS Management Platform</a>.&nbsp;</p>

<h2 class="wp-block-heading">SaaS Management today</h2>

<p>In August of 2025, Gartner® published its Magic Quadrant™️ for SaaS Management Platforms which recognized Torii as a Leader. The report encourages I&amp;O leaders to manage SaaS apps to mitigate common [problems](/blog/saas-management-for-todays-enterprise). From the report: </p>

<blockquote class="wp-block-quote">
<p>“<em>SaaS management platforms empower organizations to address the </em><strong><em>compounding challenges of SaaS application usage across the business that lead to</em></strong><em> overspend, elevated risk, lack of visibility and contract sprawl. This inaugural Magic Quadrant helps I&amp;O leaders identify suitable vendors.”</em></p>
</blockquote>

<p>The average organization has over 600 apps in its organization, most of which are shadow IT. Without a way to centrally manage SaaS, problems will get worse, not better. According to the Report: </p>

<ul class="wp-block-list">
<li><em>"Through 2027, organizations that fail to centrally manage SaaS life cycles will remain five<br />times more susceptible to a cyberincident or data loss, due to incomplete visibility into<br />SaaS usage and configuration."</em></li>

<li><em>"Through 2027, organizations that fail to attain centralized visibility and coordinate SaaS<br />life cycles will overspend on SaaS by at least 25%, due to unused entitlements and<br />unnecessary, overlapping tools."</em></li>

<li><em>"Through 2028, over 70% of organizations will centralize SaaS application management<br />using a SaaS management platform (SMP), an increase from less than 30% in 2025."</em></li>
</ul>

<h2 class="wp-block-heading">Next Steps: Adopt an SMP that is right for you</h2>

<p>The journey of building a SaaS Management Platform like Torii has been both challenging and rewarding. It started as a solution to a hidden problem. But today, Torii is a crucial component of modern IT infrastructure. We believe the recognition of Torii as a Leader in the Gartner Magic [Quadrant for SaaS Management](/blog/torii-named-a-leader-in-first-ever-gartner-magic-quadrant-for-saas-management-platforms) Platforms validates our decision eight years ago to address the root cause of issues like overspend, security risks, and lack of visibility—unmanaged SaaS applications.</p>

<p>But for you, the most crucial step is the next one.&nbsp;</p>

<p>SaaS Management is no longer optional. The best time to manage your cloud apps was years ago, but the second best time is now. If you’re ready to take the next step and learn about the SMPs available, you can get a complimentary copy of the Gartner Magic Quadrant. It’s full of excellent analysis and unbiased evaluation of vendors in the space.</p>

<p class="has-small-font-size">Gartner, Magic Quadrant for SaaS Management Platforms, Tom Cipolla, et al, 30 July 2025. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.<br />Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.<br />This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Torii.</p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/blog/busting-the-4-big-myths-about-it-management">Busting The 4 Big Myths About IT Management</a></li>
  <li><a href="/blog/it-management">What is IT Management?</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;Chris Shuptrine&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/blog-chris.webp&quot;}</name></author><summary type="html"><![CDATA[Torii CEO Uri Haramati traces the evolution of SaaS management—from niche startup to Leader in the 2025 Gartner Magic Quadrant for SaaS Management.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/the-evolution-of-saas-management-toriis-path-as-a-gartner-recognized-leader.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/the-evolution-of-saas-management-toriis-path-as-a-gartner-recognized-leader.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry></feed>