<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.2.2">Jekyll</generator><link href="https://www.toriihq.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://www.toriihq.com/" rel="alternate" type="text/html" /><updated>2026-09-15T21:26:07+00:00</updated><id>https://www.toriihq.com/feed.xml</id><title type="html">Torii — SaaS Management Platform</title><subtitle>Find hidden apps, cut SaaS waste, and automate the rest</subtitle><entry><title type="html">Google shipped hard monthly spend caps for AI agents</title><link href="https://www.toriihq.com/blog/2637-05-google-shipped-hard-monthly-spend-caps-for-ai-agents-the-5th" rel="alternate" type="text/html" title="Google shipped hard monthly spend caps for AI agents" /><published>2026-09-02T00:00:00+00:00</published><updated>2026-09-02T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/2637-05-google-shipped-hard-monthly-spend-caps-for-ai-agents-the-5th</id><content type="html" xml:base="https://www.toriihq.com/blog/2637-05-google-shipped-hard-monthly-spend-caps-for-ai-agents-the-5th"><![CDATA[<p>This summer, the companies that sell you AI tokens shipped spend cap after spend cap. Five of them, same season, same handful of vendors.</p>

<p>Not a coordinated announcement. Not one big FinOps push. A steady drip of native cost controls, one vendor after another, all landing between June and August. Once you notice the rhythm, the rhythm is the story.</p>

<h3 id="whos-building-the-meter">Who’s building the meter?</h3>

<p>The people who sell the tokens.</p>

<p>Count the native spend controls across the major model-and-cloud vendor surfaces this summer, one per surface, and you get five. OpenAI added them to ChatGPT Enterprise on Jun 18. Anthropic shipped an Enterprise Spend Limits API for Claude on Jul 2. OpenAI brought hard project and org limits back to its API on Jul 22. AWS added cost controls to Bedrock AgentCore on Aug 6. Google shipped hard monthly spend caps to Gemini Enterprise on Aug 26.</p>

<p>Five, from Jun 18 to Aug 26. About ten weeks. Same season, same handful.</p>

<p>The exact count is soft, and I’ll say so. The inclusion rule is strict: one native spend control per major model-or-cloud vendor surface. Loosen it and the number goes up, not down. Anthropic shipped a session-budget control too. GitHub Copilot added budgets. Cloudflare’s AI Gateway has spend controls of its own. Count those and the cadence gets faster, never slower.</p>

<p>So the ordinal is a footnote. The cadence is the fact: the companies whose revenue is the meter running spent the summer building the switch to cap it.</p>

<h3 id="are-these-even-the-same-kind-of-control">Are these even the same kind of control?</h3>

<p>No. There are two philosophies.</p>

<p>Anthropic and AWS bound a <em>run</em>. The limit sits on a session or a per-agent execution, and it fires when a single agent burns through its budget mid-task. OpenAI and Google bound a <em>billing period</em>. The limit is a monthly cap on the project or org, and it fires when the bill for the month crosses a line.</p>

<p>Bound-the-run versus bound-the-billing-period. Same anxiety, an agent doing something expensive when nobody’s watching, and two bets on where to put the brake. One vendor thinks the danger is a single runaway execution. The other thinks it’s the slow accumulation over thirty days.</p>

<p>What both bets share: each brake stops at the vendor’s own wall. AWS can cap a Bedrock run because AWS can see the Bedrock run. It cannot see the Gemini one. Google can cap a Gemini project because Google bills it, and has no idea what that same team spends on Claude.</p>

<h3 id="did-all-five-vendors-freshly-build-these">Did all five vendors freshly build these?</h3>

<p>Not quite. At least two are re-ships.</p>

<p>This is the tell worth slowing down on. OpenAI’s Jul 22 API control isn’t new. OpenAI had hard API spend caps, removed them earlier in 2026, and brought them back on Jul 22. Its Jun 18 ChatGPT Enterprise control isn’t net-new either. It’s a migration of an existing weekly limit to a monthly one. Anthropic, AWS, and Google are genuinely net-new to those surfaces. OpenAI, on two of the five, is adjusting a meter it already had.</p>

<p>That’s the part a pundit reading only the August release notes can’t write. Picture OpenAI shipping the hard cap, quietly removing it earlier in 2026, then reinstalling it in July and taking a bow for the new safety feature. A seller that can pull a hard spend cap and put it back whenever it suits the billing is telling you something plain: the meter isn’t a fixed customer-protection feature. It’s a dial the seller turns toward its own billing interest, on its own schedule. Which is exactly why a seller-built meter can’t be the buyer’s number. The buyer doesn’t control when it exists.</p>

<h3 id="so-the-meter-builders-are-marginal-players-you-can-ignore">So the meter-builders are marginal players you can ignore?</h3>

<p>The opposite. They’re already everywhere.</p>

<p>The same handful shipping these caps already sit in nearly every stack we see. OpenAI and Anthropic each show up in about 96% of those stacks, Gemini in about 82%, detected via SSO, finance, and browser extension, so read those as detection floors, not exact usage.</p>

<p>One clause of daylight, because it matters. That presence is of the <em>brand</em>. We detect that OpenAI, Anthropic, and Google are in the building. We are not detecting use of the specific agent or API surface each cap governs, the Bedrock AgentCore workload, the Vertex or Gemini Enterprise project, the raw OpenAI API. Presence is not proof the cap already binds anything. It establishes the one thing the argument needs: the vendors writing the meters are not niche. They’re the default.</p>

<p>And when the top work surface joins the cadence, the signal is loudest. Google Workspace is already the #2 app in our Adoption Index, ahead of Slack, Atlassian, and Microsoft 365, and that’s behavioral adoption, where work happens, not a spend ranking. So when <em>that</em> vendor ships a spend cap, it’s the surface most of your people already live on adding a meter.</p>

<h3 id="whats-the-actual-problem-with-five-good-meters">What’s the actual problem with five good meters?</h3>

<p>They’re bounded. Every one of them.</p>

<p>This is the whole thing, and it’s an argument from how the controls are scoped, not a number we measured. Each of the five caps is scoped to something the vendor bills: a project, a billing account, an API key, an org. That’s correct engineering. A cloud vendor <em>should</em> let you cap a project. Nobody built a bad meter here.</p>

<p>But name the dichotomy the scoping creates. Per-vendor wall versus cross-vendor question. Every shipped control is bounded by one vendor’s billing surface. The buyer’s real question crosses all of them and lands on a person: what does <em>this employee</em> cost across OpenAI, Claude, and Gemini, added up. None of the five meters can answer that. None can see the other two, and none was built to join spend to a named human.</p>

<p>I’ll concede the near miss, because it’s real. Cross-vendor cost <em>aggregation</em> already exists. CloudZero, Vantage, and Finout roll up multi-vendor spend, typically drawing on the vendors’ own Cost APIs. What none of those produce, and what the key-, project-, and account-scoped meters structurally can’t produce, is the join to the individual: what one named person costs across every model they touch. The aggregators sum accounts. The meters cap projects. The gap is specifically the human.</p>

<p>And a buyer went looking in exactly that gap. One prospective buyer deprioritized the entire SaaS-governance category to ask us a single thing: what does each employee cost in OpenAI, Claude, and Gemini tokens, across all three. Five vendors spent the summer shipping per-vendor meters. A buyer walked in asking for the number that lives between them.</p>

<h3 id="so-who-wins">So who wins?</h3>

<p>Genuinely unresolved.</p>

<p>Two candidate units of account, and I don’t know which one takes over. There’s the vendor’s per-project billing meter: native, scoped, shipping fast, five deep in one summer. And there’s a cross-vendor, per-employee view of what each person costs across every model they touch, which nobody ships natively and which the buyer keeps asking for.</p>

<p>Maybe the per-project meter is enough. For a lot of orgs it might be, and the cross-vendor per-employee view stays a nice-to-have that never becomes the unit anyone budgets against. Or maybe the number that decides headcount and tooling is the one that crosses every wall and lands on a person, and the vendor meters end up as five inputs to a join none of them will ever make.</p>

<p>The vendors have placed their bet: the meter they own, scoped to the surface they bill. The open question is whether that’s the unit the buyer ends up managing by. And if it isn’t, who ends up owning the number that crosses all five walls.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[This summer, the companies that sell you AI tokens shipped spend cap after spend cap. Five of them, same season, same handful of vendors.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/articles/2637-05-google-shipped-hard-monthly-spend-caps-for-ai-agents-the-5th.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/articles/2637-05-google-shipped-hard-monthly-spend-caps-for-ai-agents-the-5th.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Your Offboarding Is Finished. The Bot They Built Is Still Running.</title><link href="https://www.toriihq.com/blog/non-human-identity-sprawl" rel="alternate" type="text/html" title="Your Offboarding Is Finished. The Bot They Built Is Still Running." /><published>2026-08-19T00:00:00+00:00</published><updated>2026-08-19T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/non-human-identity-sprawl</id><content type="html" xml:base="https://www.toriihq.com/blog/non-human-identity-sprawl"><![CDATA[<h3 id="you-revoked-their-sso-the-bot-they-built-is-still-running">You revoked their SSO. The bot they built is still running.</h3>

<p>An engineer leaves. IT does what it always does: disables the account in Okta, pulls the SSO grants, reclaims the laptop. On paper, the person is gone.</p>

<p>In practice, the Slack bot they wired to a shared channel is still posting. The Zapier connection they authorized still moves data between two apps every night. The AI agent they handed a service account to still has its access, and nobody remembers it exists.</p>

<p>None of those were tied to their SSO login. They were separate credentials, OAuth grants, integration tokens, an agent’s key, created directly against the apps. Deprovisioning a person doesn’t touch them. So the tokens sit there. No owner, no review, no expiry. Live.</p>

<p>That is the gap offboarding misses. You can revoke a person cleanly and still leave a trail of working machine identities behind them. The customers we hear from already have names for what that produces:</p>

<p><i>“orphaned after projects end,”</i></p>

<p><i>“service account sprawl,”</i></p>

<p><i>“invisible, ungoverned, and overprivileged”.</i></p>

<h3 id="how-bad-is-the-sprawl-really">How bad is the sprawl, really?</h3>

<p>Bad, and worse than anyone can agree on.</p>

<p>Non-human identities now outnumber human ones by a wide margin, and the count is climbing fast. But the exact ratio depends entirely on what you measure, and where. Different vendors offer widely different counts on how many NHIs are running through your org:</p>

<figure class="wp-block-image"><img src="/assets/images/articles/reported-nhi-count.webp" alt="Reported non-human identity to human ratios by vendor, ranging from 17:1 to 144:1" /></figure>

<p>So the number is contested. Different vendors measure different environments with different methods, and the spread, 17:1 to 144:1 depending on the study, reflects that, not sloppiness. What none of them argue about is the direction. The non-human surface is now the larger one, AI agents are its fastest-growing slice, and it is compounding. Read 144:1 as the ceiling of a range, not a consensus.</p>

<h3 id="so-why-cant-your-sso-see-any-of-it">So why can’t your SSO see any of it?</h3>

<p>Because it was built to find people, and none of these are people.</p>

<p>Your SSO and IdP are built around people. They govern who a human is, what groups they belong to, what they can log into. Most identity tooling does that work, and does it well. That part is genuinely hard.</p>

<p>Here’s where it gets uncomfortable. It’s a human-identity model in a world that has gone non-human. When CyberArk surveyed the field, 88% of organizations defined only human users as privileged. The machine identities, the OAuth grant one SaaS app holds against another, the integration token, the Slack bot, the MCP server an agent runs through, never touch the IdP at all. They were provisioned directly, app to app. So when the IdP deprovisions a person, it reaches everything that person logged into and nothing they authorized on the side.</p>

<p>The industry conversation points the wrong way, too. Most writing about machine identity is cloud- and infrastructure-first: workload identity, Active Directory service accounts, secrets in a CI pipeline. That matters. But it steps right past the SaaS-app layer, the OAuth grants, integration tokens, bot tokens, and agents that live between the apps your company actually runs on. That layer is where a departing employee’s leftovers pile up. It is also the one nobody has claimed.</p>

<h3 id="what-does-governing-these-things-at-the-app-layer-actually-take">What does governing these things at the app layer actually take?</h3>

<p>The same three things you already give a human account.</p>

<p>None of this needs another vault or another scanner. Treat every token and agent at the SaaS-app layer the way you already treat a person: give it an owner, watch it for staleness, wire it into offboarding.</p>

<p><strong>Owner.</strong> The first question about any machine identity is the one nobody can usually answer: who created this, and who is accountable for it now? A token with no owner is a “decommission candidate,” in a customer’s own words. Attach a human owner to each grant and agent, and an anonymous credential becomes something you can review.</p>

<p><strong>Staleness.</strong> Is it still doing anything? “Hasn’t authenticated in six months but still has privileged access” is how one practitioner named the exact failure. Last-use data sorts the tokens that earn their access from the ones that are pure standing risk.</p>

<p><strong>Offboarding trigger.</strong> When a person leaves, their machine identities should surface as part of the same offboarding, the bot they built, the token they authorized, the agent they stood up. Then those credentials get a decision, instead of defaulting to “left running.”</p>

<p>This is where Torii sits. Our SaaS discovery already maps the app-to-app graph; it can see the OAuth grants and integration tokens between apps and attach a human owner and an offboarding trigger to each one. Visibility, ownership, and a trigger at the point of offboarding.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[When an engineer leaves, IT revokes their SSO — but the Slack bot they wired up, the Zapier connection they authorized, and the AI agent they gave a service…]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/articles/runaway-nhi.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/articles/runaway-nhi.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Productiv Deleted Your Data. Here’s How to Rebuild Your SaaS Estate From Zero.</title><link href="https://www.toriihq.com/blog/productiv-deleted-your-data-rebuild-saas-estate-from-zero" rel="alternate" type="text/html" title="Productiv Deleted Your Data. Here’s How to Rebuild Your SaaS Estate From Zero." /><published>2026-08-11T00:00:00+00:00</published><updated>2026-08-11T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/productiv-deleted-your-data-rebuild-saas-estate-from-zero</id><content type="html" xml:base="https://www.toriihq.com/blog/productiv-deleted-your-data-rebuild-saas-estate-from-zero"><![CDATA[<p>Productiv announced its shutdown on August 2, 2026, and named August 6 as the sunset date. Operations did cease on August 6. But customer access to the platform ended on August 5 — a day earlier than announced, which cost some admins their last planned export window.</p>

<p>The data itself is not sitting in cold storage somewhere. Productiv’s site states that “all production systems, data stores, and backups have been permanently and securely destroyed. No customer data has been retained.” Productiv has never given a business reason for the shutdown.</p>

<p>One clarification, since the situation has been described loosely elsewhere: this was not a conventional bankruptcy. The public record shows that, effective June 25, 2026, Productiv, Inc. made a General Assignment for the Benefit of Creditors to PFS Productiv Liquidation LLC under California law, a state-law wind-down handled outside bankruptcy court in which a company’s assets pass to an assignee who liquidates them for creditors. Claims are being administered by Stretto, Inc. at <a href="https://cases.stretto.com/Productiv" rel="nofollow noopener" target="_blank">cases.stretto.com/Productiv</a>, with a filing deadline of December 22, 2026. If you think you have a claim, that deadline is the one to calendar. <span style="font-size:0.85em;">Source: the Stretto case page, which lists the assignor, assignee, effective date, governing law, and claims bar date.</span></p>

<p>Worth saying plainly: this was a hard week for the people who built Productiv, not just the people who bought it. A team lost their jobs, and a lot of admins lost a tool they genuinely liked and had staked internal credibility on.</p>

<p>If you’re one of those admins, the export advice everyone published in the first week — <a href="/blog/why-did-productiv-shut-down">including ours</a> — is now useless to you. So here is the version that still works: what’s actually gone, what you can rebuild, and how to get most of it back in 30 days.</p>

<h2 id="what-you-lost-versus-what-you-can-rebuild">What you lost versus what you can rebuild</h2>

<p>Be precise about this before you promise anything to your VP, because the two halves have very different timelines.</p>

<p><strong>Gone for good.</strong> Historical engagement and utilization trends — the multi-year record of who logged into what, how often, and how that curve moved. In-platform notes, tags, saved views, and workflow configuration. Your license-optimization baselines: the “we reclaimed 340 seats last year” numbers that justified the tool. Any benchmark data that was Productiv’s own, not yours. None of this exists anywhere. There is no backup, no escrow, no partner copy.</p>

<p><strong>Recoverable.</strong> Your application inventory. Your annual and monthly software spend. Contract terms, renewal dates, and notice periods. App owners and business sponsors. Purchased license counts. Vendor contacts. All of it lives in systems you still control — your identity provider, your finance stack, your contract repository, your endpoints. Productiv aggregated that data; it did not originate it.</p>

<p>That distinction matters commercially, too. If a vendor offers to “restore” or “recover” your Productiv usage history, they are selling you something that cannot be delivered. The honest offer is help reconstructing the recoverable half faster, and starting a new engagement baseline today.</p>

<h2 id="the-four-sources-that-get-you-to-90-coverage">The four sources that get you to ~90% coverage</h2>

<p>This is the core of the work. Four pulls, done in parallel by whoever owns each system, will reconstruct most of a mid-market or enterprise SaaS estate. Assign owners before you start — this stalls when one person tries to do all four.</p>

<ol>
  <li><strong>Your identity provider.</strong> Okta’s System Log, Entra ID sign-in logs, or the Google Workspace audit log will give you every app users authenticated into, with unique user counts and last-sign-in dates. In Okta, export the app list with assignment counts and pair it with 90 days of sign-in events; in Entra, pull the enterprise applications list plus sign-in logs. This is your fastest path to the sanctioned app list and often takes an afternoon. What it misses: anything not behind SSO. Departmental tools bought on a card, free tiers, tools with local logins, and most of the AI apps that arrived in the last 18 months. Shadow IT is defined by its absence from this list.</li>
  <li><strong>Your finance systems.</strong> Pull 24 months of vendor-level spend from the AP ledger (NetSuite, Coupa, or your ERP) plus corporate card and expense feeds (Ramp, Brex, Expensify). Filter on software and subscription GL codes, but also scan uncoded vendors — that’s where the surprises are. This is your only real source for spend, and your best source for apps IT never knew existed. The obstacle is vendor naming: card descriptors like ADOBE *ACROPRO, resellers and marketplaces (AWS Marketplace, SHI, Insight) that mask the actual product, and parent-brand line items that cover several apps at once. Budget real time for normalization; it’s the least glamorous and most valuable hour of this project.</li>
  <li><strong>Contracts and email.</strong> Your contract repository, DocuSign’s completed-envelope list, and the procurement and AP inboxes together reconstruct renewal dates, term lengths, auto-renewal notice windows, and purchased seat counts. Search the shared drive and inboxes for “order form,” “auto-renew,” “renewal notice,” and “MSA.” What it misses: month-to-month and click-through agreements, which usually have no paper at all and show up only in the finance pull.</li>
  <li><strong>Endpoint and browser signals.</strong> OAuth grants (Google Workspace third-party apps, Entra enterprise app consents), browser extension inventories from your MDM, and installed-application reports from Intune, Jamf, or Kandji. This is the layer that catches free and freemium tools — the AI assistants, the note-takers, the design tools — that never touch finance or SSO. It’s noisy and needs filtering, but it’s the only source that sees them.</li>
</ol>

<p>Then de-duplicate, and expect it to take longer than you think. The same app will appear in three sources under three names. Normalize on the vendor’s root domain rather than the display name, decide up front whether a suite counts as one app or several, and keep a single alias column so Atlassian, Jira, and JIRA SOFTWARE-ANNUAL collapse to one row. Do this once, deliberately, or you’ll ship an inventory with a 15% inflation rate and lose the room’s trust on the first review.</p>

<p>This four-source pull is what automated discovery does continuously rather than once.</p>

<aside class="art-cta art-cta--inline">
  <p class="art-cta__eyebrow">If a manual rebuild is not realistic</p>
  <p class="art-cta__title">Torii pulls the same four sources and keeps the inventory current</p>
  <p class="art-cta__body">Connect your identity provider and your finance system, and Torii reconstructs the app inventory, spend, contracts, owners, and license counts described above, then keeps collecting so your new baseline starts today. No agents, no services engagement, no implementation fee. <a href="/alternatives/productiv">See how Torii maps to what Productiv did</a>, or add your work email for a personalized demo on your own stack.</p>
  




<style>
  /* Functional CSS — always emitted; the JS depends on .spinner / .is-hidden */
  .hs-email-form .spinner {
    border: 2px solid #f3f3f3;
    border-top: 2px solid #3498db;
    border-radius: 50%;
    width: 18px;
    height: 18px;
    animation: hs-email-spin 1s linear infinite;
    display: inline-block;
    vertical-align: middle;
    margin-left: 10px;
  }
  @keyframes hs-email-spin {
    0% { transform: rotate(0deg); }
    100% { transform: rotate(360deg); }
  }
  .hs-email-form .is-hidden { display: none; }
  .hs-email-form .form-error {
    color: #ef4444;
    font-size: 0.875rem;
    margin-top: 0.5rem;
  }
</style>

<style>
  /* Presentational CSS — skipped when bare=true */
  .hs-email-form {
    background-color: #ffffff;
    border-radius: 1rem;
    transform-origin: top;
    width: 100%;
    margin-left: auto;
    margin-right: auto;
  }
  .hs-email-form--boxed {
    border: 1px solid #3b82f6;
    padding: 2rem 1.5rem 1rem;
    box-shadow: 0 4px 6px -1px rgba(0, 0, 0, 0.1), 0 2px 4px -1px rgba(0, 0, 0, 0.06);
    max-width: 36rem;
  }
  .hs-email-form--plain {
    max-width: 42rem;
  }

  .hs-email-form .form-fields-container { display: flex; flex-direction: column; }
  .hs-email-form .form-row-wrapper { display: flex; gap: 0.75rem; align-items: flex-start; }

  .hs-email-form .form-input-email {
    height: 3rem;
    flex-grow: 1;
    padding-left: 1rem;
    padding-right: 1rem;
    min-width: 0;
    border: 1px solid #d1d5db;
    border-radius: 0.5rem;
    box-sizing: border-box;
  }
  .hs-email-form .form-input-email:focus { outline: none; border-color: #3b82f6; }

  .hs-email-form .form-submit-button {
    height: 3rem;
    padding-left: 1.25rem;
    padding-right: 1.25rem;
    font-weight: 600;
    color: #1e2e4a;
    background-color: #ffffff;
    border-radius: 0.5rem;
    border: 1px solid #c4c9d5;
    box-shadow: 0 4px 6px -1px rgba(0, 0, 0, 0.1), 0 2px 4px -1px rgba(0, 0, 0, 0.06);
    transition-property: color, background-color, border-color;
    transition-duration: 150ms;
    display: flex;
    align-items: center;
    justify-content: center;
    white-space: nowrap;
    cursor: pointer;
    font-size: 16px !important;
    outline: none;
    flex-shrink: 0;
  }
  .hs-email-form .form-submit-button:hover { background-color: #0077ff; color: #ffffff; }
  .hs-email-form .form-submit-button:focus,
  .hs-email-form .form-submit-button:active { outline: none; }

  @media (max-width: 640px) {
    .hs-email-form .form-row-wrapper { flex-direction: column; gap: 0.75rem; }
    .hs-email-form .form-submit-button { width: 100%; }
  }
</style>


<script>
(function () {
  // Init-once guard: safe even if this block is emitted more than once.
  if (window.__toriiHsEmailFormInit) return;
  window.__toriiHsEmailFormInit = true;

  var ENRICH_URL = "https://torii--hubspot-assign-assignserver-serve.modal.run/enrich";
  var DEFAULT_REDIRECT = "/book-demo";
  var PORTAL_ID = "4265482";
  var HS_FORM_ID = "7e08202e-6b18-47a0-91ef-385cc6f58bba";

  var commonPersonalDomains = [
    "mail.com", "mac.com", "inbox.com", "alice.it", "tin.it", "virgilio.it", "libero.it",
    "live.co.uk", "live.fr", "live.it", "rediff.com", "indiatimes.com", "mail.ru",
    "bk.ru", "list.ru", "inbox.ru", "email.com", "usa.com", "europe.com", "asia.com", "africamail.com"
  ];

  var bannedDomains = new Set([
    'gmail', 'yahoo', 'outlook', 'hotmail', 'aol', 'icloud', 'protonmail', 'zoho',
    'gmx', 'yandex', 'msn', 'comcast', 'verizon', 'cox', 'sbcglobal', 'ymail', 'rocketmail', 'fastmail',
    'tutanota', 'hushmail', 'optonline', 'bellsouth', 'earthlink', 'shaw', 'rogers', 'qq', 'naver', 'hanmail', 'daum', '163', '126', 'yeah',
    'lycos', 'bigpond', 'btinternet', 'blueyonder', 'ntlworld', 'talktalk', 'wanadoo', 't-online', 'laposte',
    'seznam', 'centrum', 'volny', 'sapo', 'terra', 'netcabo', 'gawab', 'rediffmail', 'proton', "baidu", "sina", "21cn", "139", "freenet", "telus", "charter", "fronter", "centurylink", "windstream",
    'mailinator', 'tempmail', '10minutemail', 'guerrillamail', 'throwawaymail', 'getnada', 'yopmail', 'trashmail', 'maildrop', 'moakt', 'fakeinbox', 'mailnesia',
    'mintemail', 'spambog', 'dispostable', 'spamgourmet', 'emailondeck', 'anonaddy', 'inboxkitten', 'burnermail', 'sharklasers', 'spam4.me', 'mytempemail', "temp-mail", "mohmal", "dropmail", "getairmail"
  ]);

  function getUTMParams() {
    var p = new URLSearchParams(window.location.search);
    return {
      utm_source: p.get('utm_source') || '',
      utm_medium: p.get('utm_medium') || '',
      utm_content: p.get('utm_content') || '',
      utm_campaign: p.get('utm_campaign') || ''
    };
  }
  function isValidEmailFormat(email) { return /^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(email); }
  function clean(v) { return v && v.trim() !== "" ? v.trim() : null; }
  function containsBannedKeyword(email) {
    var domain = email.split('@')[1] ? email.split('@')[1].split('.')[0].toLowerCase() : '';
    return bannedDomains.has(domain);
  }
  function isWorkEmail(email) {
    var parts = email.split('@');
    if (parts.length !== 2) return false;
    return commonPersonalDomains.indexOf(parts[1].toLowerCase()) === -1;
  }
  function getHubSpotUserToken() {
    var cookies = document.cookie.split('; ');
    var find = function (prefix) {
      var row = cookies.find(function (r) { return r.indexOf(prefix) === 0; });
      return row ? row.split('=')[1] : null;
    };
    return find('hubspotutk=') || find('__hstc=') || null;
  }

  // Wire ONE form, using elements found relative to that form — no global IDs.
  function wire(form) {
    if (form.dataset.hsWired) return;   // don't double-bind
    form.dataset.hsWired = '1';

    var isSubmitting = false;           // per-form, not shared
    var spinner = form.querySelector('.spinner');
    var errorEl = form.querySelector('.form-error');
    var redirect = form.getAttribute('data-redirect') || DEFAULT_REDIRECT;

    form.addEventListener('submit', function (e) {
      e.preventDefault();
      if (isSubmitting) return;
      isSubmitting = true;

      var email = form.email.value.trim();
      if (errorEl) errorEl.textContent = "";
      if (spinner) spinner.classList.remove("is-hidden");

      function fail(msg) {
        if (errorEl) errorEl.textContent = msg;
        if (spinner) spinner.classList.add("is-hidden");
        isSubmitting = false;
      }

      if (!isValidEmailFormat(email)) return fail("Please use a valid email address");
      if (containsBannedKeyword(email)) return fail("Please use a work email, not personal one");
      if (!isWorkEmail(email)) return fail("Please use a work email, not personal one");

      var hutk = getHubSpotUserToken();
      var utm = getUTMParams();
      var fields = [{ name: "email", value: email }];
      ['utm_source', 'utm_medium', 'utm_content', 'utm_campaign'].forEach(function (k) {
        if (clean(utm[k])) fields.push({ name: k, value: clean(utm[k]) });
      });

      var payload = {
        fields: fields,
        context: Object.assign(
          { pageUri: window.location.href, pageName: document.title },
          hutk ? { hutk: hutk } : {}
        )
      };

      fetch("https://api.hsforms.com/submissions/v3/integration/submit/" + PORTAL_ID + "/" + HS_FORM_ID, {
        method: "POST",
        headers: { "Content-Type": "application/json" },
        body: JSON.stringify(payload),
        keepalive: true
      }).catch(function () {});
      navigator.sendBeacon(ENRICH_URL, new Blob([JSON.stringify({ email: email })], { type: 'application/json' }));

      var sep = redirect.indexOf('?') === -1 ? '?' : '&';
      window.location.replace(redirect + sep + "email=" + encodeURIComponent(email));
    });
  }

  function init() {
    document.querySelectorAll('form.hs-email-form').forEach(wire);
  }
  if (document.readyState !== 'loading') init();
  else document.addEventListener('DOMContentLoaded', init);
})();
</script>




<form class="hs-email-form hs-email-form--plain">
  <div class="form-fields-container">
    <div class="form-row-wrapper">
      <input type="email" name="email" required="" placeholder="Your Work Email" class="form-input-email" />
      <button type="submit" class="form-submit-button" style="outline: none !important;">
        Get a personalized demo
        <span class="spinner is-hidden"></span>
      </button>
    </div>
    <p class="form-error"></p>
  </div>
</form>


</aside>

<h2 id="triage-renewals-before-you-finish-the-inventory">Triage renewals before you finish the inventory</h2>

<p>Do not wait for a complete estate map. A renewal inside the next 90 days is money leaving the building while you build a spreadsheet.</p>

<p>As soon as the finance and contract pulls are underway, build a single triage list sorted by next renewal date, with known or estimated annual value in the second column. Work only the next 90 days. For each line, do three things:</p>

<p><strong>Confirm the owner.</strong> Not the person who signed it two years ago — the person who will defend the spend this quarter. Unowned renewals auto-renew by default, every time.</p>

<p><strong>Find the notice deadline, not the renewal date.</strong> Most enterprise agreements auto-renew unless you give 30, 60, or 90 days’ written notice. The notice date is your real deadline, and for anything renewing in the next 60 days it may already have passed. Check this first; it changes what’s negotiable.</p>

<p><strong>Make the call: renew, renegotiate, or kill.</strong> You’ve lost your utilization data, so you can’t argue seat reduction from a Productiv report anymore. You can still argue from purchased-seat counts versus IdP-assigned users, from headcount changes since the last renewal, and from department owners telling you plainly whether their team uses the thing. That’s weaker evidence than you had two weeks ago, and it’s enough to hold a renegotiation.</p>

<p>Two practical notes. Ask each vendor for their own usage numbers — most account teams will share seat activity on request, and for your largest apps that partially backfills what you lost. And if a renewal is genuinely un-triageable in time, a short-term extension at the current rate is almost always available and beats renewing blind for another year.</p>

<p>This list is also the artifact Finance actually wants. Send it to them at the end of week one, unfinished, with the coverage gaps labeled.</p>

<h2 id="rebuilding-an-engagement-baseline">Rebuilding an engagement baseline</h2>

<p>Your usage history is gone, which means the new clock starts today. Every day you delay instrumentation is a day missing from the dataset you’ll need at the next renewal cycle.</p>

<p>Set this up in week one, not week four. Confirm your IdP is retaining sign-in logs long enough to be useful and export them somewhere durable — default retention in most tenants is far shorter than a renewal cycle, and you will not get those days back. Connect directly to your ten largest apps by spend via API for last-active dates, license tiers, and seat assignments; those ten usually carry most of the negotiating leverage. Turn on SCIM where you can, so provisioning and deprovisioning generate a record instead of a ticket. Keep the endpoint and OAuth telemetry flowing rather than treating it as a one-time pull.</p>

<p>Do that and you’ll have 90 days of real utilization data by mid-November, and a full renewal cycle’s worth by next summer.</p>

<p>This is also the argument against solving the problem with a spreadsheet. A hand-built inventory is accurate on the day you finish it and starts decaying immediately — new tools appear, seats change, someone renews without telling you. Worse, a static inventory can’t produce a utilization trend at all, because trends require continuous collection. The rebuild is a one-time project. The baseline is only worth having if something keeps collecting after the project ends.</p>

<h2 id="doing-this-in-torii">Doing this in Torii</h2>

<p>Everything above can be done by hand. If you would rather not, here is what the same rebuild looks like in Torii, kept short because the method is the same.</p>

<p><strong>Two connections start it.</strong> Connect your identity provider and your finance system. Discovery runs immediately against both, and the contract and endpoint sources layer in as you connect them. You are building workflows the same day instead of maintaining the spreadsheet you built last week.</p>

<p><strong>Renewals come back first.</strong> Torii rebuilds the renewal calendar before the inventory is complete: current owner, the notice deadline rather than just the renewal date, and a renew, renegotiate, or short-extension decision for each line. That is the 90-day triage list from the section above, generated rather than typed.</p>

<p><strong>What comes back.</strong> App inventory from the identity provider, software spend from AP and cards, contracts and renewal dates, app owners and sponsors, purchased license counts, and shadow SaaS and AI tools from browser and endpoint signals. What does not come back is the same for everyone: Productiv’s historical utilization trends, in-platform notes, saved views, and workflow configuration were destroyed, and no vendor can restore them.</p>

<p><strong>Who does the work.</strong> You make the two connections. A Torii specialist validates discovery and builds your workflows alongside you. There are no agents to deploy, no services engagement, and no implementation fee.</p>

<p><strong>If we ever part ways.</strong> You can export your inventory, spend, contract, owner, and license data by API or CSV at any time, on your own schedule. That is the data egress test from the next section, and you should run it while you are a happy customer.</p>

<p>Torii was named a Leader in the <a href="/reports/gartner-magic-quadrant-for-saas-management-platforms">2026 Gartner® Magic Quadrant™ for SaaS Management Platforms</a>. The <a href="/alternatives/productiv">Productiv replacement page</a> maps each Productiv capability to what Torii does.</p>

<h2 id="what-this-changed-about-vendor-selection">What this changed about vendor selection</h2>

<p>The obvious lesson is “pick a bigger vendor,” and it’s the wrong one. Company size is a weak predictor, and anyone using this moment to sell you their headcount is selling you a feeling.</p>

<p>The real lesson is narrower and more useful: ask about data egress before you sign, and test it while you’re a happy customer. Three questions belong in every SaaS evaluation from now on:</p>

<ul>
  <li>Is there a documented, self-serve export of all my objects — inventory, spend, contracts, usage history — not a CSV of the current view?</li>
  <li>Is continued data availability for some defined window after termination a contractual commitment, or a support-ticket favor?</li>
  <li>Can I pull all of it via API on a schedule I control?</li>
</ul>

<p>Then actually run that export quarterly and put the file somewhere you own. That habit, not vendor selection, is what would have made last week survivable.</p>

<p>We’ll publish the full vendor continuity questionnaire as a follow-up. In the meantime, the thing worth internalizing is that any promise of permanence — including ours — is worth exactly as much as your ability to walk away with your data.</p>

<div class="article-highlight stack">
  <div class="article-highlight-content">
    <strong>Get the working version</strong>
    <p>The <a href="/assets/files/30-Day-SaaS-Estate-Rebuild-Checklist.pdf">30-Day SaaS Estate Rebuild Checklist</a> turns the four-source framework above into a doc you can assign, with the specific exports to request from each system and a renewal triage template. It's built to be useful whatever you replace Productiv with.</p>
  </div>
</div>

<p>Still comparing platforms? Our <a href="/articles/top-5-productiv-alternatives-for-saas-management">Productiv alternatives roundup</a> covers the field, and the <a href="/alternatives/productiv">Productiv replacement page</a> maps each capability to Torii.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Productiv permanently deleted all customer data. Here's what's actually gone, what you can rebuild, and a four-source plan to reconstruct your SaaS estate in 30 days.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/articles/productiv-data-delete.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/articles/productiv-data-delete.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Why SMP Adoption is Slow</title><link href="https://www.toriihq.com/blog/competing-with-a-spreadsheet-not-a-vendor" rel="alternate" type="text/html" title="Why SMP Adoption is Slow" /><published>2026-08-07T00:00:00+00:00</published><updated>2026-08-07T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/competing-with-a-spreadsheet-not-a-vendor</id><content type="html" xml:base="https://www.toriihq.com/blog/competing-with-a-spreadsheet-not-a-vendor"><![CDATA[<h2 id="i-noticed-a-recent-trend">I noticed a recent trend</h2>

<p>Most of the new customers we onboard are coming off a spreadsheet.</p>

<p>To be fair, this isn’t new, it’s the normal. But it still struck me as important.</p>

<p>This came up on a recent call at Torii: a batch of new customers had just signed, and someone noticed that most of them were coming from a SaaS management process that relied <i>entirely</i> on one person updating a spreadsheet.</p>

<h2 id="is-this-a-critical-mass-moment">Is this a critical mass moment?</h2>

<p>We’ve seen some recent consolidation in the SMP market with vendors like <a href="https://www.toriihq.com/blog/why-did-productiv-shut-down">Productiv shutting down</a>. And yet, the SMP landscape is only growing.</p>

<p>In 2025, <a href="https://www.usu.com/en/news/usu-recognized-in-the-2025-gartner-magic-quadrant-for-saas-management-platforms">Gartner claimed</a> that “Through 2028, over 70% of organizations will centralize SaaS application management using a SaaS management platform (SMP), an increase from less than 30% in 2025.”</p>

<p>Adoption of SMPs is growing, and in 2026, it’s actually accelerating as more and more companies struggle to manage AI alongside SaaS.</p>

<h2 id="so-why-has-it-taken-so-long">So why has it taken so long?</h2>

<p>Nobody owns the problem.</p>

<p>If most teams have not bought a tool for this, the question worth asking is why not. It is not that the tools are bad or that nobody cares. It is that the SaaS stack belongs to no single person.</p>

<p>Think about who touches it. IT, finance, security, procurement, and department heads each hold a piece of it. multiple owners, multiple priorities, and no one whose job title says “the software estate is mine.” A problem nobody clearly owns is a purchase nobody is clearly assigned to make.</p>

<p>Everything else about the slow adoption hangs off that. The spreadsheet is free, it is already open, and it mostly works right up until the renewal nobody caught. That renewal will not send a calendar invite, and the sheet is not going to volunteer that a seat quietly renewed for another year. When our offboarding conversations turn to the manual state, the way people put it is plain: “the list is only as good as the last time someone updated it”. That is not a complaint about a tool. It is the honest ceiling of a shared sheet that four teams half-maintain.</p>

<p>“SaaS management” is also young enough that most teams do not yet expect it as a budget line or a slot on the org chart.</p>

<h2 id="so-no-youre-not-late-to-saas-management-yet">So no, you’re not late to SaaS management… yet</h2>

<p>If you’re still updating that spreadsheet by hand; bless you.</p>

<p>You’re keeping things on track, trying to monitor adoption, track spend, inventory the un-inventoriable, and anticipate the new surprise renewal. It’s not just hard work, it’s impossible in the modern workplace.</p>

<p>We say it all the time, but SaaS Management requires cross team collaboration. Not a single hero, but a structured effort that comes from the top. Now, in a world of shadow IT and rampant AI adoption, that effort of managing your software is more important than ever.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Fewer than 30% of organizations ran a SaaS management platform in 2025. But that is starting to change...]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/articles/slow-smp-adoption.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/articles/slow-smp-adoption.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Why Did Productiv Shut Down?</title><link href="https://www.toriihq.com/blog/why-did-productiv-shut-down" rel="alternate" type="text/html" title="Why Did Productiv Shut Down?" /><published>2026-08-03T00:00:00+00:00</published><updated>2026-08-03T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/why-did-productiv-shut-down</id><content type="html" xml:base="https://www.toriihq.com/blog/why-did-productiv-shut-down"><![CDATA[<div class="article-highlight update">
  <div class="article-highlight-content">
    <strong>Update — August 11, 2026:</strong>
    <p>This post was published on August 2, hours after Productiv's announcement, and originally advised customers to export their data before the sunset. That is no longer possible. Productiv terminated all customer access on August 5 — a day earlier than the announced August 6 sunset — and states on its website that "all production systems, data stores, and backups have been permanently and securely destroyed. No customer data has been retained."</p>
    <p>We've corrected the guidance below and added what is now known about the shutdown. If you're a former Productiv customer, the practical question is no longer what to export — it's how to rebuild.</p>
    <p><strong>Update, September 9, 2026:</strong> the public record now shows the wind-down mechanism, a General Assignment for the Benefit of Creditors effective June 25, 2026. Details in the section below.</p>
  </div>
</div>

<p>On August 2, 2026, Productiv announced it was sunsetting its SaaS management platform on August 6, 2026 — a four-day window between the announcement and the shutdown. In practice the window was shorter: Productiv terminated customer access on August 5, and ceased operations on August 6. The company did not publicly give a reason for the decision.</p>

<p>Productiv itself has never stated a cause, and we are not going to manufacture one. What the public record does show, as of September 2026, is the mechanism: a General Assignment for the Benefit of Creditors effective June 25, 2026, more than five weeks before customers were told. That is covered in the next section. For the teams affected, the timeline still matters most, because four days is not much runway to move a system of record.</p>

<aside class="art-cta art-cta--inline">
  <p class="art-cta__eyebrow">Former Productiv customer?</p>
  <p class="art-cta__title">Rebuild your SaaS estate without starting from a spreadsheet</p>
  <p class="art-cta__body">Your Productiv data is gone, which makes this a rediscovery job rather than a migration. Connect your identity provider and your finance system, and Torii rebuilds your app inventory, spend, contracts, owners, and license counts from the systems you still control. <a href="/blog/productiv-deleted-your-data-rebuild-saas-estate-from-zero">Read the step-by-step rebuild guide</a>, or add your work email for a personalized demo on your own stack.</p>
  




<style>
  /* Functional CSS — always emitted; the JS depends on .spinner / .is-hidden */
  .hs-email-form .spinner {
    border: 2px solid #f3f3f3;
    border-top: 2px solid #3498db;
    border-radius: 50%;
    width: 18px;
    height: 18px;
    animation: hs-email-spin 1s linear infinite;
    display: inline-block;
    vertical-align: middle;
    margin-left: 10px;
  }
  @keyframes hs-email-spin {
    0% { transform: rotate(0deg); }
    100% { transform: rotate(360deg); }
  }
  .hs-email-form .is-hidden { display: none; }
  .hs-email-form .form-error {
    color: #ef4444;
    font-size: 0.875rem;
    margin-top: 0.5rem;
  }
</style>

<style>
  /* Presentational CSS — skipped when bare=true */
  .hs-email-form {
    background-color: #ffffff;
    border-radius: 1rem;
    transform-origin: top;
    width: 100%;
    margin-left: auto;
    margin-right: auto;
  }
  .hs-email-form--boxed {
    border: 1px solid #3b82f6;
    padding: 2rem 1.5rem 1rem;
    box-shadow: 0 4px 6px -1px rgba(0, 0, 0, 0.1), 0 2px 4px -1px rgba(0, 0, 0, 0.06);
    max-width: 36rem;
  }
  .hs-email-form--plain {
    max-width: 42rem;
  }

  .hs-email-form .form-fields-container { display: flex; flex-direction: column; }
  .hs-email-form .form-row-wrapper { display: flex; gap: 0.75rem; align-items: flex-start; }

  .hs-email-form .form-input-email {
    height: 3rem;
    flex-grow: 1;
    padding-left: 1rem;
    padding-right: 1rem;
    min-width: 0;
    border: 1px solid #d1d5db;
    border-radius: 0.5rem;
    box-sizing: border-box;
  }
  .hs-email-form .form-input-email:focus { outline: none; border-color: #3b82f6; }

  .hs-email-form .form-submit-button {
    height: 3rem;
    padding-left: 1.25rem;
    padding-right: 1.25rem;
    font-weight: 600;
    color: #1e2e4a;
    background-color: #ffffff;
    border-radius: 0.5rem;
    border: 1px solid #c4c9d5;
    box-shadow: 0 4px 6px -1px rgba(0, 0, 0, 0.1), 0 2px 4px -1px rgba(0, 0, 0, 0.06);
    transition-property: color, background-color, border-color;
    transition-duration: 150ms;
    display: flex;
    align-items: center;
    justify-content: center;
    white-space: nowrap;
    cursor: pointer;
    font-size: 16px !important;
    outline: none;
    flex-shrink: 0;
  }
  .hs-email-form .form-submit-button:hover { background-color: #0077ff; color: #ffffff; }
  .hs-email-form .form-submit-button:focus,
  .hs-email-form .form-submit-button:active { outline: none; }

  @media (max-width: 640px) {
    .hs-email-form .form-row-wrapper { flex-direction: column; gap: 0.75rem; }
    .hs-email-form .form-submit-button { width: 100%; }
  }
</style>


<script>
(function () {
  // Init-once guard: safe even if this block is emitted more than once.
  if (window.__toriiHsEmailFormInit) return;
  window.__toriiHsEmailFormInit = true;

  var ENRICH_URL = "https://torii--hubspot-assign-assignserver-serve.modal.run/enrich";
  var DEFAULT_REDIRECT = "/book-demo";
  var PORTAL_ID = "4265482";
  var HS_FORM_ID = "7e08202e-6b18-47a0-91ef-385cc6f58bba";

  var commonPersonalDomains = [
    "mail.com", "mac.com", "inbox.com", "alice.it", "tin.it", "virgilio.it", "libero.it",
    "live.co.uk", "live.fr", "live.it", "rediff.com", "indiatimes.com", "mail.ru",
    "bk.ru", "list.ru", "inbox.ru", "email.com", "usa.com", "europe.com", "asia.com", "africamail.com"
  ];

  var bannedDomains = new Set([
    'gmail', 'yahoo', 'outlook', 'hotmail', 'aol', 'icloud', 'protonmail', 'zoho',
    'gmx', 'yandex', 'msn', 'comcast', 'verizon', 'cox', 'sbcglobal', 'ymail', 'rocketmail', 'fastmail',
    'tutanota', 'hushmail', 'optonline', 'bellsouth', 'earthlink', 'shaw', 'rogers', 'qq', 'naver', 'hanmail', 'daum', '163', '126', 'yeah',
    'lycos', 'bigpond', 'btinternet', 'blueyonder', 'ntlworld', 'talktalk', 'wanadoo', 't-online', 'laposte',
    'seznam', 'centrum', 'volny', 'sapo', 'terra', 'netcabo', 'gawab', 'rediffmail', 'proton', "baidu", "sina", "21cn", "139", "freenet", "telus", "charter", "fronter", "centurylink", "windstream",
    'mailinator', 'tempmail', '10minutemail', 'guerrillamail', 'throwawaymail', 'getnada', 'yopmail', 'trashmail', 'maildrop', 'moakt', 'fakeinbox', 'mailnesia',
    'mintemail', 'spambog', 'dispostable', 'spamgourmet', 'emailondeck', 'anonaddy', 'inboxkitten', 'burnermail', 'sharklasers', 'spam4.me', 'mytempemail', "temp-mail", "mohmal", "dropmail", "getairmail"
  ]);

  function getUTMParams() {
    var p = new URLSearchParams(window.location.search);
    return {
      utm_source: p.get('utm_source') || '',
      utm_medium: p.get('utm_medium') || '',
      utm_content: p.get('utm_content') || '',
      utm_campaign: p.get('utm_campaign') || ''
    };
  }
  function isValidEmailFormat(email) { return /^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(email); }
  function clean(v) { return v && v.trim() !== "" ? v.trim() : null; }
  function containsBannedKeyword(email) {
    var domain = email.split('@')[1] ? email.split('@')[1].split('.')[0].toLowerCase() : '';
    return bannedDomains.has(domain);
  }
  function isWorkEmail(email) {
    var parts = email.split('@');
    if (parts.length !== 2) return false;
    return commonPersonalDomains.indexOf(parts[1].toLowerCase()) === -1;
  }
  function getHubSpotUserToken() {
    var cookies = document.cookie.split('; ');
    var find = function (prefix) {
      var row = cookies.find(function (r) { return r.indexOf(prefix) === 0; });
      return row ? row.split('=')[1] : null;
    };
    return find('hubspotutk=') || find('__hstc=') || null;
  }

  // Wire ONE form, using elements found relative to that form — no global IDs.
  function wire(form) {
    if (form.dataset.hsWired) return;   // don't double-bind
    form.dataset.hsWired = '1';

    var isSubmitting = false;           // per-form, not shared
    var spinner = form.querySelector('.spinner');
    var errorEl = form.querySelector('.form-error');
    var redirect = form.getAttribute('data-redirect') || DEFAULT_REDIRECT;

    form.addEventListener('submit', function (e) {
      e.preventDefault();
      if (isSubmitting) return;
      isSubmitting = true;

      var email = form.email.value.trim();
      if (errorEl) errorEl.textContent = "";
      if (spinner) spinner.classList.remove("is-hidden");

      function fail(msg) {
        if (errorEl) errorEl.textContent = msg;
        if (spinner) spinner.classList.add("is-hidden");
        isSubmitting = false;
      }

      if (!isValidEmailFormat(email)) return fail("Please use a valid email address");
      if (containsBannedKeyword(email)) return fail("Please use a work email, not personal one");
      if (!isWorkEmail(email)) return fail("Please use a work email, not personal one");

      var hutk = getHubSpotUserToken();
      var utm = getUTMParams();
      var fields = [{ name: "email", value: email }];
      ['utm_source', 'utm_medium', 'utm_content', 'utm_campaign'].forEach(function (k) {
        if (clean(utm[k])) fields.push({ name: k, value: clean(utm[k]) });
      });

      var payload = {
        fields: fields,
        context: Object.assign(
          { pageUri: window.location.href, pageName: document.title },
          hutk ? { hutk: hutk } : {}
        )
      };

      fetch("https://api.hsforms.com/submissions/v3/integration/submit/" + PORTAL_ID + "/" + HS_FORM_ID, {
        method: "POST",
        headers: { "Content-Type": "application/json" },
        body: JSON.stringify(payload),
        keepalive: true
      }).catch(function () {});
      navigator.sendBeacon(ENRICH_URL, new Blob([JSON.stringify({ email: email })], { type: 'application/json' }));

      var sep = redirect.indexOf('?') === -1 ? '?' : '&';
      window.location.replace(redirect + sep + "email=" + encodeURIComponent(email));
    });
  }

  function init() {
    document.querySelectorAll('form.hs-email-form').forEach(wire);
  }
  if (document.readyState !== 'loading') init();
  else document.addEventListener('DOMContentLoaded', init);
})();
</script>




<form class="hs-email-form hs-email-form--plain">
  <div class="form-fields-container">
    <div class="form-row-wrapper">
      <input type="email" name="email" required="" placeholder="Your Work Email" class="form-input-email" />
      <button type="submit" class="form-submit-button" style="outline: none !important;">
        Get a personalized demo
        <span class="spinner is-hidden"></span>
      </button>
    </div>
    <p class="form-error"></p>
  </div>
</form>


</aside>

<h2 id="so-why-did-productiv-shut-down">So why did Productiv shut down?</h2>

<p>Productiv has never given a public reason. When this post was first updated on August 11, the only signal was that its website directed creditor claims to a third-party administrator, which pointed to a wind-down rather than a planned product sunset.</p>

<p><strong>Update, September 9, 2026:</strong> the public record now shows the mechanism. Effective June 25, 2026, Productiv, Inc. made a General Assignment for the Benefit of Creditors to PFS Productiv Liquidation LLC, a California limited liability company, under California law. Stretto, Inc. is administering claims, and the deadline to file one is December 22, 2026.</p>

<p>An assignment for the benefit of creditors is a state-law alternative to a Chapter 7 bankruptcy: a company transfers its assets to an assignee, who liquidates them and distributes the proceeds to creditors in order of priority. It is faster and more private than a court filing, which is consistent with how little was said publicly. It does not tell you <em>why</em> the business failed, and Productiv still has not. But it does establish that the wind-down was set in motion at least five weeks before customers were told on August 2.</p>

<p><span style="font-size:0.85em;">Source: <a href="https://cases.stretto.com/Productiv" rel="nofollow noopener" target="_blank">PFS Productiv Liquidation LLC case page, Stretto, Inc.</a>, which lists the assignor, assignee, effective date, governing law, and claims bar date.</span></p>

<p>If you believe you have a claim as a former customer, the December 22 deadline is the one to calendar. Our <a href="/blog/productiv-deleted-your-data-rebuild-saas-estate-from-zero">rebuild guide</a> covers what former customers can and cannot recover.</p>

<h2 id="what-productiv-was">What Productiv was</h2>

<p>Productiv was a SaaS management platform best known for leaning on engagement data — measuring not just which applications a company bought, but how often employees actually used them. That angle made it popular with large enterprises trying to prove license utilization and justify renewals. For those customers, Productiv often held the authoritative view of the app portfolio: the inventory, the usage signals, the spend, and the app owners.</p>

<p>When a platform like that goes away, the risk is not just losing a dashboard. It is losing the visibility that IT, Finance, and Procurement teams had come to rely on for renewals, license decisions, and offboarding.</p>

<h2 id="what-the-shutdown-means-for-customers">What the shutdown means for customers</h2>

<p>With the sunset set for August 6, current Productiv customers face an immediate, practical problem rather than a long-term evaluation.</p>

<h3 id="your-productiv-data-is-gone--heres-what-that-actually-means">Your Productiv data is gone — here’s what that actually means</h3>

<p>There is no export window left, and no recovery path. Productiv states that all production systems, data stores, and backups have been permanently destroyed, with no customer data retained. Any vendor telling you to “export before it’s too late” is working from a week-old script.</p>

<p>What that means in practice:</p>

<ul>
  <li><strong>Permanently lost:</strong> historical engagement and utilization trends, license-optimization baselines built on that history, and any workflow configuration or notes held inside the platform.</li>
  <li><strong>Fully recoverable:</strong> your app inventory, software spend, contract and renewal dates, app owners, and license counts. All of it can be reconstructed from systems you still control — your identity provider, your AP and expense data, your contract repository, and endpoint or browser signals. It takes days, not months.</li>
</ul>

<p>The immediate priority is any renewal inside the next 90 days, because that’s where an invisible auto-renewal turns into real money. Everything else can be rebuilt on a slower clock.</p>

<p>We wrote up the full method, source by source, in <a href="/blog/productiv-deleted-your-data-rebuild-saas-estate-from-zero">how to rebuild your SaaS estate from zero after Productiv</a>, including the renewal triage.</p>

<p>Beyond the data itself, two priorities remain:</p>

<ul>
  <li><strong>Re-establish discovery fast.</strong> The longer you go without a system tracking your SaaS estate, the more visibility and savings leak away in the gap — missed renewals, idle licenses, and shadow IT that no one is watching.</li>
  <li><strong>Choose a replacement that can ramp quickly.</strong> A discovery-first platform can rebuild much of what you lose automatically, through integrations, rather than forcing you to start from a blank spreadsheet.</li>
</ul>

<h2 id="what-to-do-next">What to do next</h2>

<p>Because there is nothing left to export, the platform you choose has to rebuild your SaaS estate on its own — not inherit it from Productiv. That is exactly what a discovery-first platform does: it reconstructs your app inventory, spend, owners, and licenses from the systems you still control, instead of depending on a previous vendor’s records. We put together a side-by-side look at the strongest options — Torii, Zylo, Zluri, 1Password (Trelica), and Flexera — in our guide to the <a href="/articles/top-5-productiv-alternatives-for-saas-management">top 5 Productiv alternatives for SaaS management</a>.</p>

<p>Among them, <a href="/alternatives/productiv">Torii is the closest direct replacement</a>: a discovery-first platform, named a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms, that rediscovers your estate automatically and ties every app, license, and AI tool back to a real owner and budget — then automates the renewals, license reclamation, access reviews, and offboarding that Productiv largely left to manual effort. With customer access already gone, that combination of from-scratch discovery and automation is the fastest way back to control.</p>

<div class="article-highlight sales">
  <div class="article-highlight-content">
    <strong>Migrating off Productiv?</strong>
    <p>Torii rediscovers your SaaS estate automatically through 200-plus integrations, ties each app to an owner and a budget, and automates renewals, access, and offboarding — so you regain control quickly instead of starting from scratch. <a href="/request-a-demo">See Torii in action</a>.</p>
  </div>
</div>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;Chris Shuptrine&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/blog-chris.webp&quot;}</name></author><summary type="html"><![CDATA[Productiv, Inc. shut down on August 6, 2026. Public records show a June 25 assignment for the benefit of creditors. What happened, and what to do now.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/articles/productiv.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/articles/productiv.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Connect Torii to Claude, ChatGPT, and Other AI Assistants with Hosted MCP</title><link href="https://www.toriihq.com/blog/introducing-model-context-protocol-in-torii" rel="alternate" type="text/html" title="Connect Torii to Claude, ChatGPT, and Other AI Assistants with Hosted MCP" /><published>2026-05-05T00:00:00+00:00</published><updated>2026-05-05T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/introducing-model-context-protocol-in-torii</id><content type="html" xml:base="https://www.toriihq.com/blog/introducing-model-context-protocol-in-torii"><![CDATA[<p>Every day, IT teams move between spreadsheets, dashboards, tickets, and emails to answer simple questions:</p>

<p>Which apps are underused?<br />Which contracts are coming up for renewal?<br />Who owns this app?<br />Did this offboarding workflow finish?<br />What changed in our SaaS stack last week?</p>

<p>That work takes time because the context lives in different places.</p>

<p>Torii’s hosted <a href="/blog/what-is-model-context-protocol-mcp">Model Context Protocol (MCP)</a> server gives AI assistants a secure way to access your Torii data directly. Connect tools like Claude, ChatGPT, Cursor, and other MCP-compatible clients to Torii, and your assistant can query apps, users, contracts, workflows, audit logs, transactions, and more.</p>

<p>The best part: Torii MCP uses your existing Torii account permissions. Your assistant can only access the data and actions available to you.</p>

<h2 class="wp-block-heading">How it Works</h2>

<p>MCP is an open standard that lets AI tools connect to external systems through a shared interface. Instead of building one-off integrations for every AI tool, MCP gives compatible assistants a common way to talk to systems like Torii.</p>

<p>For Torii users, that means SaaS insights that once required the UI, manual reporting, or custom API work can now be surfaced directly in the AI tools your team already uses.</p>

<p>With Torii MCP, your assistant can help you access information like:</p>

<ul class="wp-block-list">
<li>User details</li>

<li>Contract details</li>

<li>Audit log history</li>

<li>Application details</li>

<li>Workflow activity</li>

<li>Transactions</li>

<li>SaaS costs</li>

<li>Renewal data</li>

<li>App ownership</li>

<li>And more</li>
</ul>

<p>Depending on your permissions, your assistant may also be able to take supported actions in Torii, such as searching apps, matching app records, creating contracts, updating users, or running workflows.</p>

<h2 class="wp-block-heading">Hosted MCP, No Local Setup Required</h2>

<p>Torii’s MCP server is now hosted, so you can connect your AI assistant directly to Torii without installing packages, running a local server, or managing API keys.</p>

<p>Connect your MCP-compatible client to Torii’s hosted MCP server:</p>

<pre class="wp-block-code"><code>https:&#47;&#47;api.toriihq.com/mcp</code></pre>

<p>From there, sign in with your Torii account and approve the connection. Torii uses OAuth and your existing Torii role permissions, so your assistant only gets the access you already have inside Torii.</p>

<p>Torii’s hosted MCP server can work with AI clients that support remote MCP servers with OAuth, including tools like Claude, ChatGPT, Claude Code, Cursor, Windsurf, Zed, Cline, Continue, and custom apps built with official MCP SDKs.</p>

<h2 class="wp-block-heading">Torii MCP in Action</h2>

<p>Below, see how a few prompts reveal offboarding status, ownership gaps, and replacement recommendations in seconds.</p>

<script src="https://fast.wistia.com/player.js" async=""></script>
<script src="https://fast.wistia.com/embed/3yp2lny6zk.js" async="" type="module"></script>
<style>wistia-player[media-id='3yp2lny6zk']:not(:defined) { background: center / contain no-repeat url('https://fast.wistia.com/embed/medias/3yp2lny6zk/swatch'); display: block; filter: blur(5px); padding-top:87.08%; }</style>
<wistia-player media-id="3yp2lny6zk" aspect="1.1483253588516746"></wistia-player>

<p>With just a few prompts in Claude, the user learns that:</p>

<ul class="wp-block-list">
<li>Six employees are currently in an offboarding workflow, and only one — Melba Donnelly — has not been deleted yet.</li>

<li>Melba is still the app owner for Box.</li>

<li>Claude can pull a list of active Box users, analyze usage, and suggest four candidates to take over ownership.</li>
</ul>

<p>That is a simple example, but it shows the larger value: IT teams can move from question to answer without manually checking multiple screens, exporting data, or building a report first.</p>

<h2 class="wp-block-heading">What You Can Ask</h2>

<p>Once connected, your AI assistant can help answer questions like:</p>

<ul class="wp-block-list">
<li>Which apps have more than 100 users?</li>

<li>Which contracts are renewing in the next 60 days?</li>

<li>Which apps have the most unused licenses?</li>

<li>Who owns this app?</li>

<li>Which users have access to this app?</li>

<li>What workflows ran in the last seven days?</li>

<li>Which apps were added last month?</li>

<li>What changed in our SaaS stack this week?</li>
</ul>

<p>You can also use Torii MCP to dig deeper. For example, you might ask your assistant to find apps with high spend and low usage, identify contracts that need attention, or review recent workflow activity before a meeting.</p>

<h2 class="wp-block-heading">Why It Matters</h2>

<p>AI is only useful when it has the right context.</p>

<p>For SaaS management, that context lives in Torii: your apps, users, contracts, costs, workflows, ownership data, and audit history. Torii MCP brings that context into the AI tools your team already uses, so you can ask better questions and get faster answers.</p>

<p>That helps IT, procurement, finance, security, and operations teams:</p>

<ul class="wp-block-list">
<li>Reduce manual reporting</li>

<li>Find SaaS risks faster</li>

<li>Spot cost-saving opportunities</li>

<li>Understand ownership and access</li>

<li>Review workflow activity</li>

<li>Prepare for renewals</li>

<li>Make decisions with fresher data</li>
</ul>

<p>Instead of asking your team to jump between systems, Torii MCP lets them start with a question and move straight toward the answer.</p>

<h2 class="wp-block-heading">How to Get Started</h2>

<p>Ready to connect your AI assistant to Torii?</p>

<p>Use Torii’s hosted MCP server:</p>

<pre class="wp-block-code"><code>https:&#47;&#47;api.toriihq.com/mcp</code></pre>

<p>For step-by-step setup instructions, see the support guide: <a href="https://support.toriihq.com/hc/en-us/articles/49894290637467-Connecting-AI-Assistants-to-Torii-with-MCP"><strong>Connecting AI Assistants to Torii with MCP</strong>.</a></p>

<p>Want to learn more about the standard behind it? Read the <a href="https://modelcontextprotocol.io/specification/"><strong>Model Context Protocol specifications</strong>.</a></p>

<p>Torii MCP helps your team bring live SaaS context into the AI tools they already use, so they can move faster, reduce manual work, and manage software with more confidence.</p>

<h2 class="wp-block-heading">Prefer a Local MCP Setup?</h2>

<p>Torii’s hosted MCP server is the recommended setup for most users because it does not require local installation, API key management, or running your own server.</p>

<p>For teams that prefer a local setup, Torii also offers a local MCP server package that can run on your machine and connect to Torii through your API key.</p>

<p>Install the package:</p>

<!-- Bash install command -->
<pre class="line-numbers"><code class="language-bash">npm install @toriihq/torii-mcp</code></pre>

<p>You’ll need:</p>

<ul class="wp-block-list">
<li>A Torii API key</li>

<li>Node.js</li>

<li>Yarn package manager</li>
</ul>

<p>A local setup may be useful if your team wants more control over how the MCP server runs, needs to test MCP behavior in a development environment, or is connecting through a client that does not support hosted remote MCP servers yet.</p>

<p>For most users, we recommend starting with the hosted MCP server:</p>

<p><a href="https://api.toriihq.com/mcp">https://api.toriihq.com/mcp</a></p>

<p>For local setup instructions, visit Torii’s npm repository or contact your Torii Customer Support Representative.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Connect Claude, ChatGPT, and other AI assistants to Torii with hosted MCP—query apps, users, contracts, and workflows using your existing permissions.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/introducing-model-context-protocol-in-torii.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/introducing-model-context-protocol-in-torii.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">What’s Behind Grammarly’s 3x Enterprise Growth? Three Years of Usage Data Has Answers</title><link href="https://www.toriihq.com/blog/grammarly-enterprise-growth-analysis" rel="alternate" type="text/html" title="What’s Behind Grammarly’s 3x Enterprise Growth? Three Years of Usage Data Has Answers" /><published>2026-03-27T00:00:00+00:00</published><updated>2026-03-27T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/grammarly-enterprise-growth-analysis</id><content type="html" xml:base="https://www.toriihq.com/blog/grammarly-enterprise-growth-analysis"><![CDATA[<p>Torii tracks SaaS usage across enterprise customers worldwide. One trend has been hard to ignore: Grammarly's footprint has grown roughly 3x in three years.</p>

<p>In January 2023, Grammarly appeared in just 17% of customer environments. By January 2026, it had jumped to 47%. The growth wasn't steady — it came in three distinct waves, each driven by something specific Grammarly did.</p>

<p>Here's what the data looks like, and what was happening at Grammarly each time the line jumped.</p>

<table style="border-collapse:collapse;width:100%;font-family:sans-serif;font-size:13px;border:1px solid #e0e0e0;">
  <thead>
    <tr style="background:#f5f5f5;">
      <th style="padding:8px 12px;text-align:left;border-bottom:2px solid #ccc;">Period</th>
      <th style="padding:8px 12px;text-align:center;border-bottom:2px solid #ccc;">Adoption Index</th>
      <th style="padding:8px 12px;text-align:left;border-bottom:2px solid #ccc;">Notable Change</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Jan 2023</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">17%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Baseline</td>
    </tr>
    <tr style="background:#fafafa;">
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Feb–Mar 2024</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">22% → 31%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;"><strong>Spike 1: +6 points in one month</strong></td>
    </tr>
    <tr>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Dec 2024 → Jan 2025</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">30% → 38%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;"><strong>Spike 2: +7 points and never dropped back</strong></td>
    </tr>
    <tr style="background:#fafafa;">
      <td style="padding:8px 12px;border-bottom:1px solid #eee;">Sep–Oct 2025</td>
      <td style="padding:8px 12px;text-align:center;border-bottom:1px solid #eee;">41% → 46%</td>
      <td style="padding:8px 12px;border-bottom:1px solid #eee;"><strong>Spike 3: +5 points as Grammarly became Superhuman</strong></td>
    </tr>
    <tr>
      <td style="padding:8px 12px;">Jan 2026</td>
      <td style="padding:8px 12px;text-align:center;">47%</td>
      <td style="padding:8px 12px;">Peak to date</td>
    </tr>
  </tbody>
</table>

<figure class="wp-block-image size-full"><img width="1424" height="752" src="/assets/images/blog/wp/2026/03/grammarly-enterprise-growth-analysis-body-1.webp" alt="SaaS usage dashboard showing Grammarly adoption growth over time with bar chart and app list" class="wp-image-10638" /></figure>

<h2 class="wp-block-heading">Spike 1 (Feb–Mar 2024): Grammarly stopped being a spell-checker</h2>

<p>On March 26, 2024, Grammarly launched Strategic Suggestions — AI-powered recommendations that went beyond fixing grammar to advising on audience, tone, and persuasion. The same week, it shipped App Actions, letting users trigger tasks in tools like Asana and Google Calendar from within Grammarly. For the first time, the product could make a real case to IT and procurement as a productivity platform, not a writing add-on.</p>

<p>Fast Company added fuel. Its 2024 Most Innovative Companies list (published March 19) named Grammarly in the AI category and cited some striking ROI numbers: one healthcare customer reported 28x ROI, and Grammarly claimed average savings of $5,000 per employee per year. That kind of coverage circulates in the procurement channels where enterprise software decisions get made.</p>

<h2 class="wp-block-heading">Spike 2 (Dec 2024–Jan 2025): A new CEO, a new company</h2>

<p>On December 17, 2024, Grammarly announced it was acquiring Coda — a collaborative workspace product competing with Notion and Google Docs — and that Coda's co-founder Shishir Mehrotra would become Grammarly's new CEO. The message was explicit: Grammarly was no longer a writing tool; it was building an AI productivity suite for enterprise teams.</p>

<p>That announcement closed a pipeline that had been building since October. Two months earlier, Grammarly had landed on the AWS Marketplace, giving companies with existing AWS commitments a way to apply cloud credits toward Grammarly Business — a procurement shortcut that removes significant friction. In the same October window, Grammarly launched Billing Groups, ServiceNow integration, and group-level security controls: the exact features IT admins need before they can deploy something organization-wide.</p>

<p>The jump from 30% in December to 38% in January reflects deals that probably started in Q4, enabled by the AWS listing and admin tooling, then accelerated by the Coda news.</p>

<h2 class="wp-block-heading">Spike 3 (Sep–Oct 2025): The Superhuman rebrand</h2>

<p>On July 1, 2025, Grammarly acquired Superhuman — the AI email client valued at roughly $825 million. Three months later, on October 29, Grammarly rebranded the entire company as "Superhuman" and launched the Superhuman Suite: four unified products (Grammarly writing, Coda workspace, Superhuman email, and a new AI agent platform called Superhuman Go). The rebrand landed across TechCrunch, Fast Company, Built In, and others simultaneously.</p>

<p>Usage in our dataset went from 35% in August to 41% in September and 46% in October. September also brought a Forbes Cloud 100 placement at #11 — the kind of analyst recognition that validates a platform to IT procurement teams evaluating AI investments. A $1 billion non-dilutive funding round announced in May, earmarked for sales and marketing scale, almost certainly put more reps in front of enterprise buyers during this window.</p>

<figure class="wp-block-image size-full"><img width="1424" height="752" src="/assets/images/blog/wp/2026/03/grammarly-enterprise-growth-analysis-body-2.webp" alt="IT admin dashboard showing SaaS app discovery with sanctioned, under review, and shadow IT status badges alongside an app approval workflow" class="wp-image-10639" /></figure>

<h2 class="wp-block-heading">What this means for IT teams managing SaaS</h2>

<p>Each of these spikes followed the same pattern: Grammarly expanded what the product does, and enterprise adoption followed. That creates a specific challenge for IT.</p>

<p>In 2023, most companies probably had Grammarly as an employee-purchased tool — a $12/month browser extension people expensed without telling IT. By 2026, the product has become a full AI productivity suite with admin controls, data governance features, and enterprise licensing that IT should be part of evaluating and managing.</p>

<p>If you're not tracking which tools are gaining momentum in your organization, you'll find out about the enterprise version of Grammarly (or Superhuman, now) after someone in marketing has already signed a contract. The best position is to see the adoption curve before the renewal conversation happens.</p>

<p>Torii surfaces that kind of usage data automatically — which apps employees are using, which ones are growing, and which ones have grown to the point where IT needs a seat at the table. <strong><a href="/request-a-demo">Book a demo to see how it works.</a></strong></p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/articles/oauth-google-workspace-risk">How to Detect OAuth Risks in Google Workspace and Who\u2019s Behind Them in 2026</a></li>
  <li><a href="/blog/log-analysis">What is a Log Analysis?</a></li>
  <li><a href="/articles/reduce-saas-costs">7 Ways to Reduce Your SaaS Costs Without Losing Productivity</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[What’s Behind Grammarly’s 3x Enterprise Growth? Three Years of Usage Data from Torii Has Answers]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/grammarly-enterprise-growth-analysis.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/grammarly-enterprise-growth-analysis.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Introducing the Torii CLI</title><link href="https://www.toriihq.com/blog/introducing-torii-cli" rel="alternate" type="text/html" title="Introducing the Torii CLI" /><published>2026-03-17T00:00:00+00:00</published><updated>2026-03-17T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/introducing-torii-cli</id><content type="html" xml:base="https://www.toriihq.com/blog/introducing-torii-cli"><![CDATA[<p>Your SaaS data shouldn't live behind a dashboard you have to click through every time you need an answer. With the Torii CLI, it doesn't have to.</p>

<p>The <a href="https://developers.toriihq.com/docs/torii-cli">Torii CLI</a> is an OpenAPI-driven command line interface that lets you explore the Torii API, inspect schemas, and run API calls directly from your terminal. Every command is auto-generated from the live OpenAPI spec, so it stays in sync with the latest API capabilities without manual updates.</p>

<p>If you're writing automation scripts, building data pipelines, or connecting Torii to AI agents, this is your starting point.</p>

<h2 class="wp-block-heading">Why a CLI?</h2>

<p>Point-and-click interfaces work for exploring. But when you need to pull license data into a report, trigger a workflow from a script, or pipe SaaS usage stats into another tool, a CLI is faster and more composable. Every response comes back as structured JSON, so it works out of the box with <code>jq</code>, shell scripts, and automation frameworks.</p>

<p>The Torii CLI is built for:</p>

<ul class="wp-block-list">
<li><strong>Automation scripts</strong> — schedule recurring data pulls or trigger actions on a cron</li>

<li><strong>Data extraction pipelines</strong> — export application, user, and contract data for analysis</li>

<li><strong>AI and agent integrations</strong> — feed Torii data into LLMs, Claude Code, or custom agents</li>

<li><strong>Interactive exploration</strong> — browse available endpoints and test calls before writing code</li>
</ul>

<h2 class="wp-block-heading">Getting Started</h2>

<p>Install globally via npm, or run it directly with npx if you just want to try it out.</p>

<pre class="line-numbers"><code class="language-bash"># Install globally
npm install -g torii-cli

# Or run without installing
npx torii-cli discovery</code></pre>

<p>Before running commands, set your API key as an environment variable:</p>

<pre class="line-numbers"><code class="language-bash">export TORII_API_KEY="your-api-key"</code></pre>

<p>That's it. You're ready to query your Torii instance from the command line.</p>

<h2 class="wp-block-heading">How It Works</h2>

<p>The CLI dynamically fetches the OpenAPI specification from the Torii API. This means you don't need to memorize endpoints or check documentation every time the API changes. Run the <code>discovery</code> command to see every available operation:</p>

<pre class="line-numbers"><code class="language-bash"># List all available API operations
torii-cli discovery</code></pre>

<p>This returns a JSON list of every endpoint, generated directly from the spec. From there, you can run any operation. For example, to pull your top 10 applications:</p>

<pre class="line-numbers"><code class="language-bash"># List your first 10 applications
torii-cli apps list --size 10</code></pre>

<p>All responses are structured JSON, which makes it easy to pipe into other tools or parse in scripts.</p>

<h2 class="wp-block-heading">Pairing Torii CLI with AI Agents</h2>

<p>One of the most practical uses for the Torii CLI is connecting your SaaS data to AI-powered tools. Because the CLI returns structured JSON and supports the same operations as the API, it works well as a data source for LLMs and coding agents.</p>

<p>Here's what that looks like in practice. Below, a user asks Claude Code how many people in their company are using ChatGPT, Gemini, and Claude. Claude queries the Torii API to pull real usage data and return an answer in seconds.</p>

<figure class="wp-block-image size-full"><img width="800" height="278" src="/assets/images/blog/wp/2026/03/cli-1.webp" alt="Claude Code querying Torii data to show how many employees use ChatGPT, Gemini, and Claude" class="wp-image-10626" /></figure>

<p>Instead of logging into a dashboard, filtering by app category, and exporting a spreadsheet, the user gets an answer through a natural language prompt. The CLI (and the broader Torii API) makes this kind of integration straightforward.</p>

<p>This pattern applies to more than just usage questions. You can build agents that flag expiring contracts, identify orphaned accounts, surface license optimization opportunities, or generate compliance reports, all powered by the same API the CLI uses.</p>

<h2 class="wp-block-heading">What You Can Do With It</h2>

<p>The CLI gives you access to the same data and actions available through the Torii platform. A few examples:</p>

<ul class="wp-block-list">
<li><strong>Pull application inventory</strong> — list all discovered apps, filter by category, and export for audits</li>

<li><strong>Query user data</strong> — check who has access to what, identify inactive accounts, and track usage</li>

<li><strong>Monitor contracts and spend</strong> — surface renewal dates, license counts, and cost data</li>

<li><strong>Feed data into CI/CD or reporting tools</strong> — pipe JSON output into dashboards, Slack alerts, or ticketing systems</li>

<li><strong>Build custom automations</strong> — combine CLI calls with cron jobs, shell scripts, or orchestration tools</li>
</ul>

<h2 class="wp-block-heading">Get Started</h2>

<p>The Torii CLI is available now on <a href="https://www.npmjs.com/package/torii-cli">npm</a>. Install it, set your API key, and start querying your SaaS data from the terminal.</p>

<p>For full documentation, visit the <a href="https://developers.toriihq.com/docs/torii-cli">Torii Developer Docs</a>.</p>

<p>Already a Torii customer? Reach out to your Customer Success representative to get your API key and start building.</p>

<p><strong><a href="/request-a-demo">Book a demo</a></strong> to see how Torii helps teams manage SaaS with automation, visibility, and developer-friendly tools.</p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[Introducing the Torii CLI: an OpenAPI-driven command line tool to explore the Torii API, run calls, and pipe SaaS data into scripts and AI agents.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/introducing-torii-cli.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/introducing-torii-cli.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">How to Track AI Costs in 2026</title><link href="https://www.toriihq.com/blog/how-to-track-ai-costs" rel="alternate" type="text/html" title="How to Track AI Costs in 2026" /><published>2026-03-10T00:00:00+00:00</published><updated>2026-03-10T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/how-to-track-ai-costs</id><content type="html" xml:base="https://www.toriihq.com/blog/how-to-track-ai-costs"><![CDATA[<p>Most SaaS costs fit a predictable pattern. You sign a contract, assign seats, pay the invoice. But AI spending doesn't always work that way. Hidden behind seemingly low costs (only $20 for Claude/month!) are usage caps, often with little warning when your allocated usage tips into incremental PAYG token-based costs. </p>

<p>Then you have shadow AI usage and tool overlap, leading to cost optimization questions like, "We use Google Workspace, which has Gemini built in. Why also pay for ChatGPT?" or "Why are we paying so much for Cursor when we could just use Claude Code instead?"
</p>

<p>The good news: it's possible to track AI costs in 2026 down to the cent, as well as easily identify overlapping AI tools. This guide breaks down how to track AI costs in 2026: what to measure, how to do it manually, and how platforms like Torii give you a real-time view across your entire AI stack.</p>

<h2 class="wp-block-heading">Why is AI Spending Harder to Control Than SaaS?</h2>

<p>Traditional SaaS follows a predictable model: pay $X per month, or per seat per month. In either model, predicting costs is easy (it'll be the same cost unless you add more people). AI tools have upended this with their focus on 'token-based' pricing and generally opaque insights into usage.</p>

<p>Usage-based pricing is of course not new. Tools like Stripe (commission %), Twilio (PAYG usage), and Hubspot (cost per marketing contact) have used them for years. Not to mention Google Cloud and AWS's cloud compute costs. But these are much more predictable than AI token pricing, and the norm for SaaS is still monthly/yearly pre-set commitments.</p>

<p>Meanwhile, AI tool usage is...confusing? Odd? Misleading? Just take a look at this <a href="https://developers.openai.com/api/docs/pricing">API pricing breakdown</a> from OpenAI.</p>

<p>Understanding costs here is a nightmare. What model are you using? Are we caching or not? Is this batch, flex, or standard? How do I track how many tokens any given message contains? At least with standard request-based PAYG pricing you know that 1 request = 1 request to pay for.</p>

<figure class="wp-block-image size-full"><img width="1000" height="609" src="/assets/images/blog/wp/2026/03/openai_costs.webp" alt="OpenAI API pricing breakdown showing token costs by model" class="wp-image-10391" /></figure>

<p>On top of that, you have <a href="/articles/shadow-ai">shadow AI</a>. Employees are signing up for their favorite new AI tools, even though they may overlap significantly with tools your company already pays for. Then, of course, people may be signing up for ChatGPT themselves when a team plan would be much more economical.</p>

<p>The costs can compound quickly. A 100-person engineering team could be running Cursor, GitHub Copilot, and Claude Code simultaneously, each doing roughly the same thing. At standard pricing, that's anywhere from $70,000 to $130,000 per year in coding AI alone.</p>

<p>This differs from traditional SaaS because normally it's easy to identify overlaps. If you're working with Box.com, it may feel weird to also work in Dropbox for some projects, since they are effectively the same tool. Gemini and MidJourney, on the other hand, may not feel that way. Yet, with the speed of AI innovation, the difference between AI tools is shrinking. Maybe you paid for Gemini Nano Banana because it was the best image generator, then switched to MidJourney the next month because it seemed better, and so on - until you just decide to keep paying for both. (Or, you were using MidJourney not knowing Gemini was also a great image generator).</p>

<div style="background:#fff7ed;border-left:4px solid #f97316;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>The math adds up fast:</strong></p>
  <p style="margin:0;">A 100-person dev team paying for Cursor ($48K/year), Copilot ($46.8K/year), and ChatGPT Team ($36K/year) could be spending over $130K annually on tools with significant feature overlap.</p>
</div>

<h2 class="wp-block-heading">How Do I Track AI Costs Manually?</h2>

<p>The manual approach to AI cost tracking is where most companies begin. For small companies, it's relatively simple: you log into each tool's billing dashboard separately (the OpenAI usage page, the Copilot admin console, Cursor Teams billing), pull the numbers, and paste them into a spreadsheet. Then you cross-reference expense reports to catch anything employees bought on their own.</p>

<p>This approach works passably when you have two or three tools and one person keeping the spreadsheet current. It doesn't hold up as your AI stack grows.</p>

<p>The core limitation with manual tracking comes down to visibility lag between spending and awareness. Each billing dashboard gives you a static snapshot from a single vendor. You have no cross-tool view of what an individual employee is spending across their whole AI stack. You can't see that one developer has active subscriptions to Cursor, Claude Pro, and ChatGPT running at the same time.</p>

<p>A second blind spot with manual tracking is that it tells you nothing about license utilization. A billing dashboard shows what you're paying, not what's being used. You can have 50 Copilot seats and only 20 active users, and the invoice looks the same regardless. Finding that waste requires comparing the bill against actual login data, which most AI tool billing dashboards don't surface.</p>

<div style="background:#fff7ed;border-left:4px solid #f97316;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>Where manual tracking breaks down:</strong></p>
  <p style="margin:0;">Expense reimbursements are often the first time IT learns about a new AI tool, and it may take months before IT even notices. By the time you notice the charge, the subscription has been running for weeks.</p>
</div>

<h2 class="wp-block-heading">How Can I Track Costs with Torii?</h2>

<p>Torii is an AI Management Platform that replaces the per-tool billing dashboard approach with a single consolidated view. Torii's AI Apps Spend dashboard pulls all your AI tool costs into one place: total spend by tool, last 30 days vs. last 12 months, user counts, and license utilization.</p>

<figure class="wp-block-image size-full"><img width="1000" height="389" src="/assets/images/blog/wp/2026/03/dashboard1.webp" alt="Torii AI Apps Spend dashboard showing AI tool costs and license utilization" class="wp-image-10392" /></figure>

<p>That last column is where the real value shows up. If Lovable is sitting at 38% license utilization, that means 62% of the seats you're paying for aren't actively used. That's not easily visible within Lovable alone. In Torii, it surfaces right next to the cost number so you can act on it immediately.</p>

<p>Additionally, the spend-over-time chart surfaces growth trends that a manual spreadsheet would never flag in time. Cursor spend jumping from roughly $1,400 per month to over $5,400 in two months is a signal worth investigating: is the team growing, or are a handful of power users burning through credits on a premium model? Seeing the trend is the first step to asking the right question.</p>

<figure class="wp-block-image size-full"><img width="1000" height="352" src="/assets/images/blog/wp/2026/03/dashboard2.webp" alt="Torii AI spend over time chart showing monthly AI tool costs by vendor" class="wp-image-10393" /></figure>

<div style="background:#ecfdf5;border-left:4px solid #10b981;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>What Torii surfaces that billing pages don't:</strong></p>
  <p style="margin:0;">License utilization by tool, spend trends over time, and cross-tool cost comparisons in one view, without logging into a single vendor dashboard.</p>
</div>

<h2 class="wp-block-heading">How Do I Cut My AI Costs?</h2>

<p>Seeing your AI spend is the starting point, not the finish line. Once you have a consolidated view, four actions consistently move the number down.</p>

<p><strong>Reclaim idle seats.</strong> For AI tools with seat-based pricing, any AI license that hasn't been accessed in 90 days is waste. License reclamation at this threshold can <a href="/articles/reduce-saas-costs">cut AI tool costs</a> by 20-35% in organizations that haven't been actively managing it. Set a policy, automate the reclaim, and redirect those seat costs elsewhere.</p>

<p><strong>Identify tool overlap.</strong> Once you can see every AI tool in use, consolidation decisions become obvious. If multiple teams are each paying for a coding assistant, pick one standard. If you have three separate <a href="/articles/llm-shadow-ai-risk">LLM subscriptions</a> doing similar work, consolidate. A tool like Torii can help surface those duplicate tools easily.</p>

<p><strong>Rightsize tiers.</strong> Actual usage data removes the guesswork from tier and contract decisions. If 60% of your Copilot users are only accessing basic features, downgrade those seats. Annual contracts save 10-20% over monthly billing for tools you're committed to keeping long-term.</p>

<p><strong>Set ongoing guardrails.</strong> Treat AI spend like cloud compute: allocated per team, monitored monthly, with budget alerts at 80% of the limit. Require new AI tool requests to pass a lightweight approval that checks for overlap with existing tools. The goal isn't to slow down adoption. It's to stop paying for the same capability twice.</p>

<p><strong>Monitor outliers.</strong> If a certain tool or user is causing costs to climb, why is that? Perhaps there is wayward automation running, or an expensive model is being used when a more cost-efficient one would suffice. Review and set guidelines on model and token usage.</p>

<div style="background:#f5f3ff;border-left:4px solid #8b5cf6;border-radius:6px;padding:16px 20px;margin:24px 0;">
  <p style="margin:0 0 6px;"><strong>Quick wins after your first AI spend audit:</strong></p>
  <p style="margin:0;">Reclaim seats inactive for 90+ days, consolidate overlapping coding AI tools, and set monthly budget alerts per team. These three steps alone can recover 20-35% of AI spend without cutting tools people actually use.</p>
</div>

<p>AI tool adoption isn't slowing down, and neither is the spending that comes with it. Enterprise AI-native app spend grew 108% year-over-year in 2025, and with more tools hitting the market every month, the overlap problem will only compound. The companies that stay ahead of it are the ones that treat AI spend the same way they treat cloud compute: tracked by team, reviewed regularly, and tied to actual outcomes.</p>

<p>The path forward isn't complicated. Know what you have, know what's being used, and build a repeatable process to act on that data. Whether you start with a manual audit or a platform like Torii that consolidates everything into one view, the goal is the same: visibility that lets you make decisions before you get surprised by a five-figure invoice.</p>

<p><strong><a href="/request-a-demo">See how Torii tracks your AI spend across every tool. Book a demo.</a></strong></p>

<p><strong>Related reading:</strong></p>

<ul>
  <li><a href="/articles/toxic-combination-saas">What Is a Toxic Combination in SaaS in 2026?</a></li>
</ul>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[AI spending is growing fast and getting hard to control. Here's how to track AI costs across your stack in 2026, from manual methods to automated platforms.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/how-to-track-ai-costs.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/how-to-track-ai-costs.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Enterprise IGA Blueprint</title><link href="https://www.toriihq.com/blog/the-enterprise-iga-blueprint" rel="alternate" type="text/html" title="The Enterprise IGA Blueprint" /><published>2025-09-22T00:00:00+00:00</published><updated>2025-09-22T00:00:00+00:00</updated><id>https://www.toriihq.com/blog/the-enterprise-iga-blueprint</id><content type="html" xml:base="https://www.toriihq.com/blog/the-enterprise-iga-blueprint"><![CDATA[<p class="has-medium-font-size">A board-ready framework to reduce identity risk, pass audits, and prove ROI in 2–3 quarters.</p>

<h2 class="wp-block-heading">Executive Summary</h2>

<p>Identity Governance &amp; Administration (IGA) is no longer a back-office task. It is a board-level responsibility. Identity is now central to enterprise risk, regulatory compliance, and shareholder value.</p>

<p>The pressure is mounting from every direction:</p>

<ul class="wp-block-list">
<li>Breach reality: Ransomware features in 44% of breaches, the human element is present in nearly 60%, and third-party exposure has doubled to 30%.</li>

<li>Financial impact: The average breach costs $4.4M, while most organizations hit by AI-related incidents lacked basic access controls.</li>

<li>Regulatory heat: Boards face direct accountability under DORA (resilience and third-party oversight), NIS2 (expanded obligations with active enforcement), and the SEC cyber rule (4-day disclosure of material incidents).</li>

<li>Business reality: Enterprises now run an average of 1,850 SaaS apps. Machine identities outnumber humans 82:1, and AI systems are emerging as new “users” with access needs of their own.</li>
</ul>

<p>The good news is that IGA delivers results quickly.&nbsp;</p>

<p>This blueprint gives boards, executives, and audit committees the tools to turn identity governance into a measurable, board-sanctioned program. Specifically, it will:</p>

<ul class="wp-block-list">
<li>Outline clear accountability: Show exactly who should own which responsibilities—from board and committee oversight, to executive sponsorship, to daily operations through an IGA council.</li>

<li>Provide a reference architecture: A vendor-agnostic model of the essential layers of IGA (sources, control plane, Zero Trust, PAM, ITDR, AI guardrails, reporting) that boards can use to judge maturity.</li>

<li>Define a board-ready KPI framework: A concise set of metrics and targets mapped directly to regulatory requirements, so progress can be tracked quarter by quarter.</li>

<li>Map controls to standards: Demonstrate how IGA outcomes align with NIST CSF 2.0, DORA, NIS2, and SEC rules—simplifying reporting and audit prep.</li>

<li>Deliver a 180-day SaaS sprawl plan: A phased approach to bring <a href="/blog/what-is-shadow-it" title="shadow IT">shadow IT</a>, vendors, and machine identities under governance, with quick wins in the first 30 days.</li>

<li>Show the ROI case: Translate governance outcomes into financial language—license reclamation, audit efficiency, and avoided breach losses—so CFOs and boards can clearly see value.</li>
</ul>

<p>The takeaway is simple: IGA is the control plane for digital risk. It enables boards to prove compliance, reduce exposure, and demonstrate financial value—turning identity from a hidden liability into a governed asset.</p>

<h2 class="wp-block-heading">IGA is a Board-Level Concern</h2>

<p>For years, identity was treated as a back-office function. It was something that IT, SecOps, and vendor management dealt with. But today, that era is over.</p>

<p>Identity is a board-level concern because it directly impacts enterprise risk, regulatory compliance, and shareholder value.&nbsp;</p>

<p>The facts are clear: stolen or misused credentials are still the easiest way for attackers to get in to the organization.&nbsp;</p>

<p>According to&nbsp; <a href="https://www.verizon.com/business/resources/infographics/2025-dbir-infographic.pdf">Verizon’s DBIR 2025</a> reports:</p>

<ul class="wp-block-list">
<li>Ransomware was involved in 44% of breaches</li>

<li>The human element was present in ~60%</li>

<li>Third-party involvement doubled year over year to 30%</li>
</ul>

<p><a href="https://www.ibm.com/reports/data-breach">&nbsp;IBM’s 2025 study</a> pins the average cost of a breach at $4.4M.</p>

<p>Additionally, they highlight a massive AI oversight gap. Among the orgs reporting an AI-realted security incident, 97% lacked proper AI access controls.</p>

<p>As financial impacts grow, regulatory leashes tighten.</p>

<p>In Europe, DORA now requires boards of financial institutions to prove resilience across their ICT and vendor ecosystems. NIS2 is expanding the obligations across industries, and the commission is already escalating against 23 lagging states. In the US, the SEC cyber&nbsp; disclosure rule now forces boards to disclose material incidents within four business days.</p>

<p>Each of these rgulations asks the same question of the board: Can you prove, right now, that you know who (or what) has access to what?</p>

<p>Along with the financial and&nbsp; regulatory risk, there is the business reality.&nbsp;</p>

<p>Organizations use:</p>

<ul class="wp-block-list">
<li>More applications than ever, with enterprises often leveraging over <a href="/reports/saas-benchmark-annual-report-2026">1,800 apps</a></li>

<li>Machine identities, <a href="https://www.cyberark.com/threat-landscape/?prevItm=690762184&amp;prevCol=6824667&amp;ts=11872">outnumbering human identities 82 to 1</a> </li>

<li>More AI solutions than ever before</li>
</ul>

<p>The takeaway is simple: IGA is the control system for digital risk, the foundation of zero trust, and the evidence trail that boards need for regulators and investors. Without it, companies risk breaches, regulatory fines, missed disclosures, and loss of market trust. However, there is also an opportunity. With an IGA architecture in place, boards gain measurable resilience, faster audits, and the ability to show ROI in just a few quarters.</p>

<p>In this piece, we’ll build out a reference architecture for your IGA Blueprint. This guide is vendor agnostic, instead it outlines the key building blocks and the relationships between them.</p>

<h2 class="wp-block-heading">Reference Architecture: The Core Layers of IGA </h2>

<p>If IGA is indeed a board-level concern, the next logical step is to show the board what a good outcome looks like. That is the purpose of a reference architecture, it is a blueprint of the essential layers that every enterprise needs in place to govern identity effectively.</p>

<p>These layers are non-negotiable building blocks of modern identity governance. Different organizations might use different language to describe some of the business functions included, but the processes and outcomes should be similar. Each layer addresses real-world weaknesses that attackers exp[loit and regulators scrutinize. Together, they form the control plane that allows boards and executives to both reduce risk and prove compliance.</p>

<h3 class="wp-block-heading">The Core Layers of IGA</h3>

<ul class="wp-block-list">
<li><strong>Identity Sources &amp; Context: </strong>The “source of truth” for who people are, who vendors are, and what machines or AI agents exist. Without authoritative sources, everything else falls apart.<br /></li>

<li><strong>IGA as the Control Plane: </strong>Where governance actually happens: automating joiner/mover/leaver processes, approving or denying access requests, enforcing segregation-of-duties rules, and running certifications. This is the heartbeat of the architecture.<br /></li>

<li><strong>Zero Trust Enforcement: </strong>Access is never granted by default. Instead, users must prove themselves continuously via SSO, MFA, device posture, and least-privilege rules, every time they connect.<br /></li>

<li><strong>ITDR (Identity Threat Detection &amp; Response): </strong>Because policies aren’t enough, ITDR provides the ability to detect stolen tokens, anomalous logins, or suspicious privilege escalation and shut it down fast.<br /></li>

<li><strong>Privileged Access Management (PAM): </strong>Admin accounts are the master keys to the kingdom. PAM ensures they’re controlled, time-boxed, monitored, and rotated whether human or machine.<br /></li>

<li><strong>Third-Party &amp; Supplier Access: </strong>Many of today’s breaches start with a vendor. Extending IGA controls to suppliers ensures that partners play by the same rules and that offboarding happens the moment a contract ends.<br /></li>

<li><strong>AI Identity &amp; Data Guardrails: </strong>As AI systems become active participants in workflows, they must be governed as identities too. Who can they access? What can they see? How are their API keys rotated?<br /></li>

<li><strong>Evidence &amp; Reporting: </strong>You need proof. Audit trails, attestation reports, and clear metrics that map directly to DORA, NIS2, and SEC requirements. This is what lets the board sleep at night.</li>
</ul>

<p>We’ve laid out the core layers of the reference architecture, these building blocks make up an enterprise-grade identity governance program. But layers on a diagram won’t move the board. Now it’s time to establish KPIs and targets that you can measure against.</p>

<h2 class="wp-block-heading">Board-Ready KPIs and Targets (90-Day to 3-Quarter Trajectory)</h2>

<p>What directors, audit committees, and CFOs need is a scoreboard: a small set of measurable outcomes that prove whether the architecture is working and whether the investment is paying off.&nbsp;</p>

<p>In this section, we’ll lock down KPIs and targets so you can see and prove your progress.</p>

<p>Think of these as your CEO/CFO-safe metrics. They’re clear, auditable, and can be tied directly to regulatory requirements or financial returns. They also have the advantage of being time-bound: progress can be demonstrated in as little as three quarters.&nbsp;</p>

<p>We’ll break these KPIs into five groups.</p>

<h3 class="wp-block-heading">Identity Hygiene &amp; Lifecycle</h3>

<ul class="wp-block-list">
<li>Orphaned accounts (both human and non-human): Accounts without owners are a breach waiting to happen.
<ul class="wp-block-list">
<li>Target: Reduce known orphaned accounts by 80% in 2 quarters.</li>

<li>Tip: Reconcile IdP/IGA directories against HRIS and the vendor master/NHI registry. Prioritize by: app criticality, privilege level, data sensitivity, and last login.</li>
</ul>
</li>

<li>Time-to-deprovision (JML): When someone leaves, or a vendor contract ends, access should disappear immediately.
<ul class="wp-block-list">
<li>Target: ≤ 4 hours for SaaS; ≤ 24 hours for infrastructure.</li>

<li>Tip: Start the clock at the HR “termination effective” timestamp; stop it when tokens/sessions are revoked. Automate HRIS → IGA → SSO/SCIM, add a one-click “kill switch,” and run monthly mystery-user tests.</li>
</ul>
</li>

<li>% apps under SSO + SCIM-based lifecycle: Coverage is control; if it’s not behind SSO and SCIM, it’s hard to govern.
<ul class="wp-block-list">
<li>Target: 80% coverage; prioritize the top 50 apps by risk/use.</li>

<li>Tip: Build an app register (criticality, user count, SSO/SCIM support, owner). Migrate in waves (top 25, next 25, long tail). Require SSO/SCIM in new-app intake and vendor contracts.</li>
</ul>
</li>

<li>Service/NHI with owner + rotation policy: Bots and keys are identities too; unowned secrets become permanent backdoors.
<ul class="wp-block-list">
<li>Target: 95% have an accountable owner; secrets MTTR ≤ 7 days (vs. DBIR’s 94-day median).</li>

<li>Tip: Discover NHIs via cloud IAM, CI/CD, and secrets scanners. Require Owner and Purpose fields for any token/key. Enforce TTLs and auto-rotation; break builds on expired/unknown secrets. Weekly reports: “NHIs without owner” and “secrets &gt;7 days after exposure.”</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">Governance &amp; Assurance</h3>

<ul class="wp-block-list">
<li>% access under review: Certifications keep real-world access aligned with policy.
<ul class="wp-block-list">
<li>Target: ≥ 95% on schedule (quarterly for critical apps; semiannual for the rest).</li>

<li>Tip: Scope by risk tier. Show delta-only changes to reviewers. Auto-revoke non-responses after X days with advance reminders; escalate misses to the app owner’s VP.</li>
</ul>
</li>

<li>SoD violations (opened vs. closed) + age: Toxic combinations enable fraud; the point is how fast you burn down the backlog.
<ul class="wp-block-list">
<li>Target: ≥ 85% closed within 30 days.</li>

<li>Tip: Seed SoD rules from Finance (P2P/O2C/GL) and Cloud Ops (deploy vs. approve). Triage by monetary/material risk and privilege level. Track oldest open and repeat offenders; require compensating controls or removal.</li>
</ul>
</li>

<li>Exception debt (temporary access): “Temporary” tends to become permanent unless engineered to expire.
<ul class="wp-block-list">
<li>Target: ≥ 98% auto-expire on time.</li>

<li>Tip: Default expiry (e.g., 7 days) for all exceptions; disallow no-end-date grants. Monthly leadership report: exceptions &gt;30 days. Treat break-glass the same, time-boxed, recorded, reviewed.</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">Risk &amp; Detection</h3>

<ul class="wp-block-list">
<li>Privileged accounts with phishing-resistant MFA: Admins hold the master keys; weak MFA isn’t acceptable.
<ul class="wp-block-list">
<li>Target: 100% coverage.</li>

<li>Tip: Inventory privileged roles (cloud/domain admins, root, CI/CD, finance superusers). Enforce WebAuthn/FIDO2 or platform authenticators; block SMS/voice for these roles. Maintain a short, dated exceptions list with remediation owners.</li>
</ul>
</li>

<li>High-risk identity alerts MTTR (ITDR): Time-to-contain drives breach impact; automation wins.
<ul class="wp-block-list">
<li>Target: ≤ 1 hour to containment.</li>

<li>Tip: Pre-define “high risk” (token theft, impossible travel + privilege, lateral movement to crown-jewel apps). Auto-contain (kill sessions, revoke tokens, force reset). Measure start (alert create) and stop (containment evidence). Run a monthly game day.</li>
</ul>
</li>

<li>Third-party/vendor identities governed: Vendors are part of your attack surface, and often the easiest path in.
<ul class="wp-block-list">
<li>Target: ≥ 90% via IGA/SSO/PAM; inactive vendor access = 0.</li>

<li>Tip: Integrate vendor master with IGA. Make IdP-only onboarding a contract term. Require named vendor managers who attest access quarterly. Auto-disable on contract end or 30 days of inactivity.</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">Regulatory Readiness</h3>

<ul class="wp-block-list">
<li>DORA/NIS2 control attestations: You can’t comply without evidence; mapping controls avoids audit surprises.
<ul class="wp-block-list">
<li>Target: Controls mapped and evidenced across third-party risk, incident playbooks, and continuity.</li>

<li>Tip: Build a control-mapping matrix: <em>Reg requirement → Control owner → Evidence source → Test cadence</em>. Store proofs in an “evidence locker” with timestamps. Do quarterly mini-audits instead of annual scrambles.</li>
</ul>
</li>

<li>SEC 8-K readiness (4 business days): If identity failure triggers a material incident, the clock starts immediately.
<ul class="wp-block-list">
<li>Target: Able to determine materiality and draft disclosure within 4 business days; tabletop tested.</li>

<li>Tip: Define a materiality rubric, escalation tree (CISO–GC–CFO–IR), and pre-approved templates. Time the tabletop from detection → decision → draft and stage identity evidence (logs, revokes, certifications).</li>
</ul>
</li>
</ul>

<h3 class="wp-block-heading">ROI &amp; Efficiency</h3>

<ul class="wp-block-list">
<li>License reclamation via deprovisioning: Every orphaned seat is wasted spend; deprovisioning helps fund IGA.
<ul class="wp-block-list">
<li>Target: Report gross savings/quarter; make the number visible to Finance.</li>

<li>Tip: Focus on the top 10 apps by spend. Link revokes to seat removal (not just disabling). Publish a monthly “savings realized” report and forecast next-quarter savings from today’s pipeline.</li>
</ul>
</li>

<li>Access request cycle time: Faster access improves productivity, without increasing risk when guardrails are solid.
<ul class="wp-block-list">
<li>Target: Reduce median hours; show productivity regained.</li>

<li>Tip: Offer pre-approved catalog roles for low-risk access with auto-approval. Route only sensitive requests to multi-step approvals. Instrument median by app and owner; spotlight bottlenecks.</li>
</ul>
</li>

<li>Audit prep time: Continuous evidence shrinks effort and findings.
<ul class="wp-block-list">
<li>Target: Fewer hours vs. last cycle; fewer exceptions/findings.</li>

<li>Tip: Move to continuous evidence collection. Keep “audit-ready packs” per control (policy, config, sample, attestation). Give auditors read-only access to standard exports; track hours saved YoY.</li>
</ul>
</li>
</ul>

<p>This a comprehensive list of KPIs and Targets moving forward. The best way to operationalize this quickly is to pick the right denominators (i.e. top 50 apps by risk/spend + all privileged/NHI + all vendors), set a weekly burn-down goal for backlog KPIs (i.e. orphaned, SoD, exceptions), and automate timestamps for time-to-deprovision, mean time to respond/recover, and reviews (access certifications).&nbsp;</p>

<p>A lot of organizations estimate numbers, but they aren’t measuring them. But, regulators and auditors don’t want your gut feel, they want system logs. Ensure that you are always measuring and making progress on those numbers.&nbsp;</p>

<h2 class="wp-block-heading">Operating Model &amp; Governance</h2>

<p>A blueprint and a set of KPIs is only half the job. The other half is making sure the right people own the right parts of the system. This is where your operating model is critical.&nbsp;</p>

<p>Think of it as an accountability map:</p>

<ul class="wp-block-list">
<li>Who sets the rules</li>

<li>Who enforces the rules</li>

<li>Who provides the oversight</li>
</ul>

<h3 class="wp-block-heading">The Board and Committees</h3>

<p>The board and its audit/risk committee own the highest level of responsibility. They don’t manage the day-to-day minutia, but they do keep track of progress on a longer time horizon.&nbsp;</p>

<p>Board and Audit/Risk Committee Responsibilities:</p>

<ul class="wp-block-list">
<li>Set the organization’s risk appetite for identity and access.</li>

<li>Review KPI dashboards quarterly just as they do for financials</li>

<li>Oversee compliance with regulatory regimes such as the SEC cyber disclosure, DORA, and NIS2</li>
</ul>

<p>Their job is to ask tough questions in response to what they see. As KPIs start to roll in and conversations with regulators proceed, the board must keep focus on what matters.</p>

<p><em>“How many orphaned accounts remain?”</em></p>

<p><em>“Are we within SLA for vendor offboarding?”</em></p>

<p><em>“Can we prove it if regulators call?”</em></p>

<p>Often, the most importan thing they can do at this level is say <em>“Prove it to me before I have to prove it to someone else.”</em></p>

<h3 class="wp-block-heading">The Executive Triad (CISO, CIO, CFO)</h3>

<p>The executive triad consists of the CISO (accountable), CIO (co-owner), and CFO (controls). Together, these three roles create the charter, policy, and funding for identity governance.&nbsp;</p>

<ul class="wp-block-list">
<li><strong>CISO:</strong> Ultimately responsible for IGA control effectiveness and for reporting the results to the board</li>

<li><strong>CIO: </strong>Shares ownership, particularly around integration with infrastructure and the application portfolio</li>

<li><strong>CFO: </strong>Responsible for cost controls, ROI measurement, and financial compliance</li>
</ul>

<h3 class="wp-block-heading">The IGA Council</h3>

<p>Now we are at the level of daily execution. Your IGA council is a cross-functional team. A group that meets regularly (bi-weekly or monthly) to keep everyone in lockstep throughout the organmization. The IGA council should include representatives from:&nbsp;</p>

<ul class="wp-block-list">
<li>Security</li>

<li>IT/Identity Operations</li>

<li>HR</li>

<li>Procurement</li>

<li>Legal</li>

<li>Application Owners</li>
</ul>

<p>The council is responsible for the practical elements like the Segregation of Duties catalog, the Joiner/Mover/Leaver SLAs, and Vendor Access Policies. Their work ensures that there is allingment across functions so no single team carries the full burder <em>or </em>stalls the entire initiative.&nbsp;</p>

<p>In Summary:&nbsp;</p>

<ul class="wp-block-list">
<li><strong>Board:</strong> Approves the risk appetite and receives regular attestations.</li>

<li><strong>CISO:</strong> Accountable for IGA controls being effective and reported.</li>

<li><strong>IT Ops/Identity Team:</strong> Responsible for lifecycle automation, connectors, SCIM integration, and operational execution.</li>

<li><strong>App Owners:</strong> Approve or deny access, maintain SoD policies, and attest to who should have access.</li>

<li><strong>Procurement/Vendor Management:</strong> Ensure contracts include identity requirements and that offboarding happens automatically when agreements end.</li>
</ul>

<h2 class="wp-block-heading">Controls Blueprint: Tying IGA to Frameworks and Regulations</h2>

<p>Now that we’ve established the architecture and operating model, the next question a board or regulator will ask is, “How do these controls line up with recognized frameworks or laws?”</p>

<p>To answer that, we will now map your IGA program to relevant frameworks and regulations. This step is important because it shows that your initiative is anchored to external standards, it’s not simply a homegrown series of ideas.&nbsp;</p>

<h3 class="wp-block-heading">NIST Cybersecurity Framework 2.0&nbsp;</h3>

<p><a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">NIST CSF 2.0</a> is one of the most known and respected playbooks for cybersecurity governance in the U.S. and abroad. From the framework, there are two areas especially relevant to identity.</p>

<ul class="wp-block-list">
<li><strong>PR.AA (Identity Mgmt, Authn &amp; Access Control):</strong> From page 19 of the CSF 2.0, this section expects that organizations will manage identity lifecycles, enforce MFA, apply least privilege, vault and rotate credentials, prevent toxic access combinations, and conduct periodic access certifications. In other words, this is the day-to-day work of IGA. These are tasks for which the IGA council should focus to achieve. </li>

<li><strong>GV (Govern): </strong> The “<a href="https://csf.tools/reference/nist-cybersecurity-framework/v2-0/gv/">Govern</a>” function is new in CSF 2.0 and makes identity governance explicitly a board responsibility. It expects boards to set risk appetite, assign roles and responsibilities, manage supply-chain identity exposure, and track metrics for continuous improvement. This is the board’s call for direct accountability.</li>
</ul>

<h3 class="wp-block-heading">DORA (Digital Operational Resilience Act)</h3>

<p>Effective in Europe’s financial sector since January 2025, DORA requires companies to prove they can withstand ICT and third-party disruptions. For identity, that means demonstrating:</p>

<ul class="wp-block-list">
<li>Strong vendor access controls</li>

<li>Rapid revocation of third-party accounts</li>

<li>Tested incident playbooks and continuity plans</li>
</ul>

<h3 class="wp-block-heading">NIS2 Directive</h3>

<p>NIS2 expands obligations well beyond finance, making identity and least privilege first-class controls across industries like healthcare, energy, and digital services. Boards need to show they’ve assessed supply-chain risks and put governance in place for all third-party and privileged access.</p>

<h3 class="wp-block-heading">SEC Cyber Disclosure Rule</h3>

<p>In the U.S., public companies must disclose material cyber incidents within <strong>four business days</strong>. This raises identity governance from a “back office” activity to a board reporting requirement. If an identity or access failure leads to a breach, the board must be able to demonstrate:</p>

<ul class="wp-block-list">
<li>They had visibility into identity risks</li>

<li>They had tested playbooks for escalation and disclosure</li>

<li>They can provide evidence of access governance at the time of the incident</li>
</ul>

<h3 class="wp-block-heading">Why This Matters</h3>

<p>By explicitly mapping your IGA controls to NIST CSF and overlaying DORA, NIS2, and SEC requirements, you create a single story for auditors, regulators, and the board. Instead of a patchwork of policies, you can show:</p>

<ul class="wp-block-list">
<li>This control aligns with NIST.</li>

<li>This same control satisfies DORA/NIS2/SEC requirements.</li>

<li>Here’s the evidence (audit logs, certifications, revocations).</li>
</ul>

<p>This reduces redundancy, simplifies reporting, and ensures the board can answer the toughest regulatory question: <em>“Can you prove who had access, when, and why?”</em></p>

<h2 class="wp-block-heading">Build the SoD/Access Policy Backbone</h2>

<p>Once the architecture and governance model are in place, the next priority is to <strong>codify access rules</strong>; what combinations are allowed, what must be blocked, and how often they’re checked. This is your Segregation of Duties (SoD) and access policy backbone.</p>

<p>The SoD/Access Policy Backbone is a structured set of rules and guardrails that define who can do what across critical applications. It ensures no one person (or account) has too much unchecked power.&nbsp;</p>

<p>Think of it like any other task. You want a separation of duties to ensure accountability and accuracy. You want different people creating a vendor <em>and</em> approving payments, or pushing code <em>and</em> approving its release.&nbsp;</p>

<h3 class="wp-block-heading">Core Components</h3>

<p>The backbone of any effective identity governance program is built on a small set of <strong>practical components</strong>. These define <em>where to focus</em>, <em>what rules to enforce</em>, <em>how exceptions are handled</em>, and <em>how often access is checked</em>. Keeping this simple but structured makes it easier for teams to execute and for boards to oversee.</p>

<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Component</strong></td><td><strong>What It Is</strong></td><td><strong>Who’s Responsible</strong></td><td><strong>Example</strong></td></tr><tr><td><strong>Critical Apps Inventory</strong></td><td>Identify the 50 most important applications by data sensitivity and business impact (“blast radius”). Each must have a clear owner.</td><td>App Owners (with oversight from IT/IGA Council)</td><td>Salesforce, Workday, AWS, Jira; each tagged with owner and risk rating.</td></tr><tr><td><strong>SoD Library</strong></td><td>A set of prebuilt rules that block toxic combinations of access. Seeded from audit findings and real incidents.</td><td>IGA Council + App Owners</td><td>Finance: “Create vendor” + “Approve payment.” Engineering: “Deploy code” + “Approve release.”</td></tr><tr><td><strong>Access Request &amp; Emergency Access Patterns</strong></td><td>Standardize how users request access and how emergency (“break-glass”) access is granted. Ensure all are time-boxed, logged, and auto-expire.</td><td>IT Ops/Identity Team</td><td>A developer requests temporary DB admin rights; system auto-revokes after 24 hours.</td></tr><tr><td><strong>Certification Cadence</strong></td><td>Risk-based access reviews. High-risk apps reviewed quarterly; lower-risk apps semiannually. Auto-revoke if reviewers don’t respond.</td><td>App Owners (audited by Compliance)</td><td>Quarterly review in Workday; semiannual review in Jira. Non-responses trigger auto-removal of access.</td></tr></tbody></table></figure>

<p>This backbone turns abstract “least privilege” into tangible, enforceable rules. It gives the board confidence that fraud opportunities are minimized, regulators evidence that toxic combinations are managed, and business leaders assurance that emergency access is possible without leaving permanent backdoors.</p>

<h2 class="wp-block-heading">SaaS Sprawl Taming Plan (Fast Wins That Scale)</h2>

<p>SaaS sprawl is no longer measured in the dozens or even the hundreds. Torii’s research shows enterprise organizations run an average of ~<a href="/reports/saas-benchmark-annual-report-2026">1,850 apps</a>, far higher than the ~100–275 apps reported by <a href="https://www.okta.com/reports/businesses-at-work/">Okta</a>. For boards and executives, this is more than just a cost problem, it’s a governance and compliance challenge.&nbsp;</p>

<p>Every new app brings new identities, new entitlements, and new opportunities for oversight failures.</p>

<p>The good news: taming SaaS sprawl doesn’t require boiling the ocean. A phased, 180-day plan delivers fast wins, scales to enterprise portfolios, and works for mid-market companies with leaner teams.</p>

<h3 class="wp-block-heading">Phase 1 (0–30 days): Get Control of the Obvious</h3>

<ul class="wp-block-list">
<li><strong>SSO coverage for top 25 apps.</strong> Bring your most-used, highest-risk apps under single sign-on, and enable SCIM where available.</li>

<li><strong>Stop shadow IT invites.</strong> Put a hard stop on direct app invitations; enforce identity-provider onboarding only.</li>

<li><strong>Automate deprovisioning.</strong> Tie HR terminations and vendor contract ends directly to automated revokes. This closes the biggest “back door” first.</li>
</ul>

<p><em>Who owns it:</em> IT Ops/Identity team executes; App Owners and HR ensure onboarding/offboarding events are properly triggered.</p>

<h3 class="wp-block-heading">Phase 2 (30–90 days): Address Hidden Risks</h3>

<ul class="wp-block-list">
<li><strong>Service account census.</strong> Inventory all non-human accounts, assign owners, and rotate high-risk secrets.</li>

<li><strong>Certify access for top-risk apps.</strong> Run your first round of certifications on the most critical applications. Purge orphaned accounts and close aging SoD violations.</li>

<li><strong>Normalize exception handling.</strong> Ensure temporary access is time-boxed, logged, and auto-expiring.</li>
</ul>

<p><em>Who owns it:</em> IGA Council oversees; App Owners validate; Internal Audit monitors exception debt.</p>

<h3 class="wp-block-heading">Phase 3 (90–180 days): Scale and Mature</h3>

<ul class="wp-block-list">
<li><strong>Expand coverage.</strong> Push SSO/SCIM to cover ~80% of the portfolio, not just the top 25 apps.</li>

<li><strong>App-level SoD.</strong> Implement segregation-of-duties policies directly in SaaS apps that support it.</li>

<li><strong>Vendor portals.</strong> Bring supplier-facing access into the same IGA, SSO, and PAM flows as employees.</li>

<li><strong>Test response.</strong> Add ITDR detections across IdP/IGA/PAM, then run a red-team tabletop focused on identity misuse (we’ll cover more on IDTR in the next section).</li>

<li><strong>Refresh KPIs.</strong> Update the board-level KPI dashboard, set new targets, and establish next-year benchmarks based on progress.</li>
</ul>

<p><em>Who owns it:</em> CIO sponsors; CISO validates ITDR readiness; Board reviews new KPI trends.</p>

<h3 class="wp-block-heading">Why This Matters</h3>

<p>For enterprises, the scale (1,850 apps on average) makes SaaS governance a board-visible risk. For mid-market firms, fast growth means sprawl sneaks up faster than expected. This plan delivers:</p>

<ul class="wp-block-list">
<li><strong>Quick wins in the first month</strong> (orphaned accounts gone, SSO on critical apps).</li>

<li><strong>Risk reduction in the first quarter</strong> (service accounts, certifications, vendor offboarding).</li>

<li><strong>Mature governance by six months</strong> (broad coverage, tested detection, refreshed KPIs).<br /></li>
</ul>

<h2 class="wp-block-heading">ITDR Complements IGA (How They Work Together)</h2>

<p>Even the best access policies can’t stop every attack. That’s why <strong>Identity Threat Detection &amp; Response (ITDR)</strong> has become a critical partner to IGA. The two are designed to work hand-in-hand:</p>

<ul class="wp-block-list">
<li><strong>IGA prevents</strong> issues by ensuring the right people have the right access at the right time.</li>

<li><strong>ITDR detects and responds</strong> when accounts, tokens, or policies are misused despite those guardrails.</li>
</ul>

<p>Together, they close the loop: prevention on the front end, detection and containment on the back end.</p>

<h3 class="wp-block-heading">Playbook Intersections (Examples)</h3>

<ul class="wp-block-list">
<li><strong>Suspicious impossible travel</strong><strong><br /></strong> If a login shows up in two countries within minutes, ITDR auto-challenges the session. If it’s confirmed malicious, <strong>IGA policy</strong> revokes access while <strong>ITDR</strong> invalidates sessions and rotates tokens.</li>

<li><strong>Privilege escalation outside policy</strong><strong><br /></strong> When a user suddenly gains admin rights outside approved channels, <strong>PAM</strong> cuts the session, <strong>IGA</strong> generates an exception ticket, and <strong>ITDR</strong> alerts the SOC while storing evidence for audit.</li>

<li><strong>Leaked secret detected</strong><strong><br /></strong> If a secret (API key, token, password) shows up in a repo or monitoring feed, <strong>ITDR</strong> raises a high-severity alert. Then <strong>IGA/PAM</strong> rotate and re-issue credentials, forcing the owner to attest, targeting a mean-time-to-remediation of ≤ 7 days, compared to the DBIR’s 94-day median.<br /></li>
</ul>

<h3 class="wp-block-heading">Why This Matters</h3>

<p>For boards and executives, the key takeaway is that IGA and ITDR aren’t competing tools frameworks, they’re complementary layers of defense. IGA minimizes the number of doors into the enterprise; ITDR ensures that when a door is picked, the alarm rings and the lock is changed immediately.</p>

<p>This combination is what allows organizations to not only reduce breach likelihood but also meet audit and regulatory expectations for continuous monitoring and rapid response.<br /></p>

<h2 class="wp-block-heading">Executive ROI Model (Make Finance Love This)</h2>

<p>Identity governance only resonates at the board level if it’s framed in terms of <strong>financial outcomes</strong>. For directors and CFOs, the question is simple: <em>“What’s the return on this investment?”</em> The answer comes in two parts:<br />1. Hard savings you can measure today<br />2. Risk-adjusted benefits that protect against tomorrow’s losses.</p>

<h3 class="wp-block-heading">Hard Savings</h3>

<ul class="wp-block-list">
<li><strong>License reclamation through timely deprovisioning.</strong> Every orphaned seat costs money. By reclaiming SaaS licenses when users leave, you save directly: <em>number of seats × monthly license cost × reclaimed seats.</em> Finance teams see this as bottom-line savings.</li>

<li><strong>Audit prep reduction.</strong> Automated evidence collection and continuous certifications cut the hours spent on audit prep. Multiply saved hours by blended staff rates, then add in the reduced fines and fewer exceptions. That’s efficiency in dollars.</li>

<li><strong>Fewer privilege tickets.</strong> With cataloged roles and auto-approval guardrails, IT spends less time on access requests. The savings come in both reduced ticket volume and faster productivity for end users.<br /></li>
</ul>

<h3 class="wp-block-heading">Risk-Adjusted Benefits</h3>

<ul class="wp-block-list">
<li><strong>Expected Loss Avoided.</strong> The formula: <em>(Reduction in breach likelihood) × ($4.4M global average cost, per IBM)</em>. Regionalize where possible. Even modest improvements in likelihood reduction translate into millions of dollars in avoided loss.</li>

<li><strong>Ransomware containment and non-payment posture.</strong> Verizon’s 2025 DBIR shows that most organizations now decline to pay ransom. That makes <strong>response speed</strong> critical. Containing identity-driven ransomware quickly avoids secondary costs: PR damage, legal fees, downtime, and lost customer trust.<br /></li>
</ul>

<h3 class="wp-block-heading">Time-to-Value</h3>

<p>Boards don’t want ROI that takes years to materialize. Identity governance delivers visible results in <strong>2–3 quarters</strong> if you focus on the right KPIs:</p>

<ul class="wp-block-list">
<li>Orphaned accounts down</li>

<li>Time-to-deprovision reduced</li>

<li>SSO/SCIM coverage up</li>

<li>SoD backlog reduced</li>
</ul>

<p>Each of these can be tracked quarter by quarter, giving executives clear evidence that the program is paying off.</p>

<h3 class="wp-block-heading">Why Finance Should Care</h3>

<ul class="wp-block-list">
<li><strong>Direct savings</strong> (licenses, audit prep) show up in the P&amp;L quickly.</li>

<li><strong>Risk-adjusted benefits</strong> protect against catastrophic losses that could wipe out annual earnings.</li>

<li><strong>Faster time-to-value</strong> means this isn’t a long-term “trust us” program, it’s measurable progress within the board’s reporting cycle.<br /></li>
</ul>

<h2 class="wp-block-heading">Conclusion: From IT Project to Boardroom Priority</h2>

<p>Identity Governance &amp; Administration can no longer be treated as a back-office IT exercise. The data is clear: identity failures drive the majority of breaches, regulators on both sides of the Atlantic are raising the bar, and SaaS portfolios have exploded into the thousands of apps. What once felt like a technical detail is now a board-level governance issue, with financial, regulatory, and reputational consequences.</p>

<p>The blueprint we’ve laid out shows how to take control. It starts with a reference architecture that unifies prevention and detection. It moves through board-ready KPIs that let directors measure progress the same way they measure financials. It establishes a governance model with clear accountability, ties directly to NIST CSF 2.0 and regulatory overlays, and translates into fast wins against SaaS sprawl. Finally, it delivers a finance-ready ROI story that connects identity governance to both hard savings and avoided losses.</p>

<p>For boards, the next step isn’t whether to invest in IGA, it’s how quickly to elevate it into the governance agenda. For executives, the challenge is execution: embedding identity controls into everyday operations, measuring results quarter by quarter, and keeping oversight tight as the business grows.</p>

<p>The takeaway is simple: identity is the new control plane for digital business risk. Treating it as such not only reduces breach likelihood, but also positions the organization to meet regulatory demands, satisfy auditors, and protect shareholder value.</p>

<h2 class="wp-block-heading">Appendix</h2>

<h3 class="wp-block-heading">Glossary of Critical Terms for the Enterprise IGA Blueprint</h3>

<p><strong>Access Certification (Access Review)</strong></p>

<p>A periodic attestation by managers/owners to confirm users still need their current access; removals and exceptions are recorded as audit evidence.</p>

<p><strong>Access Request Catalog (Catalog Roles)</strong></p>

<p>A menu of pre-approved role bundles that users can request; low-risk items auto-approve within guardrails to reduce ticket load.</p>

<p><strong>ABAC (Attribute-Based Access Control)</strong></p>

<p>Authorization based on user/app/resource attributes (e.g., department, device posture), often layered with RBAC.</p>

<p><strong>AD / Active Directory (incl. Entra ID)</strong></p>

<p>Microsoft’s directory platforms that store identities, groups, and policies and act as core identity stores for many enterprises.</p>

<p><strong>AI Identity &amp; Data Guardrails</strong></p>

<p>Policies that treat AI systems/agents as identities—governing what data they can access, which plugins/APIs they can use, and how their secrets are managed.</p>

<p><strong>API Key / Token</strong></p>

<p>A credential used by software and services (non-human identities) to authenticate to systems; must be issued, rotated, and revoked like user passwords.</p>

<p><strong>App Owner</strong></p>

<p>The accountable person for an application’s access policies, approvals, SoD rules, and certifications.</p>

<p><strong>Audit Evidence / Evidence Locker</strong></p>

<p>Time-stamped artifacts (logs, exports, screenshots, tickets, attestations) stored systematically to prove controls are operating.</p>

<p><strong>Audit-Ready Pack</strong></p>

<p>A pre-assembled set of policy, configuration, samples, and evidence for a specific control, prepared for auditors/regulators.</p>

<p><strong>Auto-Revoke (Non-Response)</strong></p>

<p>A rule that removes access if a reviewer does not complete a certification by the deadline.</p>

<p><strong>Blast Radius (Business Impact)</strong></p>

<p>The potential harm if a system or identity is compromised (financial, regulatory, operational); used to prioritize “top 50” critical apps.</p>

<p><strong>Break-Glass (Emergency Access)</strong></p>

<p>A tightly time-boxed, logged, and monitored elevation path used in emergencies; must auto-expire and be reviewed afterward.</p>

<p><strong>CMDB (Configuration Management Database)</strong></p>

<p>A repository of infrastructure/services metadata that helps discover machines, service accounts, and ownership.</p>

<p><strong>Compensating Control</strong></p>

<p>An alternate control that reduces risk when a preferred control (e.g., removing a SoD violation) is temporarily infeasible.</p>

<p><strong>Credential Vaulting / Secret Vault</strong></p>

<p>Secure storage for passwords, keys, and certificates, typically managed by PAM; supports rotation and access auditing.</p>

<p><strong>CSF (NIST Cybersecurity Framework) 2.0</strong></p>

<p>A widely used framework; this guide maps IGA to <strong>PR.AA</strong> (Identity/Access outcomes) and <strong>GV</strong> (Govern).</p>

<p><strong>Deprovisioning (Termination Revocation)</strong></p>

<p>Automated removal of accounts/entitlements when people leave or vendors/contracts end; measured as <strong>TTD</strong>.</p>

<p><strong>Device Posture</strong></p>

<p>Security state of a device (OS version, disk encryption, EDR present) used in Zero Trust access decisions.</p>

<p><strong>Disclosure (SEC 8-K Item 1.05)</strong></p>

<p>U.S. requirement to disclose material cyber incidents within four business days of determining materiality.</p>

<p><strong>DORA (Digital Operational Resilience Act)</strong></p>

<p>EU regulation for financial entities focusing on ICT/third-party resilience; requires strong vendor access governance and tested response.</p>

<p><strong>Entitlement / Permission</strong></p>

<p>A discrete right in an application (e.g., “Billing Admin,” “Export Data”) that should be role- or policy-managed.</p>

<p><strong>Exception / Exception Debt</strong></p>

<p>Temporary access granted outside standard policy; becomes “debt” if not time-boxed and auto-expired.</p>

<p><strong>Expected Loss Avoided (ELA)</strong></p>

<p>Risk ROI metric: <em>(Reduction in breach likelihood) × (Average breach cost)</em>; used to quantify the financial impact of IGA.</p>

<p><strong>FIDO2 / WebAuthn (Phishing-Resistant MFA)</strong></p>

<p>Modern authentication standards using hardware or platform authenticators resistant to credential-phishing attacks.</p>

<p><strong>Form 8-K (Material Cyber Incident)</strong></p>

<p>The SEC filing used to disclose material cyber events; requires timely, evidence-backed decisioning on materiality.</p>

<p><strong>Govern (NIST CSF 2.0 GV)</strong></p>

<p>Framework function assigning board-level accountability for risk appetite, roles/responsibilities, supply-chain oversight, and metrics.</p>

<p><strong>HRIS (Human Resources Information System)</strong></p>

<p>The source of truth for workforce lifecycle events (hire, transfer, termination) that trigger provisioning/deprovisioning.</p>

<p><strong>IAM (Identity &amp; Access Management)</strong></p>

<p>Operational systems that authenticate and authorize users (IdP, directories, SSO, MFA); IGA governs policy on top of IAM.</p>

<p><strong>IGA (Identity Governance &amp; Administration)</strong></p>

<p>The policy/control plane that governs <strong>who</strong> gets <strong>what</strong> access, <strong>why</strong>, <strong>when</strong>, and <strong>for how long</strong>, with auditability (JML, requests, approvals, SoD, certifications).</p>

<p><strong>IGA Council</strong></p>

<p>Cross-functional working group (Security, IT, HR, Procurement, Legal, App Owners) that runs the program: SoD library, JML SLAs, vendor policy.</p>

<p><strong>IdP (Identity Provider)</strong></p>

<p>The service that authenticates users and issues assertions/tokens for SSO (e.g., Okta, Entra ID, Ping).</p>

<p><strong>Impossible Travel</strong></p>

<p>A detection signal where successive logins from distant locations cannot be legitimate given the elapsed time.</p>

<p><strong>ITDR (Identity Threat Detection &amp; Response)</strong></p>

<p>Detection/response focused on identity systems and usage (token theft, anomalous privilege, lateral movement), with automated containment.</p>

<p><strong>JEA / JIT (Just-Enough / Just-In-Time)</strong></p>

<p>Least-privilege patterns that grant only the specific rights needed, and only for the time needed—often enforced through PAM.</p>

<p><strong>JML (Joiner / Mover / Leaver)</strong></p>

<p>Lifecycle processes that create, modify, and remove access based on HR or vendor events; must be automated and auditable.</p>

<p><strong>KPI (Key Performance Indicator)</strong></p>

<p>An outcome metric used to manage performance (e.g., orphaned accounts ↓80%, TTD ≤4h/24h).</p>

<p><strong>KRI (Key Risk Indicator)</strong></p>

<p>A forward-looking signal of risk (e.g., % privileged accounts without phishing-resistant MFA).</p>

<p><strong>Least Privilege</strong></p>

<p>Granting only the minimum access necessary to perform a task; cornerstone of Zero Trust and SoD.</p>

<p><strong>Machine Identity (Non-Human Identity, NHI)</strong></p>

<p>Service accounts, workloads, bots, CI/CD and API credentials that require ownership, rotation, and certification.</p>

<p><strong>Materiality (Cyber Incidents)</strong></p>

<p>A determination of whether an incident is important to investors; triggers SEC disclosure timelines.</p>

<p><strong>MFA (Multi-Factor Authentication)</strong></p>

<p>Authentication that requires two or more factors; <strong>phishing-resistant MFA</strong> (FIDO2/WebAuthn) is preferred for privileged access.</p>

<p><strong>MTTR (Mean Time to Respond/Recover)</strong></p>

<p>Average time from alert to containment/recovery for identity incidents; measured from system logs.</p>

<p><strong>NIS2 (EU Directive)</strong></p>

<p>EU directive expanding cyber obligations and enforcement across sectors; includes supply-chain and access governance expectations.</p>

<p><strong>NIST CSF 2.0 PR.AA</strong></p>

<p>Outcomes category covering identity management, authentication, access control, SoD, credential rotation, certifications.</p>

<p><strong>OAuth 2.0 / OIDC (OpenID Connect)</strong></p>

<p>Standards for delegated authorization and federated authentication, commonly used for modern SSO.</p>

<p><strong>Offboarding (Vendor / Workforce)</strong></p>

<p>The process of revoking all access and reclaiming licenses at contract end or termination; must be automated and evidenced.</p>

<p><strong>Orphaned Account</strong></p>

<p>An account without an active owner (often after turnover or vendor churn); a high-risk hygiene defect and core KPI.</p>

<p><strong>PAM (Privileged Access Management)</strong></p>

<p>Controls for high-risk/admin access: session brokering/recording, JIT elevation, vaulting and rotation for human and machine credentials.</p>

<p><strong>PBAC (Policy-Based Access Control)</strong></p>

<p>Authorization using policies that evaluate context (risk, device, location) at decision time.</p>

<p><strong>Phishing-Resistant MFA</strong></p>

<p>MFA that resists credential phishing and man-in-the-middle attacks (e.g., FIDO2/WebAuthn, platform passkeys).</p>

<p><strong>Privilege Escalation (Outside Policy)</strong></p>

<p>A user or service gaining higher privileges through unsanctioned paths; should trigger PAM cut-off and ITDR alert.</p>

<p><strong>Provisioning / Reconciliation</strong></p>

<p>Provisioning: creating accounts/entitlements from IGA to apps. Reconciliation: pulling actual app entitlements back to detect drift.</p>

<p><strong>RBAC (Role-Based Access Control)</strong></p>

<p>Authorization based on roles that bundle entitlements by job function; often combined with ABAC.</p>

<p><strong>RACI (Responsible, Accountable, Consulted, Informed)</strong></p>

<p>A responsibility model clarifying who owns what across board, executives, council, and operations.</p>

<p><strong>Risk Appetite (Identity)</strong></p>

<p>The level of identity/access risk the board is willing to accept, used to set targets and thresholds.</p>

<p><strong>ROI (Return on Investment)</strong></p>

<p>Financial returns from IGA: hard savings (licenses, audit hours) and risk-adjusted benefits (Expected Loss Avoided).</p>

<p><strong>SCIM (System for Cross-domain Identity Management)</strong></p>

<p>Open standard that automates account provisioning/deprovisioning across SaaS applications.</p>

<p><strong>SaaS Sprawl</strong></p>

<p>Rapid growth of applications and identities (often &gt;1,800 in enterprises) that strains governance, offboarding, and SoD control.</p>

<p><strong>SAML (Security Assertion Markup Language)</strong></p>

<p>A federation standard used for SSO, especially with legacy or enterprise apps.</p>

<p><strong>SEC Cyber Disclosure Rule</strong></p>

<p>U.S. rule requiring timely disclosure of material cyber incidents and governance reporting; pushes identity oversight to the board.</p>

<p><strong>Secret / Secret Rotation</strong></p>

<p>Any credential (password, token, key) used by humans or services; rotation is the scheduled or event-driven replacement of that secret.</p>

<p><strong>Secrets MTTR</strong></p>

<p>Time from detection of leaked/compromised secrets to rotation/reissue; target ≤7 days.</p>

<p><strong>Service Account</strong></p>

<p>A non-human account used by applications or automation; must have a named owner, purpose, and rotation policy.</p>

<p><strong>Shadow IT</strong></p>

<p>Systems acquired or used outside official IT/IGA processes (e.g., direct SaaS invites); increases risk and audit scope.</p>

<p><strong>SoD (Segregation of Duties)</strong></p>

<p>Policies preventing toxic combinations of access (e.g., create vendor + approve payment) to reduce fraud/error.</p>

<p><strong>SoD Library</strong></p>

<p>A documented set of toxic-combo rules across finance, engineering, cloud ops, and data domains, seeded by audits and incidents.</p>

<p><strong>SSO (Single Sign-On)</strong></p>

<p>One identity to access many apps via federation (SAML/OIDC); enables centralized policy and telemetry.</p>

<p><strong>Supplier / Third-Party Access</strong></p>

<p>Governed access for non-employees (vendors, partners, contractors) that must follow the same IGA/PAM rules and automated offboarding.</p>

<p><strong>Tabletop Exercise (Identity/Disclosure)</strong></p>

<p>A rehearsal of incident detection, materiality decisioning, and disclosure—validates playbooks and timing (e.g., SEC 4-day rule).</p>

<p><strong>Target Coverage (e.g., SSO/SCIM ≥80%)</strong></p>

<p>A measurable adoption goal that prioritizes the highest-risk or highest-use apps first, then scales to the long tail.</p>

<p><strong>Threat Telemetry (Identity)</strong></p>

<p>Signals from IdP, IGA, PAM, and SIEM used by ITDR to detect anomalies (impossible travel, token theft, privilege surge).</p>

<p><strong>Time-to-Deprovision (TTD)</strong></p>

<p>Elapsed time from HR/vendor termination event to last access revoked; measured from system timestamps.</p>

<p><strong>Time-to-Value (TTV)</strong></p>

<p>Window (often 2–3 quarters) to show KPI improvements (e.g., orphans ↓, TTD ↓, SSO/SCIM ↑, SoD backlog ↓).</p>

<p><strong>Token Invalidation / Session Kill</strong></p>

<p>Automated response that terminates active sessions and revokes tokens after suspected compromise.</p>

<p><strong>Top 50 Critical Apps</strong></p>

<p>The prioritized application set (by blast radius and data sensitivity) used for initial control rollout, certifications, and SSO/SCIM onboarding.</p>

<p><strong>Vendor Master</strong></p>

<p>System of record for suppliers/contractors used to trigger onboarding/offboarding and to scope third-party certifications.</p>

<p><strong>WebAuthn / Passkeys</strong></p>

<p>Standards enabling passwordless or phishing-resistant authentication using device-bound or roaming authenticators.</p>

<p><strong>Zero Trust (ZTA)</strong></p>

<p>“Never trust, always verify” architecture: continuous, context-aware access decisions (identity, device, risk) with no implicit network trust.</p>

<h3 class="wp-block-heading">Resources &amp; Further Reading</h3>

<h4 class="wp-block-heading">Breach &amp; Threat Landscape</h4>

<ul class="wp-block-list">
<li><strong>Verizon 2025 Data Breach Investigations Report (DBIR) — Executive summary (PDF)</strong><strong><br /></strong><a href="https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf">https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf<br /></a>Key stats on ransomware prevalence, human element, 3rd-party involvement, and leaked secrets remediation timelines.</li>

<li><strong>Verizon 2025 DBIR (full hub)</strong><strong><br /></strong><a href="https://www.verizon.com/business/resources/reports/dbir/">https://www.verizon.com/business/resources/reports/dbir/<br /></a>Landing page with links to the full report, snapshots, and visuals.</li>

<li><strong>DBIR Highlights Infographic (PDF)</strong><strong><br /></strong><a href="https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary-infographic.pdf">https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary-infographic.pdf<br /></a>Quick scan of the year’s key trends.</li>

<li><strong>IBM Cost of a Data Breach 2025 (Main Report Page)</strong><strong><br /></strong><a href="https://www.ibm.com/reports/data-breach">https://www.ibm.com/reports/data-breach<br /></a>Summarizes global average breach cost ($4.44M) and AI oversight gaps (97% lacked AI access controls; 63% lacked AI governance policies).</li>

<li><strong>IBM Press Release (AI-specific findings)</strong><strong><br /></strong><a href="https://newsroom.ibm.com/2025-07-16-IBM-Report-Cybersecurity-AI">https://newsroom.ibm.com/2025-07-16-IBM-Report-Cybersecurity-AI<br /></a>Highlights AI-related security risks from the 2025 study.</li>
</ul>

<h4 class="wp-block-heading">Frameworks &amp; Standards</h4>

<ul class="wp-block-list">
<li><strong>NIST Cybersecurity Framework 2.0 (Full Document)</strong><strong><br /></strong><a href="https://www.nist.gov/cyberframework">https://www.nist.gov/cyberframework<br /></a>Authoritative reference for governance and identity outcomes.</li>

<li><strong>NIST CSF 2.0 — PR.AA (Identity Mgmt, Authentication &amp; Access Control)</strong><strong><br /></strong><a href="https://csf.tools/reference/nist-cybersecurity-framework/v2-0/pr/aa/">https://csf.tools/reference/nist-cybersecurity-framework/v2-0/pr/aa/<br /></a>Category page to map IGA controls.</li>

<li><strong>NIST CSF 2.0 — Govern (GV) Function</strong><strong><br /></strong><a href="https://csf.tools/reference/nist-cybersecurity-framework/v2-0/gv/">https://csf.tools/reference/nist-cybersecurity-framework/v2-0/gv/<br /></a>Board-level governance expectations and outcomes.</li>

<li><strong>NIST CSF 2.0 FAQs</strong><strong><br /></strong><a href="https://www.nist.gov/cyberframework/faqs">https://www.nist.gov/cyberframework/faqs<br /></a>Helpful clarifications for board/Audit &amp; Risk discussions.</li>
</ul>

<h4 class="wp-block-heading">Regulations &amp; Oversight</h4>

<ul class="wp-block-list">
<li><strong>DORA (Digital Operational Resilience Act) — EIOPA Overview</strong><strong><br /></strong><a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en">https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en<br /></a>What’s in scope and what boards must evidence; in force since Jan 17, 2025.</li>

<li><strong>NIS2 — European Commission Press Release</strong><strong><br /></strong><a href="https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive">https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive<br /></a>EC opened infringement procedures against 23 Member States for missed transposition.</li>

<li><strong>SEC Cybersecurity Disclosure Final Rule (Release No. 33-11216)</strong><strong><br /></strong><a href="https://www.sec.gov/files/rules/final/2023/33-11216.pdf">https://www.sec.gov/files/rules/final/2023/33-11216.pdf<br /></a>The source of the 4-business-day incident disclosure requirement (Item 1.05).</li>

<li><strong>SEC Fact Sheet — Public Company Cybersecurity Disclosures</strong><strong><br /></strong><a href="https://www.sec.gov/files/33-11216-fact-sheet.pdf">https://www.sec.gov/files/33-11216-fact-sheet.pdf<br /></a>Plain-English summary for directors and GC/IR.</li>
</ul>

<h4 class="wp-block-heading">Identity Threat Detection &amp; Response (ITDR)</h4>

<ul class="wp-block-list">
<li><strong>Microsoft: Identity Threat Detection &amp; Response (Overview)</strong><strong><br /></strong><a href="https://www.microsoft.com/en-us/security/business/solutions/identity-threat-detection-response">https://www.microsoft.com/en-us/security/business/solutions/identity-threat-detection-response<br /></a>High-level overview of ITDR.</li>

<li><strong>Microsoft Learn — Defender for Identity: ITDR Dashboard</strong><strong><br /></strong><a href="https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-daily">https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-daily<br /></a>How teams operationalize detections and MTTR.</li>

<li><strong>Microsoft Learn — What is Defender for Identity?</strong><strong><br /></strong><a href="https://learn.microsoft.com/en-us/defender-for-identity/what-is">https://learn.microsoft.com/en-us/defender-for-identity/what-is<br /></a>Productized ITDR capabilities and scope.</li>
</ul>

<h4 class="wp-block-heading">SaaS Sprawl &amp; App Portfolios</h4>

<ul class="wp-block-list">
<li><strong>Okta: Businesses at Work 2025</strong><strong><br /></strong><a href="https://www.okta.com/reports/businesses-at-work/">https://www.okta.com/reports/businesses-at-work/<br /></a>App usage trends and average app counts by org size.</li>

<li><strong>Zylo: 2025 SaaS Management Index</strong><strong><br /></strong><a href="https://zylo.com/resources/guides/saas-management-index-2025/">https://zylo.com/resources/guides/saas-management-index-2025/<br /></a>Portfolio size, category growth, and license utilization benchmarks.</li>

<li><strong>Torii Research (2025)</strong> <em>(internal)</em><em><br /></em>Enterprise portfolios average ~1,850 apps. Contact Torii for methodology and briefing deck.</li>
</ul>

<h4 class="wp-block-heading">Machine / Non-Human Identities</h4>

<p><strong>CyberArk 2025 Identity Security Landscape</strong><strong><br /></strong><a href="https://www.cyberark.com/resources/analyst-research/2025-identity-security-landscape">https://www.cyberark.com/resources/analyst-research/2025-identity-security-landscape<br /></a>Source of the “machine identities outnumber humans 82:1” statistic.</p>

<p></p>]]></content><author><name>{&quot;display_name&quot;=&gt;&quot;John Baker&quot;, &quot;github&quot;=&gt;nil, &quot;linkedin&quot;=&gt;nil, &quot;twitter&quot;=&gt;nil, &quot;image&quot;=&gt;&quot;/assets/images/team/john-baker.jpg&quot;}</name></author><summary type="html"><![CDATA[The Enterprise IGA Blueprint: a board-ready framework with reference architecture, KPIs, and a 180-day plan to reduce identity risk and prove ROI.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://www.toriihq.com/assets/images/blog/the-enterprise-iga-blueprint.webp" /><media:content medium="image" url="https://www.toriihq.com/assets/images/blog/the-enterprise-iga-blueprint.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry></feed>