SailPoint, Inc. (SAIL)
NASDAQ: SAIL · Real-Time Price · USD
19.98
+0.10 (0.50%)
At close: Sep 15, 2026, 4:00 PM EDT
20.15
+0.17 (0.85%)
After-hours: Sep 15, 2026, 7:48 PM EDT
← View all transcripts

Investor Day 2026

Jun 16, 2026

Summary

The company is targeting $2.1B+ ARR by FY 2029, with $800M+ from AI-driven solutions and a SaaS-first model. Innovations like Agentic Fabric, real-time governance, and the Entro acquisition drive differentiation and rapid migration, while a hybrid pricing model and strong customer retention fuel growth.

Scott Schmitz
SVP of Investor Relations, SailPoint

Welcome. Thank you all for coming. Really appreciate everyone's effort to get here today. Thank you for all those joining on the web. We have a great program for you today that we're really excited to tell you our story. Before that, a little bit of housekeeping. If we go to the next slide, it's our safe harbor statement. This safe harbor will also be available in the presentation posted on the web. Now we're through that. Let me help frame what we're going to do today. I think there's really three key themes that you're going to hear throughout today. The first is innovation. You'll see this clearly in our advancements around AI and real-time governance, which are actively expanding our TAM.

I think you'll also notice it's not just what we're building, but it's the velocity at which we're bringing these things to market. The second theme throughout today is going to be differentiation. This starts with our depth and breadth of identity coverage, which gives us the required context to link human and non-human identities to their human owner. This really helps accelerate AI identity security for our enterprise customers. The third theme of the day is really the multiple paths to our fiscal 2029 targets. Whether it's acquiring new customers, expanding within our existing install base, or developing new routes to market, we have multiple catalysts that are designed to deliver durable top-line growth as well as expanding operating and free cash flow margins.

I think you'll hear those themes prevalent throughout today, so I just wanted to set the stage. The agenda for today, I'm not going to drain the slide, just in the interest of time so we can get into the program. We have a comprehensive lineup of product experts, go-to-market leaders, as well as partners and customers for you today. We have plenty of time for Q&A as well. Save your questions, we'll do those at the end of the first section and at the end of the day. With that, it's my great pleasure to get started and introduce SailPoint's CEO and Founder, Mark McClain. Mark.

Mark McClain
CEO and Founder, SailPoint

Well, good morning and welcome, everyone. It's so good to be with you today. If you look at the daily headlines, there's a lot coming at us. Rapid AI advancements, shifting markets, macro disruptions. We're operating in a period of unprecedented change, which I would prefer to refer to as the new normal. This new normal of constant change leads to a sense that to survive, you must adapt, all day, every day. For those of us who have navigated some pretty choppy waters before, things like COVID or the mortgage crisis or even 9/11, we know a fundamental truth. Disruptions always precede significant market redefinitions where new winners emerge and others get left behind.

In these times of deep uncertainty, the instinct for many companies is to just play it safe, to blend in, try to weather the storm. At SailPoint, we fundamentally reject that approach. We're not in this game just to survive. We're in it to win. To understand how we win, let's look at the evolution of our space. Let's talk about what's been changing in identity governance and administration, or IGA, and where it's going to go from here. Just as the overall technology market is undergoing a massive structural redefinition in the age of AI, IGA is also undergoing a massive structural redefinition.

We believe there are five dimensions of IGA in which critical shifts are happening. First, timing. We're moving from periodic policy time reviews to continuous real-time security posture. Second, structure. We're abandoning static, rigid governance in favor of dynamic adaptive security. Third, coverage. The scope of identity has aggressively expanded from humans to humans and agents, not or, and. All the supporting non-human identity elements. Fourth, privilege.

We are moving away from permanent privileged access for a few toward right-sized democratized privilege for all. Fifth, and surrounding all of it, defense. Security operations can no longer operate in various silos. Modern security operations must encompass everything from the cloud to the network to the device with identity at the absolute center. This isn't just an evolution of IGA I'm talking about. This is the evolution of enterprise security itself. To have proof of this evolution, let's just take a look at some math.

Years ago, when we went public the first time in 2017, we defined the market opportunity as about $10 billion. By our Analyst and Investor Day, the first one we did in 2021, we'd expanded that to about a $20 billion TAM. When we reemerged as a public company in 2025, we believe that addressable market expanded to $55 billion. Today we can credibly claim that the TAM has now expanded to $90 billion for this marketplace. This isn't about a growing TAM, it's about the validation of identity as the core of security. This $90 billion TAM reflects the aggressive expansion of traditional IGA to address challenges like agentic AI, next gen privilege, data access, and threat response.

Today you see these issues represented in distinct individual markets like ITDR, identity threat detection and response, ISPM, identity security posture management, and IVIP, a newer one, identity visibility and intelligent platforms. Now we believe all of these will be converging into something we call adaptive identity. Identity has become the critical element of enterprise security. Today we're going to tell you why SailPoint is positioned to be the biggest winner in that game. When a market gets attractive, it draws a lot of attention.

More companies jump into the game, the noise gets louder, and it's really loud in identity today. In fact, we say that the identity security market has entered a phase of message convergence as announcements and claims are arriving at an unprecedented pace, all with a pretty similar set of messages. With all that noise, it's tough to stand out. It's tough to separate the signal from all that noise. As Seth Godin once argued in a great book, in a crowded market, playing it safe is the riskiest strategy of all. A white cow is visible, but you stop noticing them after the first few. A purple cow, now that gets talked about, that gets remembered, that gets sought out.

Right now, the identity security market feels like it's full of a lot of white cows. Lots of vendors reacting to this shift by making the exact same announcements. Here's the reality for all of you behind all that noise. It is, as we say in Texas, all sizzle and no steak. As we also like to say in Texas, a lot of these competitors are big hat, no cattle. Anybody can put out a press release, talk about identity and AI. When it comes down to it, these vendors cannot handle the deep, messy complexity of the modern enterprise as it escalates into an agentic world. At SailPoint, we deliver the steak, not just the sizzle. We deliver the substance.

Fair question, how do we deliver that substance? It really comes down to three interrelated advantages, our breadth, our depth, and our unparalleled ability to accelerate into agentic AI. Let's start with depth. No one in this industry has our history or our granularity of control. We have 20 years of managing fine-grained human identity data by working with many of the world's largest, most complex enterprises. Today, we manage over 5 billion entitlements across those enterprises. In fact, we possess what we call the steel thread.

It's the ability to trace a human identity as it utilizes various non-human identity accounts and services, agents, et c, all the way down to the deepest, most granular data levels of the enterprise. You cannot build that overnight, and you cannot fake it. Our heritage is not a liability. It actually gives us credibility as this new world emerges. Not just depth, now there's also breadth. We are the trusted control plane for over 3,200 organizations, many of them in the Fortune 5,000.

We are actively governing over 145 million identities by automating more than 35 billion SaaS accounts changes every year. We don't manage just some subset of those human identities, we manage all of them. We are the number one cross-platform identity provider in the world today, whether it's Azure, AWS Bedrock, Salesforce, or even older legacy on-prem applications in our customers. Our platform connects, covers them all with breadth and depth. As they say, since a picture is worth a thousand words, or at least a few hundred to save economy, this two-by-two matrix should help. On the horizontal axis, you've got breadth.

In other words, how much of the identity landscape do you cover? On the vertical axis, you've got depth. How granular is your visibility and control? When you map out the core identity competitors and where they're coming from, the limitations are pretty obvious, right? If you look at the SSO and access management vendors, they absolutely cover breadth, right? They touch every employee identity or every human identity. Truthfully, they have very little depth. They're a mile wide and an inch deep. They have the ability to let you in the front door, as we've used this analogy with some of you before, what's inside, they aren't aware of. They're blind where you're going in the building.

On the other axis, if you look at the heritage of the PAM and privilege market, they have lots of depth, very little breadth. They govern a tiny fraction of all the identities in the enterprise and are virtually blind to the rest of the landscape. At SailPoint, 20 years of solving hard identity problems across the entire landscape means we have the pattern recognition that the others don't. As always, in these two-by-two charts, the place you want to be is the upper right-hand, isn't it?

The top right quadrant. SailPoint sits here pretty much alone in this collection of vendors. We believe no other company can viably claim that combination of breadth and depth at scale, period. Having both breadth and depth is, in fact, a pretty massive structural moat. Here's the critical part. AI is now becoming a significant multiplier to that advantage. If you feed AI shallow data from a tool that either lacks breadth or depth, you're going to get limited or maybe even questionable outcomes.

Because we possess 20 years of the deepest, broadest identity data on Earth, our AI is intelligent, very intelligent, extremely intelligent about what happens in all those complex interrelated entitlements. We're using it to massively accelerate and extend our lead, extending it to this newest paradigm, the wild explosion of the agentic workforce. We're not just about defending our current market share, we're aggressively capturing this new explosive TAM. That's by focusing on, again, the wild explosion of non-human identities, or NHIs, as you've heard them referred to, and agentic AI.

With that, we are establishing a powerful new growth engine, which we expect will drive over $100 million of AI-related ARR at the end of this fiscal year. Depth, breadth, and unparalleled AI acceleration. We believe SailPoint is uniquely positioned with the platform, the data, and the proven enterprise experience to get our customers where they want to go. As I said earlier, our vision to address this world is what we refer to as adaptive identity, and we believe it's the only way forward.

Dynamically adjusting access for all identities, human or non-human, based on real-time risk, context and observed behavior. We're bringing this vision to life through two distinct accelerated paths. First, we're sitting at the cutting edge of securing this rapidly expanding agentic workforce, specifically in the context of the human workforce. It's not just about securing agents, it's about securing them in the context of humans, and that's why the and matters so much. You cannot secure agents in a vacuum as some of these startups would have you believe.

To govern non-human identities, they must be tethered to a human owner or a human context. To conquer this new frontier, last month, we introduced the SailPoint Agentic Fabric right here at Nasdaq. It places agents into the context of that human workforce, bringing them fully under control. Ultimately, it ensures that the entire human and agentic environment remains secure in real-time, all the time. We're also focused on massively accelerating how customers can get to this future Nirvana state. As you know, many enterprises today are bogged down by massive technical debt.

They're paralyzed by trying to rip out rigid, broken legacy systems from other vendors, or some of them even have challenges to manage an upgrade from our own on-prem solution, IdentityIQ. Today we are radically simplifying this process to get our customers to Nirvana by introducing SailPoint Agentic Acceleration, which is a methodology, but it is powered by a brand-new technology we call the SailPoint Virtual Architect.

The SailPoint Virtual Architect maps all that legacy structure, wherever it is coming from, leverages AI, not just to do a lift and shift, but to design the most efficient solution in the new realm, then accelerate migration to that with unprecedented speed. Put really simply, we are using AI to map the path to AI, defining the ultimate Nirvana solution and accelerating our customers' ability to get there. We are going to do that faster and better than anyone. We are doing all of this through relentless ongoing innovation, both organic and inorganic.

In just a few minutes, you will hear from Chandra about the capabilities we have been busy building here at SailPoint, but we continue to strategically insert acquired technologies into our roadmap to accelerate our vision. Just yesterday, as you saw, we announced our intent to acquire Entro Security to deepen and widen, sound familiar? Our controls for non-human identities. We will continue to scour the landscape for cutting-edge technologies that help us bring our roadmap to life even faster. To wrap it up, we have been a leader in IGA space for many, many years. By pairing our two-decade human identity advantage with our new SailPoint Agentic Fabric, we believe we have the most complete adaptive identity solution in the market, bar none.

Now with SailPoint Agentic Acceleration, we can move customers to that desired destination faster than anyone else. To show you how exactly all of this is going to translate into undeniable financial execution, I am going to steal just a little bit of Brian's thunder coming up. Today, we are going to clearly demonstrate why we expect ARR growth to accelerate as we deliver more than $2.1 billion of ARR in fiscal 2029. We expect about 40% of that revenue to be AI generated, agentic related. We are also getting there responsibly, as Brian likes to say. When we hit that $2.1 billion milestone, we expect to generate at least $400 million of free cash flow. As I noted, Brian is going to go into this in a lot more detail in a few hours this morning.

Let me say it again. We expect SailPoint's growth to accelerate. The demand for enterprise-grade multi-cloud identity governance is exploding as organizations rush to secure their AI investments and machine environments. With our specialized focus, commitment to innovation, and the rapid scaling of these agentic solutions toward our $100 million target this year, SailPoint is distinctly positioned to continue to lead in the next era of identity security. As I close, let me turn this over to Chandra. Let me key him up a little bit by highlighting again the four big challenges we are focused on for our enterprise customers around the globe. First, they are looking to us to help them secure this wild explosion of agentic workforce in the context of their human workforce.

Secondly, they need us to help them move their enterprises to real-time adaptive identity security. Third, they need us to help them democratize privilege by ensuring dynamic, right-sized access for every identity, human or non-human. Fourth, we're going to help them bring identity and the security operations center together for truly effective, truly comprehensive threat response. With that, thanks again for joining us today. Let me now hand it over to my colleague, Chandra.

Speaker 3

[Presentation]

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Good morning, and welcome again. Mark really set the stage. What I'm going to do is really get into innovation. Talk about customer outcomes and really talk about how we are using AI. If nothing, I would like you to walk away with three things today. One is there are two big rock, big mega growth innovations that we are going to be working on for the next two years. One is agentic. Second one is we are moving governance of human beings, which we have done for 20 years, from static to real-time.

Number two, we fundamentally believe, just given the security world today, it's time to move all of our customers to a minimum of least privilege and zero standing privilege, and ultimately to our vision of autonomous identity, which is really think of it as a Waymo of the identity world. It's a self-correcting, self-healing platform. Third, we are quite excited about the three different ways in which we are using AI, and we are incredibly proud of the product velocity.

Our product velocity has gone up by two and a half times in the last 18 months, and it is continuing to accelerate. Before I dive into this, I want to set the stage for what we believe is a new normal in the world of threat and security. The way to think about this is the time it takes to go from finding a vulnerability, when you actually find a vulnerability, to actually a bad actor being able to exploit it. About three, four years ago, it used to about take a year, right?

When a large corporation found a vulnerability, they will actually issue a CVE, and it took the bad actors roughly about a year to get to it. As long as you patch it within that year, you're good. Today, that one year has come down to a day, and it's trending more towards an hour. Just think of that change, where from the moment you find a vulnerability to when it could be exploited, it's trending towards one hour. It's largely driven by advanced models like Mythos and GPT-5. It's organized cybercrime activity, dev environments being overly permissive. It's a combination of it.

But it's a stratospheric change in the world of security. It's really against this backdrop that we are shifting from just securing and governing humans to securing and governing human plus AI. When I say AI here, I mean broadly. Mark really referred to them as agents. It could be agents, non-human identity credentials, right? Bots, all of it inclusive. We at SailPoint think of all of it collectively. It's not just human plus AI. It's actually the ratio. The ratio matters. We are beginning to. Well, we are at roughly about one to 100 across all of our customer base, and it's trending more towards one to 1,000. So for every human, we are going to find about 1,000 AI identities or non-human identities.

At that scale, architecturally, you have to really shift to more of a real-time architecture, as well as what we call security in line. Meaning when you have the ratio of 1: 1,000, literally a global 1,000 will have millions, if not tens of millions of these non-human identities, right, that can do things autonomously. The only way you can actually manage and be secure is the ability to respond to a threat in real time with deep identity context. That's really what we are building here. Now, this human plus AI has actually introduced two fundamentally new identity security problems today.

What I want to do is frame those problems conceptually before I go deep into it. I'm going to just illustrate it with some very conceptual basic use cases, right? The first one is really about a human or an AI, a developer writing code and putting the code in a GitHub repo, or an agent or a human accessing an API. That itself is not new. The fact that the GitHub repo and the API, they have credentials, which are really machine-readable credentials, tokens, and keys. That is also not new.

What is new is the fact that these have been largely unmanaged and ungoverned, right? A lot of them, by the way, they would not be rotated for years and years. You can no longer afford it. If you leave a key now that is not rotated frequently, the chances are it's going to get hacked into and your code could be stolen. That is new. The second one is really the autonomous AI use case, which is you have a big agent calling smaller agents, right? The smaller agents are the sub-agents accessing application and data. This flow is very, very new.

This whole chain needs to be governed, right? They need to be discovered. You have to make sure they are authorized to only access the data they are supposed to on behalf of the human they are acting. These two conceptual use cases is what we refer to as the agentic security and governance problem. Now, on the human side, the question is what's changed? Because humans have always had access to application and data. What has changed is the fact that the bad actor now can use these advanced models, advanced tech, to really hack into these application and data in no time.

This is why this time the time to exploit a vulnerability going down to an hour it really matters. In that world, you can no longer rely on these applications and data being fully secure. You have to fundamentally reimagine how humans access this application and data. That's why static governance, static privilege is dead. You can't afford it. It's grossly insufficient. You have to really risk-evaluate every access a human or an agent has to the application and data.

That's what we mean by shifting human governance from static to real-time. These are the two problems we are fundamentally committed to solving. Our big growth innovations that I talked about, agentic, real-time human governance, are about solving those two problems. We launched [inaudible] Agentic Fabric, which is our fabric to solve end-to-end agentic here at the Nasdaq last month. It'll be GA in the next two months, in less than two months. Real-time human governance, all of you are familiar with our Identity Security Cloud, ISC. This is an upgrade to ISC. We are really delivering next generation human governance or real-time human governance through next generation ISC.

Atlas is the engine, it's a shared services layer. It's the engine that powers both of these innovations. Here's what we are excited about, which is solving the agentic problem. There is a new role in every large corporation today. It could be described as the head of AI, in some places it's actually committee and so on, but that's a new role. The real-time human governance is no longer the realm of just the identity department. It's the CISO and the entire CISO's office that's really responsible for it. We are becoming strategically more relevant as well as the wallet size. The wallet size goes up when you go solve these two problems with those two executive buyers.

This is why we are quite excited about where we are innovating. The solution to this, the SailPoint solution to this for both agentic as well as real-time human governance, has three pillars: discover, govern and protect. For the last 20 years, we have talked a lot about discover and govern, right? That's really what a great IGA platform does. We are now innovating on that for this new identity type called agents and machines. Protect is new. This is new. This is why SailPoint is no longer your old legacy IGA. It's not even your grandmother's identity platform or your parents' identity platform.

This is a new SailPoint, and we are really innovating on protect. I'll talk about what I mean by that. When Mark talked about how our TAM has really expanded, even since we went IPO from $55 billion-$90 billion, a good chunk of it is driven by the fact that we are governing a net new identity type called agents. It's also because both for agents and for humans, we are now not just in the discover and governance game, we are also in the protect game.

With that, let me just dive in and talk about what we are doing in both agentic as well as real-time human governance. I'm going to really focus on what's new and what makes us very unique in solving these problems. Starting with discovery. Look, we are super thrilled about the acquisition of Entro, which I think is very complementary to what we do. With that, we have the most robust, I can confidently say we have the most robust discovery mechanism of any agent, non-human identity type. Entro covers more than 1,200 non-human identity types. We have the most robust mechanisms to discover agents and machines and credentials from any platform in the world.

What makes us really special is the fact that we will be the registry. Which means the moment an agent or a non-human is discovered, it gets. Think of us as the invent or the warehouse where all of it is stored. We automatically correlate it to the deep human context that Mark talked about. Let's take this persona, Bob. Bob has a coding agent. It's not just correlating the fact that the coding agent, Claude Code coding agent belongs to Bob. It's also all of the fine-grain context that is associated with Bob. We do that automatically in our registry. The second one, we are getting into posture.

We are going to be introducing the SailPoint risk score, which is a mechanism to really evaluate risk at an individual identity level, both for humans and agents. It's a configurable mechanism because what risk means changes from one company to another. We will give our customers the ability to configure how they calculate the risk score. Because in a world where you have millions, tens of millions of agents inside a corporation, you've got to have real-time visibility into what the risk is, right? That's really what the SailPoint risk score will provide.

That's really on discover. On govern, what's net new here or what's special is really we will be the first to market with our agent audit product in less than two months. Look, human access has been audited and has been regulated for a long time. The same thing is coming for agents. It's going to be lot more complicated. Already there are about a dozen frameworks. Every country seems to have its own framework for auditing agents. Lots of industries like healthcare and others, banking, have their own frameworks for it.

We are an audit company, we know this. This is in our wheelhouse. What we have done is consolidate all that into 10 controls. We are going to be launching that very soon. We are working with all the big four audit firms, actually, quite frankly, to make sure when we really come to market, it's very pragmatic. On the protect side, there are a few things I would love to highlight. One is just-in-time real-time authorization. Look, the hundreds of trillions of dollars that is getting spent in the world of AI and in the world of agentic, it all boils down to the fact that enterprises will have to use them to automate business processes to change the way they work.

Doing so requires, which means a bank will automate loan origination, and an insurance company will automate claims processing. Doing so requires these agents access applications and data. That is where just-in-time and real-time authorization comes in. Having the human context matters because, when a multi-agent network is authorizing a loan, it's acting on behalf of an underwriter, and you don't want this agent to access anything that the underwriter does not have permission to.

That's why mapping the agent context to the human context during authorization is the only way to do it. This is where we are highly differentiated. Second thing is prompt security. Like every one of you here, I'm sure you are all prompting in some foundation model 20, 30 times a day. You know, one of the biggest threat vectors is? That prompt being poisoned, the prompt being hijacked. It's a huge security issue.

Our prompt security, because we have a browser architecture now, we have a plugin in the browser, we can intercept these prompts in real-time. We are using machine learning to classify the prompts into high risk to low risk. If we see something, let's say, an employee is trying to upload some confidential data into ChatGPT to do some analysis, that's not safe and we'll block it. We will be doing things like that. The third one is really response remediation. In a world when you have tens of millions of agents running around, you have to assume breach at all times.

Anything else, you're really kidding yourself. There is some breach of some agent or some machine at any given moment in every corporation. In that world, the only thing you can and should do is have the ability to respond to it in real-time. What we are doing, we are launching this product in the next few weeks called Response Remediation, where anytime there is a breach, we have receivers that are really listening to events. We have built a whole event mechanism using the SSE protocol, which is an industry standard. We are creating what we call a SOC package with deep identity context.

If, let's say, one of you has an agent that gets hacked, we will create a package on what critical data that agent has access to and what the blast radius is, and send it to the SOC so that the SOC analyst who's analyzing the breach can actually use that to be surgical in their response. As you will see, we also believe from an outcome perspective, the minimum in the world of agents is actually zero standing privilege. Not even least privilege, certainly not static. And our fabric automatically delivers that. That's our promise.

Before I get into real-time human governance, I want to just mention a word on Entro. We are quite excited. Entro is a market leader in non-human identities. A simple way to think about this is the world of secrets and tokens and API keys and JWT tokens and certificates and so on. They're world-class in managing, not just discovering, governing, and protecting that. Once we close, which should be soon, we are going to be very aggressive in integrating all of Entro into the SailPoint Agentic Fabric. You should hear more from us on it.

We have publicly announced a Q3 close, maybe earlier. I think we're going to be super aggressive in terms of integration. More to come on that. Real-time human governance. Let me just demystify real-time human governance a bit, because there is a lot said about static real-time. What the hell does it mean? Governance has always been about who has access to what. What has changed is who has access to what, where, when, and why. Answering the where, when, and why is really what the security folks like to call risk context. When you really hear the word, that's really what it is. I'm just going to bring it to life with this persona called Bob. Let's say Bob is an analyst at a large corporation.

It's really questions like, should Bob have access to financial data 24/7, or should Bob only have access to the data a week before earnings, a week after earnings, and no more? Should Bob have access to Salesforce data inside salesforce.com when Bob's on vacation on a public Wi-Fi? Bob has access to an FCC folder inside the corporation. Should Bob have access to it at all times or only during a confidential M&A project? In all of those situations, there is some condition based on which Bob has access. That's really the essence of real-time human governance. You don't assume that Bob has access to everything all the time.

You are gating Bob's access. That is simply the world of real-time human governance applied to both agents and for humans. Doing so requires a few things. Which is what we have completely built here. Doing so requires the ability to classify the application and data that Bob's accessing, which is what we call privilege classification, you will see here, right? You've got to be able to apply that to not just Bob. An average Fortune 500 corporation has 60,000 employees. 60,000.

Everyone should be privileged, not just 3% or 4%, which is really today, right? Everyone should be privileged. It doesn't mean every access they have, everything will go through just in time, but at least you are risk evaluating their access. That's what we mean by democratizing privilege. We are bringing privilege everywhere. Doing so requires classifying applications and data, which is what we are doing now. Once you do that, you've got to have the mechanism to do just-in-time authorization, right?

Like I talked about, you only have access, Bob only has access a week before, a week after earnings and so on. That means you're doing just-in-time authorization. It's not really static access. That is to the right, just-in-time and real-time authorization. There should be policies, right? Every role, based on context, will have policies based on which their access should be governed. That's what in the middle we mean by governance being driven by policy and intent, not just roles. It's not just, well, Bob's role is that he can have access. No, there should be policy that will govern based, conditions based on which Bob will have access or not.

That should be done for all roles. Hopefully, that sort of demystified real-time human governance. We are delivering. We have a big launch event in early August in Black Hat. That's when we are formally launching our real-time governance or human governance. It's really an upgrade to ITDR. President Matt Mills likes to talk about it as it's not a migration, it's an upgrade. Just like how you would walk into an Apple store and upgrade your iPhone from one version to another. That's exactly what we are doing here. It's not a migration.

That's why we are confident as our customers move to our agentic suites, which will have real-time human governance, they will automatically go through the journey of moving to least privilege and zero standing privilege. That's our promise. Let me spend a minute on this notion of autonomous identity, because I said that's our end state. Scale is important, right? The context is why do we need autonomous? Because of scale, right? When you have tens of millions of identity.

Today, corporations are used to, like I said, the average Fortune 500, 60,000 employees. You have 60,000 identities. In the future, not even in the future. Today, the ratio is at least 1: 10. Or 1: 100. You're talking about 6 million identities. 1: 1,000, you're talking about 6 billion identities, right? Sorry, 600 million. These are massive numbers. The only way. You can't have a human in the loop all the time looking at what's happening with 6 million, 60 million, 600 million non-human identities all the time.

What we are doing is building a fleet of agents, these are called guardian agents, that are autonomously looking at everything that's happening with the identities inside a corporation, and looking at whether they are acting inside the policy, outside the policy. Any time they see drift, it'll automatically take some action based on policies, right? Meaning with a small drift, it'll actually stop it. If it's a major drift, it will alert the SOC or it will alert the human owner.

This is our vision for autonomous identity. You should really expect us to be delivering some of the early capabilities in this early next year. We are working on it and it's quite exciting. I talked about Atlas being the engine that powers all of this, and we launched Atlas about, I think, three, four years ago. There has been a ton of innovation in it. The one I would like to highlight is all the things we are doing to really get into protect, right? Remember I talked about discover, govern, protect, and protect is new.

We are building a risk engine, a policy engine, an intent engine. As we move to just-in-time and real-time authorization, we're moving a provisioning model from static provisioning to dynamic provisioning. All of this is getting built into Atlas. When we launch the next generation ISC with a new brand, the next generation of Atlas will go with a new brand as well. Please stay tuned on that. We are also very, very excited about extending Atlas, right? We have our ecosystem of partners that build on Atlas today. They use our APIs, workflows, and so on. We will be giving them the ability to extend Atlas.

If you are an ecosystem partner, you can configure your UI, you can configure your workflows, you can potentially extend the data model we have and so on, right? This is quite exciting, and Matt will formally announce our new monetization model for how we are going to monetize the ecosystem and give them access to our platform. This is going to enable that. Let me spend, Mark, at a very high level, talk about the breadth and the depth, right? I want to link it to the next level of how our product is differentiated. I think the best way to understand is using a building metaphor, right? Because we are very bullish and confident that we are the most differentiated platform to govern and secure both agents and humans in real-time.

It comes from the fact that we have a foundation, which is what Mark referred to as a steel thread. The ability to connect a human to a non-human context. It's not just that, it's the full depth of the context, which is what application, what data, what accounts, right? Now imagine the ability to do it across thousands of platforms. The agent here could be in AWS, the machine could be in Google, the application could be Salesforce, the data could be in Snowflake, and so on and so forth. Imagine the ability to do that across all platforms, which is what we have. We have the most robust connectivity infrastructure in the whole world.

This is really the foundation. On the foundation, we have built an authorization layer. We are the authorization last mile. We are the authorization execution layer. We are an authorization company. We are just moving it to real-time. We are moving it to the world of agents. All of these capabilities here are required to do authorization really well. Look, authorization requires data. You can't authorize if you don't know who should have access to what and when, which is what the foundation provides.

This is the SailPoint differentiation, right? The strength we have built over the last 20 years, we are now adding to it with all the agent context. This is the complex engineering we have already done, and this is what is getting released now. On top of these two is the second floor, which is all of the customer innovation I talked about. Discover, govern, protect, all of it is on the second floor. The startups of the world are starting on the second floor.

They don't have the foundation, they don't have floor one. What happens to a building if you try building a second floor without the foundation, right? That's why it's shaky. Our big platform competitors, be it CrowdStrike and Palo Alto and ServiceNow, they are all cooperators because we partner with them as well. Even they have strands of identity context, nowhere near. None of them are identity companies. They're all trying to get into the identity world, right? That's why we feel very bullish about the durable differentiation we have. Those were all the customer-facing innovations. There is a ton we are doing on the operational innovation side as well.

I'm just going to highlight a few. Architecture. There are two fundamental shifts that we are really rewiring for. One is moving to real-time. Two is building for agents. Okay. Like I talked about 1: 1,000. It's a different game altogether. We're doing it through people. You might be wondering, "Wait, guys, you've been building static for 20 years. How did you just do it?" My own leadership team, Fuad, Levent, Mitra, they really come from places like Microsoft, Okta, Salesforce, SentinelOne.

The next level leadership is where we have also hired some fantastic leaders from CrowdStrike, Salesforce, Palo Alto Networks, who have been there, done that. They are being complemented with our existing talent. SailPoint has always been distinctive in terms of domain expertise for identity. That combination is really the magic. That's how we are driving the architecture shift. User experience. We hired Mahin, who's our Head of Design, that is really leading our excellent design team, which we have had for a long time.

Mahin sort of believes in this notion of design should follow a user's emotion. You should really expect to see a lot more re-imagination. We are fundamentally reimagining the SailPoint user experience. You will actually hear more from us on it. It'll start with our Agentic Fabric launch in less than two months. You will see it, and Levent will show it, by the way. He's going to do a demo. You will start seeing glimpses of the new SailPoint user experience. Security. This is a big deal for us, right? I talked about the new normal. We are quite religious about it, quite frankly.

We are using all of the advanced tech. It's more than that. We are also rewiring how we build products, and it's a fundamental cultural change. The world is less global. It's gotten more complicated. There are lots of sovereign needs. That's why we will soon be announcing our support for five different sovereign needs, including FedRAMP High here in the U.S., as well as things like PCI for the payment industry, EU Sovereign Cloud, availability in South Korea locally, and GxP for the life sciences industry. There are a few more coming. Expect us to formally announce these things. I want to give you a sense of where we are headed, because without these, it's hard to do business on a global basis, doing these will give us a real competitive differentiation.

I call this the AI triple play. We are using AI. Sorry, we are protecting our customers' AI. That's SailPoint for AI. AI for SailPoint, which is all about how we are using AI, and we are using it to build our products, which is really tripling our velocity. We are also an open ecosystem. One of the things that I want to highlight is Chet Kapoor runs security at AWS, which is one of our deepest partners. Chet apologizes for not being able to be here in person, but he wanted to represent his views on our partnership for me, which is, we are a deep partner, right?

We are one of the very few large identity players in their Security Hub+. Which is a second party marketplace they have. As well as we participate early with them on a number of innovations. Right? There are other partners like Snowflake and CrowdStrike and so on. We are really an open architecture. I want to take it back to where I started. Two big rock innovations, two big customer outcomes, and AI triple play. Thank you for listening. I would like to show you things now for which I am going to invite my good friend and colleague, Levent Besik.

Levent Besik
Chief Product Officer, SailPoint

All right. Good morning, everyone. Thank you. I should probably plug my laptop in. All right. Perfect. All right. Good morning, everyone. I'm Levent Besik, the Chief Product Officer here at SailPoint. As Mark and Chandra mentioned earlier, we're on the frontiers of innovation to provide best-in-class identity security for humans and non-human workforce and enterprise. Today, I'd like to show you some key innovations that we've been working on and we've built for our customers, and all of these are either available today to our customers or will be very soon. I'll first start with SailPoint Agentic Fabric, which is our end-to-end solution to discover, govern, audit, and real-time protect AI and non-human identities.

I will then showcase our AI-driven privilege classification and just-in-time authorization capabilities as part of our real-time human governance. Let's start with our Agentic Fabric. Today, the fastest-growing, most highly privileged workforce inside any global company is non-human identities, which of course includes service accounts and machine secrets, and now autonomous AI. Some of our customers see over 100 times more non-human identities than humans.

Visibility and a unified inventory, as Chandra said, with human and data context, is the first step and super critical for our customers to secure this new non-human workforce. After all, if you cannot see them, you cannot govern them. If you cannot govern them, you cannot secure them. Let's dim down the lights and take a look. All right. Welcome to the unified AI and non-human identity dashboard powered by SailPoint Agentic Fabric. Right from the single pane of glass, an identity admin gets an immediate comprehensive health check of their entire non-human and AI ecosystem.

With our AI-enhanced connectors that can virtually connect to all enterprise platforms, as well as our sensors now that are deployed actually on the browser and on endpoint clients, we provide one of the most complete views of non-human identities and their human context at one place. There are multiple dimensions of insights here that I want to go through that really reveal your security posture very quickly. For instance, right here, you can see the total number of non-human identities. You can see the number of total active agents across your entire enterprise. Many of our customers, for the first time ever to see this, realize how large their AI and non-human identities are.

You can see all the exposed secrets. You can click on each of these and go and drill down. We also show you not just managed agents, but the shadow agents that obviously the administrators may not know about. Of course, the non-human high-risk agents and the abnormal behaviors that they might be utilizing, right? They might be displaying. This is a critical security insight that many of our customers, as I said, don't completely realize until they use our fabric for the first time. Let's dig in to non-human identities in a little more detail. Here you see all of our non-human identities, in this case, they're tokens that an admin can look through, slice and dice, and look at the security, severity, and different aspects of it.

Let's just focus on the high-risk ones, for instance. This shows you all of the critical factors an admin makes, right, to understand the security posture. Let's dig in into one of these to see what we actually see. Here in this case, it's a token. You can see there's a critical issue here. Let's understand what's going on here very quickly. We see the owner. We see the last time it was rotated. Clearly, that's flagged as a risk factor. It's in a production system of some sort. Here's a unique differentiator, as Mark and Chandra told us. Our Agentic Fabric has a depth and breadth of human and data context. We can add this to this view, and because we have that context, we can do some amazing things.

We can create a complete lineage map. Let's go through what that looks like. In this case, let's look at this token's life cycle, right? This was a token owned by Doran. It was created in a browser and used in a few places. Here's the interesting piece. This token has high administrative privileges. Okay. That's suspicious, is it used? Yes. It was used. It was used in a privileged production system by an AI client that probably Doran used on his laptop. Furthermore, how was it used? It was used in an access management system to create a new user, right? Attach a user policy to it. Worst of it, this was all done from an untrusted location.

This is the context we talk about. This is a full lineage, not just what the token is or the metadata around it, but how it came to life, its life cycle, where it was used, and everything. Here's the thing. I see enough that just to judge, to assess that this is dangerous, I'll just disable it. This is not an insight platform. This is an action platform. With just one click, we just revoked that token. We mitigated the risk. All right. This is the power of the SailPoint Agentic Fabric.

Let's see how this works in an agentic work. Let's head over to the agent dashboard inventory, and similar to the non-human inventory, this is the place to slice and dice and understand how many AI agents you have, where they are, who owns them. Again, you can see similar metadata across the board. You can click and show each and every one of them. And this is a purpose-built dashboard. You can see here again, let's click on one of these to see what we see.

Again, similar experience as the non-human identities, but of course, we see some interesting stuff here, right? This was a Cursor agent, again, with our suspicious actor, Doran. Sorry, Doran. Interesting stuff is happening here from your machine. And Cursor agents actor, that's interesting. Let's go to the lineage map to see what Doran has been up to. Again, Doran has been using this agent on his MacBook Pro for Cursor. All right, this is where the interesting stuff comes in, right? This agent has multiple identities that was used.

One on Sigma, one in GitHub, and let's see what this agent has been doing, right? This agent was doing Sigma. Probably it sounds like, it seems like a developer agent. It was accessing the design system and a few other things that I've seen, but suddenly, and then it accessed the GitHub. For a developer agent, we see some suspicious things, like it's accessing, for instance, financial automation service, quarterly reports, customer data. Well, that's not right. Right? That doesn't seem right. Again, with a single click, I just disable that agent on its platform that it came from.

It's great that I can take these remediation actions one by one, right? As Chandra said, we expect hundreds of thousands of these. How do we create automatic real-time access policies for agents and secrets and dictate what they can and cannot do before they're even created in the enterprise, right? Because that's what you want to do. You want to have that autonomous automatic policies, right? This is where our security policies comes into play. As you can see, we have a selection of these policies we can create, from behavior policy to identity owner.

Here, what I want to create is a policy around, in this case, since we just looked at a GitHub agent, let's configure an agentic access policy to deny cloud agents from accessing GitHub for product team. Now, why? This is actually a very common risk vector that recently we hear quite a bit from our customer base. They see a lot of these benign coding agents drift from their original purpose, and they, in some cases, then do destructive events like deleting the code base. Then they use their excessive privileges. What we want to go do is we want to create a policy to block that.

We're going to give it a name. Let's give it a name, block our GitHub access. Now, again, I can choose a variety of platforms here. I'm going to use cloud. Again, I can do a variety of targets. In this case, I want to block GitHub access. I'm going to select that. You can deny and allow policies. There's a plethora of options here of customization. I'm going to select a specific team here because I want my engineers to innovate with agents, and I can create a separate policy for them, but for product, we're almost going to deny that. I'm going to create a policy and then see how this Oops, sorry. See what happens. Okay, great. Let's check now. We create that policy.

Let's see if this works. We're going to try to read the file from GitHub. I'm member of the product team, so let's see. Hopefully, it's going to work. It's going to think. I hope it works. There you go. Request blocked by our policy. This right here is huge business value right here for our customers because this capability allows our customers to create guardrails and to adopt AI innovation securely across their organization. All right. Let's pivot from agentic identities back to human elements. As Chandra and Mark said, we also have a lot of innovation happening on real-time human governance, specifically, let's see how we are using AI to radically modernize real-time human governance.

I'm going to go to entitlements here. To achieve true zero trust, an organization must understand exactly what access entitlements they are governing and then classify them accurately in order to apply appropriate security policies. Across the enterprise landscape, we face a massive data quality problem. 64% of our application entitlements are missing descriptions or written in cryptic jargon. We're not also talking about a few 100 here.

Some customers have millions of these entitlements that they need to manage. With such sheer volume, if a manager or an auditor doesn't understand what an entitlement actually does, they often misclassify it. That is a massive security gap, a massive compliance cost. This is where we innovated with AI and created AI-recommended descriptions, which makes this traditionally laborious and critical security task a breeze. Let me show you how. In this case, we have a ton of entitlements here. A lot of them don't have any descriptions. Let's see what happens with our AI-generated recommendations. We click there. Instantly, you can see we have created some really detailed descriptions of what this is.

In this case, for instance, it's a superuser group for Workday, and we came out with a very good description here. Here's the best part. Building on those descriptions, the AI then automatically classified the exact risk level for each of the entitlements. We now flag which ones provide high privilege access. We can approve and deny a few of these, but turns out our accuracy is also pretty good. 98% of the time, 95% of the time, our customers accept and approve all these classifications.

With that confidence, you can just go ahead and bulk approve these things. You can also obviously go in and edit them if you wanted to, right? You can adjust risk tiers, but we can bulk approve these. What used to now take teams of security analysts months of manual work is fully automated, thanks to AI. We're slashing our customers' total cost of ownership. We're accelerating their deployment. We're laying the robust foundation required to enforce real-time dynamic access policies. Okay.

Now that I discovered and classified what is privileged, I want to focus on the privileges that represent the greatest risk to the organization so that I can enable zero standing privilege. We do that with just-in-time policies. I'm going to go to just-in-time console here. What happens here is that with just-in-time, a privilege is only provisioned when a user needs it, and deprovisioned or disabled once they're done. You can do this for all types of entitlements to achieve zero standing privileges, and that's what we recommend. For the most sensitive ones, you can add additional verification at the time of activation too, if you wanted to.

Let's walk through how an administrator would create an activation policy so that when a user wants to activate Workday superuser privilege, for instance, he will be asked for additional setup authentication. Right? Let's go to an activation policy here. I'm going to create a policy, I'm going to create an activation Workday superuser. There's some information here I can add. It's going to be individual policy ownership. Again, we give great flexibility here.

You can create this policy to match attributes and do a whole bunch of other flexible things here to fit your needs. Here's the best part. First, there's the why do you need this policy questionnaire that I can create. Even better, since this is such a privileged entitlement, a superuser access to Workday, right? I want people to really make sure that they are re-authenticated with multi-factor. This is where our integration with identity partners comes to play. In this case, I will require authentication, I will also create an identity policy for that multi-factor authentication. Right?

I'm going to do that. I have the policy set. I'm going to finish. Now let me switch to the user mode. This is now our administrator, right? David, which is one of our administrators. When he activates the Workday superuser policy, this is what happens. I'm going to go ahead and activate this. Again, it's time limited. I'm going to give it a reason. Okay, great. Sure. Now let me get a service ticket because this is a set up policy. Let us enter something there. Okay, great. Here's the most important part, right? We're going to begin a re-authentication ritual here. We're going to go ahead and on the phone, simulate it. We're going to approve a multi-factor authentication backed by biometrics.

We do that. We do biometrics request, it's approved, and David got his entitlement. That's how we create zero standing privilege for this entitlement. Hopefully, he can deactivate or if he just forgets, it's timed out, it will be disabled after he's done. Please bring the lights back up. That's a quick overview of our SailPoint Agentic Fabric and our real-time policy. Quick recap. We get a complete view of all of our non-human and Agentic footprint in our enterprise with critical human data context.

We were able to quickly assess and improve our security posture and create policies. We saw a single control plane on a unified platform with automated governance and real-time protection. We saw how our AI-driven capabilities deliver real business and security value by eliminating painful manual work. Finally, we saw how our real-time authorization helped our customers create a zero standing privilege posture and protect them from privilege misuse and insider threats. We are incredibly excited to bring these capabilities to market and partner with our customers on their AI and real-time human journey. Thank you. Really appreciate it. Now I'd love to have our President, Matt Mills, to stage on go-to-market.

Matt Mills
President, SailPoint

Our go-to-market session, we're going to take an opportunity and introduce you to really the broad, deep bench that we've built over the years. You'll hear shortly from our Chief Commercial Officer, Gary Nafus. You'll hear from our Chief Customer Officer, Meredith Blanchar, our Chief Marketing Officer, Wendy Wu. You're going to hear from our Head of Revenue Operations, Steve Caldwell, and the gentleman that manages and leads our global solution engineering and specialty sales, Jeff Hickman. Right?

The depth of their collective experience is extraordinary, and you'll see that for yourselves, and you'll see the deep bench that we've been able to build here. With that, let me just get started. The physicist David Deutsch once noted that humanity is always at the beginning of infinity. With AI, that infinite future is deriving faster than anything we've ever seen in technology history. We are seeing an unlimited growth of knowledge, crucially for our business, we are seeing an infinite proliferation of AI agents and non-human identities. Last September, if you'll recall, we launched Agent Identity Security. At that time, it was arguably the first solution of its kind.

We made a bold prediction that governing autonomous agents would quickly eclipse human identity management as the most critical governance and security challenge of the decade. We were right. We declared 2026 the year of the agent because we saw a fundamental truth, that the entire AI wave, from copilots to autonomous workflows, requires one absolute foundation, robust, unified identity and access control. The market urgently needs a vendor-agnostic control plane to govern the connection between humans, agents, machines, and data spanning across all platforms. For instance, Salesforce, Amazon, Microsoft, and Google.

Because as the global regulators begin to draw strict lines around AI accountability, proving what an autonomous agent is doing with your data is no longer just an IT issue. It is a massive compliance mandate. Today, that explosion, it's not a forecast any longer. This is the reality we're dealing with. Board mandates are clear. Massive budgets are activated. The AI is undeniably the engine of the modern enterprise. With this rapid AI adoption comes a rapidly growing security problem. We've been saying this now for some time, that identity is the number one breach vector, and most companies have experienced identity-related incidents up to now.

Now, take a minute, add autonomous agents. The attack service isn't just growing, it's multiplying exponentially. Agents are being created everywhere, largely outside the purview of IT. They're spawning sub-agents, connecting to critical SaaS apps, massive data lakes, and being granted broad, sweeping privilege across the enterprise. As a result, the fastest-growing form of agent governance right now is no agents governance at all. With a control plane, the trend of rapid vibe coding quickly evolves into, get this, vulnerability as a service.

All right. Let me give you a real-world example. Imagine one of your analysts deploys a cloud agent to build a financial model, granting it broad access to your firm's data lakes. Does the agent know what it is allowed to access? Does it understand an ethical wall? Can it tell the difference between useful data and restricted data? Is it violating SOX controls or creating a toxic access combination a threat actor could potentially hijack? In most enterprises today, the answer is unclear, and that's a big problem.

You cannot govern what you cannot see. You cannot secure access that you cannot trace, you cannot manage risk when agents, machine, and data are operating outside the identity control plane. We are already seeing this in the headlines, an explosion of shadow AI-related breaches, all fundamentally rooted in identity failures. The broader market, and more importantly, the regulatory landscape, is waking up to this reality at a breakneck speed. Around the world, AI governance is moving from policy discussion to operating requirements.

We're seeing this across the U.S. Treasury AI Risk Framework, the EU AI Act, DORA, NIS2. In Asia, you've got MAS and APRA. The common theme is clear. Enterprise must prove control, accountability, and data lineage across all AI-driven activity. None of that works without identity. Consider this. 60% of the 230 control objectives in the Financial Services AI Risk Management Framework depend entirely on foundational identity security to be able to achieve that compliance. 60%. Simple math, that's 138 of those 230 control objects, right?

That's a lot. It's something that cannot be ignored, and it's going to be a big problem. Here's another one, the Monetary Authority of Singapore. This was the MAS I mentioned. Strict demands for data lineage, human accountability of governance, and it states in the regulation, organizations must, not should, must deploy robust identity and access management systems. This is a powerful signal. AI compliance is no longer just about the model governance, right? It's about knowing who or what has access, what they are doing, and who is accountable, right? This is what Chandra went through.

Furthermore, tech luminaries who once really just touted the limitless power of AI, have kind of changed their tune, right? Leadership at NVIDIA, Google, Box, and Anthropic, now they're really urgently calling out for governance. I don't know if you saw it a few days ago, Anthropic called for a pause in AI development because of this growing concern. Anthropic also recently published a zero-trust framework for AI agents, reinforcing the autonomous agents require identity, task-scope permissions, observability, and controls designed for AI-driven activity. Right.

All of this together really serves as a powerful third-party validation, I think, of what we're really driving here and what we're sharing with you all today, that is the proliferation of autonomous AI cannot be secured by traditional network perimeters or firewalls. In short, agents must be secured at the identity layer. When you step back, there are really three market forces here that are coming together. The threat landscape, it's expanding. Non-human identities, AI agents, are creating really this invisible attack surface.

The regulatory requirements that I just went through, they're increasing, and compliance has shifted from a basic checkbox to the alternative of severe revenue risk. Finally, technology leadership is voicing the importance of identity, where identity has officially become the new enterprise control plane. We are seeing additional signals of momentum building in the market. I don't know if you follow Cisco, right? Cisco's acquisition of Astrix, it's a proof point that large security platforms are moving quickly into non-human identity security. New entrants into the market are shining a light on shadow AI and unmatched agents. CISOs and CIOs, well, they're increasingly recognizing that their ungoverned AI is not a future problem.

It is already emerging inside their organizations. When you bring this together with market sentiment, the technology leadership, you throw in the auditors, what are they saying or all agree on? That identity security is a critical infrastructure and necessary to effectively govern AI. Let me leave you with this, the noodle arm. All right? Identity is the central control plane for enterprise security. It's not just about securing the agents, but it is about the platform to secure your enterprise. It is the common fabric that brings the endpoints, networks, applications, and data all together so you can properly govern and secure your enterprise. All of these create a powerful tailwind for SailPoint and accelerate our go-to-market opportunity. With that, let me now invite our Chief Commercial Officer, Gary Nafus, to dive into more details on our go-to-market strategy.

Gary Nafus
Chief Commercial Officer, SailPoint

What are we going to do?

Matt Mills
President, SailPoint

Let me just give it one minute.

Gary Nafus
Chief Commercial Officer, SailPoint

It seems like we're good.

Matt Mills
President, SailPoint

[inaudible]

Gary Nafus
Chief Commercial Officer, SailPoint

Just luck. Okay. Good morning, everyone. SailPoint is attacking this $90 billion TAM that you've heard about this morning with a ton of momentum. We're attacking this with a maniacal focus on customer success and time to value. As we scale, we are taking significant market share from the incumbents. Over just the past two years, we have expanded our leadership position by nearly five points to capture 23.2% of the market, while the rest of our competitive set has either stagnated or actively regressed. According to Gartner, the IGA market grew 15% last year. SailPoint alone captured nearly 38% of that total market growth.

Most importantly, our unit economics and our customer health metrics are stronger than they've ever been. The best metrics that support the momentum in our sales are the leading indicators, such as pipeline. Our pipeline for these advanced capabilities of AI have doubled every quarter since we launched our products. To maintain this growth trajectory and capture our disproportionate share of that $90 billion TAM, we're aggressively executing on three strategic go-to-market priorities. Capturing new logos.

Speaker 8

May I have your attention, please. May I have your attention, please.

Gary Nafus
Chief Commercial Officer, SailPoint

Spoke too soon.

Speaker 8

This is your flight safety director speaking. We are conducting a test of the fire alarm system. Please disregard any-.

Gary Nafus
Chief Commercial Officer, SailPoint

All clear.

Speaker 8

Emergency. Thank you.

Gary Nafus
Chief Commercial Officer, SailPoint

All clear. Okay, good. Capturing new logos, accelerating our multi-product platform adoption. One more time. Perfect.

Speaker 8

May I have your attention, please. This is your flight safety director speaking. We are conducting a test of the fire alarm system. Please disregard all no influence or remain in your seat. Thank you.

Gary Nafus
Chief Commercial Officer, SailPoint

Perfect. It's good. Yeah, that is an agent. Unsecured, I'll tell you. The third is modernizing our customer base. Here's what gets me really excited. We're innovating within our go-to-market strategy, leveraging AI internally to unlock significant acceleration in our sales cycles, our customer time to value, and our product expansion. We're going to show you a demo here shortly of some of these capabilities. Moving on to land and expand. SailPoint has an unmatched opportunity to land and expand. We are looking at a vast, largely untapped market that is reacting to a ton of market pressures. There is an urgent, now board-driven mandate t o modernize these fragile legacy identity stacks. This imperative is backed by agentic-first budgets, enforcing the need for access governance.

These are budgets that SailPoint has typically not accessed. These are outside of identity, outside of the CIO office, all new budget pools that are now addressable by SailPoint. We're making it super easy and seamless for our customers to modernize their solutions with limited risk. These are push-button-like upgrades that just didn't exist six months ago. We have brought new deal constructs, like Flex Modernization, to streamline our customers' upgrades. This is fueling the fastest acquisition growth for SailPoint, which is to liberate the legacy IGA market. There sits out there $3.2 billion in legacy run rates just sitting in these legacy solutions.

These foundational IGA programs can't meet the modern demands that enterprises need, and when we upgrade them to our Agentic Suite, we see a 3x+ expansion opportunity put in play. By solving today's immediate identity pressures while building on the realities of agent identities for the future, we are not only protecting their business, but we're accelerating ours. We effectively turn that $3 billion legacy target into a $10 billion expansion opportunity for SailPoint. Today, with SailPoint Agentic Fabric, we have these new selling paths to engage into this opportunity. We have 4x the number of ways that we can land new logos just in the past six months. We can land human, we can land agentic, we can land both, we can have a web strategy.

We've 2x'd our selling motions via our agentic specialty sales teams, which now allows us to engage these new market buying personas and these new budgets. This market is quickly realizing that competitive architectures cannot survive in this AI era, and competitive displacement has become our fastest-growing acquisition channel, which is part of the reason why we see that two-thirds of our new logos come from failed competitive deployments. This opportunity is massive, and we are primed to own this. Let me hand it to Steve to take you through some of the platform growth opportunities that we have. Steve.

Steve Caldwell
SVP of Sales Operations, SailPoint

Thanks, Gary. As Gary had mentioned, we have more ways to land than ever before, whether that's landing agentic, landing human, landing with a platform advantage, that wedge strategy, landing up against the competitors. Just like we have new ways to land, we have more routes to market for the way we can land, whether that's through direct sales, our indirect sales team, our MSP channel, our marketplaces and more. We have more ways once we do land in terms of how we can actually expand to create deep compounding platform stickiness. When a customer lands with us, they quickly realize that identity is that central nervous system of their enterprise. They don't just stay for core governance. You heard that from Chandra. They see the vision.

They rapidly expand to manage other identity populations, whether that's non-employee, maybe non-human identities, and also agents, and then with the success of the SpaceX IPO, maybe non-humans in space, too. Customers mature from this static governance to real-time, and then being able to eventually get to that end state, which is autonomous governance, the agentic governance, utilizing more and more of the platform. They govern all identities, obviously, under one unified platform. They secure more use cases, whether that's data access governance, GRC, and just-in-time authorization. They will leverage the extensibility of the platform to integrate with the SOC, create workflows via shared signals, and allow for real-time remediation.

As a result, we are seeing a record number of customers standardized on three or more modules. This platform expansion, which we are really excited about, massively will be accelerated by our recent announcement of Entro Security. If you think about Entro today, their agentic capabilities give us deep into the software lifecycle management expertise, allowing us to secure not just the agents themselves, but the actual secrets, the tokens, the credentials, all those things that make up the workload of what an agent does.

By bringing agent governance with deep technical secrets protection, we are providing our customers with the most robust, unified security solution on the market, while decisively widening our competitive moat against the agent security solutions, those point solutions out there. We do feel like that market itself is actually commoditizing, in some cases now, consolidating as well. Our product adoption strategy is really simple. It's provide quick time to value, really drive that blueprint so our customers are successful over the long term, and then more importantly, just be there all along the way.

Just speaking about being there all along the way, here's a quick illustration of one of our customers in oil and gas and their expansion journey with us over time. When customers move from IdentityIQ, like this customer, to Identity Security Cloud, they're not just upgrading their technology. They're making this multi-year commitment to modernize their identity security program and effectively readying themselves for the future. In this age of AI agents, this customer knew early. They knew real early that you cannot just manage agents in isolation. You just can't manage humans in isolation. They have to come together to see the full context.

That's why in this case, you saw the identity team come together with the AI team to make this decision and leverage budget actually from the AI group. They understood that every AI agent, every automated process, every bot needs the identity and criticality of a unified control plane. Every security leader, especially at this example, they could not see a fragmented landscape with fragmented tools. They knew that they needed a unified control plane as the tool of choice, and it was the basic starting point for modern security.

They knew the connection between the human, the agent, the agent to the machine, the machine to the data, and then a unified policy around that. Our platform delivered that to this customer end-to-end, and it led to a 20x increase in ARR, and most recently a 50% increase in ARR when they enabled the Agentic Fabric to govern agents and non-humans via that unified governance model. Finally, we have a significant opportunity to modernize our base. It's exciting.

You'll hear from Brian later that we have about $350 million that still sits with our IdentityIQ customers, which represents about $1 billion or more opportunity for SailPoint. Much like the example that I just shared and the technology shifts that we're seeing in the market, the tailwinds that you heard from Matt, there's more a reason than ever to extend beyond just human governance. SailPoint has created glide paths for these customers to the Agentic suites that de-risk the move to the cloud. It starts with commercial constructs. Through our Flex Modernization program, we co-invest with our customers to remove any financial friction and allow them to adopt the platform as they mature. From a technology standpoint, we have moved from a migration to an upgrade.

This is a technological paradigm shift. Transitioning to the cloud is no longer this high-risk, heavy-lift migration. It is a seamless platform upgrade. We have eliminated the biggest barrier to modernization that drastically reducing the professional services burden by almost 80%-90%. We have moved to what we call internally a proof-based methodology, which leverages forward-deployed engineers and virtual agent architects that is truly game-changing. These architects are our IP, our institutional honor, our best of the best in terms of talent in the business, effectively becoming a digital twin to help migrate our customers to our cloud solution. With that, let's have Jeff Hickman, our SVP of Solution Engineering, join us on stage. Jeff?

Jeff Hickman
SVP of Sales Engineering, SailPoint

All right, get the demo set up here. All right. Before we jump into the demo, a couple of slides, as they get that queued up. Good afternoon, good morning, everybody. We're very excited to showcase this innovation. It's been talked about a couple of times throughout the day. If Flex Modernization was the license unlock, what we're talking about now is another unlock, and that's really the unlock of the cost and time of modernizing. It's driven by the SailPoint Agentic Acceleration methodology, which is powered by the virtual architect or the set of agents that Steve mentioned. This is an AI-powered capability that automates and accelerates the transition today from an on-prem IIQ environment to the cloud or the ISC environment.

One of the hardest things about doing these modernizations is really untangling years of custom code, custom workflows. If you think about it, dozens of people, if not hundreds of people and partners probably have touched these legacy systems. It creates a complex environment, and a complex code base, with very little documentation of what's really under the hood. Unlocking that legacy stack used to take months of, frankly, human analysis and consulting. The solution now is a no-cost, AI-powered virtual architect trained with over 20 years of SailPoint IP and the know-how that completes a production-ready ISC instance in a matter of hours and days, not months. In many cases, modernization becomes just as easy, if not easier, than a standard version upgrade.

The virtual architect has de-risked this transition and creates value day one. This is really the game changer when we talk about that $1 billion unlock of our greatest asset, which is our existing customer base. One key point as we move to the next slide, I want to emphasize here that this virtual architect, this is not a translation. We're not transposing code. We're not copying and pasting code from one environment to the other. This is truly a virtual architect that requires and is built on intelligent transformation.

This is the magic, is we've ingested or input 20 years of knowledge into this architect, and there's insights from all of our top human architects into this to create a skills database that trains this virtual architect. This SAA methodology combines deterministic engineering with non-deterministic LLM-based models, all informed by these architect's curated skills. The virtual architect transforms your legacy investment into a modern, scalable cloud environment ready for rapid innovation. Let's quickly review how this works. What you see on the slide is just the macro process.

First, we ingest a customer's IIQ configs. The virtual architect gets to work. The virtual architect automates the analysis, the planning, the building, and the deploy to create that functional ISC environment. The virtual architect performs the heavy lifting, which parsing that IIQ environment, mapping the dependencies, it does it within a matter of minutes, really. From there, it moves to the plan, build, and actually deploy. Crucially, I want to highlight here, there's still a human in the loop here, a human along the journey the entire way, because they validate the build, they validate that everything is working. If there's things that need to be adjusted or fixed, they jump in, and they can do that.

What's interesting is that starts to create a self-learning, self-healing capability, because everything that we find that we haven't seen before, we then build a new skill for that architect. This is the flow that we'll walk through. You'll see this represented in our virtual agent here in a second. Let's just dive into that. If you want to switch to my screen here locally, we'll walk through what this starts to look like. If we can switch to my laptop. I'm sorry? Okay. Two seconds. One of the things you're going to see as we get into this, unplug and replay back. The old tried and true. Okay, here we go. Now we're working. Took it with guests. All right. What we're going to see here, I was going to say under the covers. We talked about this being our virtual architect.

This is really a multi-agent architecture under the covers. We have six orchestrator agents, with 36 agents working under them, with 137 sub-agents working under them, all trained and working on these skills that we talked about translated from our humans. When we talk about the virtual architect, this is a complex multi-agent system that we have built ourselves. As we said, we ingested what you're looking at here. We've already ingested a customer's IIQ instance. This is a real customer. We've anonymized it. Normally the customer's name would appear here. We land on a report card. This is what you're looking at.

This is our full blueprint of what the agent has discovered within that analysis of the IIQ environment. I'm going to jump into or just highlight a few things. First, I want to key in on 79%. The agents and the architect have said in this environment, it's likely round up to 80% of it can be automated through what the architect knows how to do. That only leaves 20% that the humans have to intervene. If it was 1,000-hour project, it becomes a 200-hour project. Another thing that I want to highlight as we think about this environment, let's talk about sources here. 748, 750 sources. These are applications that are connected. This is a complex environment.

What you're seeing here for this customer is not just a vanilla, easy layup, if you will. This is very robust. There are two authoritative sources in here, human capital management systems, and then 746 connected applications to this environment. We've discovered, or the architect has discovered 19 core use cases across the system. Now we've got a view of what do we see in that IIQ environment. As we scroll down, you can see effectively our pipeline that we saw on the slide previous. This is the analyze, plan, build, deploy.

These are all the stats and activities that we're underpinning at each of those steps. You can see that those steps are complete. We have run this through the entire process. As we scroll down further, we have some more report card stats. In this case, highlighting we've about 6,000 hours effectively remediated. That 80% in this case translated to about 6,000 hours of human work that did not need to take place at this point. Scrolling down further, I want to highlight a couple of things.

Lifecycle events for folks that aren't steeped in identity like some of the folks in the room here from SailPoint, I want to highlight lifecycle events here. This is kind of a simple process. These are bread and butter use cases for identity, We're going to jump into the new hire process. Think about this. Everybody, when you guys got hired at your jobs, you walked in day one, and there's an email waiting there that says, "Welcome, Jeff. We're super excited to have you here. Here's how you access your systems.

Here's all the things you can go do." That email is a complex orchestration under the covers of a lot of things going on, and that is as nice as it is for you walking in day one knowing you can get ready and you start to work, there was a ton of work and IIQ or ISC helps make that simple and automated. This is the new hire process we're into, I want to highlight a couple of things here. One is right up here, which says, in IIQ, we had nine artifacts. Think the artifacts as a workflow or a set of rules. We had nine discrete artifacts that are now being translated into five.

I mentioned this is transformation, not transposing. We're not copying and pasting. It's not 9:9 . It's 9:5 . What's interesting in this, I'll zoom this a little bit so we can kind of see, what the agent is telling us is, hey, a lot of these things are going to collapse just into standard configuration items in ISC. We don't need them. We don't need to copy-paste it over. There is one thing it kind of called out, which is this send welcome email We need to have one custom cloud workflow that we're going to go build out of this. I'm highlighting this. Remember this SAA joiner send welcome email workflow because the agent had to go build that in ISC.

That's what it's telling us here as it's going through its work. We'll close that off. You can start to see, as I close that out, take a look at the numbers here, 30:4 , 7:3 , 7:3 . You start to see the consolidation or the mapping of what used to be complex. In ISC, it's all code. You're coding all of these workflows. Lines of code living in IIQ, sorry. When it goes to ISC, it needs to map into a SaaS environment, which is largely configuration or declarative-based. The architect knows and knows how to do that and makes that intelligent decision.

If we highlight here, overall, if you think about all of those boxes of reductions, what we're saying is the Virtual Architect has figured out how to reduce complexity by 55%, moving from IIQ to ISC. That's a 55% reduction in technical debt, things that people have to manage and maintain at a code level. It all becomes much more of a declarative instance. This is the overview, a ton of great insights. That's a macro view of what the SailPoint Virtual Architect has discovered. Let's go to the micro. In the micro side, this architect has actually already built all of the documentation for us automatically.

We have our requirements and our solution design document. Think of this as what you would hand to the 20% that I was talking about before that still needs to be created. We now hand those humans the blueprints for what they need to go create, and it sits inside the design documentation. We've got a full upgrade plan. We've got our report cards. We can dive into these. We don't need to go through them. There's a lot of text, but it's a lot of insights.

For customers, as we go in and explain what's happening and what the process and what this blueprint looks like, we can give them all this information. We can show them in detail what we're mapping from one environment to the next. That's kind of static, right? Those are reports and things we've already created, but this is actually alive. We can talk to our agent, and we have the ability through an inference window here to start asking it questions. I'll give it a softball question. Just how many workflows are going to be in ISC? As it is chewing on this, we're bringing a language model into the world of effectively IIQ. If you think about it, we're taking a look at that environment, and now the agent is coming back with insights.

We have 87 workflows. Effectively, you can just have a conversation with this architect, and you can start to understand what's inside that tangled web of years and years in IIQ of the build. I actually did something. I was thinking about this on the plane last night. I asked it another question. This took a little bit longer, I had it queued up here. I said, "Do you have any concerns or are there any security concerns, any vulnerability concerns with your current IIQ environment?" I'm not saying anything about moving to the modern platform. You can see here, the number one security concern for this customer came back that said, "Holy smokes, you've got hard-coded credentials and API keys inside your code."

If you listened to the presentation before, that is the opposite of zero standing privilege. It's the complete opposite of that. We can go, and we actually had this conversation with the CISO of this customer, and we were able to come in and say, "Look what we discovered within just your IIQ environment. There's a lot of items in here to be remediated." It opened their eyes to not only how do I protect by moving forward, and, oh, by the way, there's a recommendation in here, if we can see this, which says, "Hey, by the way, if we do migrate to ISC, when you do that, there's standard configuration items that are capabilities within ISC that would remediate this automatically and prevent it from happening." It is a way of moving into a best practice posture when you move to ISC.

Not only are we helping them with the vulnerability they've got today, but we're mapping to the future of how do you remediate that going forward in ISC. Pretty powerful to not only have a macro report card, a capability of full documentation, a way to interact with that agent in a real-time basis. If you recall, the last step in our pipeline as we went through it was build, deploy. An architect has gone in and said, "You know what? Let's just get going, and we'll build that ISC environment for you." What you're seeing is a live demo environment that was created by the virtual agent. You can see here on our homepage this certification campaigns.

These were configured in items that were within their IIQ. There's six certification campaigns that are in here. They came over. They're already working. We can demo those certification campaigns straight away out of the box. All of that data came with us, and all of those workflows came over transposed from the IIQ environment. I want to jump in. Remember that workflow we talked about as far as the new hire goes? Well, if I jump in, here's our SAA welcome email. Again, this is the welcome email. This is the description of what that email is. If I want to really go see what that looks like, remember what I said, this was code, right?

This was a set of workflows and rules, effectively, that were coded into IIQ. All of a sudden, the agent has built that, and it's come to life in a declarative form within ISC. What's amazing about this is it doesn't require a developer like you used to have in the IIQ environment, where you had to go manipulate code. Now you're an administrator that can use declarative tool sets to make changes into this workflow. You can see it's quite complex and quite robust. This customer did not want to change what this workflow was. They liked the workflow, they wanted it replicated, and the agent and the architects have built that over here in ISC. Quite powerful. This provides a platform, right? What else can we go do with this?

What I've just shown you is how do we move IIQ to ISC in a kind of similar like for like feature function kind of way. You have to do the translation, but it is the like for like. What happens if I want to start layering in all that innovation that Chandra was talking about, discovery of agents, the power of the platform getting in and using the power of the Atlas platform? Well, one of those capabilities that lives within our platform today is our identity graph, right?

This is a great way to visualize these identities. Dawn Oliver was an employee that lived in IIQ. Now she's living in ISC. We've brought her to life here. You can see her access profiles, her roles. All of her entitlements came over. I want to blow out her entitlements real quick. What you're seeing here is all of her entitlements, we can see those. There's one line in here, which is yellow, if you can actually see that right here. This entitlement is actually to an agent.

Well, we didn't have agents in IIQ. Now that we're running in ISC, we can start to layer in a demo fashion, all of the amazing innovations to bring to life for a customer when we're demoing this. Hey, look, now you're on a platform that you can start to ingest all of this amazing stuff. If I go look at this agent that we have discovered, this is a payment history agent, has four entitlements itself. I'm going to go into the details here. I can see a lot about this agent. What's interesting is, right, the source says AWS SaaS. This was discovered.

We connected this to a Bedrock environment. We pulled back and brought this agent, discovered the agents that were living in Bedrock, brought them back in. We've already discovered them, visualized. What's amazing here is we've assigned the owner. Now what we're showing is we've moved from discover, visualize to govern and protect, right? We're able to start showing that path. We can demonstrate that even though this was an IIQ environment, and we walked in to do an IIQ demo, now all of our folks and our sales engineers can say, "Hey, here's what else you can start to go do. Here's why this is an acceleration path."

It unlocks all of the other capabilities of SailPoint for these customers, and we can visualize that walking in day one. This becomes an amazing platform to jump off. If you think about this from a go-to-market perspective, what we are able to do now is as we walk into a customer's environment, we can not only show them the blueprints, show them what we discovered, or show them what we've analyzed within their IIQ environment, but we can show them what it looks like working, their workflows, their data with our new innovation working alongside that, and all of a sudden, the light bulbs start to go off as far as what the future looks like in a much faster way.

As we think about innovation here and thinking about that go-to-market posture, this engine effectively is a paradigm shifter for us because what our virtual architect knows how to do very well is speak ISC. It can build ISC from a set of artifacts, and the artifact in this case was an IIQ config. We are working on other artifacts. Imagine a world where we have RFIs or RFPs that come in with outline basic use cases. Well, we know what those use cases kind of look like when a customer says, "Hey, I need a new hire workflow use case."

Well, we know what that kind of looks like. Our agent can go stand that up for you. Instead of coming into a customer's environment and PowerPointing them, we can come in and say, "Here it is. Here is what it looks like working." That goes for new logos like Gary was talking about. It goes for the unlock of legacy platforms as we start to teach our architects how to speak other legacy platforms. This is a true unlock across not just our customer base, but a paradigm shift across our go-to-market here.

With that, I want to come back. I got one more slide to present as we wrap up. If we go to the next slide, come back to the PowerPoint here. Perfect. As we wrap this up, as we just saw, we're investing in no cost to our customers to use our virtual agents. Our goal is to accelerate our customers' journey to the cloud, preparing them to take advantage, as I said, of all this new innovation driven by this non-human explosion. If you think about this massive shift, like I said, in that very first meeting, we can sit down with a customer, show them the blueprint, as well as their live data working within a live environment with their data, their workflows.

We can eliminate hours of collection of information, analysis, demo creation, PowerPoint theory. If you step back, it means we're moving to a world where we can sell and almost simultaneously deploy. That is kind of the true north of where we want to go. Perhaps most importantly, the Virtual Architect allows us to leverage our customers' investment that they've already made.

That investment in IIQ is no longer a sunk cost. It is an accelerant into this way, into this world. Their ISC environment has stood up much more intelligently because of that past investment they've made in IIQ. It brings the customer's identity IP, as effectively if you think about it that way, into the cloud quickly and at a much lower cost, enabling the ability to rapidly adopt our latest innovations here that we saw this morning. It's a good segue.

This all sets the stage for this next bit of discussion. We're starting to unlock this blocking and tackling of IIQ to ISC. It starts to free up human time. How do we use that time and mind space freed up from those lower-level tasks to do much more strategic things? I think that's a great segue to bring up my friend Rex Thexton, who's our Senior Managing Director from Accenture, to give his perspective of what he's seeing in the landscape. [audio distortion] At Accenture, you have a front-row seat, a catbird seat to boardrooms and C-suites.

We've been telling investors today that this explosion of AI and agents is really creating a massive inflection point for customers and for us, frankly, about how you rethink security and strategies. From your vantage point in this agentic shift, what are the frameworks, or why are the frameworks that are built for human-centric governance probably not sufficient in this new world?

Rex Thexton
Senior Managing Director, Accenture

Yeah. No, I think it's a great question. Just more background, I'm a global CTO for our cybersecurity business as well. I think over the last 30, I don't know how long it's been, three or four weeks, we had this thing called the Mythos moment, right? Everybody was concerned about vulnerabilities and all these different aspects. What it finally taught people is nobody is prepared for what the frontier models can unlock from a security perspective. If you look at where identity sits in that big picture, what all these agents can do and drive that, identity is the control plane for people to be able to unlock agentic identity in their environments.

If you don't know what the agent has access to, how it has access, and what it can do, you are in big trouble. I will give you an example because the reason I brought up this Mythos moment, frontier model, when we started looking and running tests, and one of the things was it can find vulnerabilities, right? That's step one. Step two is it could find novel attack paths. When we found these novel attack paths, you know what the funny thing was? 80% of the way to break the attack path was to do an intervention with an identity capability, being able to go in and limit or revoke an identity or a token or something. A lot of them were that related, versus this patching this CVE will break the chain.

A lot of the minimum cut paths were identity-related, which I found somewhat surprising from that perspective, just initially. That was just fact-based data as we went out and mined these attack paths with some of the latest frontier models. That is super important from an unlock perspective. I think if you look at what clients struggle with, and this is what we see every day, is, "Hey, I've got this human identity infrastructure."

First, they try and adopt it and use that for non-human, and they struggle pretty adamantly with their legacy tech solutions. One of the things that we've been very focused on, and I think we talked about this last summer, is about getting our clients to modernize at little or to no cost. The funny story about that was one of my favorite consulting stories. A few years ago, there was a multi-conglomerate that wanted to break away and had to take their identity system.

I remember one of our lead consultants at the time, the client, he said, "Yeah, we're going to go in, we're going to configure this infrastructure, we're going to do all this stuff." The client goes, "What do I get?" He goes, "Nothing." That's it. I thought that was funny because that's what we're getting rid of, right? We're able to get them so that they can start unlocking the value of agentic identity. I think there's this other aspect, if you watch some of the Sequoia talks, they talk about this concept of diffusion. Clients can't unlock.

They can't keep up with the frontier models from being able to unlock the power of AI. Part of that is they all sit there. Every conversation we have is how do we do this securely? How do we do this securely, being able to leverage agentic AI? The first answer is non-human identity and being able to make sure that you know what your agents have access to, what they can do, and the context in which they have it.

That's step one. If they don't do step one, what they end up getting is, I was at a client the other day, and they ran a shadow AI discovery. They found 1,000 agents running on their network. Tokens are everywhere. That is a big problem, and that's happening no matter what. They either cut it all off or they get identity under control, and then they can adopt from that perspective. Does that make sense?

Jeff Hickman
SVP of Sales Engineering, SailPoint

Yeah. Super helpful. All right. Let's talk about some execution of our massive install base that we walked through. We introduced, obviously, the SailPoint Agentic Acceleration here today, which is heavily automating this transition. A natural question from really the larger community might be or probably should be or will be, how will this agentic innovation reshape the services industry from the traditional implementation as those traditional implementation models evolve and as more of this modernization becomes automated? How should we think about the potential impact on partners for that?

Rex Thexton
Senior Managing Director, Accenture

I think it's a different type of impact. We've been shifting to an outcome-based model for quite some time, and where we see the value of being able to unlock. If you look at what we're trying to do is provide the best outcomes for our clients. A lot of times, in the early days of identity, we could only cover the SOX apps or the regulated apps. We could only cover a portion of the estate. That's no longer going to work. What we're able to do now, instead of spending money on that, what I call the Seinfeld phase, the nothing phase, we're able to go in and get that done and then go in and scale the estate and help our clients scale.

I think there's no one better positioned than SIs in the world to be able to go, and we've been doing this for years. We've been making SAP work. We've been making the identity tools work. We've been making everything work. We have that institutional knowledge on how to best integrate and implement these capabilities from a frontier perspective. I think that's what's unique about us, we're shifting to what we do best versus spending time on what I would call the mundane, we're able to go in and start unlocking that high value and helping our clients deliver those outcomes that they're looking to deliver, being able to leverage this new technology. I mean, it's probably the most exciting time I've ever seen in my life.

I think the biggest issue that I see out in the market is our clients aren't moving at AI speed from a procurement perspective. They're still trying to go through and evaluate. I think, one of the things that we talked about early on in our partnership was how do we help our clients unlock? Clients don't want to buy another tool. They've had these processes for regulatory capabilities. There's a huge data switching mode around just the human. If you're going to go re-implement those in a new tool, different policies, it doesn't make a lot of sense. They expect their vendors, like SailPoint, to be able to come in and be able to provide this non-human identity capability.

Being able to unlock and get there faster allows them to be able to unlock the agentic future in their enterprise with that new control point. That is super important, and that's why we've been pushing you guys pretty hard to come up with something like this so we can get in there and start doing it faster. If the first inhibitor is cost and time, that doesn't work.

If you take time, cost, and uncertainty out of it, because a lot of clients are afraid to migrate because they're stuck in this mode of, I don't understand what I have today or I do it this way, and there's this, what I call this fear, uncertainty, and doubt. If you're able to unlock those three things, time, money, and confidence, they can move at pace and unlock the future, which is this agentic world. That's how they're able to provide outcomes to their clients and to their Board and to their bottom line.

Jeff Hickman
SVP of Sales Engineering, SailPoint

You said this before when we've been talking, the work doesn't go away, the work is just different.

Rex Thexton
Senior Managing Director, Accenture

Yeah.

Jeff Hickman
SVP of Sales Engineering, SailPoint

I think that was.

Rex Thexton
Senior Managing Director, Accenture

There's more of it.

Jeff Hickman
SVP of Sales Engineering, SailPoint

Really well. Yeah. More of it.

Rex Thexton
Senior Managing Director, Accenture

Yeah.

Jeff Hickman
SVP of Sales Engineering, SailPoint

Well, awesome. Thank you so much for joining us today. This was great.

Rex Thexton
Senior Managing Director, Accenture

Thanks.

Jeff Hickman
SVP of Sales Engineering, SailPoint

I'm going to turn it back over to Mr. Steve Caldwell to take us home for the go-to-market here.

Steve Caldwell
SVP of Sales Operations, SailPoint

That was good stuff. Our operational rigor, and we talk about this quite a bit, it sets us apart, and we've been investing in AI across SailPoint. Since the inception of ChatGPT in November of 2022, we've been early adopters. We do live in this world of what we call internally institutional deep fakes and enterprise software, where you can buy code, and you can buy code something that seems real. You can buy code something that can be a great POC as well. Buyers, as you heard from Jeff and Rex just moments ago, need to really change the way they evaluate enterprise software. I think profound trust and integrity becomes more essential than ever before.

When you think about the market of IGA, and you think about how IGA has evolved into identity security, IGA going to the edges and governing more identities is effectively identity security. IGA, in its acronym form, is more important than ever in the age of AI. Think about the acronym. Identities, there's more identities than ever before. There's more governance that's required than ever before. There's more administration that's required as well. Thus, the financial and security risks of a failed deployment are just simply too high in this world where AI is just moving so fast. There's no time to ever catch up if you get that decision wrong. That's why we operate now internally as something we call the velocity of trust, which is a paradigm shift in the way we sell.

You heard a lot about that from Jeff moments ago in terms of our capabilities in this area. It's moving from what we call a promise-based selling, where you're making a bet, and then you're going through an implementation, you're hoping it pays off, to moving to proof-based, where you know upfront that you're making an investment that's going to have a return. You know you're going to be successful. By utilizing Agentic Acceleration, we absorb the risk for the clients. It's risk off the buyer, now it's risk on the vendor being SailPoint. We have automated away the complexity that sometimes gets associated with identity governance or legacy IGA or competitive IGA.

What we didn't mention was our Agentic Acceleration can be applied to legacy IGA. It can be applied to competitive IGA to make those transitions to SailPoint that much more effective and timely. This allows us to simultaneously sell and deploy all at the same time, which we believe is a financial and operational motion that the competitors, the market itself cannot match. With that, I'm going to turn it over to Wendy Wu, our Chief Marketing Officer, to share the successes we're seeing with customers, the analysts, and also share with you our pricing and packaging model.

Wendy Wu
CMO, SailPoint

Thanks so much, Steve. Hi, everyone. At SailPoint, the ultimate foundation of our business is the trust. We're not a point solution. We're the definitive system of record for identity security in serving the most complex organizations on the planet. Today, we protect over half of the Fortune 500 and nearly 30% of Global 2000 from Forbes. These are organizations, they operate in the highly complex and hybrid environment under massive regulatory pressure. They chose SailPoint for one single reason. We scale, and we deliver. You can see that trust in our retention rate at 97%. That speaks to the stability of the business and the critical role that we play for our customers.

When SailPoint is deployed, we become very hard to be replaced, and we're deeply embedded in our customers' cybersecurity defense. This level of trust is validated by major independent analyst firms, as you see here. In the most recent IDC MarketScape and KuppingerCole Leadership Compass, SailPoint was positioned as the undisputed leader in identity governance, and we stood out for our market leadership and our vision. Most importantly, our customers have spoken.

Their feedback earned us the Gartner Peer Insights Customers' Choice Award for 2026. For us, these recognitions really matter because they reinforce what we see in the market today. Customers want a platform that they can trust for mission-critical identity security needs. That trust gives us a very strong foundation to expand and evolve our solution, and that allow us to capture the next wave of demand as identity expands from humans to non-humans and agents. I know you guys are wondering, how do we monetize our product portfolio?

Up until recently, our commercial baseline was built primarily around our identity and security cloud suite: Standard, Business, and Business Plus. Built on our foundational Atlas Common Services, these suites, they deliver the comprehensive out-of-box governance for human identities. Customers can easily expand with the advanced add-on capabilities such as non-employee risk management and several others. The enterprise buying behavior is shifting. Customers, they want commercial investment that can perfectly align with their maturity without a rigid lock-in. That is why we created SailPoint Navigators.

They're the flexible purchasing pathways that let customers buy and adopt exactly what they need. It just simplifies the procurement process, accelerates the sales cycles, and create a frictionless pathway for future expansion. Now, while securing human identities really drives our baseline, the market is moving incredibly fast, and we are launching the industry's third shift into the agentic era. Today, the most urgent operational risk is really the explosion of the unmanaged AI agents and machine identity that we've been talking all this morning.

To capture this market shift, we have evolved our market entry and packaging strategy. For the very first time, customers do not have to start with the SailPoint human identity solution. If a net new logo or an IIQ customer, they need to solve their agentic identity problems immediately. They can purchase the SailPoint Agentic Fabric that we just launched as a standalone solution to secure their non-human identities. What this means is it unlocks a massive new TAM for us. It allows us to really capture the enterprise who otherwise would have turned to our competitors.

As we said, the ultimate security for enterprise can only be achieved through a unified control plane, because you cannot secure agents in their own silos, and you cannot fully govern these agents without mapping its access and its accountability back to its human owners. To solve this, we have introduced our Agentic Business and Agentic Business Plus Suites. They unify both humans and agents under one control plane. For our existing customers, the upgrade path is completely seamless. Customers can step up directly from Business to Agentic Business or all the way up to Agentic Business Plus as their needs mature. Customers who are already on Business Plus, they can move directly into Agentic Business Plus.

Each upgrade represents a seamless journey with a corresponding price increase to cover the extra value we deliver. This is the future of our business. As our platform continuously discover more unmanaged non-human identities customer, naturally, they will see more risks in their environment that they want to keep under control. That creates a very compelling reason for them to expand their footprint and turning the Agentic Fabric and Agentic Suites into a highly scalable growth engine for SailPoint. Having talked about the packaging strategy, how do we price for the shift?

Let's keep it simple and predictable and really monetize the growth through a hybrid pricing model. As we know, legacy-based pricing alone today is just not adequate anymore. It does not fully capture the reality of the modern security. AI, eventually, they may optimize the number of human workers, but at the same time, it is also causing machines and agents to explode. If we only charge per human, we miss out the massive upside we have.

At the same time, the reality with our customers is they're very hesitant to commit to large upfront payments because they simply don't know how many agents are there in their environment that they need to secure. Our hybrid model solves this by balancing the budget predictability with value-based scaling. We land with seats and we grow with extra capacity. To make this initial landing completely frictionless, our commercial anchor remains on the predictable human identity licenses. To remove the upfront guesswork, we include a generous baseline of non-human identities with every single human identity that you purchase.

This really allows our customers to safely discover and secure their agentic identities on day one without having to worry about immediate overages. As their environment grows, they're likely to exceed that baseline. They can scale seamlessly by purchasing our modular capacity packs. This ensures that their ongoing financial investment scales in proportion with their actual platform usage, such as the increase in their agent volume, the API calls they're making, the workflow automation, data retention, and data refresh. Here's the bottom line.

We eliminate the initial buying friction to accelerate immediate adoption. As customers' AI and automated entities multiply, our revenue will scale in locksteps. We're directly monetizing the explosion of agent-driven work. To bring it all together, we have the trust of the world's largest organizations. We have the leading platform to secure these new identities of human and AI agents. Now, with our hybrid pricing model, we have the commercial engine to capture the financial upside of this digital explosion. As our customers' environments grow more automated and complex, our revenue will scale alongside with them. We're not just securing the future of the enterprise, we're actually building a scalable and predictable growth engine to go along with it. Thanks, everyone. I'll bring it back to Scott.

Scott Schmitz
SVP of Investor Relations, SailPoint

All right. Thank you. Thanks, Wendy. Thanks, team. That was a lot of information this morning. Hope you found it valuable. I'm going to call a little audible. We were supposed to do Q&A, I think instead, we're going to add some time to the end, and we're going to go to break, let everyone stretch their legs, get a snack, use the restroom. We'll be back in about 10, 15 minutes, and we'll start back up again. Thank you all.

[Break]

Are we good? All right. Welcome back. There's a lot of things that go into an event like this. I got to say, there's a lot of people to thank to help us prepare for today. The one thing I didn't have on my list was a fire alarm. I will add that to my checklist. Apologize for that. Anyway, we got a lot more content this afternoon, and then we'll get into the full Q&A. With that, let me introduce Meredith Blanchar, our Chief Customer Officer.

Meredith Blanchar
Chief Customer Officer, SailPoint

You can join me. I will introduce you. Hopefully no fire alarm. This morning we spent a lot of time talking about SailPoint technology. The reality is that major technological shifts like this are never just about the vendor. They really require this true forward-thinking partnership between the vendor, the customer, and the partners like Accenture. What our next guest and his organization have achieved in terms of modernizing and securing their identity perimeter really does deserve to be in the forefront. Honestly, we are just incredibly proud to play a supporting role in your story.

What I want to do for this session is flip the script a little bit, and instead of talking mostly about SailPoint, talk about the incredible transformation that is happening at one of our customers, The Vanguard Group. Vanguard has been a customer of SailPoint, a great customer, for 10 years, and it has been really fun to watch how they have matured. Talking about AI, they are not just starting to adopt AI, they are actually actively using it to design behavioral nudges to help over 50 million clients make better investment decisions.

They have rolled out tools like Expert Insights that gives their financial advisors things like superpowers. They can personalize their portfolios at scale. They have, it is called the Well on Your Way platform, and I actually saw a commercial about it the other night, and it was really interesting. It uses AI to analyze 35 million data points to help employees improve their financial well-being and move closer to retirement. With that, I want to welcome our guest, Srinath Chigullapalli, who is the Global Head of Identity at Vanguard. Srinath, thank you so much for joining us. I appreciate you taking the time out of what I am sure is a very busy schedule to share your insights with us today. It is just fantastic to have you.

Srinath Chigullapalli
Global Head of Identity, Vanguard

Thank you, Meredith. Can you guys hear me? Okay, perfect.

Meredith Blanchar
Chief Customer Officer, SailPoint

We can.

Srinath Chigullapalli
Global Head of Identity, Vanguard

It's great to be here today.

Meredith Blanchar
Chief Customer Officer, SailPoint

Okay. Well, thank you. We appreciate it. I'll set the context. You manage identity for an organization that oversees trillions in assets, and I want to learn more about your role and Vanguard in particular, understanding with all these massive AI initiatives that are rolling out, what's the most exciting AI initiative in your world right now? More importantly, as Global Head of IAM, how do you help balance this need for massive innovation, yet keep things secure?

Srinath Chigullapalli
Global Head of Identity, Vanguard

Great question. Just for everybody's benefit, I'm sure everybody has heard of Vanguard is an organization whose mission is to make sure that our clients have the best chance for investment success, right? You know us as a low-cost fund provider, our goal is to provide the best products at the best price and make sure our clients are successful. As Meredith touched on, it's 50 million clients across the world. We have a workforce of about 30,000-40,000 that provides this service at scale, right?

We're a digital-first company, we leverage emerging technologies to provide these services at scale. We don't have physical offices where people can come in and interact with us, right? Whenever we talk about a technology and especially as an exciting technology as AI, we've kind of adopted and embraced AI in a very aggressive way, right? What's fascinating is the definition of what a user has evolved over the last few years. When we talk about AI driven initiatives at Vanguard, whether we talked about the Expert Insights or benefiting our retirement clients, we're no longer talking about just human beings logging into systems, right?

The processes behind are pretty complex and autonomous combination of human systems and AI agents that act, make decisions, and execute complex workflows on behalf of our clients and advisors. My role in IAM and broadly across security in our organization, it isn't just about being a gatekeeper, right? Especially when you talk about gatekeeper, I think people think of, okay, somebody stopping people from doing things, right?

That's not what we want to be. It's about building a robust identity-first foundation of trust to be key for our clients' assets secure, right? We want our developers and their business units to innovate at lightning speed. They need to do it within a secure framework. If we can secure the identity of these AI agents and systems from day one, we give the best chance and the best confidence for our business units to innovate fast.

Meredith Blanchar
Chief Customer Officer, SailPoint

No, I appreciate the context, and I want to come back to that gatekeeper analogy here a little later in this session. I think that's really interesting. We have a crucial distinction here. We're transitioning from gen AI as a passive co-pilot, if you will, to autonomous AI agents that are acting as, like you mentioned, a very large, in this case, digital workforce. I don't know if you're hearing this discussion or debate. I certainly am, especially across CISO and CIOs.

One of the biggest organizational hurdles they have right now is structure. How do we actually govern this? There's a passionate debate around do we need a Chief AI officer? Do we do this via committee? How do we keep control of it? Vanguard's interesting. You're in one of the most highly regulated spaces in the world. I'm curious how you're thinking about this. Are you looking at a Chief AI officer? Is it a committee? Then more importantly, your team, how do they integrate or coordinate with this structure to make sure that security is moving at pace with innovation and isn't an afterthought?

Srinath Chigullapalli
Global Head of Identity, Vanguard

Yeah. It's a great question again. Look, I'm sure every leader in this room and everybody out there is thinking about the same question, right? We recognized, as an organization very early on, that AI adoption and governance cannot live in a silo. There's not one person who's going to sit and make a decision, right? We do have an AI officer. We actually merged the AI officer with the technology officer roles now. We have established dedicated AI leadership and cross-functional AI governance committees, right? There's executive sponsors, and then there's governance committees and decision-makers, which includes business leads because they have a very large stake in it, risk officers or legal teams, privacy teams, and technology champions.

The one I just held on to the last but not least is the security organization. The CISO, myself, and the security operations center, we're all part of that AI governance council, right from day one. I am in security organizations. We all have a permanent seat at the table, and we make it a non-negotiable principle that AI agent is an identity that we have to build, right? When our AI governance leads design the guardrails for what an AI system is allowed to do, what my team does is translate those guardrails into actionable policies, governable policies, right?

If an AI council decides they're going to create an advisor-facing agent that can read portfolio data, we make sure that, hey, if you rebalance the portfolio, you're not actually executing the trade because that's not the intent of it, right? That constraint we enforce it at the identity layer, right? Not just in the code, but even in the identity layer. Because of this tight partnership, we ensure that as AI leadership pushes the envelope on what's possible, as a security team, we're right there with the right architecture and the dynamic enforcement.

Meredith Blanchar
Chief Customer Officer, SailPoint

Yeah. Permanent seat at the table, I think that's phenomenal. I want to transition now and talk about agentic sprawl or this agentic wave that is coming at us, or rather on top of us right now. Enterprises are rapidly deploying autonomous AI agents, and this is creating this massive new risk vector for us. These agents adapt, they learn, they take unpredictable actions, which means that legacy static controls, completely ineffective. Completely ineffective. In fact, we were talking earlier, we have an intern group, and I was asking one of our data sciences interns, I said, "What's the one thing I should know about AI? Just tell me one thing. Take it." She said, "AI agents like to please, and they will tunnel through walls.

They will jump over buildings. They will wedge their way through even the slightest crack in the door to get you an answer to the question it thinks you asked. That is what we are dealing with here. We are dealing with this in a scale. That is why dynamic, not legacy static, dynamic context-aware governance is essential, absolutely essential to secure us in this day and age. Again, Srinath, with Vanguard operating under this kind of intense regulatory scrutiny, I am curious, how is your team thinking about the unique risks that are associated with this agentic wave? How does it differ or does it differ from previous shifts like moving to the cloud? Secondly, how are you considering this as part of your strategy?

Srinath Chigullapalli
Global Head of Identity, Vanguard

Yeah, absolutely. I will address the second part of the question first, which is how do I see this different from the earlier transitions of cloud and SaaS? We moved about 90% of our workloads to the cloud, right? We have kind of made a huge bet into moving to the cloud. When I look at those transitions, they were mostly IT-driven initiatives. They were not necessarily a business saying, "Hey, why don't we move to the cloud," right? The AI transition has been very much a joint partnership between AI, the business teams, and the IT teams, right? The willingness to adopt AI is coming from both sides.

When we started looking at this deeply, we realized that the traditional security models of being reactive are not scalable. That is not something that can fit in this, right? This is a new reality that we all have to adapt, where this adoption of technology is much faster than you can actually prevent it, right? The blast radius, as I like to say, was much smaller than when we did the cloud migration or the SaaS migration. In that world, if something went wrong, you could look at firewall logs, you go to your SIEM logs and get information about what went wrong, right?

We heard this morning, too, on the speed at which AI can cause you to identify vulnerabilities and also exploit it that quickly, right? AI agents act at machine speeds with human access, which is really scary. AI agents can query databases, aggregate data, take action, talk to other agents. It is very important that you constrain the blast radius of an agent. Especially because if an agent has a hallucination or it is given the wrong data, it can cause severe damage.

It is not just your threat is no longer an external actor coming in and causing damage. It is also a rogue agent internally, which has wrong information to add to it. That is where the active monitoring is too late. We had to realize that identity is the only viable control plane. If we do not have absolute real-time visibility of who created an agent, what is the intent, and what data does it have access to, and what is actually happening in real time, that creates a massive blind spot for us.

Meredith Blanchar
Chief Customer Officer, SailPoint

It's a massive blind spot. At the end of the day, you really can't secure what you can't see. If you have an AI agent that is operating with a generic shared service account, which is honestly what we see in a lot of these legacy setups, you have zero accountability. If that agent goes rogue, you have no idea which business unit owns it. You can't even figure out how to shut it down. By the way, if you can, you have no idea what you're breaking from a business process standpoint down the line. I want to double-click and talk a little more about SailPoint in this portion of it. Let's talk about how we solve this.

If you look across the landscape, there are a lot of vendors out there, a lot of point solutions, and they're touting discovering visibility is really their core value. That's great. Simply discovering and finding an agent, that is table stakes. Absolutely table stakes. Which is why, honestly, we give discovery, we give that capability away for free. The real power isn't finding the agent. It's once you find it, what do we do? What do we do next?

That's where we do, as Chandra spoke, have a real competitive advantage here. We are the only organization that has that enterprise-wide identity context. We can link these non-deterministic agents to their human owners, and we can govern their intent. Srinath, I want to understand from you how Vanguard looks at this. When you're deploying AI at scale, how important is context and intent as opposed to discovery? Then from an access governance standpoint, how is that driving your strategy?

Srinath Chigullapalli
Global Head of Identity, Vanguard

I love the free press, by the way. Discovery.

Meredith Blanchar
Chief Customer Officer, SailPoint

Most people do.

Srinath Chigullapalli
Global Head of Identity, Vanguard

I think you kind of mentioned it, which is when it comes to AI agents, context is everything, right? If you want to govern an agent, one, you need to find it, and two, you need to understand, hey, what is the intent that it was. We typically ask three questions. Who is the human sponsor behind the agent? I think I saw the earlier presentations talking about how you do humans with agent governance. Human sponsor is very important. Every agent must have a human owner who's ultimately accountable for its action. That enforcement is important. The second part is what is the intent of the agent? What's the purpose of this agent?

We should be able to dynamically map the permissions to the specific business function and the need that the agent is created for. You cannot generically give the broad administrative access to every agent. That's just very over-permissive. Get as close to zero standing privilege as possible. The last but not least is what data is it touching? We need to know if it's interacting with public data, proprietary data, client PII, investment information that's considered confidential in our world. All of that matter quite a bit for us when we think of managing agents. The other piece of it is, hey, you need a single pane of glass view into your human and non-human entity. I think, Chandra, we have talked about the scale of humans to machine or non-human entities being 1: 100, 1: 1,000.

The scale of impact is huge in this world. Having a single system where you can see all of this in one place is very helpful. Again, coming back to the govern aspect of it's hey, if the owner of the agent leaves the company, what's your process? Lifecycle management becomes a major concern. If the agent's behavior deviates from what its original intent is, or people change the access on it, do you have a way of flagging it and governing it and reviewing it? I like the feature of the certification of agents. We don't do that as well for service identities today. Getting into the agent world, I think that's an area that we need to really get better at.

Meredith Blanchar
Chief Customer Officer, SailPoint

No, that's great insight. Watching and flagging that behavior, that is that dynamic context that we're talking about that is so critical right now. As I'm listening to your answers, it's clear that you've managed to find that perfect balance between security and innovation. I may have you talk to other customers about that as well, but we'll talk after this. Unfortunately, and back to the gatekeeper analogy, I still have conversations where I hear from leaders that they're leveraging security as a brake pedal, and they're slamming on the brakes.

They're saying, "Okay, we got to stop, and then we'll figure out this whole AI thing, and then we'll start moving quickly." To use a Formula One analogy, foundationally, if you have good brakes, you can go 200 mi an hour right out the gate. That's how fast we need to move right now. Knowing Vanguard as a customer for 10 years, you've got a very strong foundation. I'm curious, how has that, and from a security standpoint, enabled your business to innovate faster yet still stay secure?

Srinath Chigullapalli
Global Head of Identity, Vanguard

I love the brake pedal analogy. I've been in the security industry for about four years, five years. Before that, I used to call security the no police. When we think of security at Vanguard, yes, our primary purpose is to protect client assets and Vanguard's assets. The second goal or the second mission statement we have is how do we be the enabler for the organization, right? Securing identity is our ultimate business enabler, right? Because we have a robust IAM and security frameworks, our development teams don't come to us with every little thing. We give generic frameworks, and then they can navigate risk-based approaches.

We don't spend months negotiating on with security and compliance and privacy and everybody else on, hey, if you want to launch a tool, right? We have out-of-the-box decision frameworks that we can leverage to go and implement things, right? They know that if they want to create an agent, they have to assign a human sponsor, they have to request the exact privileges through our SailPoint system, and they can deploy to production pretty rapidly.

That foundation of trust and control allows us to innovate safely, while at the same time protecting our clients and assets. Adopting latest AI breakthroughs, there's so much happening every single day, every single hour. I'm pretty sure by the time we finish this conversation, there's a new frontier model that we should be scared about. There's so much happening that you need to have a quick decision process and an easy path lane for those of you on the East Coast that we think of.

Meredith Blanchar
Chief Customer Officer, SailPoint

I think that's so important, that decision framework. I hadn't really thought about that, but having a way to react and respond quickly is going to further the trust between the organizations. That's great advice. I'm going to ask you for one other piece of advice just to close this out. What is the single biggest recommendation, words of wisdom that you would give to others that are navigating their way through this agentic space?

Srinath Chigullapalli
Global Head of Identity, Vanguard

Yeah, this is a tough question. Look, technologies like AI, quantum, blockchain, you name it, they're really pushing the pace of change. I've been in the industry for 20+ years now, the pace of this change just keeps increasing and increasing and increasing. It is exciting to see what these advantages can do, whether it's healthcare industry or financial services or client service. Security professionals, we as security professionals cannot be the roadblock. You used that analogy of brake pedal. We cannot be the roadblock. We have to figure out how to fundamentally redesign security to be more of an enabler, like what I talked about, at the beginning of the adoption, because if you tend to be the no police, then people tend to go around you, which is a much bigger risk.

You want to make sure that you are staying ahead of the game or at least at the table at the beginning and designing your systems so it's easy for people to create and adopt security as a service, right? Don't wait till you have a sprawl, agent sprawl, to think about identity. If you're waiting for developers to build dozens of autonomous agents before you come up with your agent security strategy, it's too late. You're running around to grab your arms around the whole problem, right?

You'll end up with a legacy mess of unmanaged service accounts, shadow AI, and massive security gaps, something that you have to be worried about. Start treating AI agents as first-class citizens in your identity directory. Establish your governance frameworks, partner closely with your AI leadership teams, wherever they are in the technology domain, business domain, privacy, legal and build an identity control plane that can scale at the speed of how the industry is moving. Start early and figure out a way to enable.

Meredith Blanchar
Chief Customer Officer, SailPoint

Great. Great words of advice. You mentioned don't wait for agent sprawl. I think the reality is it's out there.

Srinath Chigullapalli
Global Head of Identity, Vanguard

It's already out there, yeah.

Meredith Blanchar
Chief Customer Officer, SailPoint

We just assume it's there, and you need to tackle it. Thank you. Thank you so much for joining us, sharing your insights, and of course, for being such a great partner along the way. We really appreciate it.

Srinath Chigullapalli
Global Head of Identity, Vanguard

Awesome. Thank you.

Meredith Blanchar
Chief Customer Officer, SailPoint

At this point, I'm going to transition to our Chief People Officer, Abby Payne, and our CIO, Sree Kancharla.

Abby Payne
Chief People Officer, SailPoint

Good morning or good afternoon, everybody. I'm happy to say that I am not the last presenter before lunch. Brian Carolan gets that distinction. We'll get through some of our internal AI initiatives together with Sree. I'm really thrilled to be here. Thank you all so much for being here. I'm also excited to share how SailPoint is driving innovation through our own internal AI transformation, improving both our employee and customer experiences and while minimizing the risk that you've heard about all today. As I said, I'm joined by Sree Kancharla, our Chief Information Officer. She keeps me on the rails on the technology. I appreciate her so much.

Because look, a lot of you may look at me and go, "Gosh, your Chief People Officer is up here talking about AI infrastructure and IT readiness. Why is the Head of HR talking about this?" I'll tell on myself a little bit here. Last night, as I was practicing some of my remarks, I actually vibe coded a teleprompter, like the one in the back that we've all used today. My vibe coding did not work, in fact. It was a lot of to-do for nothing. I think when Mark asked me to do this, his vision was actually very clear that AI is not a traditional SaaS or software deployment. It's actually a fundamental shift in the way humans work together.

That's why we decided to pair these functions together during what is an incredibly transformational time. We've gotten really specific in order to avoid the AI sprawl that Meredith just talked about. To anchor our strategy around three specific outcomes: revenue generation, customer experience, and as I talked about, workforce transformation. Then to put an even more rigor to that, we've really structured our own execution internally on four core pillars or four things we really want to do well before we move to the next step.

First, tooling. We have delivered a baseline productivity tool called Neptune, everything at SailPoint's nautical, if you haven't heard that today, to our entire employee base. Really, our goal there is to better enable our crew, our employees, for both job efficiency, we've heard a lot about job efficiency, and effectiveness. The second is integration. We are connecting Gemini and other core LLMs directly to our big internal data systems and applications that allow our employees secure contextual answers and insights right at their fingers, sort of immediately to both augment and accelerate their work. Third, agents.

We are automating high-friction workflows, you've heard some of them described today, by deploying highly specialized vended agents in partnership with some of our large application vendors that you could think of, ServiceNow, Workday, Salesforce. Fourth, velocity. You heard a little bit of this from Chandra. We are really shifting IT from a centralized gatekeeper through this process to a decentralized enabler. Rather than forcing all that we do with AI through a single, sometimes time-constrained queue, we are building a secure, scalable infrastructure. I'll continue the car reference that Meredith just talked about.

IT is paving this road, the business is really driving the execution. To this point, our work has really brought us to two critical realizations. As I said, first, true AI transformation is about human behavior change. Second, as I said, this is not a traditional technology rollout. We really want to encourage exploration all across the business, create a pull to AI, not a push. We're pairing our safe technical infrastructure with a strategic organizational model that seamlessly integrates both top-down guidance, hearing from the top about what we want to do, and bottoms-up organic ideations. Top-down, we have really called on our functional leaders to take ownership of those large-scale, high-friction workflows in their own corners of the company.

We have lots of use cases, lots of those high-friction workflows that we can go address. We can't address them all through IT, that's why we're asking our other leaders to take ownership and responsibility. We're also arming them with AI toolkits. We're helping them set expectations, we're really setting a tone with our employees across the business around the importance of impactful, innovative, and responsible use of AI in all the jobs that all of our people do. Bottoms up, we've established a network of grassroots AI, what we call AI champions and super champions across the company. Steve Caldwell, who you've heard a couple of times from today, is one of our super champions across SailPoint.

They help us ideate. They help us really importantly deliver business value and priority. We could think of 10,000 cases to go build, but we want to build ones that actually solve problems. They help us troubleshoot, they really help set that tone and set best practice inside the business all across our organization. Finally, we are reinforcing this culturally across the company. This is where the people side of my job actually comes in. We're highlighting wins in AI Digest every week. We're talking about it at all hands. We're integrating it into the fabric of how we operate inside the company. We're even doing awards.

I did hear the rumors of awards being given for most tokens being used at other organizations and then huge consumption bills showing up at the end of the month. That's not the kind of awards I'm talking about. We really are just attempting to have our employees use AI as another one of their tools in their toolkit as they complete their work every day, as they deliver on the value that they create for SailPoint. We really consider AI to be a next-generation tool, an element that professional growth and development of our organization is really critical to bring those two things together.

As we look to the horizon, the journey is pretty clear. I like that this slide has a curve, but it is not that smooth. It actually behaves a little bit more like a step function. SailPoint currently sits very squarely between augmentation, so making our human employees faster and more effective, and true end-to-end automation. We actually believe we'll get there and we'll achieve this by automating all those routine operational tasks, which frees our crew, our human beings, to elevate the judgment and the human-centered approach in all that we do, particularly because we have such a strong, differentiated relationship with our customers.

We never want to lose that. That's really how we scale this business. Not by adding more people to do the same tasks, but by improving the strategic impact of every person we have by removing those volume tasks that take up so much of their day. Our goal is to seamlessly integrate AI into every facet of our business, how we build our solutions, you heard about that from Chandra, how we enhance credibility with our customers, you heard that from the revenue organization, and really how we evolve the entire operational model to include a digital workforce that is running right alongside our crew members.

This next slide is a little bit of a hot topic. As I said, with the consumption bill catching some companies off guard. We really want to be really intentional about how we both measure value and manage expense related to our AI investment. We've heard lots of different anecdotes in the market about this, but to be transparent, it is still too early for us to commit to permanent bottom-line cost savings or hard reductions in future hiring targets. Instead, we are really focusing on leading indicators, building a framework of those to score use cases on two fronts. One, the value they create for our business, and two, the feasibility of addressing them, of building them.

We're monitoring that AI spend on a weekly basis, particularly the consumption front. Really, one of Mark's longtime core values of this organization is innovation, and that has served us at SailPoint for so long. We have not built technology and then gone and run to find a problem, so we go buy it. We have first looked for a problem, identified a problem, and then built the technology. We want to apply that same rationale here. Our goal is prioritizing the use cases that we're building and investment where there's real demonstrable value, particularly to avoid the AI sprawl that you just heard from Meredith.

In fact, I do want to share a little early win we've had with Neptune, which is our enterprise-wide employee efficiency tool. Our engagement is already really high, like in the 80s%, where we have employees using Neptune every day in their work. I am happy to share that deployment has actually paid for itself, because we've been able to cancel or consolidate various SaaS applications whose functionality is now fully covered by the tool. Not only are we helping our employees do their jobs more effectively and more efficiently, we're also reducing risk in our business by reducing the number of AI or number of SaaS tools that we have in our stack.

Let's take a quick look at the set. Just go back one, maybe. Let's take a quick look at all the use cases emerging across our business. I am not going to read this slide. I just want to share the breadth and depth of what we're pursuing at SailPoint. Many of these are in various states of development or maturity, but what this really demonstrates is there is not a corner of our business where we are not thinking about how we deploy AI to make whatever role in that part of the organization more efficient and more effective. You just heard from Meredith. Actually, we flip to the next one. I will tell you a couple of ones where we've made some really nice progress.

Obviously, Meredith owns our customer support and our customer success organizations. First, in customer support, we have realized meaningful reduction in incoming support tickets from our customers, while our average time to resolution has improved by 10%. The really interesting thing here is we've seen a more than 90% increase in our knowledge base creation, meaning that our AI models are actually learning faster, which continuously improves our self-serve accuracy. In customer success, this is actually a really interesting one. In customer success, we're leveraging AI, all the data we have in all of our applications about our customers.

Think ServiceNow, Gainsight, Salesforce, even some of our professional services tools. We use all that information to leverage AI, auto-generating customer health summaries that our account managers used to manually bring together, building comprehensive 360 account views. That's really helpful to our account managers. One, they go into our customers armed with more insightful information. Two, they can extract action items from our client interactions to take actions on this quicker. Three, health score those companies.

What that does is allows us to identify and potentially remediate churn months earlier than we were previously able. This is not theoretical efficiency. We are not talking about something we think could impact our business or that we're hopeful will impact. We're seeing it today. It is real. It's active operational leverage that's giving hours back to our crew members every single day. With that, what we'd like to do is share the information we're learning in real time with our customers as they're on their own AI transformation journey, and Sree's going to talk a little bit about Customer Zero.

Sree Kancharla
CIO, SailPoint

Thank you, Abby. With all the AI innovation and transformation we are driving to accelerate SailPoint business, a unique part of our strategy is being Customer Zero. At SailPoint, we are proud to be the very first and undeniably the most demanding user of our own platform and its advanced AI capabilities. Chandra couldn't agree more about this fact because we trouble that team a lot, a lot, a lot, a lot on the real-time feedback. This brings us to, I want to focus on SailPoint Agentic Fabric. Today, we have successfully deployed some of the already existing key features which actively are protecting SailPoint as we roll out all the AI agents across our enterprise.

Whether our teams are using Gemini, Cursor, Claude, or Amazon Bedrock, our guardrails are very active. Through our discovery and unified registry capabilities, we can instantly discover agents across all SaaS platforms, endpoints, and browser profiles. At the heart of this visibility is our unified identity graph, which connects the dots between human users, entitlements, machine identities, and active agents. To give a sense of our scale of Customer Zero, we are currently governing nearly 4,000+ agents, almost 1,100 application machine accounts, and a couple of hundred service accounts.

These capabilities allow us to aggressively mitigate shadow AI risk, steering our global force into secure GenAI environments while completely shutting down any unauthorized access to the tools. Furthermore, our real-time governance and audit capabilities, we are establishing a new industry standard for life cycle management, data access governance, and continuous compliance through human-in-the-loop certifications.

Looking ahead, I'm incredibly excited about our upcoming authorized protect and respond roadmap, which will bring the real-time, just-in-time security and the prompt-level protection, which Chandra talked this morning, and Mark was also mentioning, to the market. We'll be the first one to test that, which is very exciting. We are actually working very closely with product and engineering teams around this. This internal expertise allowed us to precisely create the blueprint of our own Customer Zero journey and create the Project Odyssey by sharing our value real-world experience.

Along with, we are helping our customers eliminate any deployment bottlenecks, accelerate the time to value, and drive faster adoption with our own ISC platform. Our leadership in this space is why we feel that we are design partners working on validating all the key features, along with any incubating ideas too. We do that. Other thing I think is we are partnering with Google to see how we can connect that to ISC platform and govern Gemini AI agents too. We are able to do that as design partner because of this. Thank you so much for your time today. I would like to pass it on to Abby now.

Abby Payne
Chief People Officer, SailPoint

Thank you so much for, of course, spending some time with us today. I'm about to turn it over to Brian Carolan, our Chief Financial Officer, who's got lots of fun data, and then obviously before lunch. Thank you very much. Appreciate it.

Brian Carolan
CFO, SailPoint

Thanks, Abby, and thanks, Sree. This is what you've all been waiting for patiently. Good afternoon. Good morning. Thanks, everyone, for being here. We really appreciate you giving up your time. Hopefully, you find this a very informative day. It's a pleasure to be here to provide a detailed update on our financial strategy and the powerful momentum we're building in the business. Over the next few minutes, I'm going to walk you through our long-term vision, the clear and actionable paths we're taking to get there, and the financial discipline that underpins our entire strategy.

We're incredibly excited about the future we are building, and my goal is to give you a clear view into why we are so confident. Let's start with that future view. We've set out four ambitious but achievable targets for fiscal year 2029 that serve as our North Star. First, we expect ARR growth to accelerate to over $2.1 billion by FY 2029. This acceleration is based off the FY 2027 ARR guidance we provided last week, which we are reiterating today. Secondly, we are targeting over $800 million in ARR from our AI solutions, cementing our position as an innovation leader in identity security.

I'll get deeper into the definition shortly, but as Matt mentioned, we'll be landing humans and AI together. You cannot isolate the $800 million of AI-driven ARR to derive insights into the remaining human-centric part of the business. Lastly, we are building this business for the long term with a focus on profitability and efficiency. That's why we're committed to achieving an adjusted operating margin of over 22% and generating over $400 million in free cash flow by FY 2029. We are focused on both growth and cash flow generation to deliver shareholder value.

How do we get there? Our strategy is straightforward and consistent with the growth algorithm that we've been executing against for the past several years, with half of our growth coming from new customers and half coming from existing customers. Within each of these go-to-market motions, we have multiple durable paths to achieving greater than $2.1 billion of ARR. With respect to new logo acquisition, there are three primary drivers. First, as Matt covered, we have a target account list of 15,000 enterprises, which includes many of the world's largest and most complex organizations.

These are typically enterprises with more than 5,000 human identities and greater than $1 billion in revenue. In these accounts, we are actively displacing legacy homegrown or insufficient point solutions, and we would expect the non-human identities to far outpace human identities over time. Our SailPoint Agentic Fabric, also known as SAF, represents a large incremental go-to-market opportunity for us. It is designed to work everywhere to secure a customer's entire agentic footprint, even if they use a different platform for basic access management.

We believe this provides an incremental avenue of growth to penetrate legacy environments without the upfront upgrade. Landing the customer is just the beginning. Our expand motion is equally powerful. We expect to grow with our customers by upgrading them to our Agentic suites, migrating them from on-premises to our modern SaaS platform, and cross-selling additional capabilities and capacity to meet their evolving needs. This balanced approach gives us confidence in our ability to execute year in and year out. Looking ahead, our agentic solutions will be our primary go-to-market engine.

By the time we exit fiscal 2029, we expect this AI-driven motion to represent greater than $800 million of ARR. How do we define AI ARR? This category encompasses our Agentic Fabric, our Agentic suites, and our Agentic add-on modules. Whenever we land a new logo, win a competitive displacement, or upgrade an existing customer to our new AI solutions, we will count that full annual contract value as AI ARR. Our agentic pipeline is strong, and we expect AI ARR to be greater than $100 million by the end of this fiscal year. One important note for your models, because this AI metric captures both human and non-human identity revenue, any remaining non-AI ARR won't give you an accurate read-through on our human-centric offerings.

We chose this specific methodology because it reflects underlying customer demands and preferences. Based on this new commercial model that Wendy presented earlier, we are effectively doubling our accessible budget pool. We're moving beyond the traditional IT budgets and tapping directly into net new AI and cloud budgets owned by chief AI officers. As it relates to winning new customers, our SaaS platform is the engine driving our growth. As you can see, the green portion of these bars is growing significantly faster than the blue as customers leverage our latest innovations. While our total customer base is growing at a healthy mid to high single-digit rate, our SaaS customer base is growing in the mid to high teens year-over-year.

These are not small customers. The average ARR for a new SaaS logo is approximately $400,000, growing 20% year-over-year on a trailing 12-month basis. We believe this demonstrates the strategic importance and value of the problems we solve right from the start of the relationship. I also want to spend a moment on the migration opportunity that is also accelerating. To date, we've migrated approximately 15% of our on-premises install base. The remaining 85% represents approximately $350 million of ARR.

We expect to migrate at least 10% of this base each year, accelerating off our recent trajectory. There are several factors fueling this acceleration, including our commitment to innovation and the rapidly growing demand for AI security. As organizations adopt AI, they are recognizing a critical need for robust governance and security across all identities, human, machine, and agentic. Our platform provides the framework to secure this new frontier, that is driving a clear sense of urgency.

We're making this easier with things like you saw, SailPoint Agentic Acceleration and our flex pricing offerings, which Matt discussed earlier. Migrating customers to our platform has become significantly faster and easier, helping us unlock $1 billion+ opportunity. This is not a one-time benefit. At the time of migration, we see an immediate 2x-3x uplift in the customer's ARR. What is really exciting is what happens next. Once on our SaaS platform, we have the opportunity to expand that relationship even further, leading to a 3x-4x+ multiple on their original on-prem spend over time. In fact, we are seeing this expansion in our initial cohort of customers that have modernized with our SaaS platform.

Our growth model is built on a foundation of exceptional customer retention. For several years running, we've maintained a gross retention rate of 97% or higher. This speaks directly to the mission-critical value of our platform. We just don't retain customers, we grow alongside them. Our expand strategy is fueled by our core net retention rate drivers, migrations, suite upgrades, cross-selling, and capacity expansion. Let's look specifically at the upgrade opportunity with our new agentic suites.

Currently, our existing suites represent approximately $500 m illion of ARR. As we transition our customer base to these new agentic offerings, we anticipate a powerful upgrade motion driving a 25%-50% uplift. Ultimately, our growth is intrinsically linked to delivering compounding value to a highly successful customer base. To understand our P&L dynamics, let's look at the ARR picture again, focusing on the SaaS contribution. It's clear that SaaS is our primary growth driver. In FY 2026, our SaaS mix of net new ARR was 83%.

In fiscal 2027, we expect this mix to increase to 90%-95%. By FY 2029, we expect that to be near 100%. The transition to SaaS is fueling incredible momentum with a projected SaaS ARR compound annual growth rate of over 30% between now and fiscal year 2029. This will result in our SaaS ARR growing to greater than $1.7 billion by FY 2029, forming the vast majority of our total business. This is the definition of a durable, high-growth recurring revenue business. It's important to discuss how this transition to a SaaS-first model impacts our revenue recognition. This is a critical point for understanding our financial trajectory.

As our SaaS mix increases, it creates a temporary headwind on our recognized revenue and adjusted operating income growth. This is due to the difference between upfront or point-in-time revenue recognition for term licenses versus ratable recognition for SaaS. For example, a typical three year term deal requires 60% of the revenue to be recognized upfront in the period of sale. Conversely, the ratable recognition of a SaaS deal would result in over 50% less revenue in the initial year, but 2.5x greater revenue in years two and three.

It is important to note that our underlying ARR growth and free cash flow generation are largely unaffected in either scenario. As you can see, we expect revenue growth to re-accelerate as we move past this mix shift. We are consciously building a more durable and predictable business for the long term. Despite those revenue recognition dynamics, we are committed to expanding both our adjusted operating income and free cash flow margins. In FY 2027, we are modeling a working capital headwind from the fiscal year shift.

As we fully normalize the quarterly booking shift, mostly from December to January, we expect working capital to turn into a positive contributor starting in FY 2028. As we scale our business and our SaaS transition matures, we expect to drive significant operating leverage. This will be fueled by productivity increases across the company. As you can see, we would expect to achieve our target of 22% margin for both adjusted operating income and free cash flow by FY 2029, demonstrating the efficiency and profitability of our model at scale. As we move past the SaaS term impact, we expect our free cash flow margin to exceed our adjusted operating margin beyond FY 2029. This all comes together in our long-term financial model.

This table provides the blueprint for how we see our financial profile evolving. You can see the journey from our historical performance to our FY 2029 targets and beyond. We expect to maintain a robust adjusted gross profit margin profile as we scale our cloud infrastructure. We will drive significant leverage in our sales and marketing and R&D functions as we become more efficient and embrace new AI technologies.

We will maintain discipline in G&A. This all flows down to our FY 2029 targets of at least 22% for both adjusted operating margin and free cash flow, driven by the combination of operating leverage and the SaaS term mix we've discussed. We also expect to reduce our stock-based compensation from approximately 20% this year to the mid-teens, resulting in 2%-3% share dilution. It's important to note that we expect to see an SBC reduction in FY 2028 as we move past the two-year grants associated with the IPO.

With durable growth drivers that should sustain our 20% growth rate and expanding adjusted margin profile into the low 20s, we believe we are an attractive Rule of 40+ company. We believe there is more. While we expect to maintain our balanced growth profile between new and existing customers for the next couple of years, over time, we expect more of our growth will come from our install base, expanding our NRR profile. What we have laid out today, which supports a very compelling and accelerating growth story from new logos, existing customer expansion, migrations, and new routes to market, all of this is still in the early innings.

As such, we have multiple levers to pull to achieve and potentially exceed our long-term goals. As a result, we see many paths to expand beyond a Rule of 50. To bring it all together, I want to reiterate the three key themes that define our story. First, innovation. Our advancements in AI and real-time governance are not merely product features. They are foundational to our strategy and serve as the primary engine driving our future growth. Second, differentiation. We stand apart through our sheer depth and breadth of our identity coverage, our ability to link non-human identities to human owners, and our capacity to accelerate AI identity security for our enterprise customers.

Ultimately, we believe we are uniquely positioned with the right platform, the right data, and the proven expertise to continue to lead in the next era of identity security. Third, our multiple paths to the FY 2029 plan. As I stated earlier, there are multiple paths to achieve and potentially exceed our long-term goals. We have a clear vision, a proven strategy, and a disciplined financial plan to get there. We are building the future of identity security, and in doing so, we are confident that we will deliver significant and sustained value to you, our shareholders. Thank you. With that, I'd like to invite the rest of the team up, and we'll take some questions. Thank you.

Scott Schmitz
SVP of Investor Relations, SailPoint

Thank you, Brian. Is this on? Thank you, Brian. While the team gets assembled here, the deck you just saw today will be posted online. Comes on now. All right. Who's up first? Saket?

Saket Kalia
Analyst, Barclays

Excellent. Thanks. Saket Kalia from Barclays. Thanks so much for hosting today. Really, really informative. Mark and Brian, maybe for you, just to get right into that great target for 2029. Can we dig into the 2x-3x uplift that you're seeing from on-prem customers? What have you seen from the 15% of the base that you've converted life to date, in terms of what you're actually seeing? How are we thinking about that uplift in the path to $2 billion in FY 2029? Does that make sense?

Mark McClain
CEO and Founder, SailPoint

Sure. I could go. These microphones on?

Scott Schmitz
SVP of Investor Relations, SailPoint

Yeah, we're on.

Mark McClain
CEO and Founder, SailPoint

They're all on. Okay, great.

Scott Schmitz
SVP of Investor Relations, SailPoint

They're all on.

Brian Carolan
CFO, SailPoint

Okay. Thanks, Saket, for your question. Appreciate it. We've actually been maintaining that 2x-3x uplift fairly consistently for the past couple of years. We've been migrating or modernizing our customer base from on-prem to SaaS. We do see that typical consistent 2x-3x uplift. As I mentioned, as you extend that beyond into years three and years four, we start seeing a 3x-4x+ uplift. We think this is an exciting opportunity. We're expecting at least 10% of our on-prem base to migrate each year. It could go beyond that, especially as you see all of the innovations that we've made to make it easier for customers to migrate, and we have more upsell opportunities. I think we're being fairly reasonable with that 10% number, but it could go higher.

Scott Schmitz
SVP of Investor Relations, SailPoint

Peter, you're next.

Peter Levine
Analyst, Evercore

Thanks, guys. Peter Levine at Evercore. Mark, the comment this morning changed from, I guess, the IPO, which is now you're saying about 1,000 identities attached to one human. You have $5 billion, call it $5 trillion potential monetization opportunities. Saket's question is, if you think about the migration, are you seeing faster migrations? I know you, Brian, you said 10%, is it forcing customers now to move to the cloud quicker? Is that part of this longer term path towards the $2 billion+ ?

Brian Carolan
CFO, SailPoint

I'll start, I'll let Mark chime in. Yeah. We've been doing this, trying to meet the customer where they are, right? We feel like it's important to not force them to modernize. We want them to want to modernize and improve their overall posture. We're seeing a lot more customer interest, they're coming to us with wanting to modernize. We view that as a really big positive for us. It's all the innovations that we've come out with. It's that carrot and stick approach. That carrot's out there. It's the innovation carrot, I think it's driving it.

Mark McClain
CEO and Founder, SailPoint

I think two things come to mind, Peter. One is, that the catalyst for this is certainly the Agentic Acceleration that the customers are feeling, to your point. We wouldn't characterize them as 1,000:1 yet, they seem to be on that trajectory. They're over 100:1 is sort of our current estimation, including all machine types, not agents, just to be really clear, right? On the other hand, I would say two things are changed in what you heard today. One is the move from should we consider or is our organization thinking about agentic seems to have flipped this year to, we're doing this.

It's the rate and pace, as you heard even Sri talk about our organization, every organization we know, when they put in some of these discovery capabilities, they have a lot more than they knew. That is 100% consistent. There's more already happening than IT is typically aware of. Secondly, don't miss the importance of the Agentic Acceleration we've talked about today. We have now demonstrated that we can take months to days in that process.

When we approach customers with those three things, you've got to get to agentic. We can do it way faster than you thought and therefore way cheaper than you thought in terms of spending SI money. Those are the stick and carrot combos that we think are going to unlock. As Brian said, we're committing to a 10%+ in that migration category. Lots of reasons to think it could be higher than 10, but that's where we are today in the middle of the second quarter. Things are changing quarter-by-quarter in the world we're living in.

Scott Schmitz
SVP of Investor Relations, SailPoint

Great. Maybe Gray. Kelly, could you pass him the mic?

Gray Powell
Analyst, BTIG

Great. Gray Powell, BTIG. I just wanted to follow up on that question, and perfect timing. My notes just fizzled out on me here.

Mark McClain
CEO and Founder, SailPoint

You've got it all right here.

Gray Powell
Analyst, BTIG

I got it memorized anyway. I think it was one of the customer examples where they reduced the amounts of human work in a migration by 80%.

Mark McClain
CEO and Founder, SailPoint

Right.

Gray Powell
Analyst, BTIG

Is that what you're seeing on average? I'm just trying to like sort of-

Mark McClain
CEO and Founder, SailPoint

It's new. I'll let Matt comment. It's new, Gray, right?

Gray Powell
Analyst, BTIG

Okay.

Mark McClain
CEO and Founder, SailPoint

Just to be fair.

Gray Powell
Analyst, BTIG

Is it like a migration is going from eight or nine months to a couple of months? I'm just trying to frame that up.

Mark McClain
CEO and Founder, SailPoint

Yeah.

Matt Mills
President, SailPoint

Yeah, look, that's absolutely it. We probably, I don't know, maybe we've done a dozen of these, 15 of them, right? It's something that we're using every chance we get, and look, you're always going to have these corner cases where they've done some extreme things. Maybe they're using some of the old IBM connectors, and that'll take a little bit more elbow grease, but, I think our expectation is that 80%-90% is going to become common, in terms of the migration. Gray, the thing you should think about is that we're accelerating the piece. You heard Rex talk about the good stuff, which is the business transformation, right?

The change management, where they really excel. The slowness in these migrations was the foundational piece, right? Doing the conversion of all the connectors, having to do the research. Jeff talked a lot about it, the fact that we can actually go run and come up with the research, the discovery, really, just like we're discovering everything else. You sit here and think about some of these systems that have been around eight, nine, 10 years, probably through, as fast as a CISO goes, maybe five or six CISOs, right? You've got all this layered change that's sitting, and nobody ever finds out about it. Now we've got a tool that comes in and says, "You have this many modifications. You have this many workflows.

You have this many entitlements. You have this many identities." It delivers it in minutes. It takes a big chunk of that manual discovery work that had to take place. Yeah, I think customers are going to be thrilled. I think it's going to change the way, as Steve Caldwell said, we engage customers, and it's going to compress this process of selling and deploying. I think it's going to be pretty exciting, and it's going to change a lot.

Scott Schmitz
SVP of Investor Relations, SailPoint

Great. Maybe Shaul?

Speaker 21

Thank you so much. It's interesting that CyberArk and Varonis probably towards the end of the migration process, CyberArk, Mark, you know your good old friend has done it quite successfully. If history is any guide, I know that past performance is not indicative, I think that 10% is going to be a little faster, but again, that's my humble opinion. My question is, some of your on-premise customers, have they shown a little resistance? I know Brian talked about this carrot and stick. I'm actually interested in hearing your views about if a stick is to be used, what's that stick looks like?

Mark McClain
CEO and Founder, SailPoint

Matt always says sometimes it's a long, thin carrot.

Matt Mills
President, SailPoint

A sword stick

Mark McClain
CEO and Founder, SailPoint

It's not a stick. I think we see a couple things, and Meredith, I'm sure Matt can speak to this too very well. Within that IIQ base, there is a dispersion of types of customers. There are some small customers, I like to say it this way, that bought IIQ because that's all we had at the time. Think 12 years ago. They would've been a SaaS customer first if we had had it. It wasn't the right time in the market, et c. Some of them may or may not move with us, and if they're really small and not willing to be aggressive, we may just We don't get tied up on our customer count growth. We think about the right kinds of customers growing. The mid to larger customers in that IIQ base are feeling that pressure to move to Agentic.

I think the resistance that they had, to kind of sound like I'm beating a horse here, or the financial hump to get over, which was both the cost doubling while you had to do the migration to both products and the SI cost to make that migration happen. We're dramatically changing those with the flex pricing and with the Agentic Acceleration. There's the carrot, the true carrot, which is, "I got to get this Agentic thing solved."

One of the reasons that the team decided to separate Agentic Fabric as its own kind of unique module is if somebody is feeling so much pressure to get to that, they can actually procure SAF before they make the migration to cloud. We think most of our customers will kind of do that altogether, go from IIQ to ISC plus Agentic Fabric. Now they have multiple paths forward depending on the pressure they're feeling in their organization. I don't know if you had anything else to that.

Matt Mills
President, SailPoint

No, I would just say, look, when you look at that IIQ install base, probably 40% of them represent about 85% of the value.

Mark McClain
CEO and Founder, SailPoint

Yeah.

Matt Mills
President, SailPoint

Right. Those are the larger companies. Those are ones that really have a SaaS-first mindset. They're going to go. It was always about timing. I think one of the challenges they get into now is in their head, they still have this migration thing, which is like Voodoo for customers, right? They're like, "Migration is bad." Now we're taking some of that away. We're taking some of the economic issues away, and with what we just announced here today, that'll take a lot more.

I think you'll see a lot of these start to accelerate maybe a little bit faster. We've really spent, Gary and his team, they've done a wonderful job of understanding what the barriers are to move forward, and they just plod their way through and just kind of remove those barriers. There's not many left, to be honest with you. With all the stuff that Chandra's building and delivering, it kind of becomes a no-brainer, like I got to go.

Scott Schmitz
SVP of Investor Relations, SailPoint

Meta, will we go to you?

Meta Marshall
Analyst, Morgan Stanley

Great. Meta Marshall, Morgan Stanley. I guess just in terms of how to think about understanding you had on the slide kind of six items that you were taking into consideration on pricing. API calls, number of agents. Understanding Flex gives you a lot of flexibility in early days around pricing. Just what are you seeing in terms of that conversation of just kind of ratio of costs that we can think of in terms of humans to agents? Just as we think about that $90 billion TAM that you guys laid out, how much should we consider that expansion to be from number of agents or identities that you're managing versus kind of expansion of the platform? Thanks.

Mark McClain
CEO and Founder, SailPoint

Matt, do you want to-

Matt Mills
President, SailPoint

Yeah. I mean, what we've really tried to do, as I was saying earlier with the migrations, is create this buying habit where it's easy to buy, and there's inhibitors that have been pretty consistent since we started talking about these non-humans. One of them is nobody has any idea about how many they have, and everybody's really concerned about these runaway costs. With our pricing model, the team's done a pretty good job of removing that.

We still get our traditional uplift that we've put in historically to jump from IIQ to Business Suite or to Business Plus. You'll get that jump, but your initial buy will give you an allocation of non-humans with the product. Now you can start deploying and using, and then there'll be a series of expansion packs where you'll buy as you go forward. It lets you, and I'll call this, these are expansion packs. Meaning there's all these tiering systems historically. This is when you get to one tier, you got to buy. It's not like that. This is basically expansion packs, and you control how much you buy. It's really g iven the customer complete visibility and control of their environment, which is, I think, removing a big obstacle and getting people comfortable with moving forward.

Brian Carolan
CFO, SailPoint

Just on the TAM question too. Things have changed so much over the last couple years. When we were on the IPO roadshow, we're at $55 billion of the TAM. Most of that was human identity. This is exploding at this point in time and evolving. We feel like $90 billion is a good estimate right now, but I think that's really driven by the non-human aspect.

Scott Schmitz
SVP of Investor Relations, SailPoint

I know we'll get to everybody. I said how about Shrenik, and then we'll go to Josh and Junaid.

Shrenik Kothari
Analyst, Baird

Yeah, Shrenik Kothari from Baird. Brian, you did lay out a path from AI-related ARR, pretty much at $100 million this year, actuating pretty meaningfully to $800 million+ by FY 2029. I know you said it's hard to unpack completely. You gave a sense of languages expanded. Just curious, across the core pillars, you, of course, mentioned about the discovery and governance and then added the protect pillar. Just curious, how are you thinking about relative contribution to this AI ARR acceleration from these pillars?

Brian Carolan
CFO, SailPoint

I don't know we'd break it down that way.

Mark McClain
CEO and Founder, SailPoint

Have we really divided that way?

Brian Carolan
CFO, SailPoint

Yeah.

Mark McClain
CEO and Founder, SailPoint

They're buying that complete value proposition, and certainly the pricing just assumes you're getting all three of those core pillars. I don't know that we would be able to say they are ascribing more value to this, that, or the other. I think probably the main thing to take away from that, and we'll be a little more direct maybe than we were in the presentation. There's a lot of noise from some hot startups that are doing agentic management, and they are primarily doing discovery, classification, visibility. That's it. What we've been asked in some settings is, well, when that kind of company, I won't name them, you all probably know, but I won't. That kind of company shows up around you guys, what happens?

The answer is they show up, they start doing discovery in that enterprise account, and then the customer says, "This is great. Now how do I take action? Oh, I need to connect to SailPoint for that." Right. If we could provide that discovery and visibility and take action, why would you need that independent agent tool that only gives you visibility but doesn't allow you to respond and remediate? I think we're going to see, hopefully, a little bit of wind come out of the sails of the hot new, "Hey, I've got this agentic answer for you." Now customers are figuring out, that's great that you can help me find these things. Now I need to do something, and that's where they frankly hit a wall.

Scott Schmitz
SVP of Investor Relations, SailPoint

Great. Josh? No, that's Kelly again. Here you go.

Mark McClain
CEO and Founder, SailPoint

[inaudible]

Speaker 24

Hey, guys. Thanks for doing this. My question is more along the lines of, I felt like at the earnings call, the message was something along the lines of AI is really early, so we still want to be conservative. I feel like today the message coming out of here is kind of AI is awesome, so we're guiding to accelerating ARR. I'm just trying to reconcile those two messages. Does that mean we should expect all this excitement to be a next year and beyond thing through the 2029 target? Just how do I assess those what feel like two competing excitement points?

Mark McClain
CEO and Founder, SailPoint

Well, that was last week, Josh. No, I'm kidding. Brian can explain that.

Brian Carolan
CFO, SailPoint

We do feel it building. We tried to lay out just some data points. For example, last fiscal quarter, 40% of the identity growth came from non-human identities, right? 20% of our net new ARR was from emerging products inclusive of AI. We still feel like it's still early innings, but we see the budget building, as Gary mentioned. Budgets have been doubling quarter-over-quarter. It's there. I think what we're trying to just be a little bit prudent on is as to when it exactly hits into what quarter. We feel the tailwind's coming. It's a matter of when, not if.

Mark McClain
CEO and Founder, SailPoint

Yeah. The simple answer, Josh, is last year we were talking about the rest of this year. Today, we're talking about the next two years beyond.

Brian Carolan
CFO, SailPoint

Yeah.

Mark McClain
CEO and Founder, SailPoint

That's what we said qualitatively on the call last week was, we see this momentum coming, and everybody's like, "Well, why isn't it showing up in this year's guidance?" We said, "Because we're not comfortable calling that yet." As Brian said, we are reiterating this year's guidance. Yep. We are giving you that confidence with a two-year-out model that says, we're comfortable lifting the model two years out. That's the confidence we see in the momentum building. Hope that helps.

Scott Schmitz
SVP of Investor Relations, SailPoint

Great. Junaid?

Speaker 25

Great. Thank you. Mark, you've positioned the Agentic Fabric as this work anywhere control plane that you can sell standalone even to enterprises running legacy IGA stacks. If a customer adopts the Agentic Fabric over a fragmented or let's say messy legacy human identity foundation, how do you enforce or ensure accountable ownership without inheriting the poor data quality that's underlying that identity system?

Mark McClain
CEO and Founder, SailPoint

I'll probably let Chandra handle that one because we've talked about how this SAF is going to work in the context of other tools. There is going to be somewhat less delivered value, we think, which will ideally create magnetic pull for those customers to get onto our cloud IGA product. I'll let you talk about how would it work with an IBM or an Oracle or something else like that.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Yeah. We have really invested in a ton of tooling. When we actually bring the identity context, the human context, not just from IIQ, but from almost any legacy, we do all of the cleanup in the process of bringing it in. When we really get it's actually clean data. You can actually think of an ETL-type layer built into our connectivity so that we sort of extract, load, transform Bring clean data in. That's sort of the simple way to think about it.

Mark McClain
CEO and Founder, SailPoint

It'll likely be limited, to be fair to Chandra.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Yeah.

Mark McClain
CEO and Founder, SailPoint

In other words, we see so many of those old IGA platforms. They only got the 10% coverage of that customer's identity landscape. We'll clean up the 10% we can bring in. I think it'll create pull for them to go, "Oh, now I see what I'm lacking on the human side as I've leaned in on the agentic side," we think that'll pull them forward.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

The biggest thing we are doing, like Mark said, the coverage today of the application base is less than 10%. We have agentic tools which will allow you to build connectors to both modern as well as legacy applications in minutes. We have the ability to bring 100% of applications in coverage to our platform.

Matt Mills
President, SailPoint

Yeah. I think the only thing I would add is that the greatest tools in the world will not alleviate the customer from having clean data, right. Making sure their house is in order. We'll take all of that, and we'll extract it, and we'll consume it into our platform. They've still got to do the lift of making sure their data's good.

Mark McClain
CEO and Founder, SailPoint

Yeah. For those of you that know the long SailPoint story, we started with a compliance product before we had a lifecycle management product, and we would come alongside legacy lifecycle products like IBM and Oracle and everybody else. What would happen quite typically is we'd come in with the compliance product next to their old LCM product, and pretty quickly the customers go, "Wow, I should get all of this onto your platform."

That was a very common motion for us in the late 2000s, early 2010s. I think I see that same picture emerging. We'll come in with this agentic when they're not quite ready, supposedly, to move forward off their old IGA platform, and they'll very quickly see, "Oh, I've got to get off this old platform very quickly if I want to get the full value," like Matt said, "of clean data for my human."

Again, Chandra hit it pretty hard, that real-time human control, part of what's going to happen in this SailPoint Agentic Acceleration is people are going to look back to their human controls and realize this static once-a-year certification check of humans is ludicrous in today's world, right. It's like once a year you validated your access rights in your company, and the other 364 days, what exactly was happening, right. I think we're going to quickly see this demand for real-time human governance. That will get pulled along by the agentic world because they're going to see the delta.

Scott Schmitz
SVP of Investor Relations, SailPoint

Great. Let's go here in the back.

Rich Poland
Analyst, Wells Fargo

Hi. Rich Poland from Wells Fargo. Thanks for taking the question, guys, and putting this together today. I think just in terms of as we think about the agentic side layering on, I feel like it's created a lot more visibility into the broader environment of just machines, API keys, all these things that weren't previously under at least the purview of an identity contract prior. Does that serve as maybe some of the initial pushing point, and then the agentic layers on top of that? I guess, what are you seeing now today? Is it machines first, then more just true agentic, or both?

Mark McClain
CEO and Founder, SailPoint

Both. I think. You want to Yeah.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Yeah. There isn't really one progression, but here's a bit of a blueprint that's really emerging. It really starts with all these non-human identities, which are these credentials and tokens, because humans have been using them for a long time. They have been unmanaged. That's sort of step one. Step two is we are seeing endpoint agents. The fastest growth we are seeing are all these endpoints. Think of all these coding agents, OpenClaw, NemoClaw, those kinds of tools, right? The third category are all these enterprise agents, which are being used to automate business processes, and that's really where is Microsoft, AWS, Google, right? I would say then comes all of the application agents, right? It could be Salesforce and sales, right? That's the way I would think about it. Does that make sense?

Mark McClain
CEO and Founder, SailPoint

Both will pull that NHI world. I think to answer your question, right, I think both the movement of agentic, it'll pull along with it all the NHI infrastructure that enables that agent to do its job, and it's also exposing the lack of controls over those NHI tools in the human context pre-agent, to your point. We just were not governing and securing those things well before. It's a little bit the same point. As we shine a light on this whole area, people go, "Oh, wow, I have huge exposure here I didn't really understand." That's partly what's happening.

Scott Schmitz
SVP of Investor Relations, SailPoint

Go to the back.

Imtiaz Koujalgi
Analyst, ROTH Capital

Hey, guys. Hi, it's Imtiaz Koujalgi from ROTH Capital. I had a question about the competitive landscape. There was a lot of changes in the last few years. Okta launched the IGA product. CyberArk bought Zilla. Palo Alto acquired CyberArk in the last few quarters. One of the questions that I get is, how has that impacted you guys because you're a pure IGA player. Everyone was a pure player. IAM, PAM, and IGA were separately, and now it looks like there's a lot of overlap between every vendor offering the whole platform.

How has it impacted your business? One of the questions that I get a lot is with Palo Alto buying CyberArk, they have a big install base, almost 50,000 customers. I'm sure there's a healthy overlap between their install base and your install base. Are you seeing any impact? Do you expect any impact? I think the genesis of the question was the net new logo adds last quarter, I think, was a little bit light. Are there early concerns from that acquisition?

Mark McClain
CEO and Founder, SailPoint

I'll start it and let the guys jump in. When people say, "Are you worried about Palo Alto because they just entered the game with CyberArk, which bought Zilla?" Just so everybody's clear on the heritage there. Zilla was a very tiny IGA company, less than $10 million ARR. Never lost a deal to them, ever. That's the state of the union at the time, Palo bought CyberArk, which bought Zilla. Okay? We didn't see CyberArk as an IGA threat. In that sense, we don't see Palo Alto as an IGA threat. I'll just use IGA as the name for the moment. I should say an adaptive identity threat, to be more clear. They're a big player. They show up in a ton of accounts. You know who's an even bigger player? Microsoft, who's been coming at us in this game for four years.

As we said to you over and over, Microsoft is effectively making no dent. I won't say no, I'll say minimal. Microsoft is making minimal dent today after being at it for years with a product far advanced over Zilla's. With all due respect, I don't think the team fully understands what they didn't get when they bought CyberArk. They got a great historical PAM tool. They did not get a tool that competes with SailPoint for our core. If you listen carefully to some of their dialogue, the head of the company will repeatedly say, "Our tradition that with CyberArk, we are managing 3%-5% of the identities in a typical enterprise. Now we just have to expand to the other 100%." Simple. Simple to expand to the other 95%-97% you weren't doing before.

You can judge for yourselves how simple you think that is. We're respectful of large competitors. This company's whole existence has been competing with IBM, Oracle, Microsoft. We're good. We can take people on this turf and do just fine. That's the state of the union. Same could be said about the O company, who also talks about a rapidly expanding IGA business. As we say, still has not made a dent in our business of enterprise customers.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Mark, can I just build on that on one? To the contrary, I think what we are doing is really democratizing privilege. What we believe we have is really next generation PAM, quite frankly. Because we think PAM will have its role, which is if you are a database admin, sys admin, cloud admin, just doing session management, vaulting, and all those things, what about the remaining 97% of roles? Mark isn't managed as a privileged identity inside our company.

Mark McClain
CEO and Founder, SailPoint

Which hurts my feelings.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

None of us are. That's crazy, right? We have access to critical data. That's really what we mean, right? We believe all these historical traditional PAM RFPs will increasingly become addressable to us because we are expanding what it means to be privileged. We are going to go after that tail, is what I'm saying.

Scott Schmitz
SVP of Investor Relations, SailPoint

Maybe, Brian, do you want to address the 15 customers this quarter and-

Mark McClain
CEO and Founder, SailPoint

Oh, right.

Brian Carolan
CFO, SailPoint

Just to close off on that question.

Mark McClain
CEO and Founder, SailPoint

Oh, yeah. Sorry.

Brian Carolan
CFO, SailPoint

I wouldn't read too much into that customer count. That's a net number. Just some data points on that. Any customers that we "lost or churned," their average ARR was less than $100,000. That's to Mark's earlier point. We do might have a long tail that simple price sensitive customers, they may not need a higher level solution. The average new SaaS customer that we gained was three and a half times size that number of less than $100,000. We're good. We're playing right into our sweet spot.

Matt Mills
President, SailPoint

I would just add, when you look at that IT install, right? You get into that long tail, and they're fairly small, sub 100, like Brian said. They're probably, I wish there was a better term than laggers, right? They're slow to move, right? They're targeted by the Oktas and the smaller outfits. When somebody can say, "I can get all three pillars for less than what I'm paying, and I'm not deployed." It just becomes an easier target. That's what you saw when you got the net number here this last quarter. That was a result of that, and some number of small sub $100,000 deals that fell out. When you look at, conversely, to the ones we brought in, what did we say? 350?

Mark McClain
CEO and Founder, SailPoint

Yeah.

Matt Mills
President, SailPoint

Yeah.

Mark McClain
CEO and Founder, SailPoint

350.

Matt Mills
President, SailPoint

3.5x . We're getting much bigger lands, and those are just the long tail.

Mark McClain
CEO and Founder, SailPoint

We'll never fight the customer count war against some of these guys.

Matt Mills
President, SailPoint

Yeah.

Mark McClain
CEO and Founder, SailPoint

That's not the game we're playing.

Matt Mills
President, SailPoint

Okay.

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Thank you.

Scott Schmitz
SVP of Investor Relations, SailPoint

Thank you. Over here.

Ethan Weeks
Analyst, Piper

Great. Thanks for taking my question. This is Ethan from Piper. Can you just talk a little more about what Entro brings to your non-human identity offering, and does this fully round out the plan build, or should we expect to see maybe more inorganic or organic kind of functionality enhancements from here?

Chandra Gnanasambandam
EVP of Product and CTO, SailPoint

Yeah. They complement us quite well, right? What they do really well is on all these non-human, particularly credentials, right? Imagine there are secrets and tokens and certificates, and there are 1,000 versions of it. That's why they cover more than 1,200 of these types. It complements what we have, right? We have historically been world-class in discovering all of the machines, agents, and all that.

What we were not great at was really discovering the attached credentials with them. That is what we have acquired. Now when we go discover an identity, we can actually co-discover all of the credentials that go with that identity seamlessly. That's what we're bringing together, right? Really the identity governance and the credential governance worlds are really, that's what we are doing. We are really bringing those two. That's why it's a very complementary asset to what we have.

Mark McClain
CEO and Founder, SailPoint

I think that part of your question, Ethan, was. Sorry. What'd you say?

Ethan Weeks
Analyst, Piper

Ethan.

Mark McClain
CEO and Founder, SailPoint

I was trying to get Evan or Ethan out of my mouth, and I couldn't get it to work. Sorry. At the end of the day, you should continue Boy, it's been a long day, hasn't it? It's only halfway through. You should continue to look for Chandra and the team to, as we're laying out this roadmap, continue to look for opportunities to accelerate our vision with these kinds of great technology businesses that just don't have a lot of market traction yet.

We've done that with Savvy last year, others in the past. We see a lot of opportunities in today's landscape to accelerate our vision with some very specialized, very capable technologies that'll fold into our platform rapidly. Yes, you should continue to think we are looking around the landscape for those kinds of moves. You just want me to do the other part, plus I could see your name.

Scott Schmitz
SVP of Investor Relations, SailPoint

All right. I don't see any more hands. Any last questions?

Mark McClain
CEO and Founder, SailPoint

Oh, one more? Two. Oh, there we go.

Peter Levine
Analyst, Evercore

Thanks, Brian. Two questions for you, Brian. One, can you maybe talk to us about your ownership structure, maybe some of the conversations you guys are having and what that looks like near term, longer term? Just a follow-up question on Entro, what does that bring in terms of how much did you pay for it? Could you share with us any metrics in terms of revenue contribution?

Brian Carolan
CFO, SailPoint

Sure. The first question, obviously, we've had a long-standing relationship with Thoma Bravo. They own close to 85%-86% of the company at this point. I think they don't have intentions of being long-term public company shareholders. I don't want to speak on their behalf, but that's not really their playbook. I think they're going to be thoughtful about exit strategy. We can't get into specifics in terms of where that is and what price points it are, but it's an ongoing, very professional dialogue we have with them. You said something about the revenue. I want to make sure I understood your question.

Peter Levine
Analyst, Evercore

How much revenue is it through Entro?

Brian Carolan
CFO, SailPoint

The TB relationship? No.

Peter Levine
Analyst, Evercore

No.

Brian Carolan
CFO, SailPoint

I'm sorry.

Peter Levine
Analyst, Evercore

Intro.

Brian Carolan
CFO, SailPoint

Oh, Entro. Oh, Entro. Oh, I didn't hear you.

Peter Levine
Analyst, Evercore

I don't think you get that much revenue from TB.

Brian Carolan
CFO, SailPoint

I didn't hear you. I'm sorry. I didn't hear. I'm sorry.

Matt Mills
President, SailPoint

Could you help us with that? That would be fantastic.

Mark McClain
CEO and Founder, SailPoint

That would be a new one. We're not getting into that today. We'll lay more of that out in the future. This was primarily a technology acquisition.

Matt Mills
President, SailPoint

Yeah.

Mark McClain
CEO and Founder, SailPoint

Also a talent acquisition for us. Yeah.

Scott Schmitz
SVP of Investor Relations, SailPoint

One more from the

Shrenik Kothari
Analyst, Baird

Just had a follow-up question on the new logo success. I believe I remember from the presentation mentioned 2/3 of the new logo were from failed competitive deployments, right? I know historically it's been more about, you have a broader access centric and not have enough of depth and entitlements, which is your strength. Just curious, across that versus legacy IGA versus NarrowPanel, are these new logo sort of competitive makeups changing in terms of that 2/3 is a very strong figure. Just curious in terms of the makeup of that.

Mark McClain
CEO and Founder, SailPoint

I guess it's a combination of either I could call it more recently failed deployments as in people that we've talked about today that are more active in the market today, Microsoft, Okta, Saviynt. Some of them would be, quote, "failed deployments" of the older legacy players, Oracle, IBM, et c. Failed in the sense that, again, the different game that we were playing a decade plus ago when they were more active was, "Let's go get the Sarbanes-Oxley apps under control." 5%, maybe 10% of the application landscape.

The game today, as you've heard Chandra talk about all day, is we've got to cover every application environment, every identity. Customers have figured out there's no chance they're going to get that old legacy tool to that goal. That would be a, quote, "failed deployment" story as well. I can't get where I need to get to with Oracle, IBM, and quite a few of those are failed deployments of far more recent losses. I'll say that. Deals we will lose, and within a year or two or three, we'll be back in because that didn't go as planned. We're actually capturing both in that failed deployment stat, because I'm pretty sure that's how we characterize that, right?

Matt Mills
President, SailPoint

Yeah. I would just tell you where we play, the larger enterprise, we're replacing somebody every time. It could be an Oracle or it could be a CA or something like that, where maybe they just got long in the tooth. To Mark's point, it could be that somebody mistakenly bought, I'm not going to call them, but one of those.

Saket Kalia
Analyst, Barclays

Insert name.

Matt Mills
President, SailPoint

Somebody lost their job, and so then we got to come back in and redeploy it. There's some of that. Virtually everybody we talk to, we're moving off of something.

Mark McClain
CEO and Founder, SailPoint

Yeah. Very rarely an internal deployment in one of those real jobs.

Matt Mills
President, SailPoint

Yeah.

Saket Kalia
Analyst, Barclays

Hey, Saket again. Brian, I don't mean to get into modeling minutia, but I want to make sure the question's asked, right? Round numbers, we're going to be at $1.4 billion in ARR this year. Again, it's round numbers, right?

Brian Carolan
CFO, SailPoint

Sure.

Saket Kalia
Analyst, Barclays

$1.4 billion to $2.1 billion in 2029 is another $700 million from there, right?

Brian Carolan
CFO, SailPoint

Yeah.

Saket Kalia
Analyst, Barclays

When this is all said and done, when we're sitting here in FY 2029 and talking about the path. How do you think it would have looked, right? Right now it's, again, round numbers, $250 million of net new here, and then it's going to go to $350 million-$400 million in 2028 and 2029. There's this hockey stick.

Brian Carolan
CFO, SailPoint

Yeah.

Saket Kalia
Analyst, Barclays

Is that going to be very back-end loaded? Are we just going to beat 2027 by so much that it's going to be linear between now and 2029?

Brian Carolan
CFO, SailPoint

Yeah.

Saket Kalia
Analyst, Barclays

Do you get the spirit of the question?

Brian Carolan
CFO, SailPoint

We reiterated our FY 2027 guidance today, and we feel good about it, and we are laying out that $2.1 billion. That's an acceleration of growth between now and then. We're not going to get into the stair step of that linearity of the curve. We feel really good about where we're going. Have a lot of multiple paths to get there for FY 2029, and we feel really good about FY 2027. Yeah.

Saket Kalia
Analyst, Barclays

All right.

Mark McClain
CEO and Founder, SailPoint

You try.

Matt Mills
President, SailPoint

Feel free.

Mark McClain
CEO and Founder, SailPoint

You have to try.

Matt Mills
President, SailPoint

More mics. Pick yours.

Mark McClain
CEO and Founder, SailPoint

Yeah. You try.

Scott Schmitz
SVP of Investor Relations, SailPoint

All right. Well, I think that's probably a good place to end, full circle on the Q&A. Thank you, Saket. Thank you all really for being here today. Thanks for your interest. I think it's really obvious that we're excited about the future. We're excited about what's ahead. I hope you found today informative, and I look forward to staying updated with you along the journey. Thanks so much.

Matt Mills
President, SailPoint

Thank you.

Mark McClain
CEO and Founder, SailPoint

Thank you, everyone.