Hey, Mark. It's really good to have you. Thank you for joining us this afternoon, and thanks to everyone in the room. Mark McClain, Founder and CEO of SailPoint.
Pleasure to be here.
Mark, I think our Founder-led companies have a little bit of an advantage in that Founders tend to be a little bit more willing to think from first principles, a little bit more of a deep understanding in the technical bones of the product from day one.
I'm curious, when you think through the quality of the product today-
A lot is changing in identity.
Yeah.
What are some of the early decisions that you've made, or decisions that you've made over the last several years, that you think have set you up for today to be a leader in IGA in a world where agentic is changing?
Great question. Yeah, I guess some of it's never left Founder mode. I think that's a thing I've-
Yeah, exactly. That's exactly it.
If you start in Founder mode, you are always in Founder mode, maybe. I think, Gabriela, that is a great question, a little different than I have had in some of these settings, and I love it, actually. I think part of it is we had a very ruthless focus on being what we called market driven. It is very easy after a while to think you know more than your customers, like, "Well, we know what is going on in this market. We know what to do next." We have tried to be very careful over the years to not listen to ourselves, not to sit in a whiteboard-surrounded room and decide what is next. Get out there and listen. For a while, obviously, we have heard the concerns coming around non-human, agentic in particular.
Now, to be fair, I do not think if you had asked me two and a half , three years ago, whether we would be where we are today. This has been an evolution unlike most of us have ever seen in our careers, its speed and scale of what has happened. But it certainly did not catch us flat-footed, number one. Number two, there is a little bit of right place, right time. I am willing to acknowledge that. I love Founders who tell you that 20 years ago they knew it would be exactly like this. I think that is funny. But I think at the end of the day, I think we are finding ourselves in a very enviable position for what the world is needing right now.
What is clear that is needed is you are going to have to think about this explosion of non-human identities, particularly agents, which in fact leverage a lot of other types of non-human identities like service accounts and credentials and things like that to do their work. You are going to have to think about the problem we have been thinking about for humans, unlike most of the rest of the identity landscape or security landscape, and the way we have been thinking is deep and wide forever. Meaning to do what we do, we have to think about the breadth of all the identities an organization cares about, right? Which up until recently was mostly human, far beyond their employees, but all human identities. But we also had to map that across this incredibly deep, complex landscape of homegrown applications, vended applications, brand new SaaS applications, and 70-year-old COBOL applications.
That is the world our customers live in.
I remember drawing it in our SailPoint initiation 10 years ago.
It hasn't gotten any simpler. Like the Mark Twain quote, "The mainframe's demise is greatly exaggerated." They're still out there. I think at the end of the day, that heritage of thinking about this complex problem of lots of identities, the interrelationships between them, and the complexity of what they're trying to access in the environment. When you think about the agentic world in that context, this explosion of identities we're seeing, which are happening way faster than human identities ever grew, and the complexity of what it is they can do at machine speed. That problem just got about 10 times- 1,000 times harder, right? If you didn't start from where we're starting, I think you have a much bigger mountain to climb, and I think we're going to see that play out in these coming quarters.
I think, to poke at a couple parts of the landscape, there's a lot of brand-new funded companies right out here in the Valley saying, "We're going to solve agentic for you." Our answer to that is, how are you going to do that without the human understanding? These agents aren't operating in a vacuum. They're operating on behalf of someone, either directly like a copilot or indirectly, a digital work environment that we're trying to set up a completely automated loan origination department. Well, guess what? That's happening under the direction of some human. Some policies are involved there. Some data is involved there. What we're going to see, I think, very quickly, is agentic has to be understood in the context of human policies and human organizational dynamics. If you can't map that incredibly complex, rapidly changing environment, you can't keep up.
I don't know how some of the folks that are coming from other than that heritage are going to be able to keep up.
Let me play devil's advocate.
Please. It's been happening to me all day. I feel like I deal with the devil-
I believe it.
all day today.
If I was starting with a clean sheet of paper and building an identity governance solution for that which you just described as being 10 times - 100 times more complex and I think you could use the word adaptive, which I know you have.
Yes, we have. In fact, yep.
Or ephemeral. Fundamentally, I am building a solution for something that does not look like a human. So how could I possibly take an identity governance solution that was built for humans and, square peg, round hole, force it into a solution that can actually dynamically deal with agents?
I would argue, this is fun, Miss Devil, I am arguing with. You are not the devil, but you said devil's advocate. I think at the end of the day, it does somewhat look like a human, just not exactly like a human. Because to say it does not look like a human, well, really? What does a human identity do? It has a mission to accomplish. It has tools with which to accomplish it. It gets into systems or accesses data, analyzes that data, takes action on that data. That is what these agents are doing. Now, they are often doing it in unexpected ways. We just learned how to define amoral agents in the context of Hugging Face, where these agents went off and did things that humans would think was inappropriate, but they did not know. They were just trying to solve their little problem.
We are learning the parts that are not like human, to your point, what is not like human: scale, speed, lack of ethical, moral boundaries. Okay, that is different, but an awful lot is not different. It is not just that it is not different. Again, we come back to this postulation that you are not going to see agents behaving, even quote "autonomous agents" inside the enterprise context. They are not going to be behaving in completely independent ways, meaning they were sent off to do something, even if they are a sub-agent spun up downstream of an original agentic problem. That problem was defined by a human saying, "Solve this for me. Go create a workflow, create a business logic, do something.
Analyze data for me, give me recommendations." All those things are happening because some person said, "I need this in the enterprise," or, "I need to solve this problem or manage this workflow." I think we're going to be kind of forced back to these agents are, in fact, capable of human-like behavior, but with very different characteristics, to your point. It's that human context that's going to differentiate the kinds of compliance and governance and security controls we need that we will have to apply those policies differently, I think, to your point, in an agentic world. I don't think the concepts are going to be completely different.
Bring us now to some of the practical conversations that you're having-
Okay
with your enterprise customers. If I am a large financial institution and all of my agents are in sandboxes, and I say, "I would love for these agents to have more business context and be released from their sandboxes, so my knowledge workers can be productive. SailPoint, please solve this problem for me." What is the customer journey as you walk through what regular IGA to IGA for agents looks like?
Yeah. Honestly, it is so early, I'm not going to speak with massive conviction of exactly how that journey unfolds because we are very early. I like to say in baseball terms, I don't even think we're in the bottom of the first yet.
Yeah.
I think we're still in the top of the first. But to your point, I think that the truth is, one of the things people assume is true that is not true of, well, when an agent's operating, doesn't it inherit the constructs of its owner? Answer, no, it does not. You would think that would be true, wouldn't you? But it's not true. So when I spin up a Copilot or I set up a new agent in my Gemini environment, my ChatGPT environment, whatever, it doesn't have any constraints. It's just told to go do something. We have to give it whatever constraints it's supposed to have to do what we're asking it to do.
One of the things we will do is to say, "Look, we have that ability because we have that human context" to say, "This agent, which was authorized by Gabriela, will in fact inherit her constraints." But there's no natural way that happens in the environment today. That's not how these systems are set up. I make a comparison sometimes, Gabriela, that I hope is helpful. The internet was originally designed very open, wasn't it? Then we had to figure out how to secure it when we started doing things like commerce on it. These tools were designed to go grab information as much as possible from everywhere, look for patterns, and tell you what they find. They were not designed with security in mind. Satya's famous quote of secure by design. Nothing about LLMs was secure by design, and we're seeing the ramifications of that already.
These systems weren't designed with the idea of how am I going to constrain these things so they can't do too much? In fact, it was the opposite. How can we give these things massive freedom, feed them with as much data as possible, so they can give us the best answer? So we're having to now retrofit security concepts on the things that were designed with the exact opposite mindset. That's a problem. But we're going to bring those constructs back to our what's human-like and what's not of saying, "Well, how do you think about this in the human context?" You say, "What is the intent here? What is the context? What is the business problem trying to be solved? What are the dangers that exist around that?
How do I constrain those dangers while letting you do what you need to do to do your job?" I think we're going to bring those same concepts to agents. It's going to look different in some respects because of the lack of moral compass and the lack of constraints of speed and time. Some of what saves us in enterprises today is people can only do so much, so fast. Right? There's not much constraint. You read the forensic analysis of what happened with Hugging Face. It is mind-boggling. It is literally mind-boggling. I think even the OpenAI people are a little mind-boggled, which should scare all of us. But, I think at the end of the day, we're seeing when you have systems that were designed with an intent and you're now asking them to think about security and constraints, it's clashing.
We are going to have to have vendors like us and others who come in and say, "I am here to provide those constraints and policies and guidelines." Guardrails is maybe a good term here. We know a lot about how to do that, and we are going to try to apply those concepts into this environment.
Let me ask the drinking your own champagne question. Which of these frameworks, to your point on being at the top of the first inning, what is working within SailPoint? Do you have examples of successful agentic deployments where you have used Agentic Fabric and some of the really cool bells and
Yeah
whistles to feel less scared?
Yeah. We are still scared. I think maybe this is a simple taxonomy that is helpful. I think if you oversimplify it for a second, there is probably three kinds of agentic use cases that are
Yeah
emerging rapidly. One is you're sort of ideally giving everyone in your organization access to something, Gemini, ChatGPT, Claude, say, "Use this to be more productive in what you do all day, every day." That's kind of an agentic use case one. Agentic use case two is well-known vendor, Salesforce, ServiceNow, Workday, whoever has SAP, "I'm going to provide a bunch of agentic capabilities in the context of the application you bought from me." Agentic case number three, and this is generally true of mid to large size customers, which is the ones we serve. I have an IT organization and a development team. We're going to go build some bespoke things. So there's kind of day-to-day use coming through a vendor builds your own workflow process, not just over here, employee using the tool to do their job better today.
All three of those look and feel different. We are trying all three at some level. I think all companies almost of any scale are going to do one and two. If you're not letting your employees use AI to do their jobs better, you're at a competitive disadvantage today, no doubt in my mind. Second case, I don't know that a lot of people are going to be super cautious about adopting what ServiceNow or Salesforce or Workday gives them, because they're going to try to trust that those vendors put the appropriate guardrails and said, "This will help that application work better for you." The third one is, I think, the one that's going to get real hard and real messy, but it's also where we live in these mid to large enterprises.
Where a whole lot of what their IT franchise is built on was built in their shop. It wasn't something they took from the outside, and it's not just a person looking to be slightly more productive in building their next Word doc or spreadsheet. They're going to look at ways to leverage this technology for their unique business approach to their unique industry, and those things are going to look pretty different case to case. You well know that one investment bank does not look like another investment bank, does not look like a merchant bank, does not look like a consumer bank. And that's just in the industry of finance.
At the end of the day, this stuff's going to be very unique in these large to mid-size enterprises, and we're going to have to do what we did for years in the human space of say, "What are we seeing here? Where are the risks showing up? What kinds of things seem to catch people off guard? And how are we able to detect things early enough to put a stop to bad behavior?
There is an intelligence piece to the IP that I think sometimes is underappreciated.
The way I would articulate this is, investors will say to us, "Look, if you're an endpoint company or a network company, the bigger your install base, the more intelligence you have. It's like a crowdsourcing-
Yeah
or a network effect.
Whereas for something like SailPoint is equally good whether you have three customers using SailPoint or- however many customers you have-
Thousands
thousands of customers using SailPoint. Where would you push back to this idea that SailPoint's moat is lower than an endpoint or a network company-
Because of the network effect
because of this network effect, yeah.
I hadn't thought of it vis-a-vis that type of advantage, because you're right. The network effect to us is less that these things are all using SailPoint. We have some effect that we see because we see across all of them the kinds of things that have shown up as a problem here. Something we thought would be a good idea, turned out not to be a good idea. This customer says, "I think we're going to do that." We say, "Don't do that. We tried that, and it didn't work well.
That's a great network effect.
The two customers didn't see it amongst themselves. We saw it. But I think at the end of the day, the moat that's been surprisingly deeper than I think people thought was just the pure complexity and challenges of these complex enterprise environments. Because to poke at one of our friendly neighborhood identity players, our friends at Okta have been at IGA now for about five years. Notwithstanding a couple of comments that have been made, they haven't put a dent in our IGA business. They are winning IGA business basically below the line we care about.
In the enterprise sale scale, their solution, while I'm sure it's come a long ways, continues to not be competitive in this super complex world we live in, which just says something about how complex and hard it is to do what we do at the scale and complexity we do it. I think at the end of the day, that moat of not just understanding what needs to happen in business processes like compliance and provisioning, lifecycle management, all these things that we do, but doing it at the scale and complexity we do it, has just turned out to be a very big moat. People ask us now, "Well, aren't you running into all these folks that have had press releases? CrowdStrike and Palo Alto and Microsoft and Okta." The answer is, no, we're not actually.
We're not running into them in these competitive environments because the customers at that scale, while they would love vendor consolidation, whereas here isn't a platform that's broader going to win. In the enterprise, the platform does tend to get wider over time, but those customers will not take a completely non-capable solution just because it's provided by a vendor. Microsoft would be the clearest example here. Microsoft has a lot of offerings. People don't buy it just because Microsoft offers it. They do a lot of packaging into E5 and E7, but at the end of the day, enterprise customers will look at that. Almost inevitably they'll look at it, but they won't just buy it if they don't think it's capable of solving their problem. It means sometimes we have to fight off at the brochure level some of those competitors.
But when we get into real RFPs and real competes today, we are just not seeing those players show up because they're not there yet.
This is a brochure level question. Microsoft will talk about Agent 365.
They'll say, "This is our governance solution.
ServiceNow will talk about Agent Control Tower, and they'll say, "This is our governance solution." When they talk about governance, how is it different to when you talk about governance?
Well, two different answers. With Microsoft, to be fair, I think you can assume they have a pretty good answer for the Microsoft stack. Which is why I would contend that when you see them having success in security, it's across that broad spectrum, including identity. It's down market where the shop is truly a quote "Microsoft shop." When you get into a mid to large enterprise, nobody is a Microsoft shop. They might have a large investment in Microsoft technology. At most, it might represent 20%, 30%, 40% of that environment, but any big shop is going to have way more complexity than an all Microsoft environment. So that's just what does the solution address.
I would say the other part of it, though, is look, customers rarely trust one vendor to say, "I'll be really great at managing my competitors." You just don't see that happen very often in real life. When a customer's multi-cloud, for instance, here's one I'm really curious about, Gabriela. I don't know if you cover this. I am very curious to look about two years post-Google Wiz. Is Wiz now the best tool for managing Google Cloud, or is it still multi-cloud? Its value was multi-cloud before they bought it. Let's see a couple of years afterwards whether customers go, "Yep, I'm bringing in Wiz to manage Azure and I'm managing AWS with Wiz." I don't know. We'll see. I lived through that. There's a company called Tivoli I was part of way back in the dark ages. Tivoli was this super cool multi-vendor heterogeneous management product.
They got bought by IBM, and a few years later, we were the best at managing IBM, and nobody bought us for anything else when I decided to leave and do something else. I think at the end of the day, Microsoft's got two problems. One is just vendor perception problem of I don't know if I trust Microsoft to say they're going to manage everything in my environment when my environment is with lots of non-Microsoft. I think Okta, like us, and even like ServiceNow, arguably is independent of some of those underlying technologies. With ServiceNow, since you brought that one up, I'd say their challenge is they don't have an identity-centric construct in their environment. Again, we keep saying, how can you manage agents without the understanding of that agent is acting on behalf of this identity? There is no identity construct at the center of ServiceNow.
At Okta, which has an identity construct, I would say their challenge is they just have never had to go deep into the entitlement structure of these applications, and that is a very big challenge to do that.
This is my last AI question, I think. If we are at the top of the first inning, when do you see more notable momentum? When do you think things will change?
I think it is coming. The reason we took the tone we took on yesterday's earnings cycle calls was we have said for a while now, some moderate to minimal lag time behind when you hear customers in the enterprise talking about deploying AI, you will hear us talking about AI security, and I think it is happening. I think we have shifted in this year to customers ready to move out of pilots and experiments into broader deployments on that third type primarily, right? I think they have been doing individual productivity AI. They have been doing leverage the things from my vendors. Now I think they are moving into things they particularly themselves want to do. I have challenged some folks on this. You might have some fun going back in history here. Watch when a technology inflection happens, the lag time till you see interesting security things show up for that thing.
It was three to five years for cloud. It was a really long time.
People have talked about why that was longer, and I am not sure if I know the answer. It was less time probably from the proliferation of PCs to antivirus showing up. I do not know why would you think? I am not a deep cloud security guy, so it is not my
I think what happened with cloud was initially the workloads were pretty basic.
Maybe.
They were not really mission-critical. They were greenfield. They did not have to be backwards compatible. Multi-cloud did not really become a thing until 2018.
Fair
You could just use the inbuilt security.
Great point. I'd say the other factor I would throw into your mix, that's a really good answer, by the way, because this is what you do for a living, not me. I'd say the other thing here is, this is always funny when people say, "Why didn't you just start SailPoint as a SaaS company in 2006?" Answer is because we went to enterprise customers before we built the product and said, "Hey, it's 2006. Should we build this for SaaS?" And they said, "If you do, we won't buy it. The cloud is not secure enough for us. This is critical information. It can't live in the cloud." As you all know, about a decade later, that was a 180. The most secure environments in most enterprise shops is their cloud environment. It's more secure than their homegrown data center environment.
What happened, I think, partly there is that lag in cloud security is people weren't putting anything super critical in the cloud initially. Then they started to put important things in the cloud, and all of a sudden they went, "Uh-oh, I better be able to secure this stuff." What's clearly true of AI is they're already trying to give it access to their most critical data so they can learn from it, leverage it in decision-making. So they know AI has access to their critical data. They're trying to keep it constrained in sandboxes or private environments, SLMs instead of LLMs, whatever. But everybody knows this stuff's going to be accessing all your most important data. That's not a safeguard. So the only safeguard is, can I ensure I understand what these agents are doing and look for anomalous behavior that I can stop?
Both you and Brian, I think, are pretty balanced in how you think about the financial model.
There is so much we don't know about AI. How on earth did you come up with this $800 million target in FY 2029, given how early we are?
It was more S than WA in swag. I think what we saw was we could extrapolate a growth pattern that we feel is defensible to get to that $2.1 billion total. When we see what's happening under the covers, the kind of leaning in our customers are doing to where we're literally not talking to a single enterprise today in a new account environment who doesn't want both. They're not saying, "Hey, I don't know about this agentic thing. Let's talk about humans." Nobody is saying. They're all saying, "I need identity. I need it across the board." It's 2026, our fiscal 2027. To say by the end of 2029 that a predominant amount, if not literally almost every new account is coming in with agentic felt very safe.
To say that most of our customers that aren't on that model today move to that model also felt very safe. We actually said at least $800 million at the time, and I think that may turn out to be more prophetic. We'll see.
To your point on extrapolating growth, though, how do you extrapolate? You don't have a baseline. Is your point that you do have a baseline because customers are giving you visibility?
We have a baseline of managing their human identities.
Totally.
We, like everybody, are trying to figure out what that ratio is going to land on ultimately. Somewhere between 2x - 1x and 2,000x - 1x, I think is a safe guess. What we know is if we position this correctly, we will get our more than fair share of that agentic identity challenge. The explosiveness of that TAM doesn't feel like it's super scary to continue to hit a mid-20s ARR growth. We hope that actually ends up to be conservative, but we are not prepared to give a different guide than that. You could argue that with the explosion of agentic identities in the landscape, there is a lot of TAM that is going to present itself. If we position well to capture that TAM, we should capture a decent part of that explosion. Plus, sorry, Gabriela, real quick.
Remember, we still consider ourselves relatively lightly penetrated in human. There are still tons of Oracle Identity Management.
Oh, yeah.
We have CA Identity Governance out there. There is tons of people who have part of their enterprise running under SailPoint, but not nearly all of it. So we could grow, we would have told you maybe something like this without the agentic explosion, if we just continue to execute well on the core IGA business. So we do see multiple growth drivers in front of us. It is, as they like to say, a simple matter of execution.
You are teeing me up for my all-time favorite question.
Oh, geez.
I want to end with it.
Okay
Let me ask you the annoying one in the meanwhile. Ever since the IPO part two.
I can only imagine this is frustrating for you and Brian, where you get probably 25%, 35%, 50% of questions on your earnings calls tied to mix.
It will be, why did this term contract end up coming in differently? What happened to the SaaS number? I can imagine that it is frustrating. So talk to us a little on how you ended up in this position where you have to explain the mix every quarter, and I am curious, as a management team, how you think about moving the conversation away from that.
Well-
Is it just the nature of the business?
It is our friends at GAAP, right? At the end of the day, we have tried so hard to keep investors focused on the ARR number because it takes that noise out of the system, right? Whether we do a term deal or a SaaS deal, there is a recurring revenue stream there, right? That ARR growth, we think is the most representative number of the health of our business, because the different rev rec associated with these types of licensing, thank you, ASC 606, makes that harder to predict. I got a question today, Gabriela, like, "Well, do not customers already have that decision made as to whether they are going term or SaaS?" That individual customer does, but like every business, we have got a whole bunch of deals in our pipeline. Some are this type, some are that type.
What we can never predict is which of those exactly are going to close this quarter. We do great AI-driven probabilistic work there, but this quarter we actually got a little surprise, which we had to talk about yesterday, that we had a 97% SaaS mix. That wasn't what we planned for. So we had less term, so we had less recognized revenue, so we had a revenue shortfall that the models gobbled up right when we put our press release on the wire. We had to explain for the next few hours, "Don't worry, there's nothing wrong here," with that revenue shortfall because it was just a mix of which deals closed this quarter that were term. Term is still a diminishing part of our business. It will probably never be zero, though, so there will always be a little noise to manage here.
But if we can keep folks focused on ARR growth represents the health of our business, that number continues to be a really good number.
Okay, so now I can ask my favorite question.
Your fun question?
I remember when we did due diligence on SailPoint, not just this time around, but even
Yeah, you're welcome for a second shot. You're welcome.
The customers complain like hell about migrations.
This is where I think something like Virtual Architect comes in.
Yep.
One of my observations across technology is switching costs are going down.
Yep.
Migrations are getting easier.
Yep.
Someone like a Snowflake will even tell you their system integrators can now price fixed cost migrations as opposed to variable cost migrations at 30%-50% - 70% less time and money than it used to, old going to new.
That's old of their own to new or competitive?
No, old from Hadoop to Snowflake.
Okay, got it.
Similar for you guys, you mentioned earlier the core legacy competitors in core IGA.
Yep.
There's got to be more levers you can pull. Are you seeing a change in speed of migration? Because customers will now say, "Actually, it doesn't have to be a pain in the ass. There are easier ways in 2026 to execute a migration.
Yeah. This is very new, so I cannot point you to the rearview mirror yet, but we are very excited about it. We launched this thing called Agentic Acceleration. What we had done was we took some of our best PS architects, and we pointed them back at the tens, not hundreds, I guess at this point, well, actually no, a few hundred, migrations we have done from IdentityIQ, our on-prem product, to our SaaS product and said, "Point AI at this. With your deep expertise, help us figure out how to automate the maximum possible amount of this migration." We launched that a few months ago. We are very comfortable talking about an order of magnitude difference. Things that took months now take weeks. Things that took weeks now take days. That, we can stand by pointing it at our product. Guess what we have been working on?
Pointing it at competitors' products. Now we are starting to get some early indicators that we can probably take 90% of the time and cost out of migration from one of those tools. That has only been out for about two months. I will have to come back to you, but your point is absolutely right that with tools like that, the hurdle to get through a migration. There is still some internal change management anytime you change a tool, right? I do not know what our friends at Snowflake say about that with regard to Hadoop, but whoever is using that stuff has some different things to learn. There is some change management. There is the technology migration, then there is the humans and what they actually do to interact with the technology.
We can only do so much to take out some of that human change management, but we can make the technical hurdle, which was more substantial before, go very, very, very far down.
You will know.
We think that will open up
Better than us from talking to customers how meaningful. This sounds pretty meaningful.
What are the other reasons that customers give you as to why they do not want to switch?
That was the biggest one, honestly.
Yeah.
It was, "I know I need to do this. I've got so much going on in my shop. I should do this, but I just can't do it right now." That was a time and cost thing, to be fair. If you take the time and cost down dramatically with these technologies, we're going to be interested to watch how much pull that creates from those customers. There's very few of those customers who are super satisfied with those products. They just knew it was a big mountain to climb, and some of them are like, "I'm just not sure I'm ready to do that yet." Now I think we'll see some of that unlock. I can't predict a dramatic dip yet because we can't report it yet, but I think we are seeing those dialogues pick up in intensity pretty fast.
Is there also an intersection with, or a new focus on, modernization?
That would be our modernization from IdentityIQ to SaaS. Is that what you mean?
No. Customers saying, "Look, we have to get our data infrastructure and security in a row for AI. Therefore, if we were pushing this project out on IGA indefinitely, actually, we shouldn't be pushing it out anymore.
I think it's probably more driven by agentic than anything else. I don't know if that's what you mean by modernization in this context, but what's happening is the agentic tidal wave that they see coming at them, I think, is causing a lot of them to go, "I can't stay where I've stayed." They knew they weren't in a great place with human, but they kind of thought, "Well, I kind of think I can live with it. Probably got some risk I'm not managing well, but I think I'll live with that risk right now." I think when they see what's happening with agentic, their companies are for sure deploying it, and they've now seen the risks that can show up with it. I don't know that we're going to have a lot of people saying, "I'm just fine.
Don't need to talk to you." We mentioned this in the, I think, callbacks, not on the main call yesterday. We got a ton of POCs going on right now. We talked about the energy around that with these new technologies, the intro product, and some of the discovery tools. 20% of those are with customers who don't own our IGA. They're not even customers who are saying, "I'm going to shift my IGA forward. I just need to solve this agentic problem. Let me see what you got." That's the new motion for us to not even say, "First you got to get off of that old IBM, CA, Oracle stuff." We're saying, "You can keep it for now if you have to. Don't recommend it, but let's get your agentic problem solved." And that's a new motion for us, so
You've been very consistent in sticking to the core competencies of the company with IGA, and I know you have some flavors around that as well.
Right.
A lot of your competitors have taken a much broader approach and said, "All the swim lanes are converging. We want to do everything, and we want to do this ephemeral thing on top as well." Has anything changed on your thinking on the swim lane that you want to be in?
Great question. I'd say the swim lanes are almost disappearing the way we've thought of them, is the answer I'd give you. Here's what I mean by that. We still look at the core human SSO MFA game that both Okta and Microsoft dominate, and our friends at Ping Identity, fellow TB company, do real well there, too. At the end of the day, we looked at that market about seven, eight years ago and went, "We could probably play there, but we don't need to." I think a lot of people thought, oh, you're going to start to lose IGA business because you won't have this broad offering that Okta's now saying they'll have. CyberArk, right before their acquisition by Palo Alto Networks, bought a little startup called Zilla Security, and they were starting to plant the flag for their widening of their offering.
All we can tell you is in the enterprise clients we sell to, that has not hurt us at all. I think Okta having that breadth of offering, and I think CyberArk would tell you they're further behind chasing PAM than they were chasing us in IGA, and we will tell you they're not hurting us in IGA. They've expanded the low end of the market, I think, but they haven't hurt us in IGA. I think how we see it, though, Gabriela, it's a slightly different way to think of the question. Some of those concepts are going to start showing up in our offerings. What you won't see us do is traditional SSO MFA for humans. You won't probably see us do traditional PAM for sysadmins and DBAs, which is what PAM was mostly about. What you'll see is us incorporating real-time dynamic authorization.
You will see us talking about escalation and de-escalation of dynamic privilege. Those concepts came out of things like PAM and SSO, but we do not want to go play in last year's war. We want to play in the next war. We are not going to roll up the swim lanes. We are going to borrow some key concepts from those lanes and deliver them. I think our Navigate conference in, whatever it is, six to eight weeks from now, early October, you are going to hear us talking about real-time more than you have ever heard us talk about real-time. That would be picking up concepts from both privilege and SSO, and it is also going to be very focused on levels of privilege, dynamic privilege. The concepts are going to make their way into SailPoint's next gen.
We just never felt the need to go acquire or buy our way back into the last gen solutions.
Mark, thank you for going down some rabbit holes with me. Please join me-
My pleasure.
in thanking Mark for his time.
Thanks for being here, you all. Appreciate it.