Menu

SailPoint Bolsters SaaS Security with Savvy Acquisition

SailPoint Bolsters SaaS Security with Savvy Acquisition

Analyst(s): Krista Case
Publication Date: August 22, 2025

SailPoint has agreed to acquire key assets from Savvy Security as it launches its Accelerated Application Management offering. The move strengthens its ability to address SaaS proliferation with identity-led discovery, governance, and security capabilities.

What is Covered in this Article:

  • How the Savvy asset acquisition expands SailPoint’s capabilities in SaaS visibility, shadow IT governance, and application management.
  • The potential benefits for SailPoint in strengthening customer stickiness and competitive positioning.
  • The risks tied to integration complexity, product clarity, and market messaging could limit the impact of the acquisition.

The News: SailPoint announced the introduction of its new Accelerated Application Management module, accompanied by an agreement to acquire key assets from Savvy, a provider of identity-first SaaS security solutions. The announcement is designed to deepen visibility and control over the proliferating number of SaaS applications in use by any given enterprise.

SailPoint Bolsters SaaS Security with Savvy Acquisition

Analyst Take: With the average enterprise using hundreds of SaaS applications, their discovery, governance, and security at scale becomes a pressing vulnerability to be addressed as a priority. The potential for illicit access has never been greater, and enterprises are struggling with identity and access vulnerabilities related to rapid application proliferation and shadow IT exposure.

For its part, SailPoint is addressing this challenge by reinforcing its Identity Governance & Administration (IGA) and security capabilities in the SaaS domain while adding specialized tooling for SaaS app observability, governance, risk assessment, and real-time shadow IT detection through its planned Savvy Security acquisition.

Across the board, cybersecurity and IT teams require more than just visibility, as they are pressured to uncover and react to vulnerabilities as quickly as possible to optimize business continuity and mitigate the potential for data loss. They require the ability to identify the highest-risk vulnerabilities and automate remedial actions, so that they can be addressed swiftly as a priority. For this reason, Futurum views the ability to prioritize vulnerabilities based on risk and to automate workflows as key capabilities of the new SailPoint Accelerated Application Management offering.

If executed well, the integration of the Savvy Security assets can enhance stickiness as security practitioners increasingly prefer a platform-led approach. Clients gain visibility into shadow SaaS apps and governance control in one platform, as a result reducing vendor sprawl and potential blind spots while improving reactiveness. Cross-sell pathways may also be opened up, as customers consider adopting Accelerated Application Management to address key identity security vulnerabilities related to SaaS proliferation.

Potential upsides acknowledged, there are some risks to be mindful of. The planned deal is relatively lightweight in terms of its size, but potential integration hurdles still exist. Merging backend architectures (APIs, data models, telemetry), aligning product roadmaps, and packaging a compelling seller message will still not be an easy feat. Additionally, SailPoint just went public again in early 2025, raising over $1 billion and trading at a valuation north of $10 billion. The IPO provides funds but will result in investor milestones and pressure to innovate.

Customer interest in a more comprehensive identity security fabric, and the need to protect new applications, infrastructures, and identities, has spurred plenty of recent acquisition activity. For example, Okta acquired Auth0 in 2021 to make it easier for developers to embed identity security into their cloud native apps, and CyberArk acquired Venafi and Zilla security in 2024 to enhance its machine identity and IGA capabilities, and subsequently is slated to be acquired by Palo Alto Networks in a blockbuster planned $25 billion deal. Ultimately, SailPoint’s planned acquisition of Savvy Security assets underscores its strategy to evolve from a governance-first player into a broader identity security platform that can address SaaS-driven vulnerabilities at enterprise scale while competing head-on with rivals pursuing similarly aggressive expansion through acquisitions.

What to Watch:

  • Competitive response from players such as Okta, Ping Identity, and Microsoft, which may explore their own SaaS visibility or identity observability enhancements. If they move quickly, SailPoint’s differentiation could narrow; if not, it gains valuable breathing room.
  • Adoption and integration speed, focusing on customer reviews, pilot deployments, and roadmap alignment to gauge the ultimate success of the integrated SailPoint and Savvy SaaS identity governance offering.
  • Next asset acquisitions or partnerships, with the potential for additional bolt-ons (e.g., endpoint identity telemetry or AI-driven access analytics) that could broaden the value proposition if early gains materialize. Overextension, however, could create product sprawl and integration fatigue.

For more information, see SailPoint’s press release.

Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights from Futurum:

Is SailPoint’s IPO a Sign of Renewed Tech Optimism or Market Caution?

Can Identity Security Vendors Keep Pace with Platformization and AI-Driven Threats?

Security Summer Camp: Black Hat 2025, Def Con, And Others

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
Fortinet’s FortiOS 8.0 Pushes Secure Networking Toward AI Governance
March 16, 2026

Fortinet’s FortiOS 8.0 Pushes Secure Networking Toward AI Governance

Fernando Montenegro, VP and Practice Lead, Cybersecurity at Futurum, examines Fortinet’s FortiOS 8.0 adds AI governance, flexible SASE options, and quantum-safe protections to secure networking across hybrid environments....
Cohesity’s DSPM Bet Blurs the Line Between Visibility and Recovery
March 16, 2026

Cohesity’s DSPM Bet Blurs the Line Between Visibility and Recovery

Fernando Montenegro, VP and Practice Lead, Cybersecurity Futurum Research at The Futurum Group, examines Cohesity DSPM, powered by Cyera, ties sensitive data discovery and classification to protection and recovery readiness...
OpenAI Acquires Promptfoo, Gaining 25% Foothold in Fortune 500 Enterprises
March 11, 2026

OpenAI Acquires Promptfoo, Gaining 25% Foothold in Fortune 500 Enterprises

Mitch Ashley, VP Practice Lead at Futurum, examines OpenAI's acquisition of Promptfoo and what it signals about the security and governance requirements blocking AI agents from enterprise production....
Can Microsoft's Frontier Suite Deliver AI Excellence at Scale
March 10, 2026

Can Microsoft’s Frontier Suite Deliver AI Excellence at Scale?

Futurum analysts Keith Kirkpatrick and Fernando Montenegro share their insights on Microsoft’s Frontier Suite, and discuss the implications for both enterprise buyers and the company’s competitors....
Okta Q4 FY 2026 Earnings Highlight Agentic Identity Positioning
March 6, 2026

Okta Q4 FY 2026 Earnings Highlight Agentic Identity Positioning

Dion Hinchcliffe is Vice President & Practice Lead, CIO & Technology Buyers reviews Okta’s Q4 FY 2026 earnings, focusing on agentic identity positioning, evolving pricing models, and how large-customer platform...
Commvault-CrowdStrike SIEM Link Tests Bi-Directional Resilience
March 6, 2026

Commvault-CrowdStrike SIEM Link Tests Bi-Directional Resilience

Fernando Montenegro, VP and Practice Lead, Cybersecurity at Futurum, examines how Commvault’s bi-directional integration with CrowdStrike Falcon Next-Gen SIEM enables shared backup-integrity telemetry to fasten recovery after cyberattacks....

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.