Executive readout · one minute
Webcast research workspace
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Conference · 2026-09-10
Executive readout · one minute
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Research coverage
2 live sources
Switch sources without leaving this page or losing your listening position.
Open the source you need; every reader stays inside this workspace.
Listen and read together
The spoken word highlights as audio plays. Select any word to seek to that moment.
Hey, Mark. It's really good to have you. Thank you for joining us this afternoon, and thanks to everyone in the room. Mark McLean, founder and CEO of SailPoint.
Pleasure to be here.
Mark, I think our founder-led companies have a little bit of an advantage in that founders tend to be a little bit more willing to think from first principles, a little bit more of a deep understanding in the technical bones of the product from day one. And I'm curious, when you think through the quality of the product today, a lot is changing in identity. What are some of the early decisions that you've made or decisions that you've made over the last several years that you think have set you up for today to be a leader in IGA in a world where agentic is changing?
Great question. Yeah, I guess some of us never left founder mode. I think that's the thing.
Yeah, that's exactly it.
If you start in founder mode, you're always in founder mode, maybe. Yeah, I think, Gabriella, that's a great question. and a little different than I've had in some of these settings, and I love it, actually. I think part of it is we had a very ruthless focus on being what we called market-driven. Like, it's very easy after a while to think you know more than your customers. Like, well, we know what's going on in this market. We know what to do next. And we've tried to be very, very careful over the years to not listen to ourselves, not to sit in a whiteboard-surrounded room and decide what's next, you know, get out there and listen. And for a while, obviously, we've heard the concerns coming around non-human, agentic in particular. Now, to be fair, I don't think if you'd asked me two and a half, three years ago whether we would be where we are today, this has been an evolution unlike most of us have ever seen in our careers at speed and scale of what's happened. But it certainly didn't catch us flat-footed, number one. Number two, there's a little bit of right place, right time. I'm willing to acknowledge that. I love founders who tell you that 20 years ago they knew it would be exactly like this. I think that's funny. but I think at the end of the day I think we are finding ourselves in a very enviable position for what the world is needing right now what's clear that's needed is you're going to have to think about this explosion of non-human identities particularly agents which in fact leverage a lot of other types of non-human identities like service accounts and credentials and things like that to do their work you're going to have to think about the problem we've been thinking about for humans unlike most of the rest of the identity landscape or security landscape and the way we've been thinking is deep and wide forever. Meaning to do what we do, we have to think about the breadth of all the identities that an organization cares about, right? Which up until recently was mostly human, far beyond their employees, but all human identities. But we also had to map that across this incredibly deep, complex landscape of homegrown applications, vended applications, brand new SaaS applications, and 70-year-old COBOL applications. I mean, that's the world our customers live in.
I remember drawing it in our SailPoint initiation 10 years ago.
And it hasn't gotten any simpler. And like the Mark Twain quote, the mainframe's demise is greatly exaggerated. They're still out there. So I think at the end of the day, that heritage of thinking about this complex problem of lots of identities, the interrelationships between them, and the complexity of what they're trying to access in the environment. When you think about the agentic world in that context, this explosion of identities we're seeing which are happening way faster than human identities ever grew, and the complexity of what it is they can do at machine speed, that problem just got about 10 to 1,000 times harder, right? But if you didn't start from where we're starting, I think you have a much bigger mountain to climb. And I think we're going to see that play out in these coming quarters. I think to poke at a couple parts of the landscape, there's a lot of brand-new funded companies right out here in the Valley saying we're going to solve a gentix for you. And our answer to that is how are you going to do that without the human understanding? Like these agents aren't operating in a vacuum. They're operating on behalf of someone either directly like a co-pilot or indirectly a digital work environment that we're trying to set up a completely automated loan origination department. Well, guess what? That's happening under the direction of some human. Some policies are involved there. Some data is involved there. So what we're going to see, I think, very quickly is agentic has to be understood in the context of human policies and human organizational dynamics. And if you can't map that incredibly complex, rapidly changing environment, you can't keep up. And I don't know how some of the folks that are coming from other than that heritage are going to be able to keep up.
Let me play devil's advocate.
It's been happening to me all day. I feel like you're dealing with the devil all day today.
If I was starting with a clean sheet of paper and building an identity governance solution for that, which you just described as being 10 to 100 times more complex, and I think you could use the word adaptive, which I know you have, or ephemeral, fundamentally I'm building a solution for something that doesn't look like a human. So how could I possibly take an identity governance solution that was built for humans and square a peg round hole, force it into a solution that can actually dynamically deal with Asia.
I would argue, this is fun, Ms. Devil, I'm arguing with. You're not the devil, but you said devil's advocate. I think at the end of the day, it does somewhat look like a human, just not exactly like a human. Because to say it doesn't look like a human, well, really? What does a human identity do? It has a mission to accomplish. It has tools with which to accomplish it. It gets into systems or accesses data, analyzes that data, takes action on that data. That's what these agents are doing. Now, they're often doing it in unexpected ways. We just learned how to define amoral agents in the context of hugging face, where these agents went off and did things that humans would think was inappropriate, but they didn't They were just trying to solve their little problem. So we're learning the parts that aren't like human, to your point. What's not like human, scale, speed, lack of ethical moral boundaries, okay, that's different, but an awful lot is not different. And I think it's not just that it's not different. Again, we come back to this postulation that you aren't going to see agents behaving, even, quote, autonomous agents inside the enterprise context. They're not going to be behaving in completely independent ways, meaning they were sent off to do something. Even if they are a sub-agent spun up downstream of an original agentic problem, that problem was defined by a human saying, solve this for me. Go create a workflow, create a business logic, do something, analyze data for me, give me recommendations. All those things are happening because some person said, I need this in the enterprise, or I need to solve this problem or manage this workflow. So I think we're going to be kind of forced back to these agents are, in fact, capable of human-like behavior, but with very different characteristics, to your point. And it's that human context that's going to differentiate the kinds of compliance and governance and security controls we need that we will have to apply those policies differently, I think, to your point, in an agentic world. But I don't think the concepts are going to be completely different.
So bring us now to some of the practical conversations that you're having with your enterprise customers. If I am a large financial institution and all of my agents are in sandboxes and I say I would love for these agents to have more business context and be released from their sandboxes so my knowledge workers can be productive, of SailPoint, please solve this problem for me. What is the customer journey as you walk through what regular IGA to IGA for agents looks like?
Yeah, and honestly, it is so early. I'm not going to speak with, like, massive conviction of exactly how that journey unfolds because we are very early. I like to say in baseball terms, I don't even think we're in the bottom of the first yet. I think we're still in the top of the first. But to your point, I think that the truth is one of the things people assume is true that is not true of, well, when an agent's operating, doesn't it inherit the constructs of its owner? Answer, no, it does not. You would think that would be true, wouldn't you? But it's not true. So when I spin up a co-pilot or I set up a new agent in my Gemini environment, my chat GPT environment, whatever, it doesn't have any constraints. It's just told to go do something. We have to give it whatever constraints it's supposed to have to do what we're asking it to do. One of the things we will do is to say, look, we have that ability because we have that human context to say this agent, which was authorized by Gabriella, will in fact inherit her constraints. But there's no natural way that happens in the environment today. That's not how these systems are set up. Let me make a comparison sometimes, Gabriella, that I hope is helpful. The internet was originally designed very open, wasn't it? And then we had to figure out how to secure it when we started doing things like commerce on it. These tools were designed to go grab information as much as possible from everywhere, look for patterns, and tell you what they find. They were not designed with security in mind, Nadella's famous quote of secure by design. Nothing about LLMs was secure by design. And we're seeing the ramifications of that already. These systems weren't designed with the idea of how am I going to constrain these things so they can't do too much. In fact, it was the opposite. How can we give these things massive freedom, feed them with as much data as possible so they can give us the best answer. So we're having to now retrofit security concepts on the things that were designed with the exact opposite mindset. That's a problem. But we're going to bring those constructs back to our what's human like and what's not of saying, well, how do you think about this in a human context? You say, what is the intent here? What is the context? What is the business problem trying to be solved? What are the dangers that exist around that? How do I constrain those dangers while letting you do what you need to do to do your job? I think we're going to bring those same concepts to agents, it's going to look different in some respects because of the lack of moral compass and the lack of constraints of speed and time. Some of what saves us in enterprises today is people can only do so much so fast, right? There's not much constraint. You read the forensic analysis of what happened with Hugging Face. It is mind-boggling. It is literally mind-boggling. I think even the open-the-eye people are a little mind-boggled, which should scare all of us. But I think at the end of the day, we're seeing when you have systems that were designed with an intent and you're now asking them to think about security and constraints, it's clashing. And so we're going to have to have vendors like us and others who come in and say, I'm here to provide those constraints and policies and guidelines. Guardrails is maybe a good term here. And, yeah, we know a lot about how to do that, and we're going to try to apply those concepts into this environment.
Let me ask the drinking urine champagne question. Which of these frameworks, to your point on being at the top of the first inning, what's working within SailPoint? Do you have examples of successful agentic deployments where you've used agentic fabric and some of the really cool bell vehicles to feel less scared?
Yeah, we're still scared. But I think maybe this is a simple taxonomy that's helpful. I think, if you oversimplify for a second, there's probably three kinds of agentic use cases that are emerging rapidly. One is you're sort of ideally giving everyone in your organization access to something, Gemini, Chat, GBT, Claude. Say, use this to be more productive in what you do all day, every day. That's kind of an agentic use case one. Agentic use case two is well-known vendor, Salesforce, ServiceNow, Workday, whoever has said SAP, I'm going to provide a bunch of agentic capabilities in the context of the application you bought for me. In the case, number three, and this is generally true of mid- to large-sized customers, which is the ones we serve, I have an IT organization and a development team. We're going to go build some bespoke things. So there's kind of day-to-day use, coming to a vendor, build your own workflow process, not just over here, employee using the tool to do their job better today. All three of those look and feel kind of different. We are trying all three at some level. We're for sure, I think all companies almost of any scale are going to do one and two. Like if you're not letting your employees use AI to do their jobs better, you're at a competitive disadvantage today, no doubt in my mind. Second case, I don't know that a lot of people are going to be super cautious about adopting what ServiceNow or Salesforce or Workday gives them because they're going to try to trust that those vendors put the appropriate guardrails and said this will help that application work better for you. The third one is I think the one that's going to get real hard and real messy, but it's also where we live in these mid-to-large enterprises where a whole lot of what their IT franchise is built on was built in their shop, right? It wasn't something they took from the outside. And it's not just a person looking to be slightly more productive in building their next Word doc or spreadsheet. They're going to look at ways to leverage this technology for their unique business approach to their unique industry, and those things are going to look pretty different case to case. You well know that one investment bank does not look like another investment bank, does not look like a merchant bank, does not look like a consumer bank. And that's just in the industry of finance, right? Like, at the end of the day, this stuff's going to be very unique in these large to mid-sized enterprises, and we're going to have to do what we did for years in the human space and say, what are we seeing here? Where are the risks showing up? What kinds of things seem to catch people off guard? And how are we able to detect things early enough to put a stop to bad behavior?
There is an intelligence piece to the IP that I think sometimes is underappreciated. And the way I would articulate this is investors will say to us, look, if you're an endpoint company or a network company, the bigger your installed base, the more intelligence you have. It's like a crowdsourcing or a network effect. Whereas for something like SailPoint, SailPoint is equally good whether you have three customers using SailPoint or however many customers you have, thousands of customers using SailPoint. Where would you push back to this idea that SailPoint's moat is lower than an endpoint or a network company because of this network effect?
I hadn't thought of it vis-a-vis that type of advantage because you're right. The network effect to us is less that these things are all using SailPoint. We have some effect that we see because we see across all of them the kinds of things that have shown up as a problem here, something we thought would be a good idea it turned out not to be a good idea. This customer says, I think we're going to do that. We say, don't do that. We tried that, and it didn't work well.
That's a great network effect.
That is a very – but the two customers didn't see it amongst themselves. We saw it, right? But I think at the end of the day, the moat that's been surprisingly deeper than I think people thought was just the pure complexity and challenges of these complex enterprise environments. Because to poke at one of our friendly neighborhood identity players, right, our friends at Okta have been at IGA now for about five years, and notwithstanding a couple of comments that have been made, they haven't put a dent in our IGA business. They are winning IGA business basically below the line we care about. And in the enterprise scale, their solution, while I'm sure it's come a long ways, continues to not be competitive in this super complex world we live in, which just says something about how complex and hard it is to do what we do at the scale of complexity we do it. And so I think at the end of the day, that moat of not just understanding what needs to happen in business processes like compliance and provisioning lifecycle management, all the things that we do, but doing it at the scale and complexity we do it has just turned out to be a very big moat. And people ask us now, like, well, aren't you running into all these folks who have press releases, CrowdStrike and Palo Alto and Microsoft and Okta? And the answer is no, we're not, actually. We're not running into them in these competitive environments. Because the customers at that scale, while they would love vendor consolidation, where I was here, isn't a platform that's broader going to win? In the enterprise, the platform does tend to get wider over time, but those customers will not take a completely non-capable solution just because it's provided by a vendor. Microsoft would be the clearest example here. Microsoft has a lot of offerings. People don't buy it just because Microsoft offers it, right? They do a lot of packaging into E5 and E7, but at the end of the day, enterprise customers will look at that, almost inevitably they'll look at it, but they won't just buy it if they don't think it's capable of solving the problem. So it means sometimes we have to fight off kind of at the brochure level some of those competitors, but when we get into real RFPs and real competes today, we are just not seeing those players show up because they're not there yet.
This is a brochure level question. So Microsoft will talk about Agent 365. and they'll say, this is our governance solution. ServiceNow will talk about agent control tower, and they'll say, this is our governance solution. When they talk about governance, how is it different to when you talk about governance?
Well, two different answers. With Microsoft, to be fair, I think you can assume they have a pretty good answer for the Microsoft stack, which is why I would contend that when you see them having success in security, it's across that broad, that spectrum including identity, it's down market where the shop is truly a, quote, Microsoft shop. When you get into a mid-to-large enterprise, nobody is a Microsoft shop. They might have a large investment in Microsoft technology. At most, it might represent 20%, 30%, 40% of that environment, but any big shop is going to have way more complexity than an all-Microsoft environment. So that's just what does the solution address. I would say the other part of it, though, is, look, But customers rarely trust one vendor to say, I'll be really great at managing my competitors. You just don't see that happen very often in real life. And so when a customer is multi-cloud, for instance, here's what I'm really curious about, Gabrielle. I don't know if you covered this. I am very curious to look about two years post-Google Wiz. Is Wiz now the best tool for managing Google Cloud, or is it still multi-cloud? Its value was multi-cloud before they bought it. Let's see a couple years afterwards whether customers go, yep, I'm bringing in Wiz to manage Azure, and I'm managing AWS with Wiz. I don't know. We'll see. I lived through that. There's a company called Tivoli I was part of way back in the dark ages. Tivoli was this super cool, multi-vendor, heterogeneous management product that got bought by IBM, and a few years later, we were the best at managing IBM, and nobody bought us for anything else when I decided to leave and do something else. So I think at the end of the day, Microsoft's got two problems. One is just vendor perception problem of, I don't know if I trust Microsoft to say they're going to manage everything in my environment when my environment is with lots of non-Microsoft. I think Okta, like us, and even like ServiceNow, arguably is independent of some of those underlying technologies. With ServiceNow, since you brought that one up, I'd say their challenge is they don't have an identity-centric construct in their environment. again, we keep saying, how can you manage agents without the understanding of that agent is acting on behalf of this identity? There is no identity construct at the center of service now. And then at Okta, which has an identity construct, I would say their challenge is that they just have never had to go deep into the entitlement structure of these applications. And it's a very big challenge to do that.
This is my last AI question. If we're at the top of the first inning, when do you see more notable momentum? What do you think?
I think it's coming. The reason we took the tone we took on yesterday's earnings cycle calls was we've said for a while now, some moderate to minimal lag time behind when you hear customers in the enterprise talking about deploying AI, you will hear us talking about AI security, and I think it's happening. I think we've shifted in this year to customers ready to move out of pilots and experiments into broader deployments on that third type primarily, right? I think they've been doing individual productivity AI. They've been doing leverage the things from my vendors. Now I think they're moving into things they particularly themselves want to do. And I've challenged some folks on this. You might have some fun going back in history here. Watch when a technology inflection happens, the lag time until you see interesting security things show up for that thing.
It was three to five years for cloud. It was a really long time.
And people have talked about why that was longer. And I'm not sure if I know the answer. It was less time probably from the proliferation of PCs to antivirus showing up. But why would you think? I'm not a deep cloud security guy, so it's not mine.
I think what happened with cloud was initially the workloads were pretty basic. They weren't really mission critical. They were greenfields. They didn't have to be backwards compatible. And multi-cloud didn't really become a thing until 2018, so you could just use the inbuilt security.
Great point. I'd say the other factor I would throw into your mix, that's a really good answer, by the way, because this is what you do for a living, not me. I'd say the other thing here is, this is always funny when people say, why didn't you just start SailPoint as a SaaS company in 2006? Answer is because we went to enterprise customers before we built the product and said, hey, it's 2006. Should we build this for SaaS? And they said, if you do, we won't buy it. The cloud is not secure enough for us. This is critical information. It can't live in the cloud. And as you all know, about a decade later, that was a 180. The most secure environments in most enterprise shops is their cloud environment. It's more secure than their homegrown data center environment. And so what happened, I think, partly there is that lag in cloud security is people weren't putting anything super critical in the cloud initially. And then they started to put important things in the cloud, and all of a sudden they went, uh-oh, I better be able to secure this stuff. What's clearly true of AI is they're already trying to give it access to their most critical data so they can learn from it, leverage it in decision-making. So they know AI has access to the critical data. They're trying to keep it constrained in sandboxes or private environments, SLMs instead of LLMs, whatever. But everybody knows this stuff's going to be accessing all your most important data. That's not a safeguard. So the only safeguard is can I ensure I understand what these agents are doing and look for anomalous behavior that I can stop?
Both you and Brian, I think, are pretty balanced in how you think about the financial model. There is so much we don't know about AI. How on earth did you come up with this $800 million target in FY29, given how early we are?
It was more S than WA in SWAG. I think what we saw was we could extrapolate a growth pattern that we feel is defensible to get to that $2.1 billion total. And when we see what's happening under the covers, the kind of leaning in our customer is doing to where – We're literally not talking to a single enterprise today, a new account environment, who doesn't want both. They're not saying, hey, I don't know about this agentic thing. Let's talk about humans. Nobody is saying it. They're all saying, I need identity. I need it across the board. So it's 2026, our fiscal of 2027. So to say by the end of 29 that a predominant amount, if not literally almost every new account is coming in with agentic, felt very safe. to say that most of our customers that aren't on that model today moved to that model, also felt very safe. So we actually said at least $800 million at the time, and I think that may turn out to be more prophetic.
To your point in extrapolating growth, though, how do you extrapolate? You don't have a baseline. Or is there a point that you do have a baseline because customers are giving you visibility?
We have a baseline of managing their human identities. And we, like everybody, are trying to figure out what's that ratio going to land on ultimately. You know, somewhere between 2 to 1 and 2,000 to 1, I think is a safe guess. And what we know is if we position this correctly, we will get our more than fair share of that agentic identity challenge. And the explosiveness of that TAM doesn't feel like it's super scary to continue to hit a kind of mid-20s ARR growth. We hope that actually ends up to be conservative, but we're not prepared to give a different guide than that. You could argue that with the explosion of agentic identities in the landscape, there's a lot of TAM that's going to present itself. If we position well to capture that TAM, we should capture a decent part of that explosion. Plus, last thought, sorry, Gabrielle, real quick. Remember, we still consider ourselves relatively lightly penetrated in human. There are still tons of oracle IV of CAIG out there. There is tons of people who have part of their enterprise running under SailPoint, but not nearly all of it. So we could grow. We would have told you maybe something like this without the agentic explosion if we just continue to execute well on the core IGA business. So we do see multiple growth drivers in front of us. It's, as they like to say, a simple matter of execution.
You're chinging me up from my all-time favorite question, but I want to end with it. So let me ask you the annoying one in the meanwhile. So ever since the IPO part two, I can only imagine this is frustrating for you and Brian, where you get probably 25%, 35%, 50% of questions on your earnings calls tied to mix. And it will be, why did this term contract end up coming in differently? What happened to the SAS number? And I can imagine that it's frustrating. So talk to us a little on how you ended up in this position where you have to explain the mix every quarter. And I'm curious as a management team how you think about moving the conversation away from that. Or is it just the nature of the business?
It's our forensic gap, right? At the end of the day, we've tried so hard to keep investors focused on the ARR number because it takes that noise out of the system, right? Whether we do a term deal or a SaaS deal, there's a recurring revenue stream there, right? And that ARR growth, we think, is the most representative number of the health of our business because the different rev rec associated with these types of licensing, thank you ASC 606, makes that harder to predict. And I got a question today, Gabrielle. I was like, well, don't customers already have that decision made as to whether they're going term or SaaS? That individual customer does. But like every business, we've got a whole bunch of deals on our pipeline. Some are this type, some are that type. What we can never predict is which of those exactly are going to close this quarter. We do great AI-driven probabilistic work there, but this quarter we actually got a little surprise, which we had to talk about yesterday, that we had a 97% SaaS mix. That wasn't what we planned for. So we had less term, so we had less recognized revenue, so we had a revenue shortfall that the model gobbled up right when we put our press release on the wire, and we had to explain for the next few hours, like, don't worry, there's nothing wrong here with that revenue shortfall because it was just a mix of which deals closed this quarter that were termed. Termed is still a diminishing part of our business. It will probably never be zero, though, so there will always be a little noise to manage here. But if we can keep folks focused on ARR growth represents the health of our business, that number continues to be a really good number.
Okay, so now I can ask my favorite question. So I remember when we did due diligence on SailPoint, not just this time around, but even back in the day.
Yeah, you're welcome for a second shot. You're welcome.
The customers complain like hell about migrations. And this is where I think something like Virtual Architect comes in. So one of my observations across technology is switching costs are going down. Migrations are getting easier. Someone like a snowflake will even tell you their system integrators can now price fixed cost migrations as opposed to variable cost migrations at 30% to 50% to 70% less time and money than it used to, old going to new.
That's old of their own to new or competitive? No, old from Hadoop to stuff like that.
So similar for you guys, you mentioned earlier the core legacy competitors in core IGA. There's got to be more levers you can pull. Are you seeing a change in speed of migration? Because customers will now say, actually, it doesn't have to be a pain in the ass. there are better ways, there are easier ways in 2026 to execute a migration.
Yeah, this is very new, so I can't point you to the rearview mirror yet, but we're very excited about it. So we launched this thing called Agenic Acceleration. And what we had done was we took some of our best PS architects and we pointed them back at the tens, not hundreds, I guess at this point. Well, actually, no, a few hundred migrations we've done from IIQ, our on-prem product to our SaaS product, and said, point AI at this. with your deep expertise, help us figure out how to automate the maximum possible amount of this migration. We launched that a few months ago. We are very comfortable talking about an order of magnitude difference. So things that took months now take weeks. Things that took weeks now take days. That we can stand by pointing it at our product. Guess what we've been working on? Pointing it at competitors' products. And now we're starting to get some early indicators that we can probably take 90% of the time and cost out of migration from one of those tools. That's only been out for about two months. So I'll have to come back to you, but your point is absolutely right, that with tools like that, the hurdle to get through a migration, there's still some internal change management any time you change a tool, right? I don't know what our friends at Snowflake say about that with regard to Hadoop, but whoever is using that stuff has some different things to learn. There's some change management. There's the technology migration, then there's the humans and what they actually do to interact with the technology. We can only do so much to take out some of that human change management, but we can make the technical hurdle, which was more substantial before, go very, very, very far down. So we think that'll open up.
So you'll know better than us from talking to customers how meaningful, this sounds pretty meaningful, what are the other reasons that customers give you as to why they don't want to switch?
That was the biggest one, honestly. It was, I know I need to do this, I've got so much going on in my shop, I should do this, but I just can't do it right now. And that was a time and cost thing, to be fair, right? Well, if you take the time and cost down dramatically with these technologies, we're going to be interested to watch how much pull that creates from those customers. There's very few of those customers who are super satisfied with those products. They just knew it was a big mountain to climb, and some of them are like, I'm just not sure I'm ready to do that yet. And now I think we'll see some of that unlock. I can't predict the dramatic shift yet because we can't report it yet, but I think we are seeing those dialogues pick up in intensity pretty fast.
Is there also an intersection with or a new focus on modernization?
Our modernization from IIQ to SaaS?
No. Custom is saying, look, we have to get our data infrastructure and security in a row for AI. Therefore, if we were pushing this project out on IGA indefinitely, actually we shouldn't be pushing it out anymore.
I think it's probably more driven by agentic than anything else. I don't know if that's what you mean by modernization in this context, but what's happening is the agentic tidal wave that they see coming at them I think is causing a lot of them to go, I can't stay where I've stayed. They knew they weren't in a great place with human, but they kind of thought, well, I kind of think I can live with it. Probably got some risk I'm not managing well, but I think I'll live with that risk right now. I think when they see what's happening with Agentec, their companies are for sure deploying it, and they've now seen the risks that can show up with it. I don't know that we're going to have a lot of people saying, I'm just fine, don't need to talk to you. We mentioned this in the, I think, callbacks, not on the main call yesterday. We've got a ton of POCs going on right now. We talked about the energy around that with these new technologies, the intro product and some of the discovery tools. 20% of those are with customers who don't own RIGA. So they're not even customers who are saying, I'm going to shift my IGA forward. I just need to solve this agentic problem. Let me see what you got. So that's a new motion for us to not even say, first you've got to get off of that old IBM and CA Oracle stuff. We're saying, you can keep it for now if you have to. Don't recommend it, but let's get your agentic problem solved. And that's a new motion for us.
You've been very consistent in sticking to the core competencies of the company with IGA, and I know you have some flavors around that as well. A lot of your competitors have taken a much broader approach in that all the swim lanes are converging, we want to do everything, and we want to do this new ephemeral thing on top as well. Has anything changed on your thinking on the swim lane that you want to be in?
Great question. I'd say the swim lanes are almost disappearing the way we've thought of them, is the answer I give you. So here's what I mean by that. We still look at the core human SSO MFA game that both Okta and Microsoft dominate, and our friends at Ping, fellow TV company, do real well there too. At the end of the day, We looked at that market about seven, eight years ago when we could probably play there, but we don't need to. And I think a lot of people thought, oh, you're going to start to lose IGA business because you won't have this broad offering that Okta is now saying they'll have. And CyberArk, right before their acquisition by Palo, bought a little startup called Zilla, and they were starting to plant the flag for their widening of their offering. And all we can tell you is in the enterprise clients we sell to, that has not hurt us at all. I think Okta having that breadth of offering, and I think Cyber would tell you they're further behind chasing PAM than they were chasing us in IGA, and we will tell you they're not hurting us in IGA. They've expanded the low end of the market, I think, but they haven't hurt us in IGA. I think how we see it, though, Gabrielle, it's a slightly different way to think of the question. Some of those concepts are going to start showing up in our offerings. What you won't say is do is traditional SSO MFA for humans. you won't probably see us do traditional PAM for FIS admins and DBAs, which is what PAM was mostly about. What you'll see is that's incorporating real-time dynamic authorization. You'll see us talking about escalation and de-escalation of dynamic privilege. Those concepts came out of things like PAM and SSO, but we don't want to go play in last year's war. We want to play in the next war. So we're not going to roll up the swim lanes. We're going to borrow some key concepts from those lanes and deliver them. I think our Navigate conference, in whatever it is, six, eight weeks from now, early October, you're going to hear us talking about real-time more than you've ever heard us talk about real-time. And that would be picking up concepts from both privilege and SSO, and it's also going to be very focused on levels of privilege, dynamic privilege. So the concepts are going to make their way into SailPoint's next-gen. We just never felt the need to go acquire or buy our way back into the last-gen solutions.
Mark, thank you for going down some rabbit holes with me. Please join me.
Thanks for being here, you all. Appreciate it.