This website uses cookies

Read our Privacy policy and Terms of use for more information.

Hey {{first_name|Jedi}},

A couple issues back I made the case that the IGA market is commoditizing. The evidence was vendor behavior — five agent identity frameworks shipped in the same week at RSAC, governance getting absorbed into platforms, exactly one real IGA acquisition in a year full of identity M&A. The prediction that fell out of it was that the era of $2M implementations and 18-month timelines is ending.

Here is the thing about predictions. They are cheap until somebody shows you a production environment.

So I sat down with the crew at Bridgesoft — Srinivas, their CTO, and Som C, their CEO — to walk through a migration they recently finished with a leading international airline. Fifteen years on the same IGA platform. Seventeen applications onboarded in all that time. They moved to Bridgesoft's Identity Gateway, onboarded nearly 80 applications in roughly four months, and cut annual IAM costs by 47%.

Let's start with what you inherited. What was actually running when you got there?

Srinivas: The airline was running the same IGA platform they had put in place roughly fifteen years earlier, and it was still carrying production workloads. That is the important detail — this was not a shelved system. It was the identity governance foundation for an organization that operates on very narrow tolerances.

Fifteen years on any platform accumulates weight. Integrations nobody ever cleaned up. Workflows built around the platform's quirks rather than around what the organization actually needed. Operational knowledge concentrated in a shrinking group of people who understood how it had all been wired together. None of that shows up in an architecture diagram. All of it shows up in how long it takes to do anything.

Was the platform failing, or just aging?

Srinivas: Neither word is quite right. It was doing what it had been configured to do. But the organization had outgrown it and nobody had found a clean path forward. They were not on that platform because it was still the right tool. They were on it because there was no obvious way off.

The consequence that mattered most was onboarding velocity. New applications were slow to bring into governance — slow enough that many critical systems and regulatory workloads had never been formally onboarded at all. Those systems were processing sensitive data and carrying audit obligations across multiple jurisdictions, entirely outside the visibility of the identity program.

Did the team know?

Srinivas: Yes, and that is worth saying plainly. They knew exactly where the gaps were. They had been living with them for years. What they did not have was a credible way to close them.

Som, what made this the moment they moved?

Som C: Three things converged. Scaling the existing platform was not realistic. Maintenance costs were climbing while the pace of onboarding was not. And the regulatory environment around their key markets showed no sign of relaxing.

Once those are all true at the same time, the internal conversation stops being about whether to modernize. It shifts to whether the migration can be executed without creating new risk in the process. That second question is the real blocker for a lot of organizations, and it is a legitimate one.

So give me the numbers.

Srinivas: On the previous IGA platform, the organization onboarded 17 applications over approximately fifteen years. With Identity Gateway, they onboarded nearly 80 applications in approximately four months.

What does that four months actually cover? That is the first thing anyone reading this is going to ask.

Srinivas: It should be. The four months is the overall implementation and deployment period — the transition into the SaaS-based Identity Gateway environment plus the onboarding and configuration of applications. It is not a partial figure measured from some convenient midpoint.

Those two numbers are hard to put next to each other. What accounts for the difference?

Srinivas: Several things, and none of them are that the previous team was doing it wrong.

The first is architecture. Identity Gateway is SaaS-based, so the transition did not carry the infrastructure build that a traditional IAM deployment does. The second is prebuilt connectors — a large share of the integration work that used to be bespoke is now configuration. The third follows from the first two: the deployment had a much lower dependency on specialized resources, which is usually the real constraint. Onboarding velocity on a legacy platform is rarely limited by the software. It is limited by how many people in the building know how to do the integration.

Were those 80 applications uniform, or were you picking off the easy ones?

Srinivas: Not uniform, and I would not want the number read as 80 trivial integrations. The effort varied by complexity, and all three tiers were represented.

Tier

What it involved

Simple

Standard connectors, basic aggregation and provisioning, minimal customization

Medium

Account and entitlement aggregation, joiner-mover-leaver processes, moderate customization

Complex

Custom connectors or APIs, complex workflows, transformations, business rules, multiple provisioning scenarios

That distribution is the part I would point an evaluator to.

Any platform can show a fast number if the sample is all simple connectors. The velocity claim only means something if it holds across the complexity range.

Srinivas, CTO, Bridgesoft

Set the ratio aside for a second. What did the coverage actually buy them?

Srinivas: Visibility they had never had. With more applications under active governance, the security team could finally see which identities held access to regulatory-relevant systems — many of which had operated outside any formal entitlement review process. Least-privilege access became enforceable across a surface that had previously been too fragmented to manage consistently. The exposure they had been carrying quietly for years started to close.

Let's talk vendors. What did consolidation actually involve?

Srinivas: Identity programs built incrementally tend to accumulate vendors, and this airline was no different. Three separate solutions from three different providers covered three slices of the identity problem: one for Identity Governance and Administration, one for File Share Governance, and a third for identity capabilities in AI and automated workloads.

Moving to Identity Gateway collapsed that into a single platform. One source of truth for access policy. One integration model for the teams handling provisioning, entitlement reviews, and audit reporting. The operational overhead of managing three vendor relationships, three separate upgrade cycles, and three distinct sets of incident response procedures came off the table.

Som, is that primarily a cost story?

Som C: The cost reduction is real, but I would not lead with it. The consolidation gave the airline something the fragmented model never offered — a single place to govern human identities, non-human identities, and AI workloads together. In an industry where robotic process automation, system-to-system integrations, and AI-assisted operations are already standard, governing machines on the same platform as people is not a future requirement. It is a current one.

And the financial outcome? I want the measurement basis, not just the number.

Som C: Identity Gateway delivered approximately a 47% reduction in total annual IAM costs, which makes it roughly 2.5 times more cost-effective than the solutions it replaced.

On the basis, because cost claims get repeated and then challenged: that 47% is measured against the airline's pre-migration annual IAM cost baseline. Not a year-over-year comparison, and not a projection. The savings come primarily from reduced resource requirements and from eliminating infrastructure, managed services, and maintenance costs. Those are the line items that disappear when you stop sustaining an aging on-premises deployment.

A reduction of that size is a structural shift in what governance costs to operate at scale, not a line-item optimization.

What should someone in a similar position take from this?

Srinivas: International airlines operate across multiple regulatory jurisdictions at once. They have to prove compliance against audit frameworks that do not always align, and provision and deprovision access for crews, contractors, ground staff, and partners across geographies and time zones — reliably, quickly, with full audit trails. If your identity program is running on a platform that treats each of those as an exception rather than a case, you will feel it the same way this airline did.

Som C: I would put the takeaway as a question rather than a lesson, because it is the question we ask at the start of every engagement like this one: at what point does maintaining the platform you have cost more than building the program you need? Most organizations have an answer to that. Very few have written it down.

More about Bridgesoft: https://bridgesoft.com/

Reply

Avatar

or to participate