An identity governance subscription can look straightforward until implementation begins.
The first applications are connected. Then a legacy system needs custom integration. Contractor identities enter scope. Access reviews require additional configuration. Audit evidence needs longer retention. A new automation initiative introduces service accounts and AI agents.
The original quote may still be accurate. It simply may not represent the complete cost of the program.
Understanding IGA pricing models means looking beyond a per-user rate. It requires understanding what is counted, what is included and what it takes to operate governance across your actual environment.
Citadel Identity360 addresses this challenge through unified governance for human, non-human and AI-agent identities, supported by a consolidated commercial approach.
For enterprise buyers, the objective should be more than securing an attractive subscription price. It should be building a governance program whose costs remain understandable as coverage expands.
The Main IGA Pricing Models
IGA proposals can combine several charging structures. A subscription may use an identity-based measure while features, services or infrastructure introduce additional costs.
| Pricing model | How it works | Where costs can expand |
|---|---|---|
| Per-user or per-identity | Charges are based on a defined population of people or identities. | Contractor growth, acquisitions and the treatment of reviewers, inactive identities or duplicate records. |
| Activity-based | Charges depend on qualifying activity during a billing period. | More external users participating in billable governance activities. |
| Non-human identity-based | Particular machine, workload or agent identities are counted separately. | Growth in automation and differences between the objects discovered and those licensed. |
| Module or capability-based | Governance functions are purchased through selected modules or tiers. | Adding lifecycle automation, advanced reviews, machine governance or other capabilities. |
| Bundled or consolidated | Multiple capabilities are packaged under an agreed commercial scope. | Changes to contracted volumes, application coverage, services or infrastructure requirements. |
These models are not inherently good or bad. Their suitability depends on how closely they match the enterprise’s needs.
The essential distinction is between the billing unit and the governance outcome. A price per identity does not, by itself, explain whether that identity receives lifecycle automation, access reviews, policy controls and coordinated remediation.
1. The Billable Identity Population Is Larger Than Headcount
Employee headcount is a useful starting point, but it is not a complete licensing forecast.
A hybrid enterprise may also need to account for:
-
Contractors and temporary workers.
-
External partners and guests.
-
Reviewers and approvers.
-
Administrative identities.
-
Inactive records and identities retained during offboarding.
-
Multiple accounts associated with the same person.
How these are counted depends on the commercial model.
For example, Microsoft’s access-review licensing examples include reviewers as well as the member users being reviewed. Its guest-governance licensing uses a monthly active user model tied to specified governance actions.
These are vendor-specific examples, but they illustrate a general budgeting lesson: workforce size and billable usage are not always the same thing.
Build forecasts around the normal population, seasonal peaks and planned growth. Include acquisitions, contractor-heavy projects and changes in governance coverage.
2. Non-Human Identities Introduce Another Dimension
Service accounts, application identities, workloads, bots and AI agents can expand independently of employee numbers.
A company may maintain a stable workforce while substantially increasing its automated processes. A budget based only on people will miss that change.
The relevant scope includes both the identity population and the capabilities required to govern it:
-
Discovery and inventory.
-
Accountable ownership.
-
Lifecycle management.
-
Permission reviews.
-
Policy evaluation.
-
Retirement and remediation.
Citadel brings human, machine and AI identities into one governance model. This helps enterprises plan automated access alongside workforce access rather than treating each new identity category as an unrelated governance initiative.
For budgeting, record the relationships between agents, workloads, accounts and credentials. This creates a clearer inventory and helps avoid confusing several technical objects with one business function.
3. Implementation and Customization Shape the Real Starting Cost
Buying a platform and establishing a working governance program are different activities.
Implementation can involve identity-data cleanup, account correlation, role design, approval workflows, policy configuration, migration, testing and administrator training.
The amount of work depends on the starting environment. A clean directory with consistent ownership is different from an estate containing duplicated identities, undocumented permissions and disconnected applications.
A well-scoped implementation should identify:
-
Applications and identity populations included.
-
Required lifecycle and review workflows.
-
Data-cleanup responsibilities.
-
Integration dependencies.
-
Acceptance tests.
-
Production rollout and support responsibilities.
Citadel includes 400 hours of customization support, which can be applied to requirements such as workflows, reports, policies, approval logic and integration adaptations. This makes organization-specific requirements part of implementation planning rather than leaving every adaptation as an unbudgeted follow-on discussion. Learn more about Citadel’s customization and administration approach.
The practical value is a defined allowance for adapting governance to the business.
4. Application Integration Costs Depend on the Outcome Required
A connector name does not describe the complete integration effort.
Reading accounts from an application is different from discovering detailed entitlements, assigning ownership, provisioning permissions and verifying their removal.
For each priority application, establish the intended operating process:
-
Collect account and entitlement information.
-
Correlate accounts with the correct identities.
-
Apply ownership and approval rules.
-
Fulfill approved changes.
-
Reconcile the result.
-
Preserve evidence and resolve failures.
Citadel’s integration framework for cloud, SaaS and legacy systems combines prebuilt connectors with extensible API, directory, database and file-based methods.
This provides different routes into a common governance process. Direct integration supports automated changes where available, while disconnected applications can use assigned and tracked administrative tasks.
The financial implication is important: price the required outcome for each application, including ongoing maintenance—not simply its appearance in a connector catalog.
5. Day-to-Day Administration Continues After Go-Live
An IGA platform remains an operating responsibility long after the deployment team leaves.
Approval routes change. New applications arrive. Business units reorganize. Policies need adjustment. Reviews expose exceptions that require investigation.
These activities create recurring costs through internal effort, training and specialist support.
Useful questions include:
-
Can the internal team change routine workflows?
-
How much effort does a new certification campaign require?
-
Who maintains integrations when an application changes?
-
Which tasks require external specialists?
-
How are failures and exceptions assigned and resolved?
Citadel’s no-code-first administration is designed to make routine governance changes more accessible to IT and IAM teams. That matters because long-term economics depend partly on how independently an organization can operate its platform—not just how quickly it can deploy it.
6. Access Reviews Have an Operational Cost
A certification feature is only one part of running an effective access review.
The wider process includes preparing the population, assigning reviewers, explaining permissions, following up on overdue decisions and completing rejected-access removals.
A campaign that closes on time but leaves rejected permissions active creates further work rather than a completed control.
Budget for the full review cycle, including business-owner participation and remediation.
Citadel combines scheduled certifications with AI-assisted recommendations and risk context. These capabilities help reviewers focus their attention and make more informed decisions within the governance workflow.
The useful measure is not simply how many campaigns the platform can launch. It is how much effort is required to reach an accountable decision and complete the resulting action.
7. Evidence Retention and Infrastructure Can Add Separate Costs
An audit-ready report and long-term evidence storage are different requirements.
Separate three categories in the budget:
-
Certification decisions and remediation evidence.
-
Product audit and activity logs.
-
Data exported to storage, analytics platforms or a SIEM.
Microsoft’s data-retention documentation illustrates how retention can vary by report and license type, with options to retain data through additional services. Azure Monitor pricing also identifies charges associated with ingestion, extended retention and certain export operations.
The broader lesson is to budget for the evidence architecture, not just the report screen.
Deployment choices also affect responsibility for hosting, backups, disaster recovery, test environments and upgrades. Assign each responsibility explicitly so that vendor charges and internal infrastructure costs are both visible.
8. Growth, Renewals and True-Ups Affect Multi-Year Cost
A true-up reconciles contracted quantities with actual usage under the agreement’s rules.
Its financial impact depends on what is measured, when it is measured and how expansion is charged. Renewal pricing and the ability to reduce quantities are separate considerations.
A multi-year forecast should include:
-
Workforce and contractor growth.
-
New applications and business units.
-
Non-human identity expansion.
-
Acquisitions and migrations.
-
Additional governance capabilities.
-
Renewal and volume-adjustment terms.
-
Data export and transition work at the end of the agreement.
Model a baseline and a higher-growth scenario. This makes the commercial consequences of successful adoption visible before they become budget surprises.
How to Calculate Identity Governance TCO
A practical identity governance total cost of ownership model should cover the same period and governance scope for every proposal.
IGA TCO = subscription and expansion charges + implementation and migration + integration and customization + internal operations + infrastructure and evidence storage + support, training and transition costs.
Count each cost once. Where implementation, support or customization is included in a package, do not add it again as a separate vendor expense.
Then compare proposals against equivalent outcomes: the same identity populations, applications, lifecycle processes, reviews, retention needs and support responsibilities.
A lower subscription price is meaningful only when the scope and remaining workload are understood.
The Citadel Identity360 Advantage: Simpler Commercial Planning
Citadel’s one-plan, one-price approach brings human, non-human and agent identities into a consolidated commercial model. Installation, deployment and hypercare support are included, alongside 400 hours of customization support. These elements are described in Citadel’s commercial-model overview.
For buyers, these inclusions address several areas where IGA budgets can otherwise become fragmented:
-
Separate purchasing decisions for different identity categories.
-
Deployment services detached from the platform discussion.
-
Organization-specific configuration left outside the initial plan.
-
Production stabilization treated as an afterthought.
Combined with unified governance and accessible administration, this gives enterprises a clearer foundation for planning both implementation and ongoing operations.
The proposal should make that value tangible through an agreed identity population, application scope, delivery plan and allocation of customization work.
Budget for a Working Governance Program
The most useful pricing question is not “What is the lowest rate per user?”
It is:
“What will it cost to deliver and operate the governance outcomes our enterprise needs?”
That question brings the real budget into view: people, machines, applications, implementation, operating effort and evidence.
Citadel Identity360 connects these considerations through unified governance and a consolidated commercial approach—making it easier to evaluate the program as a whole.
Explore Citadel Identity360 and request a proposal built around your identity populations, priority applications and growth plans.
Frequently Asked Questions
What is the most common mistake when comparing IGA pricing?
Comparing subscription rates without matching scope. Identity definitions, included capabilities, application coverage and implementation responsibilities can materially change total cost.
Does per-user pricing include contractors and reviewers?
It depends on the licensing definition. Contractors, guests, reviewers and administrators may be treated differently, so the billable population should be explicit.
Are non-human identities always licensed separately?
No. Commercial models vary. Citadel includes human, non-human and agent identities within its consolidated plan.
Does a prebuilt connector eliminate integration work?
No. Prebuilt connectivity provides a starting point, but identity mappings, permissions, approval paths, testing and reconciliation still need configuration.
What does Citadel’s customization allowance cover?
Citadel includes 400 hours of customization support for organization-specific requirements such as workflows, reports, policies, approval logic and integration adaptations.
How can an enterprise reduce unexpected IGA costs?
Define the application and identity scope early, account for internal operating effort, specify evidence-retention needs and model growth over three to five years. Compare complete governance outcomes rather than headline subscription prices.