All Posts
GeneralSeptember 8, 2026 · 12 min read

IGA Pricing for Human, Contractor, and Machine Identities Explained

IGA pricing is rarely a single per-user number. If you are comparing vendors, you need to price the identity population and the commercial meter together, then model growth, add-ons, implementation, renewal, and true-...

IGA Pricing for Human, Contractor, and Machine Identities Explained

IGA pricing is rarely a single per-user number. If you are comparing vendors, you need to price the identity population and the commercial meter together, then model growth, add-ons, implementation, renewal, and true-up costs before you trust any quote. That matters whether you are buying for employees, contractors, service accounts, workloads, or AI agents.

The practical question is not “What is the list price?” It is “What is counted, when is it counted, and what happens when the identity estate expands?”

The right way to read an IGA quote

The headline SKU is only the starting point. In enterprise identity governance, the real cost depends on the billable unit, the activity definition, and the scope of what is included in the order form.

You should expect quotes to be built around one or more of these meters:

  • named or managed human users

  • active users or monthly active users

  • contractors, partners, and guests

  • service accounts, workload identities, or machine identities

  • identity records or identity cubes

  • transactions, workflow runs, API calls, SMS messages, or authentication events

  • applications, connectors, tenants, or environments

That is why two quotes with similar unit prices can have very different three-year cost profiles. A higher unit price may still be cheaper if it includes contractors, machine identities, connectors, access reviews, and implementation help. A lower price can become expensive if every expansion point is measured separately.

For a CIO or Head of IT, the decision is really about operational predictability. The best quote is the one that gives you clear identity definitions, transparent usage reporting, and a renewal structure you can defend.

How vendors count human, contractor, and machine identities

The first pricing risk is assuming every identity class is treated the same way. Vendors often use different commercial rules for workforce users, contractors, guests, and non-human identities.

Employees and workforce users

A workforce identity is usually an employee or other person governed through access-request, lifecycle, certification, or provisioning processes. The commercial wrinkle is whether the vendor counts the person, the managed record, or the licensed population.

That matters because one person can appear multiple times across directories, tenants, acquired companies, or disconnected HR systems. If duplicates are not deduplicated, your billable count can drift away from your real headcount.

A named-user model usually charges for the contracted population whether or not every user is active. An active-user model can be more economical for seasonal or intermittent populations, but only if the vendor defines “active” in a way you can actually measure. Some vendors use a monthly active definition based on authentication or authorization during a calendar month. Others count identities marked active in the governance platform.

Contractors, partners, and guests

Contractors are commercially ambiguous, which is another way of saying they are a common source of surprise spend. Depending on the vendor, they may be treated as workforce users, contingent workers, external guests, or a separate lower-cost class.

Do not assume a contractor is cheaper than an employee. Ask whether the same lifecycle controls, access reviews, provisioning, and audit evidence are included. Also ask whether a contractor converted to employee status becomes a second billable identity.

The same caution applies to guests. A guest might authenticate once, but if that identity is included in a review campaign or governance workflow, it may trigger a different meter. The distinction between external identity services and governance features matters here.

Service accounts and machine identities

This is where machine identity pricing becomes easy to misread. Service accounts, application identities, API identities, cloud workloads, managed identities, automation accounts, bots, and AI agents are not interchangeable from a commercial standpoint.

A vendor may include some of these in the base platform, charge for each workload identity, or measure activity through transactions rather than identity count. You also need to know whether discovery-only records are free, whether disabled accounts are counted, and whether one technical identity used by several applications is billed once or many times.

This is especially important because machine populations usually grow faster than human populations. A pricing model that is manageable for employees can become expensive once cloud migration, CI/CD, automation, certificates, ephemeral workloads, and AI agents start adding volume.

The main IGA pricing models

Most enterprise offers fall into a handful of commercial models. The important point is that these models are often combined in the same quote.

Model

What is counted

Main expansion risk

Named or managed identity

Contracted people, identity records, or identity cubes

Paying for unused capacity and minimum commitments

Active or monthly active identity

Unique identities active during a defined period

Ambiguous activity rules and month-end spikes

Workload or machine identity

Service principals, applications, workloads, managed identities, or non-human identities

Fast growth in machine populations

Transaction or consumption

Authentication events, workflow runs, API calls, SMS messages, or review actions

Unpredictable usage and overage invoices

Tiered or bundled suite

A package of capabilities with identity or usage bands

Needed features may sit in a higher tier

Application, connector, or environment

Connected apps, integrations, tenants, or sandboxes

Growth often triggers extra integration cost

Named or managed identity

This is the simplest to understand and the easiest to overpay for if you buy too much capacity. You are paying for a contracted number of identities, not necessarily for what is active today.

The main risk is lock-in to a quantity that no longer matches the business. If the company shrinks, divests, or changes its workforce mix, you may still be paying for ordered capacity for the full term.

Active or monthly active identity

This model can look attractive for variable populations because you pay for usage, not raw headcount. But you need a clean definition of activity.

Ask whether the vendor uses authentication events, authorization events, or simple platform status flags. Ask whether tenant aggregation applies, whether guest actions count, and whether activity is measured at month-end, over a calendar month, or by some other interval.

Workload or machine identity

This is the commercial category most likely to expand quickly without warning. Machine identity pricing may be based on workload identities, managed identities, or premium eligibility for non-human identities. In some cases, only certain controls or review features are billable.

That distinction matters. A platform may look inexpensive until privileged reviews, governance actions, or risk analytics move machine identities into a paid tier. If your cloud and automation estate is growing, you need a specific answer about how service accounts, API identities, certificates, Kubernetes workloads, serverless functions, and AI agents are treated.

Transaction or consumption

A consumption model charges for actions rather than identity counts. That can include authentication events, workflow executions, API calls, SMS messages, or review actions.

The commercial challenge is volatility. Usage can rise with adoption, integrations, seasonal peaks, or a new rollout. It can also create separate overage invoices if the allowance is exceeded.

Tiered or bundled suite

Suite pricing often makes individual features look affordable while widening the scope of what you are paying for. That can be useful if the bundle matches your operational needs. It is less useful if the bundle includes capabilities you will not deploy.

The key question is whether required governance functions sit in the base tier or a higher one, and whether connectors and advanced modules are included or priced separately.

Application, connector, or environment based pricing

This model often shows up as a multiplier on top of identity-based pricing. If you are adding applications, sandboxes, tenants, or regions, the commercial model may expand through connector charges or professional services rather than a simple license increase.

That is why integration scope belongs in the pricing discussion, not only in implementation planning.

Where true-up costs usually appear

True-up costs are the point where the contract and reality diverge. In IGA, they usually surface when the population grows faster than expected, when the billing definition is tighter than the buyer assumed, or when a new identity type enters scope.

Common pressure points include:

  • employees, contractors, guests, service accounts, or workload identities exceeding the order quantity

  • contracts that measure the peak, month-end, hourly active, or highest-ever population instead of the average

  • guest governance actions that become billable when included in review, lifecycle, or role workflows

  • machine identities that are free for discovery but billable for privileged or premium controls

  • transaction overages on API calls, workflow runs, SMS messages, or authentication events

  • new applications that require paid connectors, custom integrations, or extra environments

  • term restrictions that force you to pay for ordered capacity even when users leave or projects end

  • renewal resets where discounts disappear or prices increase

  • audit reconciliation that allows the vendor to inspect usage and invoice excess quantities

  • taxes and currency changes that affect the actual invoice

This is why true-up costs should never be treated as a side note. They are part of the commercial model.

The hidden total cost beyond licenses

A license price is not the full cost of deployment. For IGA, the real three-year cost typically includes implementation, integrations, cleanup work, and ongoing administration.

Think of total cost as this:

Three-year TCO = subscription + implementation + connectors and custom integration + data cleanup and migration + role engineering + internal administration + support and training + add-ons + overages or true-ups + taxes and exit costs.

The most common hidden items are straightforward, but they are easy to underestimate:

  • HR, directory, ITSM, ERP, cloud, database, and legacy-system integration

  • connector development, testing, maintenance, and version changes

  • identity data cleanup and duplicate resolution

  • role mining, role engineering, and separation-of-duties design

  • access-review preparation, campaign administration, and remediation

  • premium support, training, and managed services

  • sandboxes, disaster-recovery environments, and regional expansion

  • API, event, workflow, storage, report, or integration limits

  • internal FTE time for application onboarding and exception handling

  • exit assistance, data export, retention, and deletion requirements

There is also a more subtle cost: customization. Vendor-sponsored IGA research consistently warns that excessive customization increases both implementation cost and future maintenance burden. That is not an edge case. It is one of the main reasons a platform becomes expensive after the first year.

How to pressure-test IGA pricing before shortlisting vendors

The goal is not to extract a discount. The goal is to get a quote you can compare fairly. Every vendor should complete the same pricing workbook using your actual census and your actual expansion assumptions.

Here is the minimum you should ask for:

  1. Current and projected employees, contractors, partners, guests, service accounts, applications, cloud workloads, AI agents, and privileged identities.

  2. A definition of every counted unit, including duplicates, disabled records, inactive identities, rehires, shared accounts, managed identities, and service principals.

  3. The activity event that triggers billing and the exact measurement period.

  4. Separate prices for each identity class and each add-on.

  5. Included connector, application, environment, API, workflow, transaction, and support allowances.

  6. Overage rate, grace threshold, billing timing, retroactivity, audit rights, and notification process.

  7. Minimum quantities, true-down rights, reassignment rules, renewal notice, price escalator, and automatic-renewal terms.

  8. Implementation scope, included application count, custom connector assumptions, migration responsibilities, training, and ongoing administration.

  9. Three-year projections at baseline, 25% growth, 50% growth, and a high-growth machine-identity scenario.

  10. A sample monthly invoice and usage report showing which records are counted.

  11. A written answer for what happens after an acquisition, divestiture, seasonal workforce spike, or major AI rollout.

  12. Data-export, transition, retention, and termination obligations.

If a vendor cannot explain its count logic, usage telemetry, overage formula, and renewal treatment, you do not have a comparable commercial offer. You have an estimate.

For buyers evaluating Citadel Identity360 or any other IGA platform, the same logic applies. Ask for the included-feature matrix, implementation scope, usage report, and growth model in writing. That is the only way to compare commercial models for employees, contractors, vendors, service accounts, machine identities, cloud workloads, and AI agents on equal terms.

The shortlist should favor predictability, not the lowest sticker price

The lowest apparent price is not necessarily the lowest three-year cost. A quote with a higher unit price may be cheaper if it includes contractors and machine identities, useful reporting, connectors, access reviews, implementation assistance, and the right governance scope. A low human-user price can become expensive when contractors are counted as full users, service accounts require another SKU, premium reviews are separate, or growth is reconciled at a higher rate.

That is the central takeaway. IGA pricing is about commercial meters, not just software features. Once you understand what is counted, how activity is measured, and where expansion is billed, you can compare vendors on operational reality rather than headline numbers.

A practical shortlist should favor the offer that is predictable, contractually clear, and complete enough to support continuous governance over time.

FAQ

Are contractors usually cheaper than employees in IGA pricing?

Sometimes, but not reliably. Contractors may be treated as workforce users, guests, contingent workers, or a separate identity class. Ask whether the same lifecycle, access-review, provisioning, and audit controls are included and whether a contractor-to-employee conversion creates a second charge.

Are service accounts and machine identities included in the human-user price?

They may be included, limited to discovery, or charged under a workload or machine-identity SKU. Premium access reviews, privileged-role governance, or managed-identity controls can create additional licensing requirements. Get a written definition covering service principals, managed identities, cloud workloads, automation accounts, certificates, and AI agents.

What is a true-up in an IGA contract?

It is the reconciliation of measured usage against contracted entitlement. Depending on the agreement, the result may be a new purchase, a retroactive invoice, an overage charge at the then-current rate, or a renewal adjustment. Do not assume the mechanism. It must be stated in the order form.

What should a CIO ask before comparing IGA vendors?

Ask what is counted, when it is counted, which identity types are excluded, what happens at 25%, 50%, and 100% growth, which features and connectors are included, how overages are calculated, whether quantities can be reduced, and what implementation, support, tax, renewal, and exit costs are excluded.

Stay Current

Get the latest insights delivered

Compliance updates, IGA best practices, and regulatory analysis from Astranova Labs.

Browse all posts →