Saviynt announced a collaboration with Ernst & Young LLP (EY) on July 9, 2024, to address how organizations govern contractors, suppliers, and other external users. The proposed combination pairs Saviynt Identity Cloud technology with EY’s identity and access management (IAM) consulting experience. It is a partnership announcement—not evidence of a new standalone product, a completed customer deployment, or proven cost or security gains.
What Saviynt and EY announced
The announcement describes an alliance, not an acquisition or merger. Saviynt contributes its Identity Cloud platform and external-identity lifecycle capabilities; EY brings IAM consulting and solution-design experience. EY’s release role is not defined as a standardized service package: the announcement does not specify a required implementation method, delivery geography, contract scope, or whether EY must be involved in a deployment. Saviynt’s announcement and its Business Wire release describe delegated onboarding, identity-proofing integrations, lifecycle management, risk-informed access decisions, and greater offboarding visibility.
The practical question is whether those capabilities fit an organization’s actual contractor and supplier processes. The announcement does not provide customer results, implementation timelines, pricing, service-level commitments, or evidence that every described feature was generally available on July 9, 2024.
Why external users are hard to govern
External users are people who need access to an organization’s systems but are not its employees. They may include contractors, suppliers, vendors, managed-service-provider staff, temporary workers, franchisees, consultants, and business partners.
Recommended Free Tools
#1 Best Overall
Unlike employees, these people may not appear in the organization’s HR system. Their work and access can be sponsored by procurement, a business unit, legal, a project lead, or the supplier itself. When onboarding and changes happen through spreadsheets, email, tickets, or application-specific processes, it is difficult to confirm who owns each account, why access remains necessary, and whether it was removed when circumstances changed.
- External identity management governs nonemployee identities and their access to organizational resources.
- Workforce IAM generally focuses on employees and internal users.
- Customer identity and access management (CIAM) manages consumers or customers signing in to an organization’s applications.
- Third-party risk management assesses the supplier or other organization. That is related to, but distinct from, governing each person’s account and permissions.
Saviynt’s current External Identity Management product page positions the capability around contractors, vendors, franchisees, temporary employees, and other third parties, including discovery, onboarding, access reviews, and lifecycle governance.
How the proposed external-user lifecycle fits together
The release describes capabilities rather than publishing a detailed workflow or configuration guide. A useful way to evaluate the intended operating model is to trace one external worker from supplier relationship to termination:
- Establish the relationship: Identify the external organization, internal sponsor, contract or project, and business purpose for access.
- Nominate the person: Allow an authorized supplier contact or internal sponsor to submit the user’s information, with the delegation limited to an appropriate scope.
- Validate identity and relationship: Collect the required identity and contract or employment details. Use identity-proofing checks where configured and appropriate.
- Review and approve access: Apply policy, risk checks, sponsor approval, and any time limits before granting access.
- Provision access: Create or update accounts and permissions in the approved applications and resources.
- Review and change access: Reassess access when a project, role, supplier relationship, or risk level changes, and conduct access certifications.
- Terminate and verify: Trigger removal when the worker or business relationship ends, then confirm that connected systems processed the change.
This is an explanatory lifecycle model, not a published Saviynt implementation sequence. The announcement does not document screens, APIs, approval states, named proofing providers, or configuration steps.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What delegated onboarding can—and cannot—solve
Delegated onboarding lets an external organization nominate or manage its users instead of routing every initial request through an internal administrator. That could reduce manual work and make the supplier accountable for keeping user information current. It also shifts part of the process outside the organization, so delegation needs clear boundaries.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
- Limit supplier administrators to the people and relationship they are authorized to manage.
- Record supplier actions and retain an internal owner who can approve, reject, or override submissions.
- Set delegation to expire or require renewal, rather than leaving supplier access open indefinitely.
- Validate submitted information and periodically recertify users and their business need.
- Prevent duplicate identities or access being attached to the wrong sponsor, subsidiary, project, or contract.
A supplier-managed record is not automatically accurate. Nor does managing an external identity solve attribution if the target application still uses shared supplier credentials. Named accounts are preferable where the application supports them, because shared accounts make it harder to identify which person performed an action.
Identity proofing is only one control
Online identity proofing can help establish that a person is the individual they claim to be. It does not establish that the person still works for the supplier, needs every requested permission, or belongs to a supplier that remains approved. It also cannot prove that access is being used safely or that every account has been removed.
Proofing should sit alongside sponsor approval, contract or supplier validation, access reviews, monitoring, and offboarding. Ask which providers are supported, which users must be checked, how failed or inconclusive checks are handled, and whether results can be retained as auditable evidence. The announcement names no proofing vendors and does not describe those operating details.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What “risk-based access decisions” means in practice
Saviynt and EY say the proposed approach incorporates identity and organizational risk into access decisions. That could mean using context such as a person’s relationship to the organization, supplier risk, application sensitivity, requested privilege, contract duration, proofing result, or authentication strength to shape an approval or review.
Rank #3
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
Those are examples of signals an organization might evaluate, not a disclosed Saviynt scoring model. The release does not identify specific data sources, risk thresholds, or whether decisions are automated, recommended to a reviewer, or enforced only after human approval. A buyer should ask what the system actually does with a risk signal: route an approval, deny access, increase review frequency, or trigger monitoring. A “risk-based” label alone does not establish autonomous enforcement.
Offboarding is the test that matters
External access can outlast a contract, project, supplier relationship, or worker’s employment with the supplier. Saviynt’s announcement emphasizes visibility into external-user access removal, but it does not guarantee that access is removed from every application or state how quickly removal occurs.
Deprovisioning depends on connected systems, connector behavior, synchronization schedules, application owners, and access that may have been granted outside the central platform. In a proof of concept, test ordinary termination as well as difficult cases:
- A worker’s contract ends while a target application or connector is unavailable.
- An application rejects the deprovisioning request or contains a duplicate account.
- Privileged access was granted manually and was never recorded in the central system.
- A supplier fails to confirm that a user is still active.
- The same person has separate access through multiple contracts, projects, or sponsors.
Require evidence of failures, retries, escalations, and completed removals—not just a successful request leaving the governance platform.
Rank #4
- Manufactured by Hirsch Secure, Inc. — formerly Identiv. PHISHING-RESISTANT SECURITY: FIDO Alliance-certified SecureKey stores site-specific cryptographic credentials on-device to help defend against phishing, password theft and replay attacks. PASSWORDLESS + MFA: Supports FIDO2, U2F and WebAuthn for passwordless sign-in, 2FA and MFA. USB-C + NFC: Works with compatible laptops, desktops and mobile devices across Windows, macOS, Linux, ChromeOS, Android and iOS. MULTI-PROTOCOL: Supports HOTP and PIV, with SecureKey Manager for FIDO2 PIN and device management. TAA COMPLIANT: Built for personal, business, enterprise and government use. Register a second key as backup.
What the alliance might change—and what has not been demonstrated
If implemented effectively, a joined technology-and-consulting approach could help an organization reduce manual onboarding requests, improve supplier accountability, standardize approval and certification, find orphaned accounts, and coordinate procurement, business sponsors, and security teams. Those are plausible program goals, not measured outcomes from the announcement. Neither the release nor the available product material reports before-and-after customer data proving lower costs, better security, or faster offboarding.
EY’s involvement may provide capacity for identity-program design, process transformation, and integration planning. It may also add professional-services cost or reliance on specialized implementation support. Ask for a clear division between software licensing, implementation, integration work, managed services, and ongoing support; the alliance announcement does not publish EY’s service catalog, pricing, staffing model, or minimum engagement size. EY’s technology transformation page is a service route, not a published scope or price for this specific collaboration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to evaluate Saviynt and the EY collaboration
Use a proof of concept and procurement review to test the organization’s real external-user scenarios, not just a standard employee onboarding flow.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchGovernance coverage and delegation
- Can the platform govern the person and the supplier relationship, including sponsor, project, contract, or purchase-order context?
- Can suppliers nominate users without gaining excessive administrative authority?
- Are supplier actions logged, reviewable, and limited by scope or expiration?
- Can internal owners approve, reject, and override submissions, and are external-user access reviews supported?
Identity assurance and policy
- Which proofing providers and validation sources are supported, and how are failed, expired, or inconclusive checks handled?
- Can proofing be applied selectively by risk rather than universally?
- Which risk signals are native, and can policies differ by application, supplier, geography, role, or sensitivity?
- Can administrators explain why access was approved, denied, or routed for review?
Lifecycle automation and integration
- What events trigger onboarding, transfer, suspension, and termination?
- Can access be time-bounded, and what happens when a supplier does not reconfirm a user?
- Which directories, SaaS applications, ERP, ticketing, procurement, and HR systems are supported?
- Are connectors Saviynt-developed, partner-developed, custom, or API-based? What are the failure-retry and escalation paths?
- Can the platform find or address access created outside its managed workflows?
Implementation and commercial scope
- What work would Saviynt perform versus EY, and is EY required, recommended, or optional?
- How much policy and workflow customization is necessary, and what business data must be prepared?
- Who owns ongoing access reviews, exceptions, and supplier follow-up?
- Separate the subscription, implementation, integration, partner connector, and ongoing support costs in the proposal.
Saviynt’s pricing page presents tiered packages and a demo-led route rather than a standard public dollar price for External Identity Management. It says Saviynt-developed connectors are included in tier pricing, while partner-developed connectors may be sold separately through Saviynt Exchange. AWS Marketplace likewise lists custom pricing options rather than a standard public price. Confirm the connector and service costs relevant to the proposed architecture rather than inferring total cost from the platform tier.
Best Value
- VERSATILE: Designed for seamless use with our M-216C and other can wrenches, this security key insert effortlessly fits into the 3/8” side of a can wrench, ensuring a secure and efficient unlocking experience
- DUAL-HEX ADAPTABILITY: This security key insert effortlessly transitions between 5/16” and 5/32” hexes by reversing the insert
- TAMPER-PROOF ACCESS: Unlock tamper-proof cross-connect cabinets, MESA units, CATV closures, and other closures with a 5/16” hex using the specialized 5/16” side of the insert
- NETWORK INTERFACE EXCELLENCE: With its 5/32” side, this security key insert is ideal for use on most Network Interface Boxes
- DURABLE DESIGN: Crafted for reliability, this security key insert is engineered with high-quality materials, ensuring longevity and consistent performance
Where it fits against other identity approaches
Saviynt’s current product positioning places External Identity Management within its wider Identity Cloud and Identity Security offering. That may merit consideration in a large enterprise with a complex application estate, numerous external identities, audit needs, and an existing or planned identity-governance program. It is less compelling when the requirement is simply customer login, the external population is small, or the organization has not established ownership and lifecycle policies.
Compare products by the work to be governed, not by the word “external” in a product name:
| Approach | When to evaluate it | What to verify |
|---|---|---|
| Saviynt Identity Cloud | Cross-application identity governance with external workforce and supplier lifecycle needs. | Delegation, supplier relationship modeling, connector coverage, review workflows, implementation scope, and total cost. |
| Microsoft Entra External ID and Entra ID Governance | Organizations already centered on Microsoft identity, or use cases involving external or customer application identities. | Whether the combination covers supplier lifecycle governance, contract-linked access, and the required integrations. Microsoft describes External ID pricing as primarily monthly-active-user based; the pricing page identifies a free allowance for the first 50,000 MAUs in the applicable scenario and directs buyers to request a quote for other pricing. Check Microsoft’s current pricing terms. |
| SailPoint Identity Security Cloud | A direct enterprise identity-governance alternative to include in a formal evaluation. | External-user capabilities, feature fit, implementation effort, and current pricing directly with the vendor. SailPoint product information. |
| Okta Identity Governance | Organizations already using Okta for workforce identity, SSO, and lifecycle infrastructure. | Coverage for supplier relationships, delegated onboarding, contract-linked access, and external-user risk needs; obtain a current quote. Okta product information. |
| CIAM platform | Customer or consumer sign-in to the organization’s applications. | Whether the users are customers rather than suppliers, contractors, or other nonemployees needing governed workforce access. |
| Third-party risk platform | Supplier assessment is the main requirement, such as evaluating organizational risk. | Whether individual account provisioning and deprovisioning need a separate identity-governance capability or integration. |
These alternatives address different combinations of identity, governance, and supplier-risk needs; the announcement provides no evidence of feature parity, price advantage, or universal superiority for any one option.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




