EmpowerID Identity Governance manages identity lifecycles and access across cloud, on-premises, and SAP environments. It recalculates and fulfills compliant access as people join, move, or leave, while continuously reconciling actual access with policy and recording outcomes. Governance features include access requests, certifications and reviews, separation-of-duties remediation, roles, and delegated administration. Policy, approvals, fulfillment, remediation, and verification are linked as evidence of governed changes. EmpowerID lists more than 300 pre-built connectors, including Active Directory, Azure or Entra ID, SAP, Salesforce, ServiceNow, Workday, AWS, Oracle, and Windows Server. Listed protocols include SAML 2.0, OpenID Connect, SCIM 2.0, and OAuth 2.0. The Identity Fabric can run as SaaS or be deployed in a customer data center, private cloud, public cloud, or sovereign cloud in a dedicated single-tenant environment. Cloud Identity Service customers must deploy the Cloud Gateway app on at least one on-premises Windows computer to bridge managed directories and applications. Pricing is on request. Standard technical support is included with the cloud service; premium support is available for a separate fee.
Who it is for
EmpowerID suits complex organizations governing identities and access across cloud, on-premises, and SAP environments. The company identifies manufacturing, aerospace and defense, financial services, healthcare, and the public sector as target industries.
What is good
- Automates access changes as people join, move, or leave
- Includes access reviews and separation-of-duties remediation
- Lists more than 300 pre-built connectors
- Supports SaaS and dedicated single-tenant deployments
What to know first
- Pricing is available on request
- Cloud Identity Service requires an on-premises Windows gateway
- Additional external data sources may need paid configuration assistance
Verdict
EmpowerID links lifecycle automation, access governance, and evidence across a broad range of deployment environments. Organizations considering Cloud Identity Service should account for its on-premises Windows gateway requirement.
Get started with EmpowerID Identity Governance
- Visit https://www.empowerid.com/products/identity-governance.
- Contact EmpowerID for pricing on request.
- Choose SaaS or a customer data center, private cloud, public cloud, or dedicated single-tenant sovereign cloud deployment.
- For Cloud Identity Service, deploy the Cloud Gateway app on at least one on-premises Windows computer.
Questions about EmpowerID Identity Governance
How is EmpowerID Identity Governance priced?
Pricing is available on request. The modular licensing plan can be on-premises or SaaS, and most modules are licensed per non-deleted managed human person.
Can it run as SaaS?
Yes. The Identity Fabric can run as SaaS or be deployed in a customer data center, private cloud, public cloud, or dedicated single-tenant sovereign cloud.
Does Cloud Identity Service need an on-premises component?
Yes. Customers must deploy the Cloud Gateway app on at least one on-premises Windows computer to bridge managed directories and applications.
Which integrations and protocols are listed?
EmpowerID lists more than 300 pre-built connectors, including Active Directory, Azure or Entra ID, SAP, Salesforce, ServiceNow, Workday, AWS, Oracle, and Windows Server. Listed protocols include SAML 2.0, OpenID Connect, SCIM 2.0, and OAuth 2.0.
What support is included?
Standard technical support is included with the cloud service. Premium support is available for a separate fee.
What governance controls does it include?
Capabilities include access requests, access certifications and reviews, separation-of-duties remediation, roles, and delegated administration.
EmpowerID Identity Governance plans and pricing
All plansCompared on identity governance software
- Access requests
- Yes
- Access certifications
- Yes
- Lifecycle automation
- Yes
- SoD controls
- Yes
- Deployment
- hybrid




