RSA Governance & Lifecycle (G&L) is RSA’s identity governance and administration product, offered “for cloud, hybrid, and on-premises”.[8] Earlier releases were branded SecurID Governance & Lifecycle: RSA’s lifecycle table lists release 7.5 under the SecurID name and 8.0 as RSA Governance & Lifecycle.[3] The on-premises software is licensed under RSA’s End User License Agreement or a signed agreement. The cloud service is governed by the Terms of Service for RSA Cloud Offerings and the Service Description for Governance & Lifecycle Cloud Service.[1]
The licensing model is user-based. “For Governance & Lifecycle Software, the licensing model is based on number of Users and the deployment model, which will determine the number of Instances the customer may use.”[1] Catalog proof: Each production Instance includes two non-production Instances.
Editions
| Deployment | Contract | How it is sold | Source |
|---|---|---|---|
| On premises (software; hardware appliances retired) | EULA; Maintenance Agreement | Users by type; Instances by deployment model | [1][4] |
| Governance & Lifecycle Cloud Service | Terms of Service; G&L Cloud Service Description | Small, medium or large package tier | [2] |
| RSA ID Plus Identity Governance | ID Plus Service Description | Add-on to ID Plus E2 and E3 contracts from 2026-03-16 | [7] |
The cloud service “is offered in different package levels – small, medium and large tiers”, and the accepted order states the tier.[2] It delivers a cloud-hosted identity governance platform with access reviews and certification campaigns, segregation-of-duty policies, joiner-mover-leaver provisioning, access requests and role mining.[2] Catalog proof: RSA Governance & Lifecycle Cloud Service; Governance & Lifecycle Cloud is sold in small, medium and large tiers.
Metrics
RSA’s Units of Measure define three user types that apply to Governance & Lifecycle:[1]
| User type | Catalog row | Definition in brief |
|---|---|---|
| Active User | Active User | An identity “processed, managed, profiled, scored, authenticated or otherwise verified” at least once in the calendar month before the current date |
| Lite User | Lite User | An identity managed in a registered G&L environment with access to fewer systems than an average Active User, needing less functionality and management |
| Inactive User | Inactive User | A former Active or Lite User whose information is retained in the G&L environment and who no longer has access to any resources |
Lite User pricing is meant for “those who have highly reduced access”. RSA’s examples are external identities, individuals with demonstrably fewer roles and entitlements, and people relying little on IT resources beyond “corporate birth-right grants”.[1] The general User definition applies where a quote simply sells Users. It counts the maximum Users that may be managed by the software, active or not.[1] Instances are installations used at the same time in production.[1]
Counting / floors
Classifying identities. Because G&L manages identities instead of authenticating them, its user count includes everyone whose information is collected and managed in the environment. Each identity falls into one of the three types. Active Users are measured on a one-month look-back: “at least once in the course of the calendar month immediately preceding the then current date”.[1] An identity that loses all access becomes an Inactive User but is still retained, and therefore still described, in the environment.[1] Catalog proof: Active Users are counted on the preceding calendar month; Per-User licences count every authorized User, active or not.
Instances. For most Instance-licensed RSA Access Software, each production Instance includes two non-production Instances for standby, development or disaster recovery. For G&L, however, the number of Instances is determined by the number of Users and the deployment model.[1] The EULA default of one production copy applies unless the Product Notice grants more.[5] Catalog proof: Only one production copy unless the Product Notice grants more.
Beyond the licensed scope. As with all RSA Software, use beyond the Unit of Measure “requires additional or modified license grants, and additional payment of applicable license and maintenance fees”.[1] On premises, RSA may audit once a year and remotely monitor licence quantities, and overutilization may be billed up to list price.[5] In the cloud, usage beyond the committed amount is billed as metered overages, and RSA’s monitoring includes tracking entitlements.[6] Catalog proof: Use beyond the Unit of Measure requires additional licences and fees; RSA may audit once a year and monitor licence quantities remotely; Cloud charges include metered overages that RSA may bill directly.
Virtualization & partitioning
G&L is not counted by processor or host. RSA’s hardware appliances for G&L reached end of primary support in December 2021, and “Current Hardware Appliances cannot be upgraded to RSA Governance & Lifecycle 8.0”. The lifecycle table lists G&L Cloud and a software-based installation as migration options.[3] Catalog proof: Governance & Lifecycle releases are supported for about two years.
Cloud / BYOL
The cloud service is a separate subscription, with no rule for applying on-premises licences to it. The production instance carries a 99.5% monthly availability standard. Total maintenance is capped at 900 minutes per month, and service level credits are capped at 5% of the fees for the affected months.[2] RSA may provide a Non-Production Instance “at RSA’s sole discretion” for testing and development before production starts.[2] Supplemental Software listed on the order, such as on-premises connectors, is governed by the EULA.[2] The cloud service has been generally available since October 2021 and has no EOPS date.[3]
Programs
Subscription and renewal
Cloud Subscription Terms renew automatically “at the same license quantity as stated in the Order” unless notice of non-renewal or licence count reduction is given at least 90 days before the term ends.[6] Under the EULA, subscriptions without a stated term default to three years and then renew for one-year periods.[5] Lowering the user count at renewal therefore needs written notice three months ahead. Catalog proof: Cloud Subscription Terms renew at the same quantity unless reduced 90 days ahead; Subscriptions renew at the same quantity unless reduced 90 days before renewal.
Maintenance and lifecycle
On-premises G&L is maintained under the Maintenance Agreement. That agreement points to the G&L lifecycle page for EOPS dates and Extended Support.[4] The lifecycle page states that the EOPS date for a release “is originally based on when the release initially becomes available, currently two years”. G&L 8.0, generally available in August 2023, has an EOPS of June 2027. Patches and hot fixes are provided only on the latest supported versions.[3] Reinstating lapsed maintenance costs the lapsed period, the current year and a reinstatement fee.[4] Catalog proof: Governance & Lifecycle releases are supported for about two years; Reinstating lapsed support costs the lapsed period plus a fee; Extended Support.
Out of scope
- Third-party components shipped with G&L, whose own licence terms prevail where RSA is not the licensor.[5]
- The size limits of the small, medium and large cloud tiers, which are not published.
- Prices, which RSA does not publish.