LICENSEWARE

SailPoint Identity Security Cloud licensing

This article is about how SailPoint licenses the cloud suites of Identity Security Cloud and the Agentic suites: identity types, Lite and Inactive Identities, suite contents and tenant limits. It is not about the on-premises IdentityIQ product or the add-on modules, which have their own articles. It is not legal advice.

On This Page

SailPoint Identity Security Cloud licensing is the way SailPoint measures and packages its cloud identity governance suites. The licence unit is the Identity: SailPoint’s Identity Security products are singularly licensed by Identity according to identity profiles that reflect the type of identity that an Identity Cube represents.[1] The suite then decides which capabilities the tenant may use, and a tenant-level table decides how much workflow capacity it receives.[2]

Editions

Identity Security Cloud suites

The Identity Security Cloud Suites section, last updated on 2026-05-14, lists Foundations, Standard, Business, Business Plus and Atlas Enterprise.[2]

Suite Described as Notable inclusions 
Foundations For smaller organisations starting with identity security, solving immediate problems such as access request automation, basic certifications and visibility into access Atlas workflows and forms, access modeling, lifecycle management, certifications, separation of duties, view-only analytics, Harbor Pilot agents[2] 
Standard For smaller organisations consolidating identity tools into one identity security solution Foundations capabilities plus the SailPoint MCP Server[2] 
Business For organisations replacing an existing identity governance solution or adding automation and some AI functionality; everything in Standard plus Role insights, access request and certification recommendations, Access Intelligence Center, activity insights, view-only outliers[2] 
Business Plus For organisations that want to transform their programme with advanced capabilities; everything in Business plus Adaptive approvals, authoring of reports and dashboards, outliers, Identity Graph[2] 

The Harbor Pilot agents are noted as available only in AWS regions where the Amazon Bedrock model that SailPoint employs is supported.[2]

Agentic suites

The SailPoint Suites section, last updated on 2026-08-04, lists Agentic Business, Agentic Business Plus and Atlas Enterprise. Agentic Business provides least standing privilege for all identities, human and non-human, and includes SailPoint Human Fabric and SailPoint Agentic Fabric for discovery and visibility and for governance and audit. It includes everything in Standard plus Atlas, Human Fabric and Agentic Fabric capabilities. Agentic Business Plus includes everything in Agentic Business plus response and remediation, agent authorisation and further protection capabilities, with Cloud Infrastructure Entitlement Management included.[3]

On the SailPoint suites page the human-identity package is Standard, and the human plus agentic packages are Agentic Business and Agentic Business Plus. Existing Identity Security Cloud customers who wish to incorporate agentic governance need to upgrade to one of the two Agentic suites.[4]

Metrics

Metric Definition (Current Definitions, last updated 2026-08-04) 
Identity [-IU] A Person, Non-human Account or AI Agent who has access within the governed environment or is managed by the SaaS services[1] 
Person A human being regarded as an individual[1] 
Non-human Account Built-in accounts, devices, service accounts, automations, workloads or any other non-human mechanism that uses business processes, workflows or artificial intelligence to execute tasks autonomously, excluding AI Agents[1] 
AI Agent Any distinct agent, assistant, agentic workflow or other software system that uses AI models, machine learning or algorithmic decision-making and may exhibit non-deterministic behaviour[1] 
Lite Identity [-LU] A Person or Machine whose access within the governed environment is limited to five Sources[1] 
Inactive Identity An Identity or Lite Identity whose Identity State is inactive in Identity Security Cloud or IdentityIQ, or whose profile is archived in Non-Employee Risk Management[1] 
Source A customer-managed or subscribed target system governed by the offerings[1] 

The definitions page also defines Browser Profile, a profile in any browser on which the customer has deployed a SailPoint browser extension, and Endpoint, a local user device or server where identity policies, credentials and access privileges are applied and enforced.[1] The page lists them among the definitions without saying that they are separate licence units, so the Order should confirm whether either is counted.

Counting and floors

Identity versus Lite Identity

A Person or Machine whose access is limited to five Sources can be licensed as a Lite Identity; one with wider access is an Identity. The deprecated definitions drew the same line with different names: Lite User and Business Partner Identity Cubes were limited to five governed Sources and an Internal Identity had access to more than five.[5] A person with access to six Sources therefore sits on the Identity side of the boundary, and a count of Sources per person is the evidence.

Inactive Identities

In addition to Active Identities, customers may store Inactive Identities up to 30 percent of the combined total of licensed Identities and Lite Identities.[1] As an illustration of the arithmetic, a tenant licensed for 10,000 Identities and 2,000 Lite Identities has a combined total of 12,000, so the allowance is 3,600 Inactive Identities. The definitions page does not say what happens to Inactive Identities above the allowance, so that case is left to the Order and to the usage-verification clause.[6]

Non-human and AI identities

AI Agents are a separate identity type for pricing purposes, and machine accounts are not eligible to be governed as AI Agents using Agent Identity Security or other AI Agent-focused offerings.[1] For the Agentic Business and Agentic Business Plus packages customers receive an initial one-time allotment of five non-human identities for each human identity. SailPoint states that the 5:1 ratio is subject to change before General Availability but will not fall below 5:1 on General Availability or thereafter, with final terms to appear in the product documentation.[4]

Tenant-level limits

The suite tables state allowances at the tenant level unless indicated otherwise. Two columns exist. The Prior Usage Allowance applies to customers whose order was executed before 2025-11-01 and remains in effect until the next renewal or new order. The Acceptable Use Limits apply to new subscriptions and to renewals on or after 2025-11-01, from the effective date of the new order or renewal term.[2]

Suite Prior Usage Allowance Acceptable Use Limits 
Standard 15 enabled workflows with 20 steps; 100 distinct sources from the connector library; up to 5 paid integrations 15 enabled workflows with 20 steps; full connector library; no limit on paid integrations[2] 
Business 25 enabled workflows with 50 steps; full connector library 50 enabled workflows with 50 steps; full connector library[2] 
Business Plus Unlimited enabled workflows 200 enabled workflows with 100 steps[2] 
Atlas Enterprise No applicable limits on enabled workflows, connectors or integrations 300 enabled workflows with 100 steps; up to 4 personal dashboards per administrator and 20 shared dashboards per tenant[2] 

The Agentic suites show the same pattern. Agentic Business had 25 enabled workflows with 50 steps before and has 50 with 50 now, and Agentic Business Plus moved from unlimited enabled workflows to 200 with 100 steps.[3] Across all rows API calls and entitlements carry no applicable limits.[2] The tables do not state a remedy for a tenant that exceeds a limit, so the Order and the usage-verification clause are the places to look.[6]

Virtualization and partitioning

The licence unit is the identity, not a host. Required Software, if SailPoint provides it for use with the SaaS Services, is a virtual machine that connects the customer’s Sources using public APIs, connectors and integrations to the SaaS Services, and it is identified in the Documentation.[1] The documents retrieved do not state that the virtual machine is separately charged.

Cloud and self-hosted

Identity Security Cloud is SaaS. SailPoint’s SaaS Terms in the Product Specific Terms, effective December 12, 2025, state that log data, reports and similar historical data produced by the service may be deleted under SailPoint’s standard archival practice where the Documentation sets no retention commitment, and that SailPoint may create product analytics from the customer’s use that do not identify the customer or its users.[7] The FedRAMP version of Identity Security Cloud has its own terms, including hosting in the AWS GovCloud (U.S.) Region and customer representations about U.S. status.[7]

Programs

  • Prior Usage Allowance and Acceptable Use Limits. Described above.[2]
  • Initial non-human identity allotment. Described above.[4]
  • Inactive Identity allowance. Described above.[1]
  • Evaluation. A free evaluation under the Evaluation Agreement runs 30 days in a sandbox without support.[8]

Audits and compliance

The Framework Customer Agreement states that SailPoint actively monitors SaaS usage against entitlement and that a customer exceeding its rights pays the fees required to meet actual usage within 60 days of written notice.[6] A licence position for Identity Security Cloud therefore needs: the Identity and Lite Identity totals from the tenant, the number of Inactive Identities against the 30 percent allowance, the Source count per identity near the five-Source boundary, the AI Agent and non-human counts against any allotment, and the tenant’s enabled workflows against the limit column that applies to the order date.

Out of scope

IdentityIQ is in SailPoint IdentityIQ licensing. Add-on modules, SAP packages and Accelerated Application Management are in SailPoint add-ons and advanced capabilities licensing. Prices are not published.

References

  1. SailPoint Customer Agreements Definitions and Additional Terms: Current Definitions (last updated August 4, 2026)Current Definitions section. Last Updated August 4, 2026.Effective 2026-08-04. Retrieved 2026-10-07.
  2. SailPoint Customer Agreements Definitions and Additional Terms: SailPoint Identity Security Cloud Suites (last updated May 14, 2026)Identity Security Cloud Suites and Acceptable Use Limitations. Last Updated May 14, 2026.Effective 2026-05-14. Retrieved 2026-10-07.
  3. SailPoint Customer Agreements Definitions and Additional Terms: SailPoint Suites (last updated August 4, 2026)SailPoint Suites section (Agentic suites). Last Updated August 4, 2026.Effective 2026-08-04. Retrieved 2026-10-07.
  4. SailPoint Suites product pageSuite comparison and non-human identity allotment note. Undated.Retrieved 2026-10-07.
  5. SailPoint Customer Agreements Definitions and Additional Terms: Deprecated Definitions (last updated October 26, 2023)Deprecated Definitions. Last Updated October 26, 2023.Effective 2023-10-26. Retrieved 2026-10-07.
  6. SailPoint Framework Customer Agreement (last updated December 20, 2025)Sections 1, 4.2, 6, 7, 13.1, 13.3 and Exhibit A. Last updated December 20, 2025.Effective 2025-12-20. Retrieved 2026-10-07.
  7. SailPoint Product Specific Terms (effective December 12, 2025)AI Terms, SaaS Terms, SAAM, SAIR. Effective starting December 12, 2025.Effective 2025-12-12. Retrieved 2026-10-07.
  8. SailPoint Evaluation Agreement (last updated August 27, 2026)30-day sandbox evaluation. Last updated August 27, 2026.Effective 2026-08-27. Retrieved 2026-10-07.

See also

Catalog Rows Cited

8Metrics3Programs

Esc