Lutril vs SailPoint Identity Security Cloud
SailPoint is the enterprise IGA reference: certifications, lifecycle, entitlements and, since 2026, an Agentic Fabric for AI agents, for organisations with a dedicated IAM team. Lutril delivers access governance for employees and AI agents to teams without one. Where each fits.
Short answer
Choose SailPoint if you are a large enterprise with a dedicated IAM team, complex entitlements in ERP and on-prem systems, and a budget and timeline for a platform programme: it covers certifications, lifecycle, Slack and Teams requests, EU regions, agent identity and, through Agentic Fabric, tool-call policy and prompt redaction. Choose Lutril if you are a mid-market company that needs the same outcomes in weeks: discovery from Google Workspace or Microsoft 365 the day you connect, reviews that execute, time-boxed requests in Slack, Teams and the app UI, HRIS-driven lifecycle, and an MCP proxy with a kill switch, in one product with no add-on SKUs.
Where each one starts
SailPoint Identity Security Cloud
Identity-first security for humans, machines and AI, from the IGA vendor founded in 2005 in Austin and listed on NASDAQ in 2025. Suites named Standard, Agentic Business and Agentic Business Plus cover certifications, lifecycle, requests in Slack and Teams, agent ownership and, with Agentic Fabric, policy on agent tool calls. 53% of the Fortune 500 are customers.
Lutril
Access governance for employees and AI agents built for teams without an IAM department: connect Google Workspace or Microsoft 365 and discovery starts the same day; requests, approvals and reviews run in Slack, Teams and the app UI; the HRIS drives onboarding and offboarding; every agent tool call passes through the MCP proxy. One product, hosted in France.
Capability by capability
| Capability | SailPoint Identity Security Cloud | Lutril |
|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | PartialApplication Visibility via IdP connections and an extension; the SaaS Management product reached end of life on June 30, 2026Source 3 | YesGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | YesApplication Visibility extension logs sign-ins, uploads and pastes; Shadow AI Remediation extensionSource 5 | YesChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | YesDirect-connect sources remove access automatically; others create a manual taskSource 6 | YesDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | YesRequest and approve through Slack shortcutsSource 7 | YesRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | YesSame through the SailPoint bot in Microsoft TeamsSource 7 | YesSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | YesExpiration date on requests; revocation scheduled, automatic on direct-connect sourcesSource 8 | YesOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | YesWorkday connector; lifecycle states from the authoritative HR sourceSource 9 | YesLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | PartialAutomatic on connected sources; disconnected sources produce manual tasksSource 9 | YesNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | YesShadow AI Remediation, March 2026; sensors expose agents and MCP serversSource 10 | YesSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | YesAssign owners to AI agents with an automated succession planSource 11 | YesOwner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | YesAgentic Fabric evaluates policy before a call is allowed; separate offering, GA August 2026Source 12 | YesLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | YesInline prompt security redacting PII before it reaches LLMsSource 13 | YesDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | YesFrankfurt and London regions; French among 20+ UI languagesSource 14 | YesOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | YesCampaign composition, status, remediation and sign-off reports in CSV or PDFSource 16 | YesCampaign export with decisions and revocation proof, one link |
| Native integrations | Yes1,100+ enterprise applications, 20,000 custom applicationsSource 17 | YesMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offeredNo figures published; three suites, demo on requestSource 2 | Not offeredOn request |
Choose SailPoint Identity Security Cloud if
- You have thousands of identities across ERP, mainframe and on-prem systems and a team to run an IGA programme.
- You need entitlement-level governance, separation-of-duties policy and role mining at enterprise depth.
- Procurement prefers a public company with a long audit history and a large partner ecosystem.
Choose Lutril if
- You need discovery, reviews and offboarding running in weeks, not a multi-quarter implementation.
- Your team has no IAM specialist: requests and reviews must live in Slack, Teams or the app UI, not in a portal.
- Your estate is SaaS-first and includes the long tail signed up outside SSO.
- You want agent governance, prompt DLP and a kill switch in the same product, not separate suites or add-ons.
- A French-speaking team and EU hosting matter, without enterprise pricing.
Questions buyers ask
Is Lutril an IGA platform like SailPoint?
Lutril delivers the outcomes IGA promises, access reviews, lifecycle, requests and evidence, for SaaS tools and AI agents, without the entitlement modelling depth or the implementation programme of an enterprise IGA suite. If your governance scope is SaaS and agents, that is the point. If it is SAP roles and mainframe entitlements, SailPoint is built for that.
Does SailPoint govern AI agents through MCP?
Yes, through Agentic Fabric, generally available in August 2026 as a separate offering: policy evaluation before a tool call is allowed and inline prompt redaction. Lutril's MCP proxy does the same as part of the one product, with a global kill switch and agents included in the same access reviews as employees.
What happened to SailPoint's SaaS management?
SailPoint's documentation states the SaaS Management product reached end of life on June 30, 2026. Shadow IT discovery continues through Application Visibility and the browser extension. Lutril's shadow IT and shadow AI discovery is a core, ongoing part of the platform.
How long does each take to deploy?
SailPoint deployments are programmes: sources, roles, certifications and workflows configured with an implementation partner. Lutril starts discovering the day you connect Google Workspace or Microsoft 365, then adds the HRIS and native connectors for provisioning and reviews, with nothing installed on endpoints.
Sources
- 1SailPoint Identity Security Cloudread on September 2, 2026
- 2SailPoint, Identity Security Cloud suitesread on September 2, 2026
- 3SailPoint docs, Application Visibilityread on September 2, 2026
- 4SailPoint docs, SaaS Management end of liferead on September 2, 2026
- 5SailPoint docs, Application Visibility browser extensionread on September 2, 2026
- 6SailPoint docs, completing certification campaignsread on September 2, 2026
- 7SailPoint docs, collaboration platform integrationsread on September 2, 2026
- 8SailPoint docs, access requestsread on September 2, 2026
- 9SailPoint docs, lifecycle managementread on September 2, 2026
- 10SailPoint press, Shadow AI Remediationread on September 2, 2026
- 11SailPoint docs, AI agent identityread on September 2, 2026
- 12SailPoint, Agentic Fabricread on September 2, 2026
- 13SailPoint press, identity security solution for AI agentsread on September 2, 2026
- 14SailPoint status page, regionsread on September 2, 2026
- 15SailPoint docs, supported languagesread on September 2, 2026
- 16SailPoint docs, campaign status reportsread on September 2, 2026
- 17SailPoint press, connectivity expands supportread on September 2, 2026
- 18SailPoint company pageread on September 2, 2026
Lutril wrote this page. Facts about SailPoint Identity Security Cloud come from their public documentation as of September 2, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.