Saviynt Zuma
by Saviynt
Identity control plane for AI agents and non-human identities, with runtime authorization
Saviynt Zuma is an enterprise AI identity security platform that discovers, governs and controls AI agents, LLMs and other non-human identities alongside human ones. Launched in July 2026, it gives security and IAM teams visibility into shadow AI, runtime authorization over what an agent is allowed to do, and audit-ready lifecycle governance. It targets enterprises whose agent population is growing faster than their identity governance can track.
Saviynt Zuma, launched on 28 July 2026, is an enterprise AI identity security platform that extends Saviynt's identity governance heritage to AI agents and non-human identities. It is structured in three components. Zuma Insights continuously discovers AI agents, LLMs, AI applications and other non-human identities across the estate, including unsanctioned shadow AI, and tracks ownership and lifecycle changes over time. Zuma Access evaluates an agent's intent and permissions at runtime and blocks unauthorized actions before they execute, building on the Intent-Aware Runtime Authorization capability Saviynt added to its Agent Access Gateway earlier in 2026. Zuma Governance establishes ownership, least-privilege policy, lifecycle controls from registration through decommissioning, and audit-ready evidence. The product builds directly on Saviynt Identity Security for AI, released 24 March 2026, which introduced Identity Security Posture Management for AI and discovery across Amazon Bedrock, Microsoft Copilot Studio, Google Vertex AI, ServiceNow AI and Salesforce Agentforce. Zuma claims roughly 95% coverage of enterprise applications and data sources and adds agent-framework integrations including LangChain, CrewAI, n8n, Azure AI Foundry, Databricks, Snowflake and OpenAI. The launch landed alongside Saviynt reporting more than $300 million in annual recurring revenue, bookings growth above 80% and 96% customer retention; the company manages over 100 million identities, has raised roughly $870 million from investors including KKR and Carrick Capital Partners, and was valued near $3 billion. Design partners named at launch include The Auto Club, Hertz and UKG. A free trial is available, and Saviynt positions Zuma against SailPoint, Okta, CyberArk and Microsoft Entra in the emerging non-human identity market.
The CISO or IAM director at a large enterprise that has already deployed agents across Bedrock, Copilot Studio, Vertex AI or Agentforce and cannot answer who owns each one, what it can reach, or how its access changed last month.
One control plane that inventories every AI agent and non-human identity, enforces least privilege at runtime rather than at provisioning time, and produces the audit evidence a regulator or auditor will ask for.
At a Glance
- Category
- Governance & Security
- Pricing
- Subscription, Contact for pricing
- Target Market
- CISOs, CIOs, CTOs, IAM Architects, Security Engineers, Compliance Officers
- Deployment
- Cloud-first, API-based, Multi-cloud
- Founded
- 2010
- Headquarters
- Los Angeles, California, United States
- Team Size
- 500+
- Customers
- Manages 100M+ identities for global enterprises; Zuma design partners include The Auto Club, Hertz and UKG
Key Features
- ✓Zuma Insights
Continuously discovers AI agents, LLMs and non-human identities across the enterprise, including shadow AI, and tracks ownership and lifecycle change over time.
- ✓Zuma Access with runtime authorization
Evaluates each agent action against identity, context, policy and intent in real time, blocking privilege misuse before the action executes.
- ✓Zuma Governance
Applies ownership, least-privilege policy and lifecycle controls from registration to retirement, and generates audit-ready evidence for every AI identity.
- ✓Access path mapping
Traces the exact route an AI agent takes to reach a critical system or dataset, exposing indirect and inherited access nobody provisioned deliberately.
- ✓Timeline view of agent activity
Maintains an authoritative chronological record of what each agent did and when, which is what auditors and incident responders actually need.
- ✓Broad agent-platform coverage
Integrates with Amazon Bedrock and AgentCore, Microsoft Copilot Studio, Google Vertex AI, Salesforce Agentforce, ServiceNow AI, LangChain, CrewAI and n8n.
- ✓Converged identity platform
Runs on Saviynt's existing IGA, PAM and application GRC stack, so AI identities are governed in the same system as human and machine ones.
Capabilities
Use Cases
- •Shadow AI inventory
A security team discovers agents and LLM integrations that business units stood up without going through the identity provisioning process at all.
- •Blocking agent privilege misuse
Zuma Access denies an agent action that exceeds its declared intent, stopping over-permissioned automation before it touches production data.
- •Audit evidence for AI systems
Compliance teams export ownership, entitlement and activity records for every AI identity to satisfy auditors asking who approved this agent's access.
- •Agent offboarding
When a project ends or an owner leaves, lifecycle controls decommission the associated agent identities instead of leaving orphaned credentials active indefinitely.
- •Least-privilege review across agent fleets
Access path mapping shows which agents can reach crown-jewel systems, letting reviewers cut inherited entitlements that nobody deliberately granted.
Ideal For
Best For
- ✓Discovering shadow AI - unsanctioned agents, LLM integrations and service identities created outside the IAM process
- ✓Enforcing least privilege on AI agents at runtime, blocking actions that exceed intent or policy before they execute
- ✓Governing the full lifecycle of non-human identities from registration through ownership transfer to decommissioning
- ✓Producing audit-ready evidence of AI agent access and activity for regulators, internal audit and SOX-style controls
- ✓Consolidating human, non-human and AI identity governance on one platform instead of buying a separate NHI point tool
Not Ideal For
- ✗Small or mid-market teams - Saviynt implementations are widely reported as complex and time-consuming, typically requiring a systems integrator or expensive in-house expertise
- ✗Buyers who need peer validation of this specific product now; Zuma launched in July 2026 and has no independent reviews, so the available 4.3/5 G2 rating covers Saviynt's older Identity Cloud rather than Zuma
- ✗Organizations wanting a lightweight, self-serve agent-permissions tool, since Zuma assumes an enterprise IGA operating model and administrative staffing
- ✗Teams that need transparent published pricing, as Saviynt licenses per identity under negotiated enterprise agreements with no public rate card
Integrations
Deployment
Market & Ratings
Manages 100M+ identities for global enterprises; Zuma design partners include The Auto Club, Hertz and UKG
Market Analysis
Pros
- ✓Extends an established, well-rated IGA platform rather than asking buyers to adopt an unproven startup for a security-critical control plane
- ✓Runtime authorization based on intent is a meaningful step beyond static entitlement review, which is what most legacy IAM offers for agents
- ✓Broad, specific coverage of the platforms enterprises actually build agents on - Bedrock, Copilot Studio, Vertex AI, Agentforce, ServiceNow AI, LangChain and CrewAI
- ✓Strong commercial signals at launch: $300M+ ARR, 80%+ bookings growth and 96% customer retention
Cons
- ✗Saviynt's recurring and well-documented weakness is implementation - G2 and PeerSpot reviewers describe setup as complex and time-consuming, and say it is not as easy to use as advertised without heavy training or expert help
- ✗Administrator experience is criticized specifically: reviewers describe a modern frontend over a backend they call a mess, and PeerSpot notes the interface lacks intuitiveness
- ✗Support quality draws mixed reviews across G2, PeerSpot and Reddit, with reports of slow responses and unresolved issues
- ✗Zuma itself is weeks old, so there is no independent review data, no analyst evaluation and no reference architecture for it yet; the 4.3/5 G2 score reflects Saviynt Identity Cloud, not Zuma
- ✗No published pricing, and per-identity licensing has unclear economics when agent counts scale far beyond headcount
Pricing
Zuma
Contact for pricing
- ✓Zuma Insights discovery and posture
- ✓Zuma Access runtime authorization
- ✓Zuma Governance lifecycle and audit evidence
- ✓Integrations across major agent platforms
- ✓Free trial available
Saviynt publishes no rate card. It licenses on a per-identity subscription basis and bundles IGA, application access governance and PAM into a single SKU for many customers rather than charging separate add-ons, which is how it competes with SailPoint (list roughly $20-$40 per identity per year in mid-enterprise deals). The open question for Zuma is how non-human identities are counted, since agent populations can outnumber employees by an order of magnitude; G2 reviewers already ask Saviynt for simpler pricing across its capabilities. A free trial is offered.
Security & Compliance
Connect
Sources
This page was written from 6 sources, 4 on domains other than saviynt.com.
- 1.msspalert.com — saviynt launches zuma ai identity security platform as arr t
- 2.finance.yahoo.com — saviynt exceeds 300 million arr 180000228
- 3.securitybrief.asia — saviynt launches zuma ai identity security platform
- 4.g2.com — reviews
- 5.saviynt.com — saviynt identity security for ai agent governancevendor
- 6.saviynt.com — zumavendor
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Legit Security VibeGuard
Endpoint guardrails that discover every coding agent on a developer's machine and police what it is allowed to do
Bigeye AI Trust Platform
Governance, observability and runtime enforcement for the data your AI agents are allowed to touch
Filigran XTM One
An AI agent layer that runs threat exposure management across OpenCTI and OpenAEV as one loop
Snyk Evo Continuous Offensive Security
Autonomous AI pentesting and agent red teaming that attacks your apps continuously, not once a year