Thesis: SailPoint is the independent system of record for who should have access, and the migration of its installed base from on-premise software to cloud subscription is the value creation event the market is discounting as a growth problem. The entire bull case reduces to one management-supplied number: the revenue multiple a customer pays after migrating. It is unaudited, it has been stated two different ways, and it decides everything.
The business
Identity security divides into three jobs, and the three vendors most often named together do not compete for the same budget line.
SailPoint governs. It answers who should have access, whether that access still complies with regulation, and whether it can be certified, audited and revoked automatically. A new employee joins, SailPoint provisions access by role, tracks entitlements, flags excessive permissions and produces the evidence trail an auditor asks for. Okta authenticates: who is logging in, verify them, broker single sign-on. CyberArk vaults: protect the privileged accounts, rotate the credentials, record the session.
SailPoint is the policy maker and the auditor. Okta is the gatekeeper at the door. CyberArk is the vault holding the keys to the kingdom. Large regulated enterprises typically run all three, which is the most important fact about this market and the one most often lost in arguments about consolidation.
Commercially the company is mid-transition. The legacy on-premise product, IdentityIQ, was sold as perpetual licence plus maintenance: lumpy revenue, a thin annuity and heavy professional services. Identity Security Cloud replaces that with subscription. Roughly two thirds of recurring revenue is now cloud, and around fifteen per cent of the on-premise base has migrated, with management targeting about half by fiscal 2029.
Where the numbers sit
Annual recurring revenue reached one point one six billion dollars in the first quarter of fiscal 2027, up twenty-six per cent, of which cloud recurring revenue was seven hundred and eighty-one million, up thirty-six per cent. Ninety-two per cent of net new recurring revenue arrived as cloud subscription, against sixty-nine per cent a year earlier. Net retention was one hundred and thirteen per cent with gross retention at ninety-seven per cent.
The account mix supports the compounding argument. Customers spending above one million dollars grew thirty-two per cent to two hundred and twenty-five; those above two hundred and fifty thousand grew twenty-four per cent. Total customers grew sixteen per cent. Recurring revenue growing at twenty-six per cent against a customer count growing at sixteen is the expansion story stated arithmetically.
Two things cut against it. Guidance implies deceleration to twenty-one or twenty-two per cent recurring revenue growth for the full year, and on the fourth-quarter call sell-side analysts pointed out that guided net new recurring revenue for fiscal 2027 was marginally below what the company delivered in fiscal 2026 in absolute terms. Management attributed this to conservatism rather than competition. And the company remains substantially loss-making on a reported basis, with a first-quarter net loss of seventy-five million dollars against thirty-eight million of adjusted operating income, the gap being share-based compensation and intangible amortisation.
The market has not been persuaded. Shares fell by double digits after both of the last two results, including a beat-and-raise quarter. Two consecutive drawdowns on good numbers is the clearest available evidence that investors do not believe the growth bridge.
Bull case
Governance sits in the compliance-mandated layer of security spend. An enterprise can defer an endpoint upgrade; it cannot decide to stop certifying access without answering to auditors, regulators and a board risk committee. Access certifications, separation-of-duties controls and joiner-mover-leaver automation map directly onto financial reporting and data protection obligations. That makes the budget line structurally more durable than discretionary security spend, and it explains ninety-seven per cent gross retention.
The migration is not a platform swap but a repricing event. On-premise customers moving to cloud typically expand scope at the same time, bringing more applications, more identities and more workflows under governance, and attaching modules for cloud entitlements, non-employee risk and privileged access. Management has put the uplift at two to three times prior spend, and at its June investor day showed migration at three to four times with subsequent expansion beyond four. That is the mechanism by which a decelerating headline growth rate can coexist with an improving business.
Neutrality is the strategic argument, and it is stronger than it sounds. As Okta bundles governance into access management, Palo Alto folds CyberArk into a single identity platform, and Microsoft embeds entitlement management inside its own security suite, the concentration risk becomes obvious: the vendor that grants access is also the vendor certifying that the access is appropriate. That is self-attestation, and boards and auditors are structurally uncomfortable with it. Separation of duties is a principle enterprises already apply to their own staff; extending it to the vendor layer is not a stretch.
The governed surface is also expanding. Non-human identities already outnumber humans in large estates, and AI agents will widen that gap considerably. Regulators will not treat those identities as optional. SailPoint has moved directly at this, acquiring Entro Security in June 2026 for non-human identity and secrets management, launching an agentic identity fabric, and repackaging its commercial model around agentic suites with usage-based capacity. Emerging products reached twenty per cent of net new recurring revenue in the first quarter with contribution more than doubling.
One under-noticed signal: in April 2026 SailPoint hired the product leader responsible for Microsoft’s human and agentic identity platform as its chief product officer. Companies do not usually recruit from the competitor they claim to be structurally advantaged against unless the competitive threat is being taken seriously, and the competitor does not usually lose that person unless the smaller company has the better story.
Bear case
The transition is a self-inflicted drag on both reported growth and margin, and management has quantified it: absent the change in cloud mix, revenue growth would be roughly three hundred basis points higher and adjusted operating margin roughly two hundred basis points higher. That is the cost of the strategy. The benefit remains an assertion.
The premise that Microsoft retreated from this market does not survive examination. Entra Permissions Management was retired on 1 November 2025, but the capability was folded into Microsoft Defender for Cloud rather than abandoned. Microsoft withdrew a standalone product and kept the function inside a platform customers already pay for, which is the bundling argument rather than a refutation of it.
The same pattern holds elsewhere. CyberArk’s governance line, acquired with Zilla Security in early 2025, survived the Palo Alto acquisition and now sits inside the Idira identity platform as one module among many. Okta’s governance product passed two thousand customers in about three years and is explicitly sold as part of a suite. Three of the four largest adjacent vendors now treat governance as a platform component rather than a category. SailPoint’s counter is that none of them appears in its large enterprise deals with any frequency, which is a management assertion that no disclosure allows an outsider to test.
Growth is decelerating from a high base while the company is still loss-making, and the share register is unusual. Thoma Bravo retains control following the February 2025 re-listing, holds five of nine board seats, and has not sold a share into the public market since the lock-up expired in August 2025. The free float is thin. Every share eventually distributed is incremental supply, and the stock still trades below its listing price.
Finally, for a company whose entire proposition is control and auditability, two disclosures in 2026 deserve mention: a high-severity authentication flaw in the on-premise product allowing unauthenticated access to protected interfaces, and a breach of a subset of the company’s source-code repositories through a third-party application. Neither appears to have reached customer production environments. Both are the kind of item a competitor raises in a governance bake-off.
The deciding question
What does a migrated customer actually pay?
Everything rests on this. If the multiple is genuinely three to four times prior spend with further expansion beyond that, then roughly three hundred and fifty million dollars of remaining on-premise recurring revenue converts into well over a billion, the fiscal 2029 targets are arithmetic rather than ambition, and today’s optical deceleration is the best entry point the story will offer. If the realised multiple is closer to the low end, the migration is a mix-shift that improves revenue quality without changing the growth rate, and a business decelerating toward twenty per cent while still loss-making looks ordinary.
Three observations sharpen the point. The multiple is a management figure that no external party can audit. It has been stated as two to three times on earnings calls and as three to four times, before expansion, in investor day material; both are the company’s own numbers and the inconsistency has not been reconciled. And management has repeatedly declined to disclose net retention split between cloud and on-premise cohorts, which is precisely the disclosure that would settle it, saying only that migration contributes low single digits to the blended figure.
That refusal is informative in both directions. A cohort dramatically outperforming would be an easy thing to disclose.
What to monitor
Migration pace against the stated target of roughly ten per cent of the on-premise base per year. Falling behind pushes the entire value creation argument to the right, and the on-premise base is finite.
Net retention. One hundred and thirteen per cent with two thirds of the base already on cloud sets the bar. If cloud cohorts genuinely expand at multiples of on-premise, the blended figure should be rising as mix shifts, not holding flat.
Emerging and agentic products as a share of net new recurring revenue, currently around twenty per cent. This is the cleanest read on whether machine and agent identity governance is a real revenue line or a positioning exercise, and it matters more than the AI branding.
The million-dollar cohort. Thirty-two per cent growth with ten sequential additions is the expansion engine working. Deceleration there, while total customer growth stays in the mid-teens, would indicate the compounding has stalled at the top.
Thoma Bravo. Any registered secondary offering should be assessed through its disclosed terms, seller participation and effect on the shares available for trading.
Bottom line
SailPoint occupies the one layer of identity that compliance obligations make non-discretionary, and it does so as the only vendor of scale with no incentive to grade its own homework. That neutrality argument is genuinely differentiated and it is getting stronger as every adjacent platform consolidates.
The problem is that the investment case does not rest on the neutrality argument. It rests on the migration multiple, which is a number the company supplies, states two ways, and declines to evidence through cohort disclosure. Until that changes, the position requires taking management at its word on the single variable that determines the outcome.
The market’s behaviour is consistent with that discomfort. Two consecutive double-digit falls on results that beat expectations is not a verdict on the quarter. It is a verdict on the bridge.