Industry guide · Internal Tools

Identity Governance and Access Certification: Why Do Managers Approve Everything They Cannot Understand?

Identity Governance and Access Certification software visual showing id card, approved team member, and lock keyhole.
The short answer

Expect $100,000 to $200,000 for a first release in 14 to 20 weeks, and $280,000 to $650,000 phased over 9 to 18 months for a full identity governance build in our delivery experience. Building is justified when a meaningful share of your applications have no standard connector, when entitlement names are meaningless to the managers certifying them, and when your approval hierarchy and audit evidence needs do not fit a product's campaign model. It is not justified if your estate is essentially Microsoft or Okta with modern applications: Entra ID Governance or Okta Identity Governance will do this properly for far less than a build.

The quarterly ritual everybody knows is theatre

A compliance analyst exports entitlements from eleven systems, pivots them into spreadsheets by manager, and emails 340 of them. A manager in operations opens hers and finds 61 rows. One says FIN_GL_JE_POST_ALL. Another says SAP role Z_MM_INV_02. A third says database role rw_prod_billing. She has fourteen direct reports, a day job, and no basis whatsoever for judging whether any of these are appropriate. She selects all, clicks approve, and returns the spreadsheet in four minutes.

The campaign completes at 98 percent approval. The evidence pack goes to the auditor. Everyone involved knows the exercise proved nothing, and the reason is not laziness. It is that the manager was asked a question she was structurally unable to answer. Nobody told her that FIN_GL_JE_POST_ALL lets a person post journal entries without a second approver, that only four people in the company should hold it, or that her report last used it eleven months ago.

Meanwhile the actual risk is somewhere else entirely. A developer who moved to a different team in 2022 still holds production database access, because the move was a transfer rather than a leaver and no process covers transfers. A contractor's account in a legacy application that was never connected to the identity system is still live two years after the engagement ended, because the offboarding checklist covers the systems someone remembered in 2019.

What SailPoint, Saviynt and the platform vendors do well

These products exist because the problem is real, and where they fit they are a better buy than a build. SailPoint and Saviynt have deep connector libraries, mature campaign engines, role mining and policy models developed over many years. Omada and One Identity are strong in their segments. Microsoft Entra ID Governance and Okta Identity Governance are excellent value if your estate is largely within their ecosystem, because the identity data is already there and access reviews become a configuration exercise rather than a project.

Two things push organisations past them. The first is the long tail of applications. A bank or a hospital group runs a core system from the 1990s, a specialist clinical or trading application, several vendor hosted systems with no API, and a handful of tools where access is defined inside the application by a local administrator. None of these have a standard connector. Every governance product supports building custom connectors, and that is real engineering work you will do regardless of which licence you hold. The uncomfortable arithmetic is that if two thirds of your risk sits in applications you must integrate manually anyway, a large licence buys you the campaign engine and not much else.

The second is entitlement semantics. A connector can extract that a user holds a role called Z_MM_INV_02. Nothing extracts what that role permits, who should hold it, or whether it combines with another role to break a segregation of duties rule. That knowledge lives with application owners, and building the process to capture and maintain it is the actual project. Products give you fields to store it in. They do not give you the descriptions, and campaigns run on undescribed entitlements are the rubber stamp you already have.

Make the reviewer's question answerable

The design principle worth building around is that a reviewer must be able to decide from what is on screen, without asking anyone. That means every entitlement presented in a campaign carries a plain language description written by its application owner and reviewed on a cycle, a risk rating, whether it is privileged, and any segregation of duties conflicts it participates in.

Then add usage. Last used date changes reviewer behaviour more than any other single field, because approving access a person has not touched in a year feels different from approving access they used yesterday. Usage data is harder to get than entitlement data, since it means pulling application logs or authentication events, and it is worth the effort. Add peer comparison where it is meaningful: this person holds three entitlements that none of their fourteen colleagues in the same role hold. That is the outlier a reviewer can act on. Finally, make revocation the cheap path. If approving is one click and revoking triggers an email thread, you have designed for approval. Revocation should be one click too, with the de-provisioning executed automatically and reversibly if it turns out to be wrong.

The joiner, mover, leaver gap is where the real risk lives

Certification campaigns are a periodic backstop. The continuous control is lifecycle, and movers are the weak point in nearly every organisation. Leavers get attention because HR (Human Resources) triggers a termination and someone disables accounts. Movers accumulate: each transfer adds the new team's access and rarely removes the old, so a person who has been at the company eleven years and moved four times holds the union of every role they have ever needed.

Build the mover event explicitly. When the HR system reports a department, manager or job code change, generate a review of that person's existing access against their new position, routed to the new manager with the old manager copied, with a deadline and an escalation. This is a smaller piece of engineering than a campaign engine and it prevents more accumulation than any quarterly review does.

Handle the systems outside your identity provider with the same seriousness. Every application that a person could have access to needs to be in the leaver checklist, including the ones with local accounts, and the system should track which of those have confirmed removal rather than assuming it. Orphaned accounts with no matching active employee should be detected continuously and surfaced, not discovered during an annual review.

Connectors are the budget, so plan them deliberately

Modern applications supporting SCIM or a decent API are quick. The rest fall into a few patterns and each has a known cost shape. Database backed applications where entitlements live in tables can be read directly with a read only account, which is fast but requires the vendor to tell you the schema and requires you to handle their upgrades. Vendor hosted systems with only a user interface need either a scheduled export the vendor can produce or, as a last resort, automated interaction with the interface, which is fragile and needs an owner. Mainframe and terminal systems usually have a reporting path that an administrator has been running manually for years, and turning that into a scheduled feed is often the cheapest win available.

Where no automated path exists, do not pretend otherwise. Build an attested manual feed: the application owner uploads a signed extract on a schedule, the system records who provided it and when, and it ages visibly if it is not refreshed. That is honest, it is auditable, and it beats a connector that silently returns stale data.

What it costs and how long it takes

From the projects Digital Heroes has delivered, a first release covering the identity and entitlement data model, HR feed integration, connectors for your top applications by risk, the campaign engine and revocation workflow runs $100,000 to $200,000 and ships in 14 to 20 weeks. The full build adding the long tail of connectors, segregation of duties policy, mover and leaver automation, usage data collection, privileged access handling and audit evidence generation runs $280,000 to $650,000 phased over 9 to 18 months.

What drives cost up: the number of applications and how hostile each one is to integration, which is by far the dominant factor. Segregation of duties policy, because defining the rules is a business exercise involving finance and internal audit rather than an engineering task. Usage data collection, which multiplies the integration work per application. Regulatory evidence requirements. And organisational complexity, since a group with multiple legal entities and different approval hierarchies per entity is a materially different build from a single company.

What keeps it down: rank applications by risk and integrate the top ten properly rather than forty superficially. A campaign covering your ten most sensitive systems with meaningful descriptions and usage data is worth more than one covering everything with role codes nobody understands.

When to buy instead

If your estate is essentially Microsoft or Okta with modern applications, buy the native governance product. The identity data is already in place and you will be running real access reviews in weeks rather than months. Anyone who tells you to build in that situation is selling you a project.

If you have a large but conventional application estate with good connector coverage, evaluate SailPoint or Saviynt properly. Their campaign engines and role mining are mature and rebuilding them is not a good use of money.

Build when a large share of your risk sits in applications with no standard connector, when your approval hierarchy crosses legal entities or works differently by business unit, when segregation of duties rules are specific to your own process design, or when you have licensed a governance product and are still running the campaigns that matter in spreadsheets. The last one is the clearest signal, and it is more common than vendors would like.

How to choose a developer

Ask them to describe integrating your three worst applications by name. If the answer is generic, they have not done this. Ask specifically what they do when an application has no API and no export capability, and expect the attested manual feed rather than a promise.

Ask how they will make entitlements understandable to a reviewer, and listen for a process to capture and maintain descriptions from application owners rather than a database column. The column is easy. The process is the work.

Ask how revocation actually executes, end to end, including what happens when de-provisioning fails silently on one system. An access review that produces revocation decisions nobody carries out is worse than no review, because now there is documented evidence that you knew.

Ask how movers are handled, since that is where accumulation happens and where most implementations are thin.

Get code and infrastructure ownership in writing before kickoff. At Digital Heroes the client owns the code from the first commit. A system that holds the map of who can do what across your entire organisation should not be rented from a supplier you cannot replace.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. ITIF's 2025 report documents that SMEs operate at roughly 60% of large-firm productivity in advanced economies (citing McKinsey), that CRM platforms deliver a 25-40% improvement in customer retention and a 15-30% boost in sales, and that digital advertising returns about $8 in profit per dollar spent on Google Search and Ads. Source: Information Technology and Innovation Foundation (ITIF) (2025) →
  2. McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
  3. Only about 30% of digital transformations succeed at meeting their objectives, but getting six critical success factors in place (leadership commitment, talent, agile culture, progress monitoring, clear strategy, and a modernized platform) raises the odds of success from 30% to 80%. Source: Boston Consulting Group (BCG) (2020) →
  4. OECD research finds that digitalisation offers SMEs opportunities to improve performance, spur innovation, enhance productivity and compete more evenly with larger firms; it reports that increased use of online platforms produced significant multi-factor productivity gains in SME-heavy sectors such as hospitality and retail, while smaller firms lag in adoption due to skills, resource and financing gaps. Source: OECD (2021) →
Vikram R. · VP Engineering · Delhi

Vikram runs the engineering function at Digital Heroes, from how teams are structured to how code gets reviewed and released. He writes about the trade offs behind build decisions: what to buy, what to build, and where technical debt is worth taking on deliberately.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom identity governance software cost?
A first release with the identity and entitlement model, HR feed integration, connectors for your highest risk applications, the campaign engine and revocation workflow runs $100,000 to $200,000 over 14 to 20 weeks in Digital Heroes delivery experience. The full build with the long tail of connectors, segregation of duties policy, mover and leaver automation and usage data runs $280,000 to $650,000 over 9 to 18 months. Application count and integration hostility dominate the cost.
Should we buy SailPoint or Saviynt instead of building?
If your applications have good connector coverage and your approval structure is conventional, buy, because their campaign engines and role mining represent years of development you should not rebuild. The arithmetic changes when most of your risk sits in applications you would have to integrate manually anyway, since at that point a large licence is buying you a campaign engine while you fund the connectors regardless.
Why do managers approve everything in an access review?
Because they are asked a question they cannot answer. A row saying FIN_GL_JE_POST_ALL tells a manager nothing about what the permission does, who should hold it, or whether their report has used it. Reviews become meaningful when every entitlement carries a plain language description from its application owner, a risk rating, any segregation of duties conflicts, and a last used date.
How do you handle applications with no standard connector?
Take them in order of how hostile they are: database backed applications can be read directly with a read only account, vendor hosted systems can often produce a scheduled export, and mainframe or terminal systems usually have a report an administrator already runs manually. Where nothing automated exists, build an attested manual feed where the application owner uploads a signed extract on a schedule that visibly ages if it is not refreshed.
What is the biggest gap in most identity governance implementations?
Movers. Leavers get attention because HR triggers a termination, but internal transfers quietly add new access without removing the old, so a long tenured employee ends up holding the union of every role they have ever needed. Generating a targeted review when the HR system reports a department, manager or job code change is a small piece of engineering that prevents more accumulation than quarterly campaigns do.
Does adding last used dates really change reviewer behaviour?
Yes, more than any other single field in our experience. Approving access a person has not touched in a year feels materially different from approving access they used yesterday, and reviewers start revoking rather than rubber stamping. Usage data is harder to collect than entitlement data because it means pulling application logs or authentication events per system, which is why many implementations skip it and why campaigns stay theatre.
How do you make sure revoked access is actually removed?
Design revocation as the cheap path and then verify it. One click to revoke, automatic de-provisioning where a write path exists, a tracked task with an owner where it does not, and a confirmation step that checks the entitlement is gone on the next collection cycle. A review that produces decisions nobody executes is worse than no review, because it creates documented evidence that the organisation knew.
How long before we can run a credible access certification campaign?
Realistically 14 to 20 weeks to a first campaign covering your highest risk applications with meaningful descriptions, and that assumes application owners engage on describing their entitlements. That description work is the schedule risk, not the engineering. A campaign over ten sensitive systems with understandable entitlements is worth considerably more to an auditor than one over forty systems full of role codes.
Our estate is mostly Microsoft. Do we need a custom build?
Almost certainly not, and we would say so directly. Entra ID Governance covers access reviews, lifecycle workflows and entitlement management well when the identity data is already in the tenant, and you will be running real reviews in weeks. Revisit the question only if you acquire a business with a legacy estate, or if a specific regulated application sits outside the tenant and carries most of your risk.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
How do I vet a development agency for an internal tools project?
Ask to see two or three internal tools they have shipped and whether those clients still use them daily, because internal tools fail on adoption, not code quality. Good signs: they ask to see your current spreadsheet or process before quoting, they propose a phased build instead of one big launch, and they spell out who handles training and post-launch changes. Walk away from anyone who gives a fixed price before seeing your actual workflow, since internal tools live or die on process details.
How much does a custom internal tool cost to build?
Most custom internal tools cost $8,000 to $40,000 to build, based on Digital Heroes delivery data across 2,000+ client projects. A single-purpose tool like an approval dashboard or inventory tracker sits at the low end, while a multi-department platform with role-based access and several integrations pushes past $40,000. The three biggest cost drivers are the number of user roles, the number of systems the tool must connect to, and custom reporting requirements.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
How do I know when spreadsheets are no longer enough to run my operations?
Replace the spreadsheet once more than three people edit it, versions travel by email, or a single broken formula could cost real money. Other reliable signals: staff keep personal shadow copies, month-end reporting takes days of manual assembly, and nobody can say who changed a number or why. In Digital Heroes discovery calls the tipping point is almost always a specific expensive error, a mispriced quote, a missed order, or payroll built on a tab someone sorted wrong.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
Does it matter which tech stack the agency wants to use?
Yes, but not in the way most buyers expect: the goal is boring, popular technology such as React, Node.js or Python, and PostgreSQL, because any future team can maintain it and hiring a replacement developer takes days, not months. The red flag is an agency-proprietary framework or an unusual language, which welds you to that one vendor no matter what your contract says about code ownership. A useful test: could you find three freelancers fluent in this stack within a week? If not, push back.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?