Identity Governance and Access Certification: Why Do Managers Approve Everything They Cannot Understand?
Expect $100,000 to $200,000 for a first release in 14 to 20 weeks, and $280,000 to $650,000 phased over 9 to 18 months for a full identity governance build in our delivery experience. Building is justified when a meaningful share of your applications have no standard connector, when entitlement names are meaningless to the managers certifying them, and when your approval hierarchy and audit evidence needs do not fit a product's campaign model. It is not justified if your estate is essentially Microsoft or Okta with modern applications: Entra ID Governance or Okta Identity Governance will do this properly for far less than a build.
The quarterly ritual everybody knows is theatre
A compliance analyst exports entitlements from eleven systems, pivots them into spreadsheets by manager, and emails 340 of them. A manager in operations opens hers and finds 61 rows. One says FIN_GL_JE_POST_ALL. Another says SAP role Z_MM_INV_02. A third says database role rw_prod_billing. She has fourteen direct reports, a day job, and no basis whatsoever for judging whether any of these are appropriate. She selects all, clicks approve, and returns the spreadsheet in four minutes.
The campaign completes at 98 percent approval. The evidence pack goes to the auditor. Everyone involved knows the exercise proved nothing, and the reason is not laziness. It is that the manager was asked a question she was structurally unable to answer. Nobody told her that FIN_GL_JE_POST_ALL lets a person post journal entries without a second approver, that only four people in the company should hold it, or that her report last used it eleven months ago.
Meanwhile the actual risk is somewhere else entirely. A developer who moved to a different team in 2022 still holds production database access, because the move was a transfer rather than a leaver and no process covers transfers. A contractor's account in a legacy application that was never connected to the identity system is still live two years after the engagement ended, because the offboarding checklist covers the systems someone remembered in 2019.
What SailPoint, Saviynt and the platform vendors do well
These products exist because the problem is real, and where they fit they are a better buy than a build. SailPoint and Saviynt have deep connector libraries, mature campaign engines, role mining and policy models developed over many years. Omada and One Identity are strong in their segments. Microsoft Entra ID Governance and Okta Identity Governance are excellent value if your estate is largely within their ecosystem, because the identity data is already there and access reviews become a configuration exercise rather than a project.
Two things push organisations past them. The first is the long tail of applications. A bank or a hospital group runs a core system from the 1990s, a specialist clinical or trading application, several vendor hosted systems with no API, and a handful of tools where access is defined inside the application by a local administrator. None of these have a standard connector. Every governance product supports building custom connectors, and that is real engineering work you will do regardless of which licence you hold. The uncomfortable arithmetic is that if two thirds of your risk sits in applications you must integrate manually anyway, a large licence buys you the campaign engine and not much else.
The second is entitlement semantics. A connector can extract that a user holds a role called Z_MM_INV_02. Nothing extracts what that role permits, who should hold it, or whether it combines with another role to break a segregation of duties rule. That knowledge lives with application owners, and building the process to capture and maintain it is the actual project. Products give you fields to store it in. They do not give you the descriptions, and campaigns run on undescribed entitlements are the rubber stamp you already have.
Make the reviewer's question answerable
The design principle worth building around is that a reviewer must be able to decide from what is on screen, without asking anyone. That means every entitlement presented in a campaign carries a plain language description written by its application owner and reviewed on a cycle, a risk rating, whether it is privileged, and any segregation of duties conflicts it participates in.
Then add usage. Last used date changes reviewer behaviour more than any other single field, because approving access a person has not touched in a year feels different from approving access they used yesterday. Usage data is harder to get than entitlement data, since it means pulling application logs or authentication events, and it is worth the effort. Add peer comparison where it is meaningful: this person holds three entitlements that none of their fourteen colleagues in the same role hold. That is the outlier a reviewer can act on. Finally, make revocation the cheap path. If approving is one click and revoking triggers an email thread, you have designed for approval. Revocation should be one click too, with the de-provisioning executed automatically and reversibly if it turns out to be wrong.
The joiner, mover, leaver gap is where the real risk lives
Certification campaigns are a periodic backstop. The continuous control is lifecycle, and movers are the weak point in nearly every organisation. Leavers get attention because HR (Human Resources) triggers a termination and someone disables accounts. Movers accumulate: each transfer adds the new team's access and rarely removes the old, so a person who has been at the company eleven years and moved four times holds the union of every role they have ever needed.
Build the mover event explicitly. When the HR system reports a department, manager or job code change, generate a review of that person's existing access against their new position, routed to the new manager with the old manager copied, with a deadline and an escalation. This is a smaller piece of engineering than a campaign engine and it prevents more accumulation than any quarterly review does.
Handle the systems outside your identity provider with the same seriousness. Every application that a person could have access to needs to be in the leaver checklist, including the ones with local accounts, and the system should track which of those have confirmed removal rather than assuming it. Orphaned accounts with no matching active employee should be detected continuously and surfaced, not discovered during an annual review.
Connectors are the budget, so plan them deliberately
Modern applications supporting SCIM or a decent API are quick. The rest fall into a few patterns and each has a known cost shape. Database backed applications where entitlements live in tables can be read directly with a read only account, which is fast but requires the vendor to tell you the schema and requires you to handle their upgrades. Vendor hosted systems with only a user interface need either a scheduled export the vendor can produce or, as a last resort, automated interaction with the interface, which is fragile and needs an owner. Mainframe and terminal systems usually have a reporting path that an administrator has been running manually for years, and turning that into a scheduled feed is often the cheapest win available.
Where no automated path exists, do not pretend otherwise. Build an attested manual feed: the application owner uploads a signed extract on a schedule, the system records who provided it and when, and it ages visibly if it is not refreshed. That is honest, it is auditable, and it beats a connector that silently returns stale data.
What it costs and how long it takes
From the projects Digital Heroes has delivered, a first release covering the identity and entitlement data model, HR feed integration, connectors for your top applications by risk, the campaign engine and revocation workflow runs $100,000 to $200,000 and ships in 14 to 20 weeks. The full build adding the long tail of connectors, segregation of duties policy, mover and leaver automation, usage data collection, privileged access handling and audit evidence generation runs $280,000 to $650,000 phased over 9 to 18 months.
What drives cost up: the number of applications and how hostile each one is to integration, which is by far the dominant factor. Segregation of duties policy, because defining the rules is a business exercise involving finance and internal audit rather than an engineering task. Usage data collection, which multiplies the integration work per application. Regulatory evidence requirements. And organisational complexity, since a group with multiple legal entities and different approval hierarchies per entity is a materially different build from a single company.
What keeps it down: rank applications by risk and integrate the top ten properly rather than forty superficially. A campaign covering your ten most sensitive systems with meaningful descriptions and usage data is worth more than one covering everything with role codes nobody understands.
When to buy instead
If your estate is essentially Microsoft or Okta with modern applications, buy the native governance product. The identity data is already in place and you will be running real access reviews in weeks rather than months. Anyone who tells you to build in that situation is selling you a project.
If you have a large but conventional application estate with good connector coverage, evaluate SailPoint or Saviynt properly. Their campaign engines and role mining are mature and rebuilding them is not a good use of money.
Build when a large share of your risk sits in applications with no standard connector, when your approval hierarchy crosses legal entities or works differently by business unit, when segregation of duties rules are specific to your own process design, or when you have licensed a governance product and are still running the campaigns that matter in spreadsheets. The last one is the clearest signal, and it is more common than vendors would like.
How to choose a developer
Ask them to describe integrating your three worst applications by name. If the answer is generic, they have not done this. Ask specifically what they do when an application has no API and no export capability, and expect the attested manual feed rather than a promise.
Ask how they will make entitlements understandable to a reviewer, and listen for a process to capture and maintain descriptions from application owners rather than a database column. The column is easy. The process is the work.
Ask how revocation actually executes, end to end, including what happens when de-provisioning fails silently on one system. An access review that produces revocation decisions nobody carries out is worse than no review, because now there is documented evidence that you knew.
Ask how movers are handled, since that is where accumulation happens and where most implementations are thin.
Get code and infrastructure ownership in writing before kickoff. At Digital Heroes the client owns the code from the first commit. A system that holds the map of who can do what across your entire organisation should not be rented from a supplier you cannot replace.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- ITIF's 2025 report documents that SMEs operate at roughly 60% of large-firm productivity in advanced economies (citing McKinsey), that CRM platforms deliver a 25-40% improvement in customer retention and a 15-30% boost in sales, and that digital advertising returns about $8 in profit per dollar spent on Google Search and Ads. Source: Information Technology and Innovation Foundation (ITIF) (2025) →
- McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
- Only about 30% of digital transformations succeed at meeting their objectives, but getting six critical success factors in place (leadership commitment, talent, agile culture, progress monitoring, clear strategy, and a modernized platform) raises the odds of success from 30% to 80%. Source: Boston Consulting Group (BCG) (2020) →
- OECD research finds that digitalisation offers SMEs opportunities to improve performance, spur innovation, enhance productivity and compete more evenly with larger firms; it reports that increased use of online platforms produced significant multi-factor productivity gains in SME-heavy sectors such as hospitality and retail, while smaller firms lag in adoption due to skills, resource and financing gaps. Source: OECD (2021) →
Vikram runs the engineering function at Digital Heroes, from how teams are structured to how code gets reviewed and released. He writes about the trade offs behind build decisions: what to buy, what to build, and where technical debt is worth taking on deliberately.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does custom identity governance software cost?
Should we buy SailPoint or Saviynt instead of building?
Why do managers approve everything in an access review?
How do you handle applications with no standard connector?
What is the biggest gap in most identity governance implementations?
Does adding last used dates really change reviewer behaviour?
How do you make sure revoked access is actually removed?
How long before we can run a credible access certification campaign?
Our estate is mostly Microsoft. Do we need a custom build?
How do I calculate whether custom software will pay for itself?
How many SaaS seats do we need before building custom becomes cheaper?
Can we migrate years of data out of our current system into new custom software?
How do I vet a development agency for an internal tools project?
How much does a custom internal tool cost to build?
How long does it take to build a custom web or mobile app from scratch?
How do I know when spreadsheets are no longer enough to run my operations?
Can I build my product on a no-code tool like Bubble instead of hiring developers?
Does it matter which tech stack the agency wants to use?
Who can build a custom internal tools system?
Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other internal tools companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.