Gartner® named a new identity category. Here's why I think it matters.
The Gartner August 2026 Innovation Insight introduces Identity Visibility and Intelligence Platforms (IVIP). Oleria CEO Jagadeesh Kunda on what the category means for CISOs.

Key Takeaways
- Gartner introduced the new Identity Visibility and Intelligence Platform (IVIP) category, with Oleria recognized as a Representative Provider.
- IVIP aims to unify fragmented identity data and provide Visibility, Intelligence, and Action (VIA) across the enterprise.
- The rise of AI agents, non-human identities, and disconnected systems is making traditional identity governance increasingly difficult.
- Identity leaders should evaluate whether their platforms can see all identity types, use real activity data to assess risk, and take action without additional integration projects.
This summary was created with AI and reviewed by an editor.
Ask AI to write a summary
Featured event: A CISO’s take
Join Jim Alkove and Ramy Houssaini to learn how forward-thinking security teams are addressing Enterprise AI Copilot risks.
Oleria named in the new Gartner® Identity Visibility and IntelligencePlatform (IVIP) category
On August 24, Gartner published an Innovation Insight introducing a new IAM category calledIdentity Visibility and Intelligence Platforms, or IVIP. Rebecca Archambault and Nathan Harris wrote it. Oleria is listed as one of the Representative Providers.
I want to explain why I think this is a bigger deal than most category launches, and whatI'd do about it if I were a CISO reading the research this week.
Why the category needed a name
Every identity team I talk to lives with the same gap. They have an IGA. They have a PAM. Theyhave SSO, several cloud IAMs, an ITDR tool, some ISPM tool that got bought lastyear, and a spreadsheet nobody wants to admit still runs the quarterly access review.
What they don't have is a straight answer to the one question that matters. Who has access to what, why do they have it, and is that acceptable right now?
The data is scattered across ten systems that were never designed to be read together. You can spend a decade adding tools to that pile and get further from the answer instead of closer. I've watched teams do it.

As we see it, the Gartner research puts a name on the layer that finally solves this. IVIP aggregates and normalizes identity, access, entitlement, and control dataacross the whole environment. Then it applies intelligence on top so you can act. Gartner uses a framing they call VIA: Visibility, Intelligence, Action.
Naming things matters. When a category has a name, buyers can budget for it, analysts canrank it, and boards can ask about it. Before this research, most of mycustomers had to invent their own vocabulary to justify the investment. Nowthey don't.
The claim I'd underline
The single sentence in the research I'd underline for any identity leader is this – “IVIP introduces a new evolution of IGA, which is expected to replace “light IGA.”. Gartner expects IVIP to replace what the market has been calling “light IGA.”
That is a market-defining statement. Light IGA has been the pragmatic answer for mid-market and cloud-first companies who looked at a full legacy IGA deployment, priced it out, and decided they'd rather live with the gap. IVIP changes the trade. You can get the visibility and the intelligence without signing up for the eighteen-month implementation.
If you're aCISO whose IGA project has been stalled or descoped, this is worth a conversation with your team.
Why this is a now problem
Three forces are making the identity problem harder faster than most teams are equipped for.
First, agenticAI. Every agent is an identity. Every MCP server is an identity. The identity population inside most enterprises has stopped being a headcount plus some service accounts and started being a live graph that changes hourly. Anyone who tells you their annual access review still works probably has not counted their agents.
Second, siloed data. The Gartner research is blunt about this. Resources that were never onboarded to IGA, applications that are still disconnected, cloud entitlements that live in the cloud provider's own console. You cannot govern what you cannot see.
Third, and this one is the finding I did not expect to see in a Gartner note but agree with completely: emotion-driven decisions. Identity investment often runs on intuition and vendor relationships rather than evidence. IVIP exists to put evidence back in the room.
A word on the M&A wave
We/I believe the research is honest about the market being in motion. There have been major acquisitions in this space over the last twelve months, and the platform vendors are all expanding their IVIP capabilities.
The Gartner guidance to buyers is sensible – “evaluate the IVIP capabilities available within your existing tooling (identity fabric) to determine if they can deliver sufficient visibility and intelligence.” Ask them what their real IVIP capabilities are today, not on the roadmap. Ask them what is committed and by when. Then decide whether to wait or move.
My own view, from having sat on both sides of this table, is that waiting is the more expensive option in most cases. The identity attack surface is compounding while roadmaps are being drafted. Every quarter you wait, the graph gets messier and the cleanup gets harder.
Where Oleria fits
Oleria is one of the Representative Providers Gartner includes in its Identity Visibility and Intelligence Platform (IVIP)research. We/I feel the mix of listed platform vendors highlights how important identity visibility has become to modern security programs.
In our/my view, what we've focused on at Oleria maps directly to the Gartner VIA framing.
On visibility, we unify human, nonhuman, and AI identities in one graph, along with their entitlements and resource-level access. On intelligence, we use actual activity to distinguish the access someone uses from the access they merely have. That distinction is where most of the risk lives. On action, we make revocation and least-privilege enforcement continuous instead of annual.
If you had told me five years ago that Gartner would publish a category research report that mapped this cleanly to what we were building, I would have taken the bet.
Three questions to bring to your next IAM vendor call
If you take one thing from the Gartner research and turn it into a conversation this quarter, make it these three questions. They work whether you're talking to an incumbent vendor or a new one.
• Does the platform see human, nonhuman, and AI identities in one place? If the answer is workforce-only, you're buying a 2022product for a 2026 problem.
• Does it use actual activity, or only entitlements, to score risk? The gap between the two is the difference between compliance theatre and a working security control.
• Can it act on what it finds without another integration project? Visibility that leads to a ticket in a queue is the trap Gartner is warning about.
Frequently asked questions
What is an Identity Visibility andIntelligence Platform (IVIP)?
IVIP has emerged as an essential, foundational technology that aggregates, normalizes, and analyzes identities, their access, policies and IAM control configurations across multiple domains (cloud, on-premises, and SaaS) and disparate systems.By delivering a unified view of identity posture and enabling a continuous risk-assessment process, IVIP platforms not only reveal under-the-hood gaps in access but also empower organizations to operationalize mitigation strategies. Gartner introduced the term in its August 2026 Innovation Insight authored by Rebecca Archambault and Nathan Harris.
How is IVIP different from IGA?
IGA focuses on provisioning workflows, access certifications, and lifecycle management. IVIP focuses on continuous visibility, intelligence, and action across the full identity graph, including identities and resources that were never onboarded toIGA. Gartner expects IVIP to replace what the market has been calling lightIGA.
How does IVIP relate to ISPM andITDR?
ISPM (Identity Security Posture Management) and ITDR (Identity Threat Detection and Response) rely on identity data and context to deliver security insights and threat detection. IVIP serves as the foundational identity data and intelligence layer that provides this context, powering ISPM, ITDR, IGA, AM,PAM, dashboards, and AI-driven identity use cases.
Who are the representative IVIP vendors named by Gartner?
The Gartner August 2026 Innovation Insight names fifteen Representative Providers:Andromeda Security, Authmind, Axiad, Axonius, Cisco, CrowdStrike, Elimity,Gurucul, Nexis, ObserveID, Oleria, Radiant Logic, ServiceNow (Veza),Silverfort, and Zluri. Gartner is clear that being listed is not an endorsement or ranking.
Why does agentic AI make IVIP more urgent?
Every AI agent and MCP server is an identity with access to systems and data. Traditional IAM tooling was built for a stable population of humans and service accounts.Agentic AI creates a fast-moving identity graph that changes hourly, and we believe the Gartner research is explicit that continuous, intelligent visibility into these identities is now essential.
Where does Oleria fit in the IVIP category?
Oleria is listed as one of the fifteen Representative IVIP Providers in the Gartner Innovation Insight. Oleria unifies human, nonhuman, and AI identities in a single access graph, uses actual activity to distinguish exploitable over-privilege from theoretical entitlement, and enforces least privilege continuously rather than annually.
Read the full Gartner research
The fullInnovation Insight is available as a complimentary download. It covers the conceptual model, the risks Gartner identifies for buyers, and the full recommendations for cybersecurity leaders.
Download Innovation Insight: IdentityVisibility and Intelligence Platforms
.webp)

%20(1).png)