Skip to content
§
§ · build vs buy

Build vs Buy Identity Governance and Access Certification Software

Buy if your estate sits inside Microsoft or Okta with modern applications, because native governance turns access reviews into configuration and you will be running real campaigns in weeks.

Internal Tools Development software overview illustration for Identity Governance AND Access Build vs Buy Guide.
The short answer

Buy if your estate sits inside Microsoft or Okta with modern applications, because native governance turns access reviews into configuration and you will be running real campaigns in weeks. Build when most of your risk lives in applications with no standard connector, since you fund that integration either way: a first release runs $100,000 to $200,000 across fourteen to twenty weeks.

The buy answer is correct more often than anyone selling a build will say

Identity governance is a mature product category and the incumbents earned their position. SailPoint and Saviynt carry deep connector libraries, mature campaign engines, role mining and policy models developed over many years. Omada and One Identity are strong in their segments. Microsoft Entra ID Governance and Okta Identity Governance represent unusually good value when your identity data already sits in the tenant, because access reviews, lifecycle workflows and entitlement management become a configuration exercise rather than a project.

So the first recommendation for a great many organisations is straightforward. If your applications are largely software as a service with modern identity integration, and your directory is Entra or Okta, buy the native product. You will be running credible reviews inside a quarter. Anyone advising a custom build in that situation is selling you a project rather than solving your problem, and we say so on discovery calls regularly.

Buy as well if your estate is large but conventional. A few hundred applications with good connector coverage is exactly what SailPoint and Saviynt were designed for, and rebuilding a campaign engine and role mining is not a defensible use of money. The correct move there is a proper evaluation, a realistic proof of value on your five worst applications, and a hard look at how many of them the connector library actually covers before contract signature rather than after.

One more buy signal: if you have no internal identity owner. These systems require somebody who understands your access model and can chase application owners for entitlement descriptions. A packaged product with vendor services attached survives that gap. A custom build does not.

The connector arithmetic that flips the decision

Two things push organisations past the packaged products, and the first is the long tail. A bank or a hospital group runs a core system written in the 1990s, a specialist clinical or trading application, several vendor hosted systems with no application programming interface, and a handful of tools where access is defined inside the application by a local administrator. None of these has a standard connector.

Every governance product supports custom connectors, and building them is real engineering work you will perform regardless of which licence you hold. That produces uncomfortable arithmetic. If two thirds of your genuine risk sits in applications you must integrate manually anyway, a large licence is buying you a campaign engine and not much else, while you fund the hard part twice.

The second driver is entitlement semantics. A connector can extract that a user holds a role called Z_MM_INV_02. Nothing extracts what that role permits, who should hold it, or whether it combines with another role to break a segregation of duties rule. That knowledge lives with application owners, and capturing and maintaining it is the actual project. Products give you fields to store descriptions in. They do not give you descriptions, and a campaign run over undescribed entitlements is the rubber stamp you already have.

The third condition is structural. A group with multiple legal entities, different approval hierarchies per entity, and segregation of duties rules derived from its own process design is materially harder to fit into a product campaign model than a single company. The clearest signal of all, and it is common: you have already licensed a governance product and the campaigns that actually matter are still being run in spreadsheets.

What the two paths cost

Price the buy side by identity, not by employee, because that is how these products bill and the difference surprises people. Licensed identities typically include contractors, service accounts and non human identities, so the count that appears on the invoice is often well above your headcount. Ask for the counting definition in writing during evaluation, then add implementation services, connector development for anything outside the standard library, and annual support.

The build side prices in two bands. A first release covering the identity and entitlement data model, human resources (HR) feed integration, connectors for your highest risk applications, the campaign engine and the revocation workflow runs $100,000 to $200,000 and ships in fourteen to twenty weeks. The full build adding the long tail of connectors, segregation of duties policy, mover and leaver automation, usage data collection, privileged access handling and audit evidence generation runs $280,000 to $650,000 phased over nine to eighteen months.

The dominant cost driver on either path is the same: how many applications you integrate and how hostile each one is. Segregation of duties policy adds cost because defining the rules is a business exercise involving finance and internal audit rather than an engineering task. Usage data collection multiplies integration work per application. Organisational complexity across legal entities changes the shape of the whole build.

What holds cost down is discipline about scope. Rank applications by risk and integrate ten properly rather than forty superficially. A campaign covering your ten most sensitive systems with meaningful descriptions and last used dates is worth considerably more to an auditor than one covering everything with role codes nobody understands. Add fifteen to twenty percent of build cost annually for support and continued connector work.

Costs that land after the licence is signed

Four items. The first is entitlement description work, and it is the schedule risk on every project of this type. Application owners have to write plain language descriptions of what each entitlement permits, and they have day jobs. No product and no developer can do this for you. Plan for it as a named workstream with an executive sponsor, because a campaign engine delivered on time into an organisation that never wrote the descriptions produces the same theatre at a higher cost.

The second is usage data. Last used dates change reviewer behaviour more than any other single field, because approving access a person has not touched in a year feels different from approving access they used yesterday. Collecting it means pulling application logs or authentication events per system, which is a second integration on top of the entitlement extraction. Most implementations skip it, and that is precisely why their campaigns stay meaningless.

The third is revocation execution. Deciding to remove access is easy. Removing it across a system with no write path requires a tracked task with an owner and a confirmation check on the next collection cycle. A review that produces decisions nobody carries out is worse than no review, because it creates documented evidence that the organisation knew.

The fourth is the audit calendar. Your certification window, whether that is a financial controls audit or an information security certification cycle, sets a date you do not control. Working backwards from it usually shows that the description work has to start before the software does, which reverses the sequence most organisations assume.

A ten application test

Rank your applications by the damage a wrongly held entitlement could do, take the top ten, and check three things for each.

Does it have a standard connector in the products you are evaluating? Not a claimed integration, an actual supported connector. Count how many of the ten do. If seven or more are covered, buy. If four or fewer are covered, you are funding custom integration whichever way you go and the licence stops carrying its weight.

Can the application owner describe each sensitive entitlement in one sentence today? If not, note that the description work is your critical path regardless of the tooling decision.

Is there any way to observe usage, meaning logs or authentication events showing when an entitlement was last exercised? Applications where usage is unobtainable will always produce weaker reviews, and knowing that up front changes how you prioritise.

Then two organisational questions. Does your approval hierarchy differ by legal entity or business unit? And are your segregation of duties rules specific to processes you designed rather than standard patterns? Yes to both, with poor connector coverage, is a clear build case. Good connector coverage with a conventional hierarchy is a clear buy.

Sequencing, and how to pick a builder

If you build, start with the data model and the human resources feed, then the top ten applications by risk, then the campaign engine and revocation. Movers come next and they deserve their place, because internal transfers quietly add access without removing the old, and a targeted review triggered by a department, manager or job code change prevents more accumulation than quarterly campaigns do. It is also a smaller piece of engineering than the campaign engine.

When interviewing, ask them to describe integrating your three worst applications by name. A generic answer means they have not done this. Ask specifically what happens when an application has no interface and no export capability, and expect an attested manual feed, meaning the application owner uploads a signed extract on a schedule and the record ages visibly if it is not refreshed, rather than a promise of automation.

Ask how they will make entitlements understandable to a reviewer, and listen for a process to capture and maintain descriptions from application owners rather than a database column. The column is trivial. The process is the work. Ask how revocation executes end to end including silent de-provisioning failures. Ask how movers are handled, since that is where most implementations are thin.

Get code and infrastructure ownership in writing before kickoff. A system holding the map of who can do what across your organisation should not be rented from a supplier you cannot replace. Digital Heroes works from a written product requirements document before any code, so the entitlement model, campaign scope and revocation guarantees are agreed on paper with your internal audit function. The team is fifty plus people across more than 2,000 delivered projects, holds Fiverr Vetted Pro status, publishes to 2.5 million subscribers at Digital Marketing Heroes on YouTube, and contracts through an India LLP, a US LLC or a UK LTD so assignment happens under your own law.

If you want a second opinion before signing anything, Digital Heroes builds and runs its own products, so the people choosing your architecture live with those decisions on their own revenue. You can take that specification to any other firm on your shortlist.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  2. Technology 'Leaders' grow revenue at more than twice the rate of 'Laggards'; laggards surrendered 15% in foregone annual revenue in 2018 and stood to miss out on as much as 46% in revenue gains by 2023 if they did not change their enterprise technology approach. Based on a survey of more than 8,300 organizations across 20 industries and 20 countries. Source: Accenture (2019) →
  3. Independent reporting of Gartner's 2025 survey confirms 59% of finance leaders use AI, up from 37% in 2023, with error and anomaly detection (34%) and accounts payable automation (37%) among the leading use cases. Source: CPA Practice Advisor (reporting Gartner) (2025) →
  4. Per Sensor Tower's State of Mobile 2026, worldwide consumers spent about $85 billion on apps in 2025 (up 21% YoY), and for the first time non-game apps surpassed games in consumer spending; generative-AI in-app purchase revenue more than tripled to top $5 billion. Source: Sensor Tower (via TechCrunch) (2026) →
FAQ

Frequently asked questions

How much does custom identity governance software cost?

A first release with the identity and entitlement model, human resources feed integration, connectors for your highest risk applications, the campaign engine and revocation workflow runs $100,000 to $200,000 across fourteen to twenty weeks. The full build adding the long tail of connectors, segregation of duties policy, mover and leaver automation and usage data runs $280,000 to $650,000 over nine to eighteen months. Application count and integration difficulty dominate.

Should we buy SailPoint or Saviynt rather than build?

If your applications have good connector coverage and your approval structure is conventional, buy, because their campaign engines and role mining represent years of development nobody should rebuild. The arithmetic changes when most of your risk sits in applications you would integrate manually regardless, since at that point a large licence buys a campaign engine while you separately fund the connectors that carry the actual exposure.

How long until we can run a credible access certification campaign?

Realistically fourteen to twenty weeks to a first campaign over your highest risk applications, and that assumes application owners engage on describing their entitlements. That description work is the schedule risk, not the engineering, and it usually has to begin before the software does. Working backwards from your audit window normally shows the descriptions are the critical path rather than the campaign engine.

What do we do about applications with no standard connector?

Take them in order of difficulty. Database backed applications can often be read directly with a read only account. Vendor hosted systems can frequently produce a scheduled export. Mainframe and terminal systems usually have a report an administrator already runs by hand, and scheduling it is often the cheapest win available. Where nothing automated exists, use an attested manual feed with a signed extract that visibly ages if not refreshed.

Who should own this system internally once it is live?

Someone accountable for the access model, usually inside security or internal audit, with authority to chase application owners for entitlement descriptions and revocation confirmations. Budget fifteen to twenty percent of build cost annually for support and continued connector work. Organisations with no internal identity owner should buy a packaged product with vendor services attached, because a custom build assumes a person who keeps it honest.

Who builds custom identity governance and certification systems?

Identity specialist consultancies and custom development firms with enterprise integration experience. Digital Heroes suits groups that need the entitlement model, campaign scope and revocation guarantees agreed in writing with internal audit before code exists, and that need contracting and intellectual property assignment in their own jurisdiction through an India LLP, a US LLC or a UK LTD. More than 2,000 delivered projects and Fiverr Vetted Pro status back that.

What makes Digital Heroes different from a generic dev shop for this?

The refusal to treat entitlement descriptions as a database column. The product requirements document defines the process for capturing and refreshing descriptions from application owners, and the attested manual feed pattern for systems with no automation, because those two decisions determine whether campaigns mean anything. The client also owns the repository and infrastructure from the first commit, which matters for a system mapping who can do what across the organisation.

How do we verify a development partner is legitimate before paying?

Confirm the D-U-N-S registration matches the entity signing your contract, then read public Clutch and Trustpilot profiles for reviews describing comparable enterprise integration work rather than the average score. Ask which legal entity signs and under which jurisdiction, since that decides your recourse. Request a redacted prior agreement showing full intellectual property assignment, and require repository and cloud account access from week one.

What does it cost to keep custom software running after launch?

Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.

How much should a small business budget for its first custom app or website?

For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.

How do I calculate whether custom software will pay for itself?

Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.

Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?

Yes, and connecting your existing tools is one of the main reasons to build custom: mainstream platforms like QuickBooks, Stripe, Shopify, and Google Workspace all publish documented APIs. Budget 1 to 3 weeks of work per integration depending on API quality and how much data flows in both directions. Ask any vendor whether they have integrated with your specific tools before, because quirks like QuickBooks' OAuth token handling and API rate limits get learned on someone's project, and it should not be yours.

When does a company outgrow Airtable?

The usual breaking points are record limits, permissions, and automation complexity. Airtable's Team plan caps each base at 50,000 records and Business at 125,000, so operations logging thousands of rows a month hit the ceiling within a year or two. The other trigger Digital Heroes sees constantly is permissions: restricting who can view specific fields or records is clumsy below Airtable's Enterprise tier, which becomes a genuine problem once salaries, pricing, or client contracts live in the base.

Can we migrate years of data out of our current system into new custom software?

Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.

What does an internal tool cost for a small business with 20 to 50 employees?

Plan on $5,000 to $15,000 for a focused tool that replaces one painful spreadsheet workflow, such as job scheduling, quoting, or PTO tracking. In Digital Heroes projects at this size, the sweet spot is one core workflow, two or three user roles, and a single integration, usually QuickBooks or Google Workspace. Quotes far below $5,000 usually mean a template with your logo on it rather than software built around your process.

What should I prepare before contacting an agency about an internal tool?

Bring the spreadsheet or document you run the process on today, a list of everyone who touches the workflow and what each person does, and one sentence describing the outcome you want. You do not need wireframes or a technical spec; a 30-minute screen-share of the current process beats a 20-page requirements document. Decide your rough budget band and name a single internal decision-maker, because projects without one take noticeably longer in Digital Heroes experience.

How many developers does it take to build an internal tool?

Two to four people covers nearly every internal tool: one or two developers, a part-time designer, and a project manager who doubles as your single point of contact. Internal tools rarely need consumer-product polish, so a full-time dedicated designer is usually wasted budget. On Digital Heroes projects, a two-person core team handles the typical 4 to 8 week build, with a specialist pulled in briefly for a tricky integration or a security review.

How do I calculate the ROI of a custom internal tool?

Count hours first: multiply the weekly hours staff spend on the manual process by their loaded hourly cost, then add the cost of errors such as mispriced quotes or missed renewals. A tool saving a 10-person team 5 hours each per week recovers about 2,500 hours a year, which repays a $20,000 to $30,000 build well inside a year at typical wages. Most internal tools Digital Heroes delivers reach payback in 6 to 18 months, with quoting and billing tools at the fast end because they plug revenue leaks, not just time.

Can we start on Airtable or Retool now and move to custom software later?

Yes, and it is often the smartest sequence: run the workflow on Airtable or Retool for 6 to 12 months to learn what you actually need, then go custom once the process stabilizes. The no-code version becomes free requirements documentation, and its data exports cleanly into a custom database. The one risk is waiting too long, because teams stack automations and workarounds until migration becomes a project of its own, so set a concrete trigger in advance, such as hitting Airtable's 50,000-record Team plan cap.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply