- Large enterprises, with a particular emphasis on Fortune 500 organizations.
- Concentration in financial services — firms managing access for employees, customers, and third parties at scale.
- Also relevant to other regulated industries, notably healthcare, where access control and compliance are critical.
- Broader enterprise buyers who need to secure access across applications, APIs, data platforms, and agentic AI systems.
- Reference customers named in "about us" (Cisco, FM Global, Wells Fargo, Accenture) suggest a customer base of large, complex, likely globally-operating organizations rather than small or mid-market businesses.
- No explicit geographic restriction is stated; the profile points to large-scale, global enterprise operations rather than a specific region.
- Highly risk-aware: motivated by the cost and frequency of identity-related breaches (cited stats include a 20% YoY increase in identity-related breaches, 93% of breaches involving identity data, 70% due to unauthorized access, and an average $76M cost per unauthorized-access breach).
- Frustrated by fragmentation — native, app-by-app access controls that make consistent security practice difficult to manage and maintain.
- Values centralization and consistency: a single platform and one policy language spanning applications, APIs, data platforms, AI systems, and infrastructure, rather than managing access piecemeal per system.
- Prioritizes control paired with visibility — wants enforcement distributed across environments but decisions centrally managed and recorded in business-readable language (via the Smart Decision Engine), supporting audit and governance needs.
- Looks for standardization and speed to value through out-of-the-box Authorizers™ and integrations rather than building policy enforcement from scratch.
- Increasingly concerned with governing not just human identities but AI agents — wants defined boundaries for what agents can access, do, and expose.
- Operates environments spanning multiple applications, APIs, microservices, and data platforms — implying an existing stack of SaaS applications, API gateways, and microservices architecture.
- Actively deploying or piloting agentic AI systems, suggesting emerging investment in AI agent frameworks that require new access-control boundaries.
- Likely already has some native, app-level access control mechanisms in place per system (called out as fragmented in the pain points), rather than a single unified authorization layer.
- Given the financial-services and regulated-industry focus, likely operates within complex, security- and compliance-conscious IT environments with many disparate identity and access touchpoints.
- No key competitors have been provided, so no inference can be made about specific competing tools or vendors currently in use.