What you are evaluating
Map which SKU does single sign-on, customer identity, identity governance, or privileged identity before an evaluation. This is a fabric for hybrid IBM, mainframe, and regulated estates, not a single greenfield software-as-a-service identity provider.
A useful evaluation context
This can be evaluated by a hybrid IBM or mainframe estate that needs a fabric across workforce, customer, governance, and privileged identity rather than a greenfield-only identity provider.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Workforce and customer identity features include multifactor authentication, orchestration, consent, and directory services.
- Identity governance and privileged identity sit in the same brand family and must be selected as explicit modules.
- Application Gateway fronts legacy applications so they can consume modern authentication without a full rewrite.
Where it fits in the work
- List the Verify SKUs on the proposed bill of materials and mark each as workforce, customer, governance, privileged, or gateway.
- In a lab, connect one legacy application through Application Gateway and one modern application through federation.
- Run a synthetic joiner through the licensed governance or directory module, then revoke access and confirm both applications refuse the next session.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an isolated Verify lab, authenticate a synthetic user to one modern application and one gateway-fronted legacy application, then disable the user in the licensed identity module.
Evidence to look for
Both applications reject the next sign-in after disablement, and the audit trail shows which SKU enforced the revocation.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which Verify SKU in the quote performs single sign-on, which performs identity governance, and which performs privileged identity?
- Does Application Gateway in the lab actually authenticate the legacy application you must keep, or only a sample?
- For a government SKU, what is the current authorization package and data-residency boundary?