They've already started our count. They have. All right. Good morning. I'm Rob Owens with Piper Sandler, and I manage our technology practice and cover cybersecurity infrastructure software. Pleased to be joined on stage with Mark McClain from SailPoint, and we'll just dive right in. Okay. Let's do it. I'll leave a little time if there's questions from the audience as well. Interesting news over the weekend relative to the slowing and better understanding of AI and what these things can do. And as maybe the, can't call you the little boy, but the one who cried wolf, if you will, to say, "Hey, guys, we're going to have to manage this stuff. It's our fairy tale. There's a lot of proof points that point towards SailPoint's value proposition. I don't want to say take us through the last 72 hours because this has been ongoing since the advent of AI, but maybe you can articulate your view on what just happened over the weekend and how it speaks to the need that SailPoint serves in the marketplace. Yeah, I think if it wasn't already apparent, I think it's become more apparent that at least part of the risk of what's happening in the world with AI and agentic is the fact that these are a flavor of identity, these non-human identities. And now what we've seen is, particularly in the Hugging Face incident, the idea that they are somewhat not only just autonomous, but incapable of self-regulating what should or shouldn't happen in a given context. And so what people are recognizing is I'm feeling tremendous pressure that we serve mid to large enterprises, and I think most folks know. I'm feeling tremendous pressure from my board, from my senior leadership to implement AI technologies to become more efficient, more effective, more productive all across my organization with these tools. I am now once again presented with the very clear and present danger that I do not know that I have the right tools and technologies in place to help guard and protect myself from the way these things can go off the rails. I think it is that, I am not sure in my 40 years in tech I have ever seen something quite so much a foot on the gas, foot on the brake scenario, where people are feeling tremendous pressure to go faster and adopt this tech, and feeling tremendous pressure to keep their foot pretty hard on the brake until they feel that they can safely navigate these technologies. We just got reminded again that we need tools that apparently we do not have yet to keep these things in check. Yeah. Can you talk about SailPoint's right to win? You have got an enterprise customer base. You definitely provided a much needed capability around governance. By everybody bringing to the new governance world. Yeah. Maybe you can help us connect the divide. Yeah, and we've now decided to articulate what we think are three core pillars of what's needed in this new world. We talk about you have to discover, govern and protect. One of the things that wasn't much— What's the hardest part of that, those three? Protect. Protect. Definitely. Because everybody has a discover. You go to RSA. Boom. It was all about discovery, right? There's so much noise. You can't protect what you don't know. Right. But it was more so an understanding of what you don't know than it was protecting, in my opinion. 100%, Rob. I think what you found was- Yeah, right. Everybody saying in the realm of human identities, you might not have had perfect visibility, but you had a pretty darn good handle. You theoretically knew everybody you were paying on your payroll, and you hopefully had a pretty good handle on all the non-employee humans that were engaging with your technology. Could be contractors, could be business supply chain, distribution chain. You theoretically understood all the humans that were interacting with your systems. What is very clear today is companies do not have a great handle on the non-human identities that have access to their systems. This goes back, by the way, not just to the agentic revolution we are in now, but even for a number of years we have had other flavors of non-human identities, software bots, intelligent devices, even service accounts that could take action or at least provide access to systems, and very rarely were those things tracked, cataloged, classified. This discovery is step 1. That is what everybody is talking about. You cannot secure or govern what you cannot see, so you have to find it, understand it, classify it, would be the term. Then you have to govern it. Now let us, what is, you asked me- Sure what is governance, right? In our minds, governance has always been, do you have the ability to determine what policy you want to enforce in your environment? Can you describe it and postulate in a way that the technology can implement that policy, and you can hold people to that policy? Ultimately, that is what all of the policy things IGA has been about, which was mostly life cycle and compliance certifications. It was, do you know what should be true in the environment, and can you validate that what you expect to be true is actually true, right? That was really what governance has been all about. Now we have got this whole thing about protect, which is if I can find it and classify it, if I can set up policies to determine what should be true and compare my actual to my desired state, the third really hard problem is, and when can I detect if something has gone awry or is going awry, and what do I do about it? I think the reason you said, what is the hardest? Because that third pillar is absolutely not going to be solved by any one security vendor. I think there is a little bit of a dialogue in the investor community of who is going to win in this agentic age. Who is going to win? The answer is multiple winners, I believe. You will need the collaboration of all the various lenses we bring to security. You need to understand what is happening on the network. You need to understand what is happening on the device. You need to see what you can see transversing the cloud, but you absolutely need to understand from an identity lens what these things are and what they are supposed to be doing, and whether they are doing what you expect. That is the lens that is the newest to the You are the longest-term security analyst as far as I know these days. You have seen all these various evolutions of security technologies. Identity is a relatively recent focusing lens on security. Yeah. We are just now beginning to understand it. It used to be an infrastructure play. That is right. Identity, far and away. You just had to have it. You needed to know who had access to your systems, but it wasn't really that security-oriented. Now we're learning it has to be security. The devil's advocate asks, why does a legacy governance player- have a right to win? What have they done to change their platform, and how is this a modern approach- where you're seeing other people, I would argue, do governance light? Yep. They are buying lightweight, cloud type of governance solutions. Yep. Why does the big behemoth? What have you done to change architecture? I have rarely been referred to as a behemoth, Rob. This is new for me. I am excited about that. Where have you changed architecture, and why do you have a right to win moving forward if you think about where the world is going? Well, number one, even though we are 20 years old, we resist the term legacy. That is reserved for the really legacy people like IBM and Oracle. At the end of the day, I think our right to win comes from a couple of things. One is when we did our re-IPO last year, we reminded people that if you understand the identity landscape, you probably had a taxonomy of three core areas. You had access, think SSO and MFA, Okta being the dominant player there. You had privilege, PAM, CyberArk being the dominant player there. But what you might not have thought about is what was their purview or their approach? The nature of access in SSO is, think, very wide and very shallow, right? Okta and players like that, Ping Identity and even Microsoft, are very good at covering the landscape of all of the identities you cared about, this is human identities, but very shallow, meaning they got you logged in. They did not really do much after that. They did not really know what you could do after you logged in. They just said, "I am going to make sure you are really Rob, and I am going to make sure you can log into the stuff you are supposed to and not log into the stuff you are not supposed to." But a lot of security happens after login. We have often drawn this metaphor of a security guard in a skyscraper in New York, right? You go to a New York banker meeting, and you check in at the ground floor, and you have your little license, and you say, "Hi, I am Mark. Here is my picture. I am really Mark." You walk around that security guard's desk to the elevator and go up there, they have no idea where you go, what you do. Did you try to break into something? Did you try to get into the executive suite where you are not supposed to be? That security guard's job was just to make sure you entered the building, and you were really who you said you were. That is pretty analogous to SSO MFA. I know who you are. I let you in. I do not know what you are doing after that. So there is a lot of security risk that is unmanaged with just that shallow, wide piece. Privilege was the opposite, right? It is very deep, but limited control over limited applications. After Nikesh and Palo Alto Networks bought CyberArk, he came out and said, "Look, we typically, with that tooling, manage 3%-5% of the identities in a typical enterprise. Right. We're managing the super important, critical access of database guys and systems administrators and SAP administrators. Yeah, super important. You don't touch 97% of the identities in the enterprise, and that was the human identity. The challenge these other identity landscape players have is they're coming from either a shallow-wide or a narrow-deep offering. SailPoint's nature has always been deep and wide. That's who we are. It's what we do. We had to understand all the identities you cared about and very deeply understand what they could do. What's new for us, Rob, and you know this, is protection has to be very real time. That's new for SailPoint. We had to learn to say, we're going to have to get into these real-time authorization decisions because I think two words we're going to hear a lot in the world of AI and agents is context and intent. What we just saw with Hugging Face was these things went way out of bounds on both the context they were supposed to stay in and the intent of what they were supposed to do. That's why in a world of agentic, we're going to have to understand context and intent and have the power to say, I see something that's either about to or actually going off the rails. I got to stop it right now. That's real time, and that's new for SailPoint. We will have the ability to either do that for things that are happening or talk to the right associated security tool to go make that stop. Sometimes we won't have the control to shut off a network segment or a device, but CrowdStrike or Palo or Zscaler or somebody will have that power, but we'll have to be collaborative. What they won't have, though, is the identity context. That's what we'll have. I think it's important to understand relative to the SailPoint story, if we can call it the go private period, if you will. There was a re-architecting during that period, right? Single data layer, ability to build applications on top of that. Yep. So maybe you can speak to where the platform is now because I think some people still remember the struggle between SaaS versus on-prem. Yeah and the parity of function and things of that nature. Yeah. We started 20 years ago as an on-prem software business, and I remind people that we were on-prem because that's what the market told us they would buy. It's hard to remember that 20 years ago, people didn't put important things in the cloud because the cloud wasn't secure enough. Then about eight years into AWS and Azure and Google Cloud, people started to go, "Oh, wait, I think that's more secure than my own data center. I'm going to put the most secure things in the cloud." Well, that's when we shifted into a SaaS offering, and it took a while, like you said, to close some of those gaps functionally from our very robust on-prem product. But we did that a while ago, and now what we've been focused on is these modern capabilities that are needed to manage this incredibly complex landscape. Back to that right to win question, Rob, a little bit. Here is what I tell people about the craziness about, oh, you can just hire a bunch of kids out of Stanford, and they can go build any tool. Really? I couldn't hire a bunch of 23-year-olds and say, "Let's go take on Workday," because I don't understand HCM, and they don't understand HCM. It takes more than just tooling to know how to go win in an enterprise market space. You have to know the nuances of those issues. You have to understand why buyers buy what they buy, what issues are important, what aren't as important. We spent 20 years getting best in the world at that for identities, and now we're applying that depth of knowledge. Like the latest, greatest Silicon Valley startups, we're applying all the AI technologies to do that faster, better, in more sophisticated ways than we ever have. I like to say, if you want to bet, do you want to bet on the brand-new kid without domain knowledge who's got AI tools, or the guy who really understands the problem and is using those same AI tools to deliver a solution? Your choice. You put up a very good quarter recently, 25% ARR growth, which is one of the faster, I think, in cyber right now, but not showing the acceleration that the Street wants. Yeah. You've always been an optimistic but conservative guy, at least over our relationship. I'll take that moniker. Okay. You're talking about acceleration a couple of years out relative to the business. Yeah. So maybe square things for investors. Yeah In terms of where you're at now, where you're seeing the opportunity, and why gunslinger Mark McClain is willing to sign off on. I am from Texas. Watch out. You are from Texas. Yeah. Willing to sign off on acceleration. Well, look, at the end of the day, we tried to walk a very fine line this last quarter, for those of you who are paying close attention, and we said we are going to give you as much qualitative enthusiasm as we can and quantitatively kind of stay in the guardrails for the moment for two primary reasons. Like you have heard many vendors say for many years, we can get excited about pipeline. Pipeline is great, but pipeline is pipeline until it converts into contracts. We are seeing significant accelerating growth of our pipeline with what is happening in the world. But as of the end of Q2, we couldn't point to a rearview mirror set of proof around these are the ways these deals get done, here is the sales cycles, here is the competitive dynamics in those deals. Because as you know, Rob, everybody in the security space and a few folks from outside the security space are saying, "Agentic is my bailiwick. I am going to solve your agentic problem." It is everywhere right now. I think what the market is looking for is who am I going to talk to, engage with? I think very rapidly they will get beyond the brochures and the websites to let me see your products, let me see what you can actually do. Let us get in here in a POC with my data, my identities, and let us see who can do what. We are inviting our competitors into that environment. Let us get in front of the customer with our stuff and let us quit jabbering in press releases and see who can do what. What we saw this last quarter was tremendous momentum for getting invited into those dialogues, engaging in those POCs, delivering what we can, and talking about what is around the corner, which we will be showing up here probably next month in some of the announcements we will make at our Navigate conference. We are very much seeing that momentum build. We just could not, in good confidence, say, "I will absolutely commit to you, here is my acceleration in the future," because I have not seen proof of it yet. We laid as many seeds as we could out to tell people we are seeing all the signs that that could be coming, but we did not choose to get in front of it with the numbers. Yeah. Amidst all this change, Mark, it does feel like there is better visibility this time around. Yes with the story. Yes, there is Is that a function of the market? Is that a function of changes in go to market? Maybe help us understand. Little of both. I think the market. I have told people sometimes history, the great thing about being old is you have seen some stuff. The bad thing is you forget a lot of it. Yeah, you forget most of it and you are really tired. I am not really tired. At the end of the day though, I have told people, if it is helpful, go back and look at a lot of technology inflections and just watch the subsequent lagging curve of security products. When did antivirus start as a big industry? Not long after PCs proliferated. When did cloud security get big? Not long after SaaS and cloud started to be a thing. It turns out that we deliver inflective technologies, and I do not think we have ever seen something inflect as fast as AI. Then people start to see the risks and the concerns and the vulnerabilities and the threats, and then they go, "Oh, I need products that help me address those risks." That is what we are seeing now. I think we are seeing enough of the AI rollout, and it is still not wildly rolling out, as people know. They are still kind of foot on the gas and the brake, like I said, but people are saying, "I see enough of this happening, I better start looking at the tools I need to secure and control it." Wow, did Hugging Face put a big exclamation point on you do not have what you need to control this stuff today. Yeah. I would differentiate for all of you for a moment, Hugging Face moment from Mythos moment. Mythos moment says what happens when bad actors get ahold of technology and use it to try to attack you? Hugging Face moment says even if there is no bad actor, this stuff can go off the rails and create damage in ways you may not expect. So you better have good controls against threats from the outside and things that can go awry, so to speak, from the inside if you do not have controls over what these things are doing. We do, Rob, see this inflection of the security interest that I think is slightly lagging the accelerant we are seeing in the market around AI in the enterprise, and now we are going to see people start to show up and say, "Here is what I can do to solve that problem." I think it is kind of game on. Are you seeing that AI accelerant slow whatsoever in terms of the agentic deployment opportunities? Just so folks can get their reins around it. I think Hugging Face might cause people to tap the brakes a little bit, honestly. It is so recent, who knows? A little bit. But I think it may have kind of spooked people a little bit. By the same token, these same companies, these same C-suite leaders in these big businesses are getting so much pressure from their boards, from everywhere to go get at the forefront, at least not I do not want to say the forefront, just not be lagging in their adoption of AI. Because everybody's conclusion is if you do not lean in on AI and your competitor does, you are probably going to lose to that competitor. Yeah. You cannot get real far behind here or you are going to have a problem. I think people are feeling a need to kind of stay up with it vis-à-vis their industry. It does vary by industry, clearly, but vis-à-vis their industry, how do I stay leaning forward enough to not get left behind? While these security threats have shown up and kind of spooked people, I do not think we are fundamentally seeing people back off. Look, the whole recent should we slow down the AI revolution, I think what you got to know is what happened with Hugging Face happened with older tools. You could stop AI development today, and nobody is going to, but you could stop it today, and those threats are still very real. Absolutely. Your story is not void of AI and AI revenue. Correct. You've posted a nice $60 million-$70 million ARR relative to AI. Where are some of those targets? What's driving that now? This is kind of before the agentic evolution. Yeah. What we're seeing, this is a little counter to what you hear out in the market, also probably frustrating for you in the investment community, apologies for this, is that we aren't going to say, "Hey, here's our human identity line of revenue, and here's our agentic identity line of revenue. Sure. Because now customers are just going to buy identity protection, that's going to imply, do you understand the agents your humans are using, and do you understand the humans that can access your agents? We see no way to protect the enterprise treating these as independent control centers. Our heritage of very deep controls over humans, we think is a distinct advantage going into the agentic revolution. Because don't lose sight of the fact that the predominant use of agents for the foreseeable future is very directly tied to humans. Think copilots, think agents in your SaaS deployments from Workday; Salesforce. People say, "Oh, but what about these swarms and digital workforces of agents doing all this work?" I'm like, well, that doesn't come out of thin air, right? Somebody in the organization says, "Let's go revamp our loan origination process using digital workforce." Great. The guy in charge of loan origination is defining what that looks like, what policies apply, what data is needed, what protections are needed. Even a digital workforce going off to solve a problem is doing so at the direction of humans. Another way to flip this around if you are confused is, there will be no lawsuits against agents. Some human will ultimately be accountable in every enterprise, and you have already seen the EU, as you would expect, stepping up with the earliest signs of compliance and regulatory frameworks for managing agents. We are going to do that here in the U.S. We are going to see people say, "You got to prove to me what agents you are using, what access they have, who authorized them to do what they are doing." These are enterprises. They are regulated. They have to stay with the rules for the most part. All that is coming, just like it did for humans, and we are going to have these security risks. We see these core drivers being the same as they were for humans, which is you have to be regulated and compliant, and you have to actually securely protect your enterprise. Both of these things are going to apply to agents. Buzzwords around cyber deal with platform now. Mark, the first time around when we met, you made a conscious decision to get out of the single sign-on market. We anti-platformed. You anti-platformed. Is that still the right decision? Yeah Identity security play, is it going to be solved by a group of companies or is it going to be more singular in focus? I think the term platform is very, very broadly bandied about at the moment. I think at a minimum, you got to look at two core definitions. One is you've just amalgamated a group of products under a brand that can be sold together. Procurement people like that version. I have fewer vendors, I get consolidated buying power, et cetera. The other that's a platform play is true technology integration. I think for customers that tends to matter the most, like, I want these things I'm buying to work together. Of course, if you build them from the ground up, that's way more true than if you buy them and stitch them together after the fact. I think where we're headed is there's going to be, I think, a few, but maybe not very many platforms centered around identity. The biggest security players today, our favorite platform players, CrowdStrike and Palo, would have you believe, "Oh, identity's just going to be part of our platform." I'm like, well, the thing that Palo bought, all due respect, Udi's a friend, great guy, you've known Udi for years. CyberArk did a subset of identity. They didn't do an awful lot of what the rest of us have done in identity, and that didn't magically change after Palo Alto bought them. CrowdStrike brought an even smaller early-stage player called SGNL. Great little company, super interesting technology. Also didn't really cover most of what a lot of us already did in the industry. They've either got to get busy building something that took us 20 years to get really good at. I don't think they're going to close that gap very quickly with development, or they've got to find somebody to buy. As you know, if you track our industry, there's not a lot of things to go buy. So we think the platform players are going to come at it, just like Microsoft has so far, which is, look, I can give you all this stuff together. I remind people that in the enterprise buying segment, they would like to get it from one vendor, as long as it actually solves the problem. Microsoft's offering today does not solve the problem, which is why they've effectively been a non-factor in enterprise IGA. They just don't win there. Okta's IGA, by the way, same story. Okta's now had an IGA offering for many years. It is not making a dent in the enterprise segment of IGA. So at the end of the day, there has to be an offering that actually addresses the problem. As we've been discussing, the problem just got a lot harder with agentic than it was with just humans. So we're pretty comfortable that there's going to be kind of an identity centric center of gravity that's needed in this emerging era, and we're as well positioned as anyone to have a pole position there. Yeah. Final question for you. Can you talk about new customer acquisition from the standpoint that SailPoint's always been, you've always done very well in regulated industry- Yep and with larger companies. But I think in a lot of ways that's beginning to change just as this identity game is beginning to change. So maybe you can highlight your new customer acquisition strategies, what you guys are doing to take advantage of it. Yeah. We still feel like our bread and butter is going to continue to be mid to large enterprises. The way we count that, by the way, we're less than 20% penetrated. If we count all the 3 to, call it 4,000 or 5,000 employees and up, we are 15%, 17% penetrated in those businesses around the world. There's a lot of new accounts to go get in what we would consider our sweet spot. Oops, mic, sorry. At the mid to lower end of that enterprise segment, we will never mess with SMB in the foreseeable future, sub-thousand. That's just not where we're going to play. In that 1,000- 5,000 range, we plan to go after that quite a bit more aggressively because with this SailPoint Agentic Fabric we announced recently, SailPoint Agentic Fabric, excuse me, that does allow us to go into those smaller shops to go, look, if you just want to attack this agentic thing, and you're probably dealing with it even in a smaller shop, here's an offering. Don't have to buy off on the whole soup to nuts IGA deal. We think that's going to open up through MSSPs, through lower end channel partners, and we're actively working on that right now. All right. Well, I think that's all we have time for. We ripped through a lot of stuff in 24 and a half minutes. We did. Good for us. Thank you guys. All right. Thank you all for being here. Appreciate it.
Loading workspace