Back to Insights
Guide

The SailPoint Horizons Model, Explained

By Vidyaa Ganesh · Published

When a vendor publishes a maturity model, the reasonable first question is why a company selling identity security software would want to be honest about how few of its customers have advanced identity programs. SailPoint's answer is a research report, not a rubric: The Horizons of Identity Security is now in its third annual edition, built on a survey of 375 IAM decision-makers across the Americas, Europe, and Asia, conducted in June 2025. That is real sample size behind real questions, which is more than most maturity frameworks can say. It is also, unavoidably, a vendor-run study. Both things are true, and a useful reading of the report holds them at the same time.

This article covers what the Horizons model is, what its research gives you that an analyst rubric cannot, where a vendor-funded study reasonably stops, and how its five horizons relate to a measurable, deterministic scale.

What the Model Is

SailPoint groups organizations into five horizons of identity maturity, numbered 1 through 5, based on capability across four dimensions: strategy, technology, operating model, and talent. That is a program-level lens, closer in spirit to Gartner's maturity model than to a control-by-control audit. The report is explicit about what placement in a horizon requires: to be counted in one horizon, SailPoint states, “customer capabilities need to cover most environments and identities,” not just exist in a pilot or a flagship business unit. That is a coverage bar, and it is a reasonable one. A program that automated provisioning for one division does not get credit for automating provisioning.

In broad strokes, the horizons run from foundational to strategic. Horizon 1 organizations are still building a centralized identity platform and basic governance, with structured application onboarding as the near-term task. Horizon 2 organizations have deployed identity tooling but still automate provisioning and certification workflows one system at a time rather than consistently. Horizon 3 marks a real transition: identity operations move from static, rule-based controls to contextual, real-time decisions. Horizons 4 and 5, updated in the 2025-2026 edition to include AI agent governance and machine identity security as explicit thresholds, describe organizations running automated identity operations at scale and treating identity as infrastructure for AI systems rather than a compliance function bolted onto them.

What It Is Good For

The report's central value is that it is empirical where most maturity content is not. A 375-respondent survey, run annually for three years, produces a population distribution that an analyst rubric or a consultant scorecard cannot: SailPoint reports that 63% of organizations remain in horizons 1 and 2, relying on manual processes, while only 10% have reached horizons 4 or 5. That distribution is directly comparable to other independent research. The IDSA's 2024 survey of 521 security professionals found only 8% at the highest maturity level on its own scale. Different instruments, similar shape: a large majority of organizations cluster in the early-to-mid range, and very few reach the top.

The report is also unusually candid for vendor research. The 2025-2026 edition notes that some organizations moved backward in maturity year over year, a finding that does nothing for SailPoint's sales narrative and would be easy to omit. It also surveys what actually blocks progress rather than only what predicts spend: only 25% of respondents said their organization treats identity as a strategic business enabler, while the majority still describe it as a security control or a compliance checkbox. A maturity report willing to publish its own uncomfortable numbers, on the same population it is trying to sell to, is doing something more useful than a marketing deck.

And unlike Gartner's program maturity model, the Horizons report is free. The executive summary and the full report are downloadable without a subscription, which matters for a framework that wants to function as a shared vocabulary. A model that cannot be read cannot be checked.

Where It Stops in Practice

Four limits are worth naming plainly, not because the research is bad, but because knowing what a source cannot tell you is how you use it correctly.

It is vendor-run. SailPoint sells identity governance software. Its report's headline claims, including that identity security delivers a higher return than other security domains and that mature organizations see double-digit ROI multiples, are the kind of finding a vendor has every incentive to produce. That does not make the numbers false. It does mean they deserve the same scrutiny you would apply to any study where the sponsor benefits from the conclusion, and it is why the report is more useful for its maturity distribution and horizon definitions than for its ROI arithmetic.

Placement is self-reported. Respondents describe their own program; nothing in the methodology verifies the claim against deployed systems. Self-report surveys reliably skew optimistic, which is one reason a program that assesses itself at Horizon 3 is worth checking against evidence before it becomes the number in a board deck.

No control-level granularity. Four dimensions and five horizons tell you roughly where a program sits. They do not tell you which of the underlying capabilities, privileged access, joiner-mover-leaver automation, session recording, is the one holding the program back. That is the same gap the Gartner model has, and for the same reason: a program-level rubric is not built to produce a punch list. Knowing you are in Horizon 2 tells you the general shape of the work ahead. It does not tell you whether to fund privileged access automation or workforce authentication first, and those are different budget conversations.

No gating on foundational controls. The coverage requirement within a horizon is real, but it applies within that horizon's own capability set. Nothing in the model stops an organization with strong operating-model and talent scores from landing in a mid horizon while a genuinely foundational control, workforce MFA, an inventory of privileged accounts, sits well behind. A model built around identity as a strategic platform is answering a different question than a model built to catch that specific failure mode.

Relating Horizons to a Measurable Scale

Unlike Gartner's five-stage rubric, SailPoint's horizons do not correspond level-for-level to a staged capability model, and it would be a disservice to the research to force one. A horizon blends strategy, technology, operating model, and talent into a single placement, so two organizations in the same horizon can differ substantially in raw control maturity while matching on ambition and organizational buy-in. The honest comparison is directional, not a crosswalk table: an organization in Horizons 1 to 2 is very likely early-stage on a control-level scale as well, and an organization in Horizons 4 to 5 is very likely well advanced. The middle is where the two kinds of model diverge, because strategic intent and control coverage do not always move together.

That is precisely the gap a control-level assessment fills. AXIS scores 37 questions across nine domains, applies a cap when foundational controls are missing regardless of how strong the surrounding program looks, and computes the result the same way for every organization, so the output does not depend on how optimistic the respondent felt that week. It reads out in a five-level scale built to cross-reference against the frameworks practitioners already use, with a domain-by-domain breakdown and an industry benchmark behind it. For what those five levels look like in day-to-day practice, see The IAM Maturity Model, Explained, and for how SailPoint's findings compare with Gartner's analyst rubric, see the Gartner explainer.

Common Questions

Is the Horizons report free? Yes. Unlike Gartner's program maturity model, SailPoint's report and executive summary are available for download without a subscription, though SailPoint collects contact information for the download.

Which horizon are most organizations in? In the 2025-2026 edition, 63% of surveyed organizations sit in Horizons 1 or 2, and only 10% have reached Horizons 4 or 5. That is consistent with what other independent maturity research finds using different instruments and different samples.

Can I self-assess against the Horizons model? The report describes what distinguishes each horizon, but it does not publish a scored questionnaire the way a control-level assessment does. A practical path is to read the horizon descriptions for the strategic and organizational picture, then run a deterministic, control-level assessment for the number you can defend and track over time.

Should I trust the ROI figures? Treat them the way you would any finding published by a vendor with a stake in the answer: plausible directionally, not a number to put in a business case without independent verification. The maturity distribution and horizon definitions rest on the survey itself and are more directly checkable.

AXIS is free to use. Get a deterministic, control-level maturity score with a domain breakdown and an industry benchmark behind it.

Start Assessment

Sources

  • SailPoint, “The Horizons of Identity Security, 2025-2026” (375 IAM decision-makers, surveyed June 2025)
  • SailPoint, “Executive Summary: Horizons of Identity Security 2025-2026”
  • SailPoint, “SailPoint's 2025 Horizons of Identity Report Reveals Identity Security Is the Highest-ROI Security Investment” (press release, September 3, 2025)
  • IDSA, “2024 Trends in Securing Digital Identities” (521 professionals)
  • Gartner, “IAM Program Maturity Model” (September 2025, subscription required)

SailPoint and SailPoint Horizons are trademarks of SailPoint Technologies. AXIS is not affiliated with or endorsed by SailPoint. References to the Horizons model are descriptive.