SailPoint, Inc. (SAIL) Earnings Call Transcript & Summary
September 15, 2026
Earnings Call Speaker Segments
Robbie Owens
analystAll right. Good morning. I'm Rob Owens with Piper, and I manage our technology practice and cover cybersecurity and infrastructure software. Pleased to be joined on stage with Mark McClain from SailPoint, and we'll just dive right in. Okay. I'll leave a little time if there's questions from the audience as well.
Robbie Owens
analystSo interesting news over the weekend relative to the slowing and better understanding of AI and what these things can do. And as maybe the -- I can't call you the little boy, but the one who cried wolf, if you will, to say, hey, guys, we're going to have to manage this stuff. There's just -- there's a lot of proof points that point towards SailPoint's value proposition. So I don't want to say take us through the last 72 hours because this has been ongoing since the advent of AI. But maybe you can articulate your view on what just happened over the weekend and how it speaks to where the need that SailPoint serves in the marketplace.
Mark McClain
executiveYes. I think if it wasn't already apparent, I think it's become more apparent that at least part of the risk of what's happening in the world with AI and agentic is the fact that these are a flavor of identity, these nonhuman identities. And now what we've seen is, particularly in the Hugging Face incident, the idea that they are somewhat not only just autonomous but incapable of self-regulating what should or shouldn't happen in a given context. And so what people are recognizing is -- I'm feeling tremendous pressure that we serve mid- to large enterprises, I think most folks know. I'm feeling tremendous pressure from my Board, from my senior leadership to implement AI technologies to become more efficient, more effective, more productive all across my organization with these tools. And I'm now once again presented with a very clear and present danger that I don't know that I have the right tools and technologies in place to help guard and protect myself from the way these things seem to go off the rails. And so I think it's that some people I'm not sure in my 40 years in tech, I've ever seen something quite so much a foot on the gas, foot on the brake scenario where people are feeling tremendous pressure to go faster and adopt this tech and feeling tremendous pressure to keep their foot pretty hard on the brake until they feel that they can safely navigate these technologies. And we just got reminded again that we need tools that apparently we don't have yet to keep these things in check.
Robbie Owens
analystYes. Can you talk about SailPoint's right to win? You've got an enterprise customer base, and you definitely provided a much needed capability around governance [indiscernible] by everybody to the new governance world. Maybe you can help us connect the divide.
Mark McClain
executiveYes. And we've now decided to kind of articulate what we think are 3 core pillars of what's needed in this new world. We talk about you have to discover, govern and protect. One of the things that wasn't...
Robbie Owens
analystWhat's the hardest part of that?
Mark McClain
executiveProtect.
Robbie Owens
analystBecause everybody has a discovery. You go to RSA, it was all about discovery. You can't protect what you don't know, right? But it was more so an understanding of what you don't know than it was protecting, in my opinion.
Mark McClain
executive100%, Rob. I think what you found was everybody saying, in the realm of human identities, you might not have had perfect visibility, but you had a pretty darn good handle. You theoretically knew everybody you were paying on your payroll, and you hopefully had a pretty good handle on all the nonemployee humans that were engaging with your technology. Could be contractors, could be business supply chain, distribution chain. You theoretically understood all the humans that were interacting with your systems. What's very clear today is companies do not have a great handle on the nonhuman identities that have access to their systems. And this goes back, by the way, not just to the agentic revolution we're in now, but even for a number of years, we've had other flavors of nonhuman identity, software bots, intelligent devices. Even service accounts that could take action or at least provide access to systems. And very rarely were those things tracked, cataloged, classified. And so this discovery is step one. That's what I was talking about. You can't secure or govern what you can't see. So you have to find it, understand it, classify it, would be the term. Then you have to governance. So now let's share what is governance, right? In our mind, governance has always been, do you have the ability to determine what policy you want to enforce in your environment? Can you describe it and postulate in a way that the technology can implement that policy and you can hold people to that policy. Ultimately, that's what all the policy IGA has been about, which was mostly life cycle and compliance certifications. But it was, do you know what should be true in the environment? And can you validate that what you expect to be true is actually true, right? That was really what governance has been all about. But now we've got this whole thing about protect, which is if I can find it and classify it, if I can set up policies to determine what should be true and compare my actual to my desired state, the third really hard problem is and when can I detect that something has gone awry or is going awry and what do I do about it? And I think the reason you said why -- what's the hardest, because that third pillar is absolutely not going to be solved by any one security vendor. I think there's a little bit of a dialogue in the investor community of who's going to win, who's going to win in this agentic age, who's going to win? The answer is multiple winners, I believe. Like you will need the collaboration of all the various lenses we bring to security. You need to understand what's happening on the network. You need to understand what's happening on the device. You need to see what you can see traversing the cloud, but you absolutely need to understand from an identity lens, what these things are and what they're supposed to be doing and whether they're doing what you expect. And that's the lens that's the newest because you're the longest-term security analyst as far as I know these days. You've seen all these various evolutions of security technologies. Identity is a relatively recent focusing lens on security, and we're just now beginning to...
Robbie Owens
analystYou used to be an infrastructure play. That's identity.
Mark McClain
executiveYou had to have it. You didn't know who had access to your systems, but it wasn't really that security oriented. Now we're learning it has to be secured.
Robbie Owens
analystSo the devil's advocate asks, why does a legacy governance player have a right to win? What have they done to change their platform? And how is this a modern approach? Where you're seeing other people, I would argue do governance lite. They're buying lightweight cloud type of governance solutions. So why does the big behemoth? What have you done?
Mark McClain
executive[indiscernible] this is new for me.
Robbie Owens
analystWhere have you changed architecture? And why do you have a right to win moving forward if you think about where the world is going?
Mark McClain
executiveWell, number one, even though we are 20 years old, we resist the term legacy. That's reserved for the really legacy people like IBM and Oracle. But at the end of the day, I think our right to win comes from a couple of things. One is when we did our re-IPO last year, we kind of reminded people that if you understand the identity landscape, you probably had a taxonomy of 3 core areas. You had access, think SSO and MFA, Okta being the dominant player there. You had privilege, PAM, CyberArk being the dominant player there. But what you might not have thought about is what was sort of their purview or their approach. The nature of access and SSO is think very wide and very shallow, right? Okta and players like that, Ping and even Microsoft are very good at covering the landscape of all of the identities you cared about. This is human identities, but very shallow, meaning they got you logged in. They didn't really do much after that. They didn't really know what you could do after you logged in. They just said, I'm going to make sure you're really Rob, and I'm going to make sure you can log into the stuff you're supposed to and not log into the stuff you're not supposed to. But a lot of security happens after log in. We've often drawn this metaphor of a security guard in a skyscraper in New York, right? You go to a New York banker meeting and you check in at the ground floor and you have your little license and you say, hi, I'm Mark, here's my picture. I'm really Mark. You walk around that security guard's desk to the elevator and go up there. They have no idea where you go, what you do. Did you try to break into something? Did you try to get into the executive suite where you're not supposed to be? That security guard's job was just to make sure you entered the building and you were really who you said you were. That is pretty analogous to SSO, MFA. I know who you are, I let you in. I don't know what you're doing after that. So there's a lot of security risk that's unmanaged with just that shallow wide piece. Privilege was the opposite, right? It's very deep, but limited control over limited applications. After Nikesh and Palo bought CyberArk, he came out and said, look, we typically, with that tooling, manage 3% to 5% of the identities in a total enterprise, right? We're managing the super important critical access of database guys and systems administrators and SAP administrators. Yes, super important. You don't touch 97% of the identities in the enterprise, and that was the human identity. So the challenge these other identity landscape players have is they're coming from either a shallow wide or a narrow deep offering. SailPoint's nature has always been deep and wide. That's who we are. It's what we do. We had to understand all the identities you cared about and very deeply understand what they could do. What's new for us, Rob, and you know this, is protection has to be very real time. Well, that's new for SailPoint. We had to learn to say we're going to have to get into these real-time authorization decisions because I think 2 words we're going to hear a lot in the world of AI and agentic agents is context and intent. What we just saw with Hugging Face was these things went way out of bounds on both the context they were supposed to stay in and the intent of what they were supposed to do. That's why in a world of agentic, we're going to have to understand context and intent and have the power to say, I see something that's either about to or actually going off the rails, I got to stop it right now. And that's real time. And that's new for SailPoint. We will have the ability to either do that for things that are happening or talk to the right associated security tool to go make that stop. Sometimes we won't have the control to shut off a network segment or a device, but CrowdStrike or Palo or Zscaler or somebody will have that power, but we'll have to be collaborative. What they won't have, though, is the identity context. That's what we'll have.
Robbie Owens
analystI think it's important to understand relative to the SailPoint story, if we can call it the go-private period, if you will, there was a rearchitecting during that period, right? Single data layer, ability to kind of build applications on top of that. So maybe you can speak to where the platform is now? Because I think some people still remember the struggle between SaaS versus on-prem and parity of function and things of that nature.
Mark McClain
executiveYes. We started 20 years ago as an on-prem software business. And I remind people that we were on-prem because that's what the market told us they would buy. It's hard to remember that 20 years ago, people didn't put important things in the cloud because the cloud wasn't secure enough. And then about 8 years into AWS and Azure and Google Cloud, people started to go, oh, wait, I think that's more secure than my own data center. I'm going to put the most secure things in the cloud. Well, that's when we shifted into a SaaS offering, and it took a while, like you said, to close some of those gaps functionally from our very robust on-prem product. But we did that a while ago. And now what we've been focused on is these modern capabilities that are needed to manage this incredibly complex landscape. And back to that right to win question, Rob, a little bit. Here's what I tell people about the craziness about, oh, you can just hire a bunch of kids out of Stanford and they can go build any tool. Really, like I couldn't hire a bunch of 23-year-olds and say, let's go take on Workday because I don't understand HCM and they don't understand HCM. It takes more than just tooling to know how to go win in an enterprise market space. You have to know the nuances of those issues. You have to understand why buyers buy what they buy, what issues are important, what aren't as important. We spent 20 years getting best in the world at that for identities. And now we're applying that depth of knowledge, but like the latest, greatest Silicon Valley start-ups, we're applying all the AI technologies to do that faster, better and more sophisticated ways than we ever have. So I'd like to say, if you want to bet, do you want to bet on the brand-new kid without domain knowledge who's got AI tools or the guy who really understands the problem and is using those same AI tools to deliver a solution, your choice.
Robbie Owens
analystAnd you put up a very good quarter recently, 25% ARR growth, which is one of the faster, I think, in cyber right now, but not showing the acceleration that the Street wants. Now you've always been an optimistic but conservative guy, at least over our relationship...
Mark McClain
executiveI'll take that, moniker.
Robbie Owens
analystOkay. And you're talking about acceleration a couple of years out relative to the business. So maybe square things for investors in terms of where you're at now, where you're seeing the opportunity and why gunslinger Mark McClain is willing to sign off -- you are from Texas, willing to sign off on acceleration.
Mark McClain
executiveWell, look, at the end of the day, we tried to walk a very fine line this last quarter for those of you who are paying close attention. And we said, we're going to give you as much qualitative enthusiasm as we can and quantitatively kind of stay in the guardrails for the moment for 2 primary reasons. Like you've heard many vendors say for many years, we can get excited about pipeline. Pipeline is great. But pipeline is pipeline until it converts into contracts. We are seeing significant accelerating growth of our pipeline with what's happening in the world. But as of the end of Q2, we couldn't point to a rearview mirror set of proof around these are the ways these deals get done. Here's the sales cycles, here's the competitive dynamics in those deals because as you know, Rob, everybody in the security space and a few folks from outside the security space are saying, agentic is my bailiwick. I'm going to solve your agentic problem, right? It is everywhere right now. And so I think what the market is looking for is who am I going to talk to, engage with. And I think very rapidly, they'll get beyond the brochures and the websites to let me see your products. Let me see what you can actually do. Let's get in here in a POC with my data, my identities and let's see who can do what. And we are inviting our competitors into that environment. Like let's get in front of the customer with our stuff, and let's quit jabbering in press releases and see who can do what. And so what we saw this last quarter was tremendous momentum for getting invited into those dialogues, engaging in those POCs, delivering what we can and talking about what's around the corner, which will be showing up here probably next month in some of the announcements we'll make at our Navigate conference. So we are very much seeing that momentum build. We just couldn't, in good confidence, say, I will absolutely commit to you, here's my acceleration in the future because I haven't seen proof of it yet. But we laid as many seeds as we could out to tell people, we're seeing all the signs that, that could be coming, but we didn't choose to get in front of it with the numbers.
Robbie Owens
analystYes. And amidst all this changed market, it does feel like there's better visibility this time around with the story. So is that a function of the market? Is that a function of changes in go-to-market? Maybe help us understand.
Mark McClain
executiveA little of both. I think the market -- I've told people sometimes history -- the great thing about being old is you've seen some stuff.
Robbie Owens
analystThe bad thing is you forget a lot of it.
Mark McClain
executiveYes, you forget most of it and you're really tired. But -- I'm not really tired. But at the end of the day, though, I've told people, if it's helpful, go back and look at a lot of technology inflections and just watch the subsequent lagging curve of security products. When did antivirus start as a big industry? Oh, not long after PCs proliferated. When did cloud security get big? Oh, not long after SaaS and cloud started to be a thing. It turns out that we deliver inflected technologies, and I don't think we've ever seen something inflect as fast as AI. And then people start to see the risks and the concerns and the vulnerabilities and the threats and then they go, oh, I need products that help me address those risks. That's what we're seeing now. I think we're seeing enough of the AI rollout, and it's still not wildly rolling out. As people know, they're still kind of foot on the gas and the brake, like I said. But people are saying, I see enough of this happening. I better start looking at the tools I need to secure and control it. And wow, did Hugging Face put a big exclamation point on, you do not have what you need to control this stuff today. And so I think -- and by the way, I would differentiate for all of you for a moment, Hugging Face moment from Mythos moment. Mythos moment says, what happens when bad actors get a hold of technology and use it to try to attack you. Hugging Face moment says, even if there's no bad actor, this stuff can go off the rails and create damage in ways you may not expect. So you better have good controls against threats from the outside and things that can go awry, so to speak, from the inside if you don't have controls over what these things are doing. So we do, Rob, see this inflection of the security interest that I think is slightly lagging the accelerant we're seeing in the market around AI in the enterprise. And now we're going to see people start to show up and say, here's what I can do to solve that problem. And I think it's kind of game on.
Robbie Owens
analystAre you seeing that AI accelerant slow whatsoever in terms of the agentic deployment opportunities just so folks can get their bearings...
Mark McClain
executiveI think Hugging Face might cause people to tap the brakes a little bit, honestly. I mean, it's so recent, who knows, a little bit. But I think it may have kind of spooked people a little bit. But by the same token, I mean, these same companies, these same C-suite leaders in these big businesses are getting so much pressure from their boards, from everywhere to go get at the -- at least not -- I want to say at the forefront, just not be lagging in their adoption of AI because everybody's conclusion is if you don't lean in on AI and your competitor does, you're probably going to lose to that competitor. So you can't get real far behind here or you're going to have a problem. So I think people are feeling a need to kind of stay up with it vis-a-vis their industry. It does vary by industry, clearly. But vis-a-vis their industry, how do I stay leaning forward enough to not get left behind. So while these security threats have shown up and kind of spooked people, I don't think we're fundamentally seeing people back off. And look, the whole recent -- should we slow down the AI revolution? I think what you got to know is what happened with Hugging Face happened with older tools. Like you could stop AI development today and nobody is going to. But you could stop it today and those threats are still very real.
Robbie Owens
analystAbsolutely. And your story is not void of AI and AI revenue?
Mark McClain
executiveCorrect.
Robbie Owens
analystYou've posted a nice $60 million, $70 million ARR relative to AI. Where are some of those targets? What's driving that now? And this is kind of before the agentic evolution.
Mark McClain
executiveYes. What we're saying, and this is a little counter to what you hear out in the market and also probably frustrating for you and the investment community, apologies for this, is that we aren't going to say, hey, here's our human identity line of revenue and here's our agentic identity line of revenue because now customers are just going to buy identity protection. And that's going to imply, do you understand the agents your humans are using? And do you understand the humans that can access your agents? We see no way to protect the enterprise treating these as independent control centers. And so our heritage of very deep controls over humans, we think, is a distinct advantage going into the agentic revolution because don't lose sight of the fact that the predominant use of agents for the foreseeable future is very directly tied to humans, think copilots, think agents in your SaaS deployments from Workday, Salesforce. And then people say, oh, but what about these swarms and digital workforces of agents doing all this work? I'm like, well, that doesn't come out of thin air, right? Somebody in the organization says, let's go revamp our loan origination process using digital workforce. Great. The guy in charge of loan origination is defining what that looks like, what policies apply, what data is needed, what protections are needed. Like even a digital workforce going on to solve a problem is doing so at the direction of humans. Another way to flip this around if you're confused is there will be no lawsuits against agents. Some human will ultimately be accountable in every enterprise. And you've already seen the EU, as you would expect, stepping up with the earliest signs of compliance and regulatory frameworks for managing agents. We're going to do that here in the U.S. We're going to see people say, you got to prove to me what agents you're using, what access they have, who authorized them to do what they're doing. These are enterprises. They are regulated. They have to stay with the rules for the most part. So all that is coming just like it did for humans, and we're going to have these security risks. So we see kind of these core drivers being the same as they were for humans, which is you have to be regulated and compliant and you have to actually securely protect your enterprise. Both of these things are going to apply to agents.
Robbie Owens
analystAnd those words around cyber going platform. And Mark, the first time around when we met, you made a conscious decision to get out of the single sign-on market -- anti-platform. Is that still the right decision? And as we look at this identity security play, is it going to be solved by a group of companies? Or is it going to be more singular in focus?
Mark McClain
executiveI think the term platform is very, very broadly about this moment. I think at a minimum, you got to look at 2 core definitions. One is you just amalgamated a group of products under a brand that can be sold together. Procurement people like that version. I have fewer vendors, I get consolidated buying power, et cetera. The other that's a platform play is true technology integration. And I think for customers, that tends to matter the most. Like I want these things I'm buying to work together. And of course, if you build them from the ground up, that's way more true than if you buy them and stitch them together after the fact. Well, I think where we're headed is there's going to be, I think, a few, but maybe not very many platforms centered around identity. The biggest security players today, our favorite platform players, CrowdStrike and Palo would have you believe, oh, identity is just going to be part of our platform. I'm like, well, the thing that Palo bought, all due respect, Udi is a friend, great guy, you know Udi for years. Cyber did a subset of identity. They didn't do an awful lot of what the rest of us have done in identity, and that didn't magically change after Palo Alto bought them. And Cyber -- sorry, Crowd bought an even smaller early-stage player called SGNL, great little company, super interesting technology, also didn't really cover most of what a lot of us already did in the industry. So they've either got to get busy building something that took us 20 years to get really good at. I don't think they're going to close that gap very quickly with development or they've got to find somebody to buy. And if you track our industry, there's not a lot of things to go buy. So we think the platform players are going to come at it just like Microsoft has so far, which is, look, I can give you all this stuff together. And I remind people that in the enterprise buying segment, they would like to get it from one vendor as long as it actually solves the problem. Microsoft's offering today does not solve the problem, which is why they've effectively been a nonfactor in enterprise IGA. They just don't win there. So -- and Okta's IGA, by the way, same story. Okta has now had an IGA offering for many years. It is not making a dent in the enterprise segment of IGA. So at the end of the day, there has to be an offering that actually addresses the problem. And as we've been discussing, the problem just got a lot harder with agentic than it was with just human. So we're pretty comfortable that there's going to be kind of an identity-centric center of gravity that's needed in this emerging era, and we're as well positioned as anyone to have a pole position there.
Robbie Owens
analystYes. Final question for you. Can you talk about new customer acquisition from the standpoint that SailPoint has always been -- you've always been very well-regulated industry and with larger companies. But I think -- in a lot of ways, that's beginning to change just as this identity game is beginning to change. So maybe you can highlight your new customer acquisition strategies, what you guys are doing to take advantage of it.
Mark McClain
executiveYes. We still feel like our bread and butter is going to continue to be mid- to large enterprises. And the way we count that, by the way, we're less than 20% penetrated. If we count all the 3,000 to, call it, 4,000 or 5,000 employees and up, we are 15%, 17% penetrated in those businesses around the world. There's a lot of new accounts to go get in what we consider our sweet spot -- sorry. At the mid- to lower end of that enterprise segment, we will never invest in SMB in the foreseeable future, sub 1,000. That's just not where we're going to play. In that 1,000 to 5,000 range, we plan to go after that quite a bit more aggressively because with this agentic framework we announced recently -- Agentic Fabric, excuse me, that does allow us to go into those smaller shops to go, look, if you just want to attack this agentic thing and you're probably dealing with it even in a smaller shop, here's an offering. Don't have to buy off on the whole soup to nuts IGA deal. And we think that's going to open up through MSSPs, through lower-end channel partners, and we're actively working on that right now.
Robbie Owens
analystAll right. Well, I think that's all we have time for.
Mark McClain
executiveWe ripped through a lot of stuff in 24.5 minutes. You did it for us.
Robbie Owens
analystThank you, guys.
Mark McClain
executiveAll right. Thank you all for being here. Appreciate it.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete SailPoint, Inc. transcript — plus 255,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to SailPoint, Inc. earnings transcripts and 255,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.