Last reviewed: 28 September 2026. Vendor facts in this guide were checked against C1's own pricing, hosting, support and release-notes pages on that date.
C1, the identity governance platform formerly called ConductorOne, can serve a mid-market company, but it is built and priced for larger identity programs. This review is for IT and security leads at companies of 50 to 500 employees who have C1 on a shortlist for access reviews, provisioning or AI agent governance, and want to know what it costs, what it covers and what to compare it with.
C1 quotes every deal from a scoped program of managed identities or from usage, and it publishes no list price. Its entry support tier, which C1 lists for companies under 500 employees, commits to a first response on critical issues within one business day, during US Eastern hours. Its pricing page lists no module for SaaS contracts, renewals or spend. Mid-market teams that want automated access reviews and licence control from one European vendor should compare C1 with Corma, and Lumos, Zluri and Torii are the other alternatives covered below.
If you manage identity for several thousand employees with a dedicated identity team, C1 was designed for your situation and the mid-market trade-offs in this guide will weigh less.
Key takeaways
- ConductorOne became C1 in April 2026, and C1's release notes state that the product and existing conductor.one tenant URLs did not change.
- C1 publishes pricing models, not prices: Platform pricing scoped by managed identities from 100 to 20,000, or usage-based Flex pricing billed in C1 Tokens.
- C1's Basic support tier, listed for companies under 500 employees, promises a one-business-day P0 response during US Eastern hours and a 99.5% uptime SLA.
- Since September 2026, new C1 customers can host tenant data in the EU on AWS Frankfurt, so EU data residency alone no longer separates C1 from European vendors.
- C1 can govern AI agents down to runtime tool calls, while teams that mainly need agent inventory and access reviews can use a lighter mid-market IGA tool.
Table of contents
- What is C1 (formerly ConductorOne)?
- How much does C1 cost?
- What does C1 cover, and what does it leave out?
- Is C1 a good fit for a company of 50 to 500 employees?
- Can C1 govern AI agents?
- What are the best C1 alternatives for automated access reviews?
- How to choose between C1 and a mid-market alternative
- Why Corma for mid-market identity governance
- Frequently asked questions
What is C1 (formerly ConductorOne)?
C1 is an identity governance and security platform that controls access for employees, contractors, service accounts and AI agents. It is the same company and the same product that was called ConductorOne until April 2026.
C1's product release notes, in an entry dated 10 April 2026, announce that "ConductorOne is now C1" with a new logo and refreshed visuals. The same entry states that "nothing about how C1 works has changed" and that customer tenant URLs on tenant.conductor.one stay the same. The website moved to c1.ai, and the company lists offices in San Francisco and Portland.
The company raised a $79 million Series B led by Greycroft in October 2025, still under the ConductorOne name. Today its homepage presents C1 as "the identity platform built for the AI era", with three pillars: governing workforce identity, securing agents and helping teams put AI to work.
In category terms, C1 is an identity governance and administration (IGA) platform: it decides who gets access to which systems, reviews that access over time and produces the evidence auditors ask for. The rename matters for buyers in one practical way: many reviews and pricing trackers still describe "ConductorOne", and some were written before C1 changed its pricing page, so check the date of anything you read.
How much does C1 cost?
C1 does not publish a price. Its pricing page describes two ways to buy, states that "exact pricing" is "scoped with you", and ends every configuration with an invitation to book a demo for a tailored quote.
- Platform pricing is SKU-based. You choose a program size in managed identities (100, 500, 1,000, 5,000, 10,000 or 20,000), a platform level (Pro, or Advanced for on-premises integrations and connectivity), then product modules.
- Flex pricing is usage-based. Billable events consume C1 Tokens, usage and spend are visible in the product, and billing is monthly.
Third-party estimates fill the gap, with caveats. The pricing tracker checkthat.ai, last updated on 22 April 2026, reports annual contract values from about $4,300 to $20,000 with a median around $14,000, "based on 3 completed deals". Three deals do not make a price list. The same page states that c1.ai/pricing returned a 404 error; that page is now live, with models but no numbers. And the same site's C1 profile describes an ideal customer of 500+ employees, which sits awkwardly with an entry tier it sizes at 100 to 300 employees. Treat those figures as directional.
What the primary source does settle: C1 program sizes start at 100 managed identities, so a 150-person company can buy C1. Where company size shows is in the service model, covered in the fit section below. Managed identities are also not limited to employees: C1 describes its Lifecycle module as covering "your workforce, agents, and enterprise resources", so ask how contractors, service accounts and agents are counted before you compare quotes.
Corma takes the opposite approach at the entry point. Its published pricing includes a Freemium tier and an Essential tier from €3 per user per month on an annual engagement, both focused on visibility and finance. Automated access reviews sit in the Pro tier, which is quoted after a demo, and Enterprise pricing is custom from 1,000 users. Neither vendor lists a price for automated access reviews; the difference is that a Corma evaluation can start on a free or published tier without a sales cycle.
C1 and Corma pricing at a glance (checked 28 September 2026)
| Criterion | C1 | Corma |
|---|---|---|
| Published prices | None. Exact pricing scoped with sales | Freemium, and Essential from €3/user/month (annual) |
| Pricing unit | Managed identities (Platform) or C1 Tokens (Flex) | Users |
| Free option | None listed on the pricing page | Freemium tier (identity provider connection, browser extension, SSO connection) |
| Access reviews included in | C1 Comply module | Pro tier (quoted after a demo) |
| Billing | Annual or multi-year contracts with PO billing and NET terms; Flex billed monthly | Annual engagement; custom pricing from 1,000 users |
Sources: c1.ai/pricing, c1.ai/pricing/value, corma.io/pricing.
What does C1 cover, and what does it leave out?
C1 covers the full identity governance cycle, from lifecycle and access requests to just-in-time access, access reviews and segregation of duties, and adds AI gateways, a credential vault and agents. Its pricing page lists no module for SaaS contracts, renewals, invoices or licence spend.
C1 product modules, as listed on c1.ai/pricing
| Module | What C1 says it does | Family |
|---|---|---|
| C1 Lifecycle | Manage the lifecycle of your workforce, agents and enterprise resources | Govern |
| C1 Access | App self-service and policy-controlled requests, JIT access and RBAC | Govern |
| C1 Comply | Access reviews, SoD, evidence and remediation | Govern |
| C1 LLM Gateway | Policy-based routing across inference providers | Run |
| C1 MCP Gateway | Identity-aware policy for MCP with enforced guardrails | Run |
| C1 Vault | Agent-ready credential vault | Run |
| C1 Agents | Automate multi-step, complex enterprise work | Work |
Platform levels: Pro (integrations, visibility, identity security, shadow detection) and Advanced (Pro plus on-premises integrations and connectivity).
On security and hosting, C1 answers most of the questions a European security review asks. Its trust and security page lists SOC 2 Type II and ISO 27001 certification, a GDPR DPA and a HIPAA BAA, with audit reports available under NDA. Its hosting page lists a US environment on AWS, an EU environment in AWS Frankfurt with Ireland for disaster recovery, and a federal environment marked "coming soon".
The missing SaaS spend layer is a deliberate position. In a June 2025 post, C1 Field CISO Kevin Paige argued that buyers confuse the two categories and summed it up this way: "A governance platform secures your business. An SMP gives you a dashboard." For a company with separate security and procurement teams, that split can work.
At 50 to 500 employees, the same app inventory usually feeds both jobs, because you cannot review access to an application nobody knows exists. Satelia, a 70-employee healthtech company in Bordeaux preparing for ISO 27001 and SOC 2, is a concrete case. Its auditors asked for proof of controlled access management, and its manual reports listed about 30 applications. Corma's discovery surfaced 160, and the same inventory exposed overlapping subscriptions to Notion, Google Drive and Confluence. For a team without a separate SaaS management function, access governance and licence control were one project, not two.
Is C1 a good fit for a company of 50 to 500 employees?
C1 can fit a company of this size if you accept an enterprise vendor's service model. Its published support grid puts companies under 500 employees on the Basic tier, with a one-business-day first response on critical issues, support hours in US Eastern time and no named customer success manager.
C1 support tiers by company size (c1.ai/pricing/support, 28 September 2026)
| Criterion | Basic (under 500 employees) | Business (under 1,000) | Enterprise (1,000 to 15,000) |
|---|---|---|---|
| Channels | Email and portal, Slack as an add-on | Email, portal, Slack | Email, portal, Slack, Teams |
| Named CSM | No | No | Yes |
| P0 coverage | 6:30 AM to 8:30 PM ET, Monday to Friday | 6:30 AM to 8:30 PM ET, Monday to Friday | 24/7 on-call |
| P0 first response | 1 business day | 2 business hours | 30 minutes |
| Uptime SLA | 99.5% | 99.9% | 99.99% |
Two details matter for a European team. First, 6:30 AM to 8:30 PM Eastern is 12:30 to 2:30 the next morning in Paris or Berlin for most of the year, so a provisioning failure at 9:00 on a Monday in Europe waits until the afternoon for the support window to open. Second, a 99.5% uptime commitment allows up to about 3.6 hours of downtime in a 30-day month, against about 43 minutes at 99.9%. Neither is unusual for software at this price point, but both belong in your scoring grid next to features.
How long does a C1 rollout take?
On a cloud-first stack, a C1 rollout typically takes a few weeks. C1 CEO Alex Bovee told BankInfoSecurity in October 2025: "Our average customer goes live in less than four weeks, sometimes hooking up hundreds of applications in that time frame." checkthat.ai reports three-week deployments for cloud-native customers and two to three months for hybrid environments with legacy systems. Both statements hold: the variable is your legacy estate, not the vendor. Corma onboarding is also typically completed in under a month for SaaS-first companies, so speed alone will not separate the two on a cloud stack.
What do users say about C1?
Practitioner feedback on C1 is positive on product quality. In Reddit threads on r/IdentityManagement and r/cybersecurity, identity practitioners praise its connectors, its UX and how easy it is to stand up. The objections raised in the same communities concern the category rather than C1. One thread is titled "Is a dedicated IGA system even worth it if only 20-30% of app landscape…" That is the right question for a 50 to 500 employee company: how much of your real app estate will the tool govern, and at what cost per covered app.
If a next-business-day support model or a scoped enterprise quote does not suit a team your size, see how Corma's identity governance platform runs access reviews and joiner-mover-leaver workflows for companies of 50 to 500 employees.
Can C1 govern AI agents?
Yes. C1 treats AI agents as identities it can discover, credential and review, and since July 2026 it also governs what agents do at runtime, one tool call at a time. AI agent governance is the set of controls that decide what an agent can access and do, who owns it, and how that access is reviewed and removed. C1 shipped three launches on it in 2026.
C1 AI agent governance launches in 2026 (C1 announcements)
| Date | Launch | What it does, in C1's words |
|---|---|---|
| 19 March 2026 | AI Access Management | "A unified control plane for managing access to AI tools and data used by employees, AI personal assistants, and enterprise agents" |
| 27 July 2026 | Shadow AI discovery | Finds "unsanctioned AI tools, AI agents, MCP servers, and exposed credentials across the cloud and endpoints" |
| 29 July 2026 | Agent runtime governance | "Every tool call goes through a single governed gateway", each call is scored for risk, and risky calls can be blocked or routed for human approval |
| Current pricing page | LLM Gateway, MCP Gateway, Vault, Agents | Sold as modules next to identity governance |
For a company of 50 to 500 employees, the first agent risk is usually inventory, not runtime. Which AI tools and agents are connected to your SaaS apps, which OAuth grants and API tokens they hold, who owns each one, and whether that access is removed when the owner leaves. An agent whose owner has left keeps its token and becomes an orphaned non-human identity, which auditors treat like any other orphaned account. Corma's guide to an AI agent governance framework walks through those controls in a 30-day plan.
Corma covers that first layer inside the access governance cycle you already run for people. It treats each agent as a non-human identity with least privilege, access reviews and an audit trail. Its pricing page lists NHI discovery (service accounts, API tokens, OAuth), NHI lifecycle governance and AI agent identity visibility, and its shadow AI detection scans your SaaS environment, browser extensions and connected apps for AI tools in use.
Corma does not list a runtime gateway for agent tool calls. If you are putting agents with write access into production and need to block individual actions as they happen, C1 goes further, and so does Lumos, which lists MCP governance of agent tool calls. Corma's product choice reflects a stated view: an episode summary of a podcast interview with CEO Héloïse Rozès sums up her position as "Non à l'Autopilot mais Oui au Copilot" (no to autopilot, yes to copilot), and Corma's own automation agents run with admin approval and an audit trail.
What are the best C1 alternatives for automated access reviews?
The closest C1 alternatives for automated access reviews are Corma, Lumos, Zluri and Torii. All four automate access reviews. They differ on whether they also manage SaaS spend, how far they govern AI agents, whether they publish prices and what they state about EU data residency.
C1 and four alternatives, as stated on vendor pricing and security pages (28 September 2026)
| Vendor | Access reviews | SaaS licence and renewal management | AI agent coverage | Public prices | EU data residency |
|---|---|---|---|---|---|
| C1 | Yes (Comply module) | Not listed | Runtime tool-call governance, MCP and LLM gateways, agent vault | No, scoped quote | EU instance in AWS Frankfurt for new customers since September 2026 |
| Corma | Yes (Pro tier) | Yes: contracts, licence reclaim, spend dashboard | NHI discovery, AI agent identity visibility, shadow AI detection | Free tier, Essential from €3/user/month; Pro quoted | Listed on the pricing page; Paris-based company |
| Lumos | Yes | Not listed on the pricing page | AI agents that govern access; MCP governance of agent tool calls | No | Not stated on the pages checked |
| Zluri | Yes, with segregation of duties | Yes: spend and renewals | Monitoring of AI apps | No | Not stated on the security page (GDPR, SOC 2 Type II, ISO 27001 and ISO 27701 listed) |
| Torii | Yes | Yes: cost optimisation, contracts and renewals | Non-human identities, agentic governance, AI discovery and spend | No | Not stated; security page lists AWS hosting, SOC 2 Type II and GDPR |
Sources: c1.ai/pricing and /pricing/hosting, corma.io/pricing, lumos.com/pricing, zluri.com/pricing and /security, toriihq.com/pricing and /security. "Not stated" means the vendor did not say it on those pages, not that the option does not exist.
Corma
Corma is a European platform that combines SaaS management and identity governance for companies of 50 to 500 employees. Its automated access reviews replace spreadsheet campaigns with reminders, one-click certification or revocation, and audit-ready PDF or CSV reports. It is the option in this list that pairs a Paris headquarters with EU data residency and a published entry price.
Lumos
Lumos is the closest to C1 on AI agents: its pricing page lists access reviews, lifecycle management, a self-service AppStore, AI agents that govern access and MCP governance for agent tool calls. It publishes no prices. Our Corma vs Lumos comparison covers the differences in detail.
Zluri
Zluri combines identity governance (access requests, access reviews, segregation of duties), identity security posture management and SaaS management with spend and renewal tracking. It lists GDPR, SOC 2 Type II, ISO 27001 and ISO 27701 on its security page. See the Corma vs Zluri comparison.
Torii
Torii leads with SaaS management (shadow IT, cost optimisation, contract and renewal management) and also lists identity governance modules, including access reviews, non-human identities and agentic governance, plus AI discovery and spend tracking. See the Corma vs Torii comparison.
If your company is standardised on Okta or Microsoft Entra ID, price their native governance add-ons before adding a vendor; our Okta vs Microsoft Entra ID guide compares the two for mid-size companies. For a wider market view that includes enterprise suites such as SailPoint, see our ranking of the best IGA solutions for mid-market companies.
How to choose between C1 and a mid-market alternative
Choose C1 when identity is a program with its own team, when agents with write access are heading into production, or when legacy systems need on-premises connectors. Choose a mid-market alternative when one IT team owns identity, licences and audits together, and needs to start without a long sales cycle.
Decision grid for a company of 50 to 500 employees
| Your situation | C1 fits better | A mid-market IGA fits better |
|---|---|---|
| Who runs identity | A dedicated identity or security engineering team | IT generalists who also run SaaS, devices and onboarding |
| AI agents | Agents with write access in production, needing per-tool-call control | An inventory of agents and tokens, named owners and periodic reviews |
| App estate | Legacy or on-premises systems (Advanced platform level) | Mostly SaaS behind Google Workspace, Microsoft Entra ID, Okta or JumpCloud |
| Licence spend | Owned by another tool or team | The same team must reclaim unused licences and track renewals |
| Support expectations | Enterprise tier: 30-minute P0 response and a named CSM (listed for 1,000+ employees) | Under 500 employees, where C1 lists Basic support; compare with each alternative's written SLA |
| Budget process | Comfortable with a scoped quote after a demo | Prefers to start on a free or published tier |
For European buyers, add three regulatory checks to the grid. If your company is in scope of NIS2, Article 21(2)(i) lists "human resources security, access control policies and asset management" among the minimum risk-management measures, which is exactly the evidence an IGA tool produces. Article 21(2)(d) adds "supply chain security", and your IGA vendor is one of those suppliers because it holds a map of every account in your company.
Under the GDPR, Article 28(3) requires that processing by a processor "shall be governed by a contract", so ask each vendor for its DPA and subprocessor list. C1 offers a GDPR DPA; Corma is an EU company with EU data residency. Finally, check where your tenant will actually live: C1's EU instance is offered to new customers who need tenant data held in the EU, so existing US tenants should ask what a move involves.
Why Corma for mid-market identity governance
Corma is a European platform that automates software licence, contract and identity access management for companies of 50 to 500 employees. Where C1 splits governance from SaaS management by design, Corma runs both from one inventory.
- One inventory for access and licences. Discovery finds the apps, the access reviews certify who uses them, and the same data drives licence reclaim and renewal decisions, as the Satelia case showed.
- European by default. Corma is headquartered in Paris, lists EU data residency on its pricing page and is ISO/IEC 27001:2022 certified.
- Built for mid-market speed. Native connectors to Google Workspace, Microsoft Entra ID, Okta and JumpCloud, more than 200 integrations in the Pro tier, and onboarding typically completed in under a month.
- Audit-ready access reviews. Automated campaigns, audit-ready PDF and CSV reports, automated access token revocation and least-privilege enforcement.
- AI agents in the same review cycle. NHI discovery, NHI lifecycle governance and AI agent identity visibility sit next to human access, not in a separate product.
- A transparent entry point. A free tier and a published starting price, and recognition in the 2025 Gartner® Magic Quadrant™ for SaaS Management Platforms.
Comparing C1 with a mid-market option? Request a demo with your own app list and see your access reviews, non-human identities and licences in one place.
Frequently asked questions
Is there a free trial or POC option for C1?
C1's pricing page offers demos and tailored quotes and lists no free plan or self-serve trial, so a proof of concept has to be agreed with C1's sales team during scoping. Corma, by comparison, publishes a Freemium tier that connects your identity provider and browser extension at no cost.
How does C1 handle AI agent and non-human identity pricing?
C1 Platform pricing is sized in managed identities, and C1 describes its Lifecycle module as covering "your workforce, agents, and enterprise resources". The pricing page does not state how each agent or service account is counted, so confirm the counting rule before comparing quotes. Flex pricing charges C1 Tokens per billable event instead.
What contract terms does C1 offer?
C1's trust and pricing pages list annual and multi-year contracts with PO billing and NET terms, a custom MSA, and an available GDPR DPA and HIPAA BAA. Flex pricing, the usage-based option, is billed monthly with usage and spend visible in the product.
Are there per-connector or per-application fees with C1?
C1's public pricing page lists no per-connector fee. It does tie on-premises integrations and connectivity to the Advanced platform level, so a company with legacy or on-premises systems should expect to move up from the Pro level.
Does C1 support just-in-time access?
Yes. The C1 Access module covers app self-service, policy-controlled access requests, just-in-time (JIT) access and role-based access control. Just-in-time access grants a permission for a limited period and removes it automatically, which reduces standing privileges on sensitive systems.
%20as%20a%20mid-market%20IGA.avif)





