Is C1, formerly ConductorOne, right for mid-market IGA? Pricing, coverage and alternatives

1
minute of reading
Is C1, formerly ConductorOne, right for mid-market IGA? Pricing, coverage and alternatives

Last reviewed: 28 September 2026. Vendor facts in this guide were checked against C1's own pricing, hosting, support and release-notes pages on that date.

C1, the identity governance platform formerly called ConductorOne, can serve a mid-market company, but it is built and priced for larger identity programs. This review is for IT and security leads at companies of 50 to 500 employees who have C1 on a shortlist for access reviews, provisioning or AI agent governance, and want to know what it costs, what it covers and what to compare it with.

C1 quotes every deal from a scoped program of managed identities or from usage, and it publishes no list price. Its entry support tier, which C1 lists for companies under 500 employees, commits to a first response on critical issues within one business day, during US Eastern hours. Its pricing page lists no module for SaaS contracts, renewals or spend. Mid-market teams that want automated access reviews and licence control from one European vendor should compare C1 with Corma, and Lumos, Zluri and Torii are the other alternatives covered below.

If you manage identity for several thousand employees with a dedicated identity team, C1 was designed for your situation and the mid-market trade-offs in this guide will weigh less.

Key takeaways

  • ConductorOne became C1 in April 2026, and C1's release notes state that the product and existing conductor.one tenant URLs did not change.
  • C1 publishes pricing models, not prices: Platform pricing scoped by managed identities from 100 to 20,000, or usage-based Flex pricing billed in C1 Tokens.
  • C1's Basic support tier, listed for companies under 500 employees, promises a one-business-day P0 response during US Eastern hours and a 99.5% uptime SLA.
  • Since September 2026, new C1 customers can host tenant data in the EU on AWS Frankfurt, so EU data residency alone no longer separates C1 from European vendors.
  • C1 can govern AI agents down to runtime tool calls, while teams that mainly need agent inventory and access reviews can use a lighter mid-market IGA tool.

What is C1 (formerly ConductorOne)?

C1 is an identity governance and security platform that controls access for employees, contractors, service accounts and AI agents. It is the same company and the same product that was called ConductorOne until April 2026.

C1's product release notes, in an entry dated 10 April 2026, announce that "ConductorOne is now C1" with a new logo and refreshed visuals. The same entry states that "nothing about how C1 works has changed" and that customer tenant URLs on tenant.conductor.one stay the same. The website moved to c1.ai, and the company lists offices in San Francisco and Portland.

The company raised a $79 million Series B led by Greycroft in October 2025, still under the ConductorOne name. Today its homepage presents C1 as "the identity platform built for the AI era", with three pillars: governing workforce identity, securing agents and helping teams put AI to work.

In category terms, C1 is an identity governance and administration (IGA) platform: it decides who gets access to which systems, reviews that access over time and produces the evidence auditors ask for. The rename matters for buyers in one practical way: many reviews and pricing trackers still describe "ConductorOne", and some were written before C1 changed its pricing page, so check the date of anything you read.

How much does C1 cost?

C1 does not publish a price. Its pricing page describes two ways to buy, states that "exact pricing" is "scoped with you", and ends every configuration with an invitation to book a demo for a tailored quote.

  • Platform pricing is SKU-based. You choose a program size in managed identities (100, 500, 1,000, 5,000, 10,000 or 20,000), a platform level (Pro, or Advanced for on-premises integrations and connectivity), then product modules.
  • Flex pricing is usage-based. Billable events consume C1 Tokens, usage and spend are visible in the product, and billing is monthly.

Third-party estimates fill the gap, with caveats. The pricing tracker checkthat.ai, last updated on 22 April 2026, reports annual contract values from about $4,300 to $20,000 with a median around $14,000, "based on 3 completed deals". Three deals do not make a price list. The same page states that c1.ai/pricing returned a 404 error; that page is now live, with models but no numbers. And the same site's C1 profile describes an ideal customer of 500+ employees, which sits awkwardly with an entry tier it sizes at 100 to 300 employees. Treat those figures as directional.

What the primary source does settle: C1 program sizes start at 100 managed identities, so a 150-person company can buy C1. Where company size shows is in the service model, covered in the fit section below. Managed identities are also not limited to employees: C1 describes its Lifecycle module as covering "your workforce, agents, and enterprise resources", so ask how contractors, service accounts and agents are counted before you compare quotes.

Corma takes the opposite approach at the entry point. Its published pricing includes a Freemium tier and an Essential tier from €3 per user per month on an annual engagement, both focused on visibility and finance. Automated access reviews sit in the Pro tier, which is quoted after a demo, and Enterprise pricing is custom from 1,000 users. Neither vendor lists a price for automated access reviews; the difference is that a Corma evaluation can start on a free or published tier without a sales cycle.

C1 and Corma pricing at a glance (checked 28 September 2026)

CriterionC1Corma
Published pricesNone. Exact pricing scoped with salesFreemium, and Essential from €3/user/month (annual)
Pricing unitManaged identities (Platform) or C1 Tokens (Flex)Users
Free optionNone listed on the pricing pageFreemium tier (identity provider connection, browser extension, SSO connection)
Access reviews included inC1 Comply modulePro tier (quoted after a demo)
BillingAnnual or multi-year contracts with PO billing and NET terms; Flex billed monthlyAnnual engagement; custom pricing from 1,000 users

Sources: c1.ai/pricing, c1.ai/pricing/value, corma.io/pricing.

What does C1 cover, and what does it leave out?

C1 covers the full identity governance cycle, from lifecycle and access requests to just-in-time access, access reviews and segregation of duties, and adds AI gateways, a credential vault and agents. Its pricing page lists no module for SaaS contracts, renewals, invoices or licence spend.

C1 product modules, as listed on c1.ai/pricing

ModuleWhat C1 says it doesFamily
C1 LifecycleManage the lifecycle of your workforce, agents and enterprise resourcesGovern
C1 AccessApp self-service and policy-controlled requests, JIT access and RBACGovern
C1 ComplyAccess reviews, SoD, evidence and remediationGovern
C1 LLM GatewayPolicy-based routing across inference providersRun
C1 MCP GatewayIdentity-aware policy for MCP with enforced guardrailsRun
C1 VaultAgent-ready credential vaultRun
C1 AgentsAutomate multi-step, complex enterprise workWork

Platform levels: Pro (integrations, visibility, identity security, shadow detection) and Advanced (Pro plus on-premises integrations and connectivity).

On security and hosting, C1 answers most of the questions a European security review asks. Its trust and security page lists SOC 2 Type II and ISO 27001 certification, a GDPR DPA and a HIPAA BAA, with audit reports available under NDA. Its hosting page lists a US environment on AWS, an EU environment in AWS Frankfurt with Ireland for disaster recovery, and a federal environment marked "coming soon".

The missing SaaS spend layer is a deliberate position. In a June 2025 post, C1 Field CISO Kevin Paige argued that buyers confuse the two categories and summed it up this way: "A governance platform secures your business. An SMP gives you a dashboard." For a company with separate security and procurement teams, that split can work.

At 50 to 500 employees, the same app inventory usually feeds both jobs, because you cannot review access to an application nobody knows exists. Satelia, a 70-employee healthtech company in Bordeaux preparing for ISO 27001 and SOC 2, is a concrete case. Its auditors asked for proof of controlled access management, and its manual reports listed about 30 applications. Corma's discovery surfaced 160, and the same inventory exposed overlapping subscriptions to Notion, Google Drive and Confluence. For a team without a separate SaaS management function, access governance and licence control were one project, not two.

Is C1 a good fit for a company of 50 to 500 employees?

C1 can fit a company of this size if you accept an enterprise vendor's service model. Its published support grid puts companies under 500 employees on the Basic tier, with a one-business-day first response on critical issues, support hours in US Eastern time and no named customer success manager.

C1 support tiers by company size (c1.ai/pricing/support, 28 September 2026)

CriterionBasic (under 500 employees)Business (under 1,000)Enterprise (1,000 to 15,000)
ChannelsEmail and portal, Slack as an add-onEmail, portal, SlackEmail, portal, Slack, Teams
Named CSMNoNoYes
P0 coverage6:30 AM to 8:30 PM ET, Monday to Friday6:30 AM to 8:30 PM ET, Monday to Friday24/7 on-call
P0 first response1 business day2 business hours30 minutes
Uptime SLA99.5%99.9%99.99%

Two details matter for a European team. First, 6:30 AM to 8:30 PM Eastern is 12:30 to 2:30 the next morning in Paris or Berlin for most of the year, so a provisioning failure at 9:00 on a Monday in Europe waits until the afternoon for the support window to open. Second, a 99.5% uptime commitment allows up to about 3.6 hours of downtime in a 30-day month, against about 43 minutes at 99.9%. Neither is unusual for software at this price point, but both belong in your scoring grid next to features.

How long does a C1 rollout take?

On a cloud-first stack, a C1 rollout typically takes a few weeks. C1 CEO Alex Bovee told BankInfoSecurity in October 2025: "Our average customer goes live in less than four weeks, sometimes hooking up hundreds of applications in that time frame." checkthat.ai reports three-week deployments for cloud-native customers and two to three months for hybrid environments with legacy systems. Both statements hold: the variable is your legacy estate, not the vendor. Corma onboarding is also typically completed in under a month for SaaS-first companies, so speed alone will not separate the two on a cloud stack.

What do users say about C1?

Practitioner feedback on C1 is positive on product quality. In Reddit threads on r/IdentityManagement and r/cybersecurity, identity practitioners praise its connectors, its UX and how easy it is to stand up. The objections raised in the same communities concern the category rather than C1. One thread is titled "Is a dedicated IGA system even worth it if only 20-30% of app landscape…" That is the right question for a 50 to 500 employee company: how much of your real app estate will the tool govern, and at what cost per covered app.

If a next-business-day support model or a scoped enterprise quote does not suit a team your size, see how Corma's identity governance platform runs access reviews and joiner-mover-leaver workflows for companies of 50 to 500 employees.

Can C1 govern AI agents?

Yes. C1 treats AI agents as identities it can discover, credential and review, and since July 2026 it also governs what agents do at runtime, one tool call at a time. AI agent governance is the set of controls that decide what an agent can access and do, who owns it, and how that access is reviewed and removed. C1 shipped three launches on it in 2026.

C1 AI agent governance launches in 2026 (C1 announcements)

DateLaunchWhat it does, in C1's words
19 March 2026AI Access Management"A unified control plane for managing access to AI tools and data used by employees, AI personal assistants, and enterprise agents"
27 July 2026Shadow AI discoveryFinds "unsanctioned AI tools, AI agents, MCP servers, and exposed credentials across the cloud and endpoints"
29 July 2026Agent runtime governance"Every tool call goes through a single governed gateway", each call is scored for risk, and risky calls can be blocked or routed for human approval
Current pricing pageLLM Gateway, MCP Gateway, Vault, AgentsSold as modules next to identity governance

For a company of 50 to 500 employees, the first agent risk is usually inventory, not runtime. Which AI tools and agents are connected to your SaaS apps, which OAuth grants and API tokens they hold, who owns each one, and whether that access is removed when the owner leaves. An agent whose owner has left keeps its token and becomes an orphaned non-human identity, which auditors treat like any other orphaned account. Corma's guide to an AI agent governance framework walks through those controls in a 30-day plan.

Corma covers that first layer inside the access governance cycle you already run for people. It treats each agent as a non-human identity with least privilege, access reviews and an audit trail. Its pricing page lists NHI discovery (service accounts, API tokens, OAuth), NHI lifecycle governance and AI agent identity visibility, and its shadow AI detection scans your SaaS environment, browser extensions and connected apps for AI tools in use.

Corma does not list a runtime gateway for agent tool calls. If you are putting agents with write access into production and need to block individual actions as they happen, C1 goes further, and so does Lumos, which lists MCP governance of agent tool calls. Corma's product choice reflects a stated view: an episode summary of a podcast interview with CEO Héloïse Rozès sums up her position as "Non à l'Autopilot mais Oui au Copilot" (no to autopilot, yes to copilot), and Corma's own automation agents run with admin approval and an audit trail.

What are the best C1 alternatives for automated access reviews?

The closest C1 alternatives for automated access reviews are Corma, Lumos, Zluri and Torii. All four automate access reviews. They differ on whether they also manage SaaS spend, how far they govern AI agents, whether they publish prices and what they state about EU data residency.

C1 and four alternatives, as stated on vendor pricing and security pages (28 September 2026)

VendorAccess reviewsSaaS licence and renewal managementAI agent coveragePublic pricesEU data residency
C1Yes (Comply module)Not listedRuntime tool-call governance, MCP and LLM gateways, agent vaultNo, scoped quoteEU instance in AWS Frankfurt for new customers since September 2026
CormaYes (Pro tier)Yes: contracts, licence reclaim, spend dashboardNHI discovery, AI agent identity visibility, shadow AI detectionFree tier, Essential from €3/user/month; Pro quotedListed on the pricing page; Paris-based company
LumosYesNot listed on the pricing pageAI agents that govern access; MCP governance of agent tool callsNoNot stated on the pages checked
ZluriYes, with segregation of dutiesYes: spend and renewalsMonitoring of AI appsNoNot stated on the security page (GDPR, SOC 2 Type II, ISO 27001 and ISO 27701 listed)
ToriiYesYes: cost optimisation, contracts and renewalsNon-human identities, agentic governance, AI discovery and spendNoNot stated; security page lists AWS hosting, SOC 2 Type II and GDPR

Sources: c1.ai/pricing and /pricing/hosting, corma.io/pricing, lumos.com/pricing, zluri.com/pricing and /security, toriihq.com/pricing and /security. "Not stated" means the vendor did not say it on those pages, not that the option does not exist.

Corma

Corma is a European platform that combines SaaS management and identity governance for companies of 50 to 500 employees. Its automated access reviews replace spreadsheet campaigns with reminders, one-click certification or revocation, and audit-ready PDF or CSV reports. It is the option in this list that pairs a Paris headquarters with EU data residency and a published entry price.

Lumos

Lumos is the closest to C1 on AI agents: its pricing page lists access reviews, lifecycle management, a self-service AppStore, AI agents that govern access and MCP governance for agent tool calls. It publishes no prices. Our Corma vs Lumos comparison covers the differences in detail.

Zluri

Zluri combines identity governance (access requests, access reviews, segregation of duties), identity security posture management and SaaS management with spend and renewal tracking. It lists GDPR, SOC 2 Type II, ISO 27001 and ISO 27701 on its security page. See the Corma vs Zluri comparison.

Torii

Torii leads with SaaS management (shadow IT, cost optimisation, contract and renewal management) and also lists identity governance modules, including access reviews, non-human identities and agentic governance, plus AI discovery and spend tracking. See the Corma vs Torii comparison.

If your company is standardised on Okta or Microsoft Entra ID, price their native governance add-ons before adding a vendor; our Okta vs Microsoft Entra ID guide compares the two for mid-size companies. For a wider market view that includes enterprise suites such as SailPoint, see our ranking of the best IGA solutions for mid-market companies.

How to choose between C1 and a mid-market alternative

Choose C1 when identity is a program with its own team, when agents with write access are heading into production, or when legacy systems need on-premises connectors. Choose a mid-market alternative when one IT team owns identity, licences and audits together, and needs to start without a long sales cycle.

Decision grid for a company of 50 to 500 employees

Your situationC1 fits betterA mid-market IGA fits better
Who runs identityA dedicated identity or security engineering teamIT generalists who also run SaaS, devices and onboarding
AI agentsAgents with write access in production, needing per-tool-call controlAn inventory of agents and tokens, named owners and periodic reviews
App estateLegacy or on-premises systems (Advanced platform level)Mostly SaaS behind Google Workspace, Microsoft Entra ID, Okta or JumpCloud
Licence spendOwned by another tool or teamThe same team must reclaim unused licences and track renewals
Support expectationsEnterprise tier: 30-minute P0 response and a named CSM (listed for 1,000+ employees)Under 500 employees, where C1 lists Basic support; compare with each alternative's written SLA
Budget processComfortable with a scoped quote after a demoPrefers to start on a free or published tier

For European buyers, add three regulatory checks to the grid. If your company is in scope of NIS2, Article 21(2)(i) lists "human resources security, access control policies and asset management" among the minimum risk-management measures, which is exactly the evidence an IGA tool produces. Article 21(2)(d) adds "supply chain security", and your IGA vendor is one of those suppliers because it holds a map of every account in your company.

Under the GDPR, Article 28(3) requires that processing by a processor "shall be governed by a contract", so ask each vendor for its DPA and subprocessor list. C1 offers a GDPR DPA; Corma is an EU company with EU data residency. Finally, check where your tenant will actually live: C1's EU instance is offered to new customers who need tenant data held in the EU, so existing US tenants should ask what a move involves.

Why Corma for mid-market identity governance

Corma is a European platform that automates software licence, contract and identity access management for companies of 50 to 500 employees. Where C1 splits governance from SaaS management by design, Corma runs both from one inventory.

  • One inventory for access and licences. Discovery finds the apps, the access reviews certify who uses them, and the same data drives licence reclaim and renewal decisions, as the Satelia case showed.
  • European by default. Corma is headquartered in Paris, lists EU data residency on its pricing page and is ISO/IEC 27001:2022 certified.
  • Built for mid-market speed. Native connectors to Google Workspace, Microsoft Entra ID, Okta and JumpCloud, more than 200 integrations in the Pro tier, and onboarding typically completed in under a month.
  • Audit-ready access reviews. Automated campaigns, audit-ready PDF and CSV reports, automated access token revocation and least-privilege enforcement.
  • AI agents in the same review cycle. NHI discovery, NHI lifecycle governance and AI agent identity visibility sit next to human access, not in a separate product.
  • A transparent entry point. A free tier and a published starting price, and recognition in the 2025 Gartner® Magic Quadrant™ for SaaS Management Platforms.

Comparing C1 with a mid-market option? Request a demo with your own app list and see your access reviews, non-human identities and licences in one place.

Frequently asked questions

Is there a free trial or POC option for C1?

C1's pricing page offers demos and tailored quotes and lists no free plan or self-serve trial, so a proof of concept has to be agreed with C1's sales team during scoping. Corma, by comparison, publishes a Freemium tier that connects your identity provider and browser extension at no cost.

How does C1 handle AI agent and non-human identity pricing?

C1 Platform pricing is sized in managed identities, and C1 describes its Lifecycle module as covering "your workforce, agents, and enterprise resources". The pricing page does not state how each agent or service account is counted, so confirm the counting rule before comparing quotes. Flex pricing charges C1 Tokens per billable event instead.

What contract terms does C1 offer?

C1's trust and pricing pages list annual and multi-year contracts with PO billing and NET terms, a custom MSA, and an available GDPR DPA and HIPAA BAA. Flex pricing, the usage-based option, is billed monthly with usage and spend visible in the product.

Are there per-connector or per-application fees with C1?

C1's public pricing page lists no per-connector fee. It does tie on-premises integrations and connectivity to the Advanced platform level, so a company with legacy or on-premises systems should expect to move up from the Pro level.

Does C1 support just-in-time access?

Yes. The C1 Access module covers app self-service, policy-controlled access requests, just-in-time (JIT) access and role-based access control. Just-in-time access grants a permission for a limited period and removes it automatically, which reduces standing privileges on sensitive systems.

Is C1, formerly ConductorOne, right for mid-market IGA? Pricing, coverage and alternatives

Is C1, formerly ConductorOne, right for mid-market IGA? Pricing, coverage and alternatives

Read Article
Okta pricing 2027: real cost per user, hidden fees and what mid-market teams pay
October 5, 2026

Okta pricing 2027: real cost per user, hidden fees and what mid-market teams pay

Read Article
Corma’s custom agents in action at Infinox
The IT Circle
September 22, 2026

Corma’s custom agents in action at Infinox

Read Article

The new standard in license management

Ready to revolutionize your IT governance?

Isometric illustration of a calculator with black number keys and orange operation buttons on screen
Black circular icon with two white rounded rectangles resembling a simple ghost or face designOrange circular icon with two white vertical bars on the left sideDark circular icon with white pause symbol and dotted pattern