The founding insight behind SPHERE arrived in the wreckage of Lehman Brothers, where Rita Gurevich learned that an enterprise can own enormous quantities of technology without knowing, cleanly, who owns access to it. When the bank failed in 2008, its systems and data had to be separated among buyers without leaking one buyer’s information to another. The job was part archaeology, part air-traffic control. Accounts, groups, applications and permissions had accumulated histories that no tidy diagram could explain.
Gurevich stayed for the unwinding. She later described it as a historic big-data exercise. The experience exposed a problem that survived the bank: even sophisticated companies managed access through fragmented tools, spreadsheets and institutional memory. Two years of additional work at Barclays Capital and data-protection vendor StealthBits confirmed that this was not a Lehman oddity. Manual access management was the first thing to fail. It was slow, incomplete and dangerous precisely where an organization could least tolerate a casual deletion.
In 2010, she founded SPHERE. The early pitch was refreshingly unpolished. The team called itself “access control janitors.” They traced permissions, found owners, removed excessive access and helped regulated companies survive audits. Barclays was among the first clients. Starting in the middle of a recession, with giant banks as customers, looked backwards. It gave SPHERE unusually demanding training data.
“We called ourselves ‘access control janitors’ - we analyzed and cleaned up permissions to lower risk.”Rita Gurevich, founder and CEO
The awkward mile after discovery
SPHERE now calls the category identity hygiene. Strip away the label and the work is concrete: discover accounts and groups, understand their access paths, identify a responsible owner, rank the risk, collect a decision, make the approved change and keep evidence for auditors. Its SPHEREboard platform does that across accounts, data and Active Directory in cloud and on-premises environments.
The distinction matters because enterprise security has no shortage of scanners. A dashboard can announce that a service account is overprivileged. It cannot safely assume the account is useless. It may run billing, move files overnight or hold together a 20-year-old application. The difficult mile comes after the finding: getting business context, coordinating teams and changing access without causing an outage. SPHERE’s consulting years became a library of those edge cases, then workflows and automation.
The product family divides the mess into useful scopes. Accounts+ inventories privileged and ordinary accounts and maps relationships between identities and systems. SecureAD examines nested groups, stale accounts, circular structures and missing ownership in Microsoft Active Directory. SPHEREboard for Data focuses on inappropriate access to sensitive files. A purpose-built CyberArk edition discovers unprotected privileged accounts and automates their onboarding into CyberArk’s vaulting system. Hygiene Managed Services adds implementation and practitioners for teams that need more than a license.
The natural buyers are chief information security officers and the identity, infrastructure, audit and compliance teams beneath them. The sweet spot is not a 40-person startup with one cloud directory. It is a bank, airline, hospital or asset manager with years of acquisitions, regional systems and privileged accounts tucked inside critical processes. Publicly named customers include Goldman Sachs, Freddie Mac, Northwell Health and JetBlue. Older company material said its work reached four of the world’s top ten banks. Those organizations already own identity tools; the budget case for SPHERE is that expensive controls underperform when the underlying account inventory is wrong, ownership is missing or remediation lives in a spreadsheet. The company sells through a demo-led enterprise motion, then supports deployment with services and partners. There is an irony here that buyers of automation will recognize: the larger and messier the installation, the more human judgment is needed to get the automation safely started.
A case study with numbers, not incense
JetBlue offers the cleanest public view of what customers can do with it. The airline deployed SecureAD against an Active Directory environment that had become difficult to maintain. SPHEREboard exposed known and unknown risk, attached owners to groups and accounts, and staged the cleanup. JetBlue confirmed ownership for 90 percent of its AD groups and accounts. Inactive or redundant items represented nearly a quarter of the total account population. Of the outdated groups and accounts the project identified, roughly 75 percent were retired.
The less obvious achievement is that the airline kept operating. Identity cleanup fails when remediation is treated as a bulk-delete contest. SPHERE’s staged process builds an audit trail and asks accountable humans before changing the source system. That also explains when the approach will struggle: it needs access to authoritative systems, cooperation from application and business owners, and a willingness to act on findings. A company that wants a passive report, has no credible ownership data and cannot coordinate changes will produce a lovely backlog.
The business model grew up before it raised money
SPHERE bootstrapped for roughly a decade. That constraint shaped the company more than any category slogan. It had to sell work that produced an outcome, learn the client’s systems and earn another engagement. SPHEREboard began as internal automation, then became a customer product in 2015. The services operation did not vanish; it became the implementation and managed-services layer around enterprise software.
Gurevich changed her mind about outside capital in 2020 after Forgepoint Capital approached her. The attraction was not merely cash. A specialist cybersecurity investor could add executive networks and help SPHERE reach beyond the relationships that had sustained its bootstrapped years. Forgepoint led a $10 million Series A in February 2021. Edison Partners led a $31 million Series B in November 2022, with Forgepoint participating. The disclosed cost of the acceleration was $41 million in outside funding and the expectations attached to it.
By 2025, according to figures the company released the following February, recurring software revenue had grown 60 percent year over year and represented most of its revenue mix. The customer base grew 40 percent and retention was 96 percent. Absolute revenue and customer counts were not included in that announcement, so percentages should be read as directional evidence, not a map of scale.
The part worth stealing
- Start with a repeated, expensive workflow where failure has consequences.
- Do the work manually until the edge cases stop surprising you.
- Turn institutional knowledge into a sequence, not merely a dashboard.
- Measure completed remediation and durable control, not findings generated.
- Integrate with systems customers already trust instead of demanding a clean slate.
A connective layer, not another castle
SPHERE sits beside several crowded markets. Identity governance products such as SailPoint and Saviynt govern access lifecycles. Privileged-access systems such as CyberArk protect powerful credentials. Directory-security vendors inspect Active Directory and identity attack paths. Authorization platforms build searchable maps of who can reach what. An enterprise can also attack the problem with consultants and scripts.
SPHERE’s position is upstream and between those systems. It finds access the existing program has not brought under control, enriches it with ownership and risk context, and carries a decision back into remediation. That is why CyberArk is both a major platform in the same identity universe and a named partner. The joint product helps find accounts that should be vaulted, then automates the handoff. With BigID, sensitive-data classification determines which open permissions deserve attention first.
Complex, regulated estates with stale accounts, nested groups, incomplete ownership and a mandate to prove cleanup.
Small, cloud-native teams with simple directories, few legacy systems and enough staff to review access directly.
A SaaS platform plus implementation, support or managed expertise, sold through direct and partner-led enterprise motions.
Manual scripts, spreadsheets, consulting projects or adjacent identity and directory tools with different remediation depth.
The conditions are important. SPHERE’s advantage compounds with organizational mess: hybrid infrastructure, mergers, old Active Directory forests, regulated data and too many people involved in a change. It weakens when the environment is young and legible. Automation also cannot manufacture executive sponsorship. If owners ignore campaigns or security teams lack permission to remediate, discovery simply makes the stalemate more accurately documented.
The janitor becomes the category designer
The company’s language has grown more ambitious. Identity hygiene is becoming identity intelligence, a layer that connects IAM systems and covers human as well as non-human identities. That expansion is sensible: service accounts, machines and AI agents multiply faster than employee directories, while each still needs an owner, purpose and lifecycle. SPHERE was named a representative vendor in Gartner’s emerging Identity Visibility and Intelligence Platforms category, according to the company’s 2026 announcement.
Yet SPHERE is most persuasive when it stays close to the janitor metaphor. Hygiene is repetitive. It is preventive. Nobody applauds the absence of a permissions incident, and the work is never permanently finished. A startup cannot make that glamorous without sounding silly. It can make it measurable, safer and much less manual.
That is the durable lesson from Lehman. The flashy systems got the attention, but the tangled permissions determined whether assets could be separated without exposing the wrong data. Sixteen years after SPHERE’s founding, companies are adding AI agents to environments that still contain forgotten groups and accounts. Before the robots receive keys, someone has to label the doors.