One Identity Vendor or Many Across a PE Portfolio
A PE firm should not mandate one identity vendor across its portfolio, but it should require each portco to document why it chose Auth0 or Clerk. At the portco level, the decision follows the usual B2B SaaS fundamentals: team size, enterprise SSO needs, and engineering bandwidth.
Both layers deserve their own answer.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
The portco-level decision looks like any other B2B SaaS decision
At the level of a single portfolio company's product, the Auth0 versus Clerk decision comes down to the same fundamentals as anywhere else: team size, whether enterprise SSO is a current sales requirement, and how much engineering bandwidth exists to own a more configurable tool. A portco with a lean engineering team and a self-serve sales motion is usually better served by Clerk's faster path; one with an enterprise sales motion already underway benefits from Auth0's federation depth.
The wrinkle unique to a PE-owned company is that this decision often gets made, or remade, right after a platform investment, when a new operating team arrives and inherits whatever the prior team set up, sometimes without full documentation of why.
Why standardizing across the portfolio is tempting, and where it breaks down
PE firms often push standardization across portfolio companies for systems like accounting platforms or HR software, where the operational efficiency gains are clear and the underlying business needs are similar enough across the portfolio. Identity infrastructure doesn't standardize as cleanly, because a portco's authentication needs are downstream of its specific product and customer base, not a shared back-office function every portco needs in roughly the same shape.
An operating partner used to seeing clean efficiency gains from standardizing a back-office system can reasonably expect the same from identity, and that expectation is worth correcting early rather than after a portco's engineering team has already pushed back on a mandate that doesn't fit its product.
Forcing a portco with enterprise SSO requirements onto Clerk because it's the portfolio standard, or forcing a self-serve portco onto Auth0's heavier configuration because that's what a sister company uses, tends to create friction without the efficiency gain standardization is supposed to deliver.
Where portfolio-level thinking does add real value
What does transfer well across the portfolio is the evaluation process itself: a shared framework for how a portco's operating team should weigh the Auth0-versus-Clerk decision, and a shared vendor relationship for compliance tooling like Vanta or Drata that plugs into either identity provider. This gives the firm's operating partners a consistent lens to evaluate a portco's identity choice without dictating the specific product, which respects that each portco's technical needs genuinely differ.
What comes up in diligence, and why it matters for exit
Whichever tool a portco chose, a future acquirer's technical diligence team will ask about it, specifically how well-documented the configuration is and whether the choice was deliberate or accidental. A portco that can explain, with documentation, why it's on Auth0 or Clerk and how the setup maps to its customer base signals operational maturity in a diligence process that a portco with an undocumented, ad hoc identity setup does not. This is a smaller line item than most diligence findings, but it's the kind of detail that compounds with others into a buyer's overall impression of how well-run the business is.
A decision framework for operating partners
Don't mandate a portfolio-wide identity vendor. Instead, require every portco to document its identity provider choice and the reasoning behind it as part of standard technical hygiene, the same way you'd expect documentation for any other core system. Review that documentation during quarterly technical check-ins, and flag any portco whose setup looks undocumented or accidental rather than deliberate, since that's the actual risk worth managing at the portfolio level, not which specific vendor a given portco happens to use.
Operating partners can apply this in three steps:
- Decline to mandate a single identity vendor across the portfolio, since each portco's needs and engineering capacity differ.
- Require every portco to document its identity provider choice and the reasoning behind it, as it would for any other core system.
- Review that documentation during quarterly technical check-ins, and flag any portco whose setup looks undocumented or accidental.
A carve-out worth naming: shared services and holding-company systems
The one place standardization genuinely does make sense is a shared services layer the firm itself operates, such as a portfolio-wide reporting tool or a holding-company system used by finance staff across multiple portcos. That system isn't downstream of any single portco's product or customer base, it's the firm's own infrastructure, and it's fair to treat it like any other firm-level system decision, choosing one identity provider deliberately rather than letting it inherit whatever a given portco happened to already use.
Keep this carve-out narrow and explicit, though, so it doesn't quietly expand into the argument for standardizing every portco's customer-facing product identity, which is the mandate this whole approach is deliberately avoiding.
What Good Looks Like
A portfolio company operating well here can produce clear documentation of its identity provider choice and configuration on request during a diligence process, and an operating partner overseeing several portcos can name, for each one, whether its identity setup is deliberate and documented or a gap worth flagging.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Vanta works across a portfolio regardless of which identity provider each portco runs, making it a reasonable standardization point even when identity itself isn't.
Drata gives operating partners a consistent way to check on access control hygiene across portcos without dictating their specific identity vendor.
CrowdStrike is a common portfolio-level security standardization point that pairs with whichever identity provider a portco chooses.
Frequently Asked Questions
Should a PE firm mandate one identity vendor across its whole portfolio?
Generally not. Unlike back-office systems, identity infrastructure needs are downstream of each portco's specific product and customer base, so a portfolio-wide mandate tends to create friction without a clear efficiency gain. A shared evaluation framework serves the portfolio better than a shared mandate.
Does a portco's choice of Auth0 versus Clerk affect valuation at exit?
Not directly on its own, but undocumented or accidental technical decisions generally do factor into a buyer's diligence impression of operational maturity. A well-documented, deliberate identity choice, whichever vendor it is, is a small positive signal; an undocumented one is a small negative one.
How often should operating partners review a portco's identity provider setup?
Folding it into existing quarterly technical check-ins is usually sufficient, rather than a dedicated identity-specific review. The goal is catching undocumented or drifting setups early, not micromanaging a technical decision that's genuinely the portco's own team's call to make.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Database Infrastructure for Lower-Middle-Market PE Portfolio Companies
Lower-middle-market PE portfolio companies rolling up acquisitions need consistent, diligence-ready database infrastructure. Here's the comparison.
Standardizing Feature Flags Across a PE Portfolio's Portcos
A PE platform integrating several lower-middle-market portfolio companies benefits from one flag standard. Comparing LaunchDarkly and Split at that level.
SOC 2 Across a PE Portfolio: Vanta, Drata or Secureframe
How a private equity firm should think about rolling SOC 2 out across lower-middle-market portfolio companies, and where Vanta, Drata and Secureframe each fit.
CrowdStrike vs SentinelOne for PE Portfolio Companies
A portco's endpoint fleet is usually several acquired companies' fleets stitched together. A worked example for standardizing on CrowdStrike or SentinelOne.
A Post-Close Security Worksheet for PE Portfolio Companies
A worksheet for standardizing Snyk or GitHub Advanced Security across a private equity portfolio company's engineering team after close.
AWS or Google Cloud for a PE-Backed Portfolio Company Pre-Exit
A decision guide for lower-middle-market PE portfolio company leaders weighing AWS against Google Cloud ahead of a sale or roll-up.