Abstract
Enterprise buyers increasingly meet their first vendor shortlist inside an AI engine response rather than on a search results page or an analyst grid. This study measures which access management vendors four AI engines name, in what order, and on what evidence, when asked buyer-intent questions about enterprise single sign-on. 10,000 buyer-intent queries were issued to ChatGPT, Gemini, Google AI Overview and Google AI Mode in the United States, Canada, India and Germany in October 2026. The analysed corpus contains 160,000 responses, 1,094,000 cited sources and 934,000 brand mentions. Microsoft and Okta account for 37.8% of all brand mentions, and both appear in every engine and every market. Twelve of 67 brand entities appear in all four engines, while 38 appear in only one. Evidence bases diverge sharply: vendor sites supply 82.4% of ChatGPT’s cited sources but 14.1% of Google AI Overview’s, and pairwise Jaccard overlap of cited domains ranges from 0.05 to 0.24. The leading two brands are identical in all four markets. The results describe a stable two-vendor head on a long, engine-specific tail, built from evidence bases that the four engines barely share.
1. Introduction
1.1 Background
Software evaluation used to begin with a list of links. A buyer searched, opened several vendor pages and analyst summaries, and assembled a shortlist by hand. AI engines compress that step. A single response now names a handful of vendors, orders them, attaches a sentence of rationale to each, and cites a small set of pages as support.
The structural consequence for a vendor is binary at the first step. A vendor named in the response enters the consideration set before any sales contact. A vendor not named has to be discovered by some other route, after a shortlist already exists. Position inside the response matters as well, since a reader encounters the first-named vendor before the others.
These responses are not uniform. Each engine draws on its own retrieval index, applies its own synthesis, and answers differently by market. Measuring one engine therefore describes one slice of the buyer’s exposure. This report measures four engines in four markets under one query set.
1.2 Why this category
Enterprise single sign-on is a suitable instrument for three reasons drawn from the corpus itself. First, the vendor set is mature: the engines converge on a recognisable group of established vendors, led by Microsoft Entra ID and Okta Workforce Identity Cloud, with JumpCloud, Ping Identity and OneLogin named as secondary options. Second, the evaluation criteria are stable and shared. All four engines frame the decision around centralised SSO, automated SCIM provisioning, SAML and OIDC federation, and adaptive or phishing-resistant MFA. Third, the buying question is research-heavy. The query set includes multi-requirement questions (protocol support, provisioning, MFA) and a problem statement written from the IT team’s perspective, the kind of question a buyer brings to an AI engine before contacting vendors.
Stable criteria make differences between engines easier to read. When every engine agrees on what matters, divergence in which vendors are named reflects retrieval and synthesis rather than disagreement about the category.
1.3 Contribution
This study provides a side-by-side measurement of four AI engines answering the same enterprise SSO questions in the same four markets within one collection window. It reports brand visibility, product-level naming, first-mention position, citation volume, source mix, link decay and cross-engine source overlap on a common set of definitions. It quantifies how much of the vendor shortlist is shared across engines and how much is specific to one engine. A single-engine measurement cannot show either the shared head or the engine-specific tail, and cannot show that the engines rest their responses on largely separate evidence.