What is Identity Governance and Administration (IGA)?
Identity Governance and Administration (IGA) is a framework of policies and software that controls who has access to what across an organization, and proves that access is appropriate. IGA platforms manage the full identity lifecycle, run access certifications, and enforce separation of duties to meet audit and compliance requirements.
What it does
IGA platforms sit inside the broader Identity and Access Management (IAM) category. They automate the day-to-day work of managing identities and entitlements across every application and system in an organization.
Core functions include:
- Joiner-mover-leaver (JML) lifecycle. Provisioning accounts when someone joins, adjusting access when they change roles, and deprovisioning accounts when they leave.
- Access certifications. Scheduling periodic reviews where managers or application owners confirm that each user still needs their current access. Flagging or revoking access that is not recertified.
- Role management. Defining role-based access control (RBAC) models, detecting role conflicts, and enforcing separation of duties (SoD) policies.
- Access request workflows. Letting users request access through a self-service portal, routing requests for approval, and logging every decision.
- Audit reporting. Producing evidence for auditors that access is reviewed, approved, and revoked on schedule.
Why teams buy it
Compliance frameworks such as SOX, SOC 2, ISO 27001, and HIPAA require organizations to show that access is granted on a least-privilege basis and reviewed regularly. Manual spreadsheet-based reviews do not scale past a few hundred accounts. IGA automates the evidence collection and review process, cutting audit preparation time and reducing the risk of orphaned or over-privileged accounts.
Security teams also use IGA to reduce the blast radius of a compromised account. When access is tightly scoped and regularly reviewed, attackers gain less from any single credential.