Start with Identity
← Guides
Fundamentals · Beginner

What Is Identity Governance and Administration (IGA)?

By SWI Community Team · Updated 2026-08-29 · 6 min

Identity Governance and Administration (IGA) answers a deceptively hard question: who has access to what, why, and should they still have it? It is the control plane that keeps access correct and auditable over time.

Core functions

  • Access requests and approvals with a clear trail.
  • Access certifications (periodic reviews) so managers confirm their people still need what they have.
  • Provisioning and deprovisioning across connected systems.
  • Separation of duties (SoD) to prevent toxic combinations of access.
  • Role management to keep entitlements understandable.

Why it matters

Access tends to accumulate. People change roles, projects end, and permissions linger. That drift is a top audit finding and a real breach risk. IGA exists to detect and reverse it, which is why it is central to compliance with SOC 2, ISO 27001, and similar frameworks. See our audit preparation guide.

IGA vs adjacent tools

IAM handles authentication and SSO; IGA handles governance. In the cloud, CIEM does entitlement right-sizing, and PAM governs privileged accounts specifically.

Why IGA programs stall

The uncomfortable pattern is that governance failures are almost never product failures:

  • Identity data quality. The HR system, the directory, and the applications disagree about who exists and which accounts belong to whom. Reconciliation is a project in its own right and it happens whether or not you budget for it.
  • Connector coverage for the long tail. Governance demos well against Active Directory. It struggles against the mainframe, the ERP with no modern API, and the homegrown application whose owner left.
  • Rubber-stamped certification. Show a manager APP_FIN_GL_RW_PROD and they approve it. Campaigns that produce real revocations translate entitlements into business language and show usage data alongside the grant.
  • Movers. Joiners and leavers are handled; internal transfers accumulate entitlements from every role a person has ever held. This is the most common audit finding in the discipline.

What good looks like

A working governance program can answer four questions without a project: who has access to this system and why, what changed in the last 30 days, which entitlements have gone unused for six months, and who owns this service account. Measure campaigns on revocation rate rather than completion rate, because completion measures compliance theatre and revocation measures risk reduction.

The non-human gap

Service accounts, workloads, and now AI agents outnumber employees in most environments and appear in almost no certification campaign, because there is no manager to attest for them. Ownership assignment is the prerequisite, and it is where the category is expanding: SailPoint acquired Entro Security in June 2026 specifically to extend governance to non-human identities. See what is non-human identity.

Where to start

Where to start

Browse IGA platforms, compare SailPoint vs Saviynt, or read how to choose an IGA platform.

Frequently asked questions

What is IGA?
IGA stands for Identity Governance and Administration: the policies and processes for requesting, approving, reviewing, and certifying access so it stays appropriate over time.
What is the difference between IGA and IAM?
IAM handles the mechanics of authentication and access. IGA adds the governance layer of certifications, access requests, and policy enforcement.
What is an access certification?
A periodic review where managers or resource owners confirm that users still need the access they hold, removing anything no longer justified.
Last reviewed By SWI Community TeamSuggest a correctionHow we research