Skip to main content
Category: Identity & Access Management

Identity Governance and Administration

Also known as: IGA, Identity Governance, IGA solution
Simply put

Identity Governance and Administration (IGA) is a cybersecurity discipline that manages who has access to an organization's systems and data, and whether that access is appropriate. It combines the practical work of creating and updating user accounts with the oversight needed to ensure people only have the access they should. IGA relies on policies, processes, and technology working together to keep account holders' identities and access rights under control.

Formal definition

IGA is a core component of identity and access management (IAM) infrastructure that integrates identity lifecycle management with access governance. It encompasses the policies, processes, and technologies used to provision users, manage account holder identities, and govern access rights across an organization's digital environment. Typical capabilities include automated user provisioning and deprovisioning, access request and approval workflows, access certification and review, and policy enforcement over entitlements. As a governance-focused discipline, IGA supports oversight and accountability for access decisions; however, organizational and legal accountability for those decisions remains with the client organization and its officers, and specific feature coverage may vary by provider.

Why it matters

Access is one of the most persistent sources of organizational risk. When user accounts accumulate more entitlements than a person's role requires, or when access is not removed after someone changes jobs or leaves, the organization is left with excess privilege that expands its attack surface and complicates accountability. Identity Governance and Administration (IGA) matters because it brings structure and oversight to these access decisions, combining the operational work of provisioning and deprovisioning accounts with the governance work of reviewing and certifying whether access remains appropriate over time.

Who it's relevant to

Security and IAM Leaders
CISOs, virtual CISOs, and IAM program owners use IGA to establish oversight and accountability over access decisions across the organization. In a vCISO or fractional engagement, the focus is typically on strategy, policy, and governance design, defining how access is requested, approved, and reviewed, rather than day-to-day administration of the IGA platform, which usually remains with internal operational teams unless explicitly contracted.
Compliance, Audit, and Risk Functions
Teams responsible for governance and audit rely on IGA to produce evidence of who has access to what, how it was approved, and how it is periodically certified. This supports readiness for access-related control expectations, though an IGA deployment supports rather than guarantees any particular audit outcome or certification, and accountability for the underlying decisions remains with the organization.
IT and Identity Operations Teams
IT and identity operations staff carry out the provisioning and deprovisioning work and administer the workflows and policies that IGA enforces. Their engagement is essential because the accuracy of entitlement data and the timeliness of account changes directly affect how well the governance layer performs.
Business and Application Owners
Managers and system owners who approve access requests and participate in access certification are central to IGA's effectiveness. Because these reviewers determine whether access remains appropriate, IGA value depends on their cooperation and their understanding that access is a business-risk responsibility, not solely a technical one.

Inside IGA

Identity Lifecycle Management
The processes for creating, updating, and disabling identities as people join, move within, or leave an organization, often driven by an authoritative source such as an HR system. Sometimes described as joiner-mover-leaver processes.
Provisioning and Deprovisioning
The granting and removal of accounts and entitlements across connected systems. Timely deprovisioning is particularly important to avoid orphaned accounts that retain access after a person's role or employment changes.
Access Request and Approval Workflows
Structured processes through which users request access and designated approvers grant or deny it, typically with a record of who approved what and why.
Access Certification and Recertification
Periodic reviews in which managers or resource owners attest that existing access remains appropriate, helping detect and remove excessive or accumulated privileges.
Role-Based Access and Role Management
The modeling and maintenance of roles that bundle entitlements, intended to simplify assignment and support consistency with least-privilege objectives. Effectiveness depends on how well roles reflect actual business needs.
Segregation of Duties (SoD) Controls
Policy checks that prevent a single individual from holding conflicting entitlements that together could enable fraud or error, with enforcement typically applied during access requests or reviews.
Audit, Logging, and Reporting
Records and reports of access decisions, changes, and reviews used to demonstrate control operation to auditors and to support investigations. These often provide evidence supporting readiness for frameworks such as SOC 2 or ISO 27001.

Common questions

Answers to the questions practitioners most commonly ask about IGA.

Does implementing IGA mean a virtual CISO takes over day-to-day account provisioning and access administration?
No. IGA is a governance and policy discipline, not a set of operational tasks a virtual CISO performs by hand. A vCISO typically helps define access policies, ownership models, certification cadences, and the requirements an IGA program should meet, but the hands-on administration such as creating accounts, running access reviews in a tool, or configuring connectors generally sits with internal IT, identity administrators, or a contracted service provider unless the engagement explicitly includes that work. Accountability for who has access to what usually remains with the client organization and its officers.
Is IGA the same thing as an identity provider or single sign-on solution?
Not exactly, though the terms are often conflated. Access management technologies such as single sign-on and identity providers focus on authenticating users and granting access at login. IGA focuses on the governance layer: defining who should have access, why, for how long, and providing the review, certification, and audit trail behind those decisions. In many environments the two work together, but treating IGA as merely an SSO feature overlooks its role in access certification, segregation of duties, and lifecycle governance. A vCISO can help clarify where one discipline ends and the other begins for a given organization.
How would a virtual CISO typically approach starting an IGA program?
In many engagements a vCISO begins with governance rather than tooling: identifying critical systems and data, mapping who owns access decisions, and assessing current joiner-mover-leaver processes. From there they often help define access policies, review cadences, and roles before recommending or scoping technology. The specific approach may vary by provider and depends heavily on organizational maturity, available stakeholder access, and how well existing identity data is documented.
How does an IGA effort relate to compliance frameworks a virtual CISO might reference?
Frameworks such as ISO 27001, SOC 2, and PCI DSS commonly include expectations around access control, access review, and segregation of duties, and a well-run IGA program can support readiness for those expectations. However, a virtual CISO engagement supports readiness and evidence preparation rather than guaranteeing certification or a passing audit. The outcome depends on client cooperation, accurate identity data, and consistent execution of the processes the vCISO helps define.
What organizational prerequisites make an IGA program more successful?
IGA value often depends on factors outside the technology itself, including defined data and system ownership, cooperation from HR and IT on lifecycle events, a reasonable level of identity data hygiene, and executive sponsorship for access certifications that business owners must actually complete. Where these are weak, a vCISO may recommend addressing foundational governance and stakeholder alignment before investing heavily in an IGA platform.
Who within an organization should be involved in an IGA initiative?
IGA is a cross-functional effort rather than a purely technical one. It typically involves IT and identity administrators, business system owners who approve and review access, HR for accurate joiner-mover-leaver signals, compliance or audit stakeholders, and executive leadership who remain accountable for access risk decisions. A virtual CISO commonly acts as the advisor and coordinator across these groups, directing the program while responsibility for execution and final accountability stays with the client.

Common misconceptions

IGA is just a technical tool that IT installs and turns on.
IGA is a governance and business risk discipline as much as a technology. Its value depends on defined policies, role and ownership decisions, stakeholder cooperation, and ongoing review processes. A tool deployment without governance and business engagement often fails to reduce access risk. Treating IGA as purely technical is a mistake an experienced practitioner would correct.
Implementing IGA makes an organization compliant or certified.
IGA can support readiness for and provide evidence toward frameworks and regulations such as NIST CSF, ISO 27001, SOC 2, HIPAA, or PCI DSS, but it does not by itself confer compliance or certification. Certification requires independent assessment, and compliance depends on the full control environment and how it is operated over time.
A virtual CISO who advises on IGA becomes accountable for access decisions and any resulting breaches.
A virtual, fractional, or advisory CISO typically directs strategy and provides governance guidance for IGA, but legal and organizational accountability for access decisions generally remains with the client organization and its officers unless a contract explicitly specifies otherwise. Hands-on administration and operational execution are usually out of scope unless separately contracted.

Best practices

Anchor IGA to an authoritative identity source, such as an HR system, so that joiner, mover, and leaver events reliably trigger provisioning and, critically, timely deprovisioning.
Prioritize timely removal of access to prevent orphaned accounts and privilege accumulation, and periodically reconcile actual entitlements against what policy intends.
Establish regular access certification cycles with the right resource owners and managers as reviewers, and ensure certifications result in real remediation rather than rubber-stamping.
Define and enforce segregation of duties and least-privilege policies, and validate that role models reflect current business needs rather than historical, accumulated access.
Treat IGA as a governance program with clear ownership, defined scope, and executive sponsorship, recognizing that outcomes depend on organizational maturity and stakeholder cooperation.
Maintain audit-ready logging and reporting so access decisions and reviews can be evidenced, while being clear that such evidence supports, but does not guarantee, compliance or certification.