IGA
Identity Governance and Administration. The discipline of managing who has access to what, why, and for how long. Covers access certification, segregation of duties, joiner-mover-leaver lifecycle, and audit reporting.
IGA is the least glamorous and most audited part of identity, and the discipline where tooling helps least without process. The recurring failure is buying a platform to answer "who has access to what" in an environment where the authoritative data is spread across an HR system, a directory, and dozens of applications with no consistent notion of a user. Connector coverage and data quality decide the outcome, not the product.
See also: what is IGA, access certification, joiner-mover-leaver, IGA vendors
Related on Start with Identity
- GlossaryCIAM
Customer Identity and Access Management. The identity stack for end users of a product, distinct from workforce IAM. CIAM optimizes for self-service signup, con
- GlossaryDeprovisioning
Removing access when a user leaves or changes roles. Failed deprovisioning leaves orphaned accounts that auditors flag and attackers exploit. SCIM with HR-drive
- GlossarySegregation of Duties (SoD)
Ensuring no single user can complete a sensitive process unilaterally, for example, both creating and approving a vendor payment. SoD policies are encoded into
- RankingBest IGA Tools: Top 5 Identity Governance Platforms
The top 5 IGA tools (SailPoint, Saviynt, Veza, Omada, One Identity), scored on a 10-dimension rubric, with where each one wins and who should look elsewhere.
- RankingCompliant IGA Platforms: SOC 2, ISO 27001:2022 & FedRAMP
The most compliance-ready IGA platforms in 2026: SailPoint, Saviynt, Omada, One Identity, and RSA Governance. Ranked on SOC 2 Type II, ISO 27001:2022, FedRAMP,
- GuideHow to Choose an IGA Platform
[Identity Governance](/guides/fundamentals/what-is-iga/) projects succeed or fail on fit and connectors. Here is how to choose well. Access reviews and certific