What is identity governance and administration?

Identity governance and administration (IGA) covers two related things: the lifecycle of an account from creation to removal, and the periodic review that confirms the access an account holds is still the access it should have.

Access management asks "may this person do this now." Governance asks "should this person still be able to do this at all," and it asks on a schedule rather than at the moment of use.

Joiner → Mover → Leaver
Joiner → Mover → Leaver

The two halves

Administration is lifecycle. An account is created when someone joins, changed when they move, and disabled when they leave. The failure mode is the middle step: people change roles, gain new access, and keep the old.

Governance is review. On a cycle, someone who understands the business confirms that each person's access is still appropriate, and either attests to it or revokes it. The output is a record that the review happened and what it decided.

Event What should happen What often happens
Joins Access granted for the role Access copied from a colleague, including rights the role does not need
Changes role Old access removed, new access granted New access granted, old access retained
Leaves Account disabled the same day Account disabled eventually, if someone tells IT
Review cycle Each access confirmed or revoked by an owner Review approved in bulk to clear the queue

Why it matters

Accumulated access is what turns one compromised account into broad reach. An account that has collected rights across six role changes is more valuable to an attacker than any individual grant ever was.

Reviews also produce something an assessor can read. "We review access quarterly" is a claim. A record showing who reviewed what, when, and what they revoked is evidence.

Where frameworks ask for it

Framework Requirement
NIST SP 800-53 AC-2 Account Management, including AC-2(3) disable inactive accounts and review enhancements; PS-4 Personnel Termination; PS-5 Personnel Transfer
NIST SP 800-171 3.1.1 limit system access to authorized users; 3.1.2 limit access to permitted transactions and functions
CMMC Level 2 AC.L2-3.1.1, AC.L2-3.1.2
ISO/IEC 27001 Annex A controls on access rights and review of user access rights
SOC 2 Logical access provisioning, modification, and removal

What the kit does

Item

  • Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned.
  • Discover systems, accounts, and privileged group membership, so a review starts from the current state rather than a spreadsheet
  • Active Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and SAML 2.0 providers
  • Assign documents to named people and collect a signed attestation
  • Current State Compliance, a ledger of control findings with rescan
  • Analysis of cloud account permissions
  • Run the joiner, mover, and leaver process across applications the kit does not manage

The scope statement matters here and is stated plainly: lifecycle and review cover kit accounts today. Governance across other applications is planned and is not shipping. Read the availability word, not the category name.

Common questions

Is IGA the same as single sign-on?

No. Single sign-on is authentication: proving who is asking. IGA is about which access that identity holds and whether it is still right.

Is IGA the same as privileged access management?

No. Privileged access management governs a privileged session as it happens. IGA governs the entitlement that made the session possible.

How often should access be reviewed?

Frameworks rarely name an interval. Quarterly is common for privileged access and annually for ordinary access. The useful test is whether a reviewer can actually judge each item in the time they have, because a review that is rubber-stamped produces a record that misleads.

Does the kit do full IGA today?

No. Lifecycle and periodic access review cover kit accounts. Wider governance is planned. See capabilities for the availability words on every row.

Related pages

Sources