What is identity governance and administration (IGA)?

Identity governance and administration (IGA) is the class of IAM platform that manages the lifecycle of identities and their access: provisioning and deprovisioning accounts, access requests and approvals, certification campaigns, and audit reporting. IGA answers who has access to what, whether they should, and who approved it — the system of record auditors ask for. Deploying IGA to full coverage is a separate, harder problem than buying it.

Also known as: identity governance · IGA platform · access certification · identity lifecycle management

What IGA actually does

Joiner-mover-leaver automation grants and revokes access as people arrive, change roles and leave. Access request workflows put approvals on record. Certification campaigns force owners to re-confirm access periodically. Role and policy models keep entitlements structured, and audit reporting turns all of it into evidence. Every regulated enterprise needs these functions; most buy a major IGA platform to get them.

The deployment gap

IGA value depends entirely on connected applications — an app outside the platform is invisible to governance. Connectors cover the popular SaaS layer; the long tail of legacy and homegrown systems becomes per-app integration projects, which is where programs stall and services bills climb to multiples of the license. Identity-operations platforms like Way Security attack exactly this layer, automating onboarding and ongoing operations so the IGA investment actually reaches the whole estate.

// In the Cyberdis portfolio

Way Security connects the apps that keep IGA from reaching full coverage — distributed by Cyberdis.

// FAQ

Common questions.

What is the difference between IAM and IGA?

IAM is the umbrella for all identity and access technology. IGA is the governance slice: lifecycle, requests, certifications and audit. Access management (SSO, MFA) handles the moment of login; IGA handles whether the access should exist at all.

What is the difference between IGA and PAM?

PAM (privileged access management) secures the most powerful accounts with vaulting and session control. IGA governs everyone’s access at lifecycle level. They complement each other, and auditors typically expect both.

Why do IGA deployments take years?

Per-application integration labor. Each connected app needs connectors, data mapping and process design, and enterprises run hundreds of apps that are not in any connector catalog. Automating that onboarding is the highest-leverage fix — see our explainer on why IAM implementations stall.

Related explainers: What are identity operations?Why do IAM implementations stall?What are non-human identities (NHI)?

Weighing approaches? AI-powered IAM automation vs consulting-led implementation