Identity term · last reviewed 2026-08-14
IGA
Also known as: Identity Governance and Administration
IGA is the governance layer that certifies, reviews, and audits who has access to what across every application in a company, sitting on top of the provisioning connectors that create and remove the underlying accounts.
How it works
IGA (Identity Governance and Administration) is the layer that answers "who has access to what, and should they" across every app in a company, not just one. It combines access certification (periodic manager or owner review of who holds what entitlement), access requests with approval workflows, role mining, and audit reporting, sitting on top of the provisioning connectors (often SCIM or proprietary APIs) that actually create and remove accounts. SailPoint and Saviynt dominate enterprise IGA; Okta and Entra ship lighter governance modules aimed at mid-market buyers who do not want a separate platform.
When it matters
IGA matters once a company has enough apps and enough employees that nobody can eyeball who has access to what anymore, typically a few hundred employees and dozens of SaaS apps with sensitive data. It is also a straight line item in SOC 2 and ISO 27001 audits: auditors want evidence of periodic access reviews and reference IGA and workflow tooling by name. Buying a full IGA platform before that scale is premature, most 20-person startups can run access reviews from a spreadsheet and RBAC roles for a year or two. See SOC 2 for Startups.
Common misconceptions
- "IGA is the same as IAM." IAM systems authenticate and authorize users in real time. IGA governs and audits those access decisions over time, using RBAC or ABAC roles as its raw material. You need IAM in place before there is anything for IGA to govern.
- "A SOC 2 audit requires a dedicated IGA tool." Auditors want evidence of a repeatable access review process, not a specific product. A documented quarterly review in a spreadsheet passes for a Series A company; a 2,000-person company needs the automation.
- "IGA is only about compliance." The real payoff is catching orphaned accounts and excess entitlements before they become a breach, compliance evidence is a byproduct of doing that well.
Explained in depth