Identity Governance and Administration (IGA)
Identity Governance and Administration (IGA) is the organizational and technical control of digital identities and their access rights over the entire lifecycle. IGA ensures that employees, external partners and technical accounts receive exactly the permissions they need for their tasks – and that these rights are reliably adjusted or revoked when roles change or people leave.
Typical IGA processes are recertifications, role management, access requests and audit reporting. The aim is for users to access only the resources they actually need, and for this to be documented traceably at all times. Especially in regulated industries, identity governance is a decisive factor for compliance with legal requirements. IGA thus complements classic identity and access management with control, verification and evidence functions and reduces risks from superfluous or outdated permissions.
In interaction with Identity Security, IGA forms the governance layer of identity management: while operational systems control authentication and access, IGA ensures that permissions are assigned correctly, reviewed regularly and demonstrated in an audit-proof manner.