Access governance
Quick answer
Access governance is the request-approve-review-revoke machinery of IGA. In SailPoint, users request roles or entitlements through a self-service catalog, approvers decide, access is provisioned, and it is later reviewed in certifications and removed when no longer needed.
Key takeaways
- Self-service access request from a catalog
- Multi-level, policy-aware approvals
- Provisioning on approval, revocation on review
- Access history for every identity
- Ties requests, policy and certification together
Access governance is the discipline of ensuring that access across the enterprise is appropriate, controlled and continuously reviewed. It is the umbrella over roles, certifications, policy and requests, and it is, in a sense, the whole point of SailPoint.
What access governance means
Where provisioning and aggregation move access data, governance is the layer of judgement over it: deciding what access should exist, granting it through controlled processes, reviewing it periodically, and removing what is no longer justified. It turns raw access data into managed, defensible access.
The pillars
- Roles, express access in business-meaningful terms.
- Access requests, a controlled channel for granting access.
- Certifications, periodic review and attestation.
- Policy (SoD), prevent and detect toxic combinations.
- Lifecycle automation, keep access aligned to status.
Why it matters
Without governance, access sprawls, audits fail and breaches spread. Access governance is what lets an organisation answer, confidently and with evidence, who has access to what and why, which is exactly what regulators, security teams and boards demand.
Common pitfalls
- Automating grants but not reviews, so sprawl continues.
- Governing raw entitlements instead of roles.
- Treating governance as a project rather than an ongoing programme.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
Access governance centres on?
- A. Policy (SoD) check. Requests are checked against SoD and risk before approval.
- B. Provisioned. Approval triggers provisioning or a manual work item.
- C. Request, approve, review, revoke. It is the request-approve-review-revoke machinery of IGA.
Show answer
C. Request, approve, review, revoke. It is the request-approve-review-revoke machinery of IGA.
Request, approve, review, revoke. It is the request-approve-review-revoke machinery of IGA.
Before routing a request, IdentityIQ runs a?
- A. Request, approve, review, revoke. It is the request-approve-review-revoke machinery of IGA.
- B. Policy (SoD) check. Requests are checked against SoD and risk before approval.
- C. Provisioned. Approval triggers provisioning or a manual work item.
Show answer
B. Policy (SoD) check. Requests are checked against SoD and risk before approval.
Policy (SoD) check. Requests are checked against SoD and risk before approval.
Approved access is then?
- A. Provisioned. Approval triggers provisioning or a manual work item.
- B. Policy (SoD) check. Requests are checked against SoD and risk before approval.
- C. Request, approve, review, revoke. It is the request-approve-review-revoke machinery of IGA.
Show answer
A. Provisioned. Approval triggers provisioning or a manual work item.
Provisioned. Approval triggers provisioning or a manual work item.