IT CanvassTalk to an advisor
Core concepts · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · intermediate

Access governance

Access governance covers how access is requested, approved, reviewed and revoked, the day-to-day machinery of least privilege.

Quick answer

Access governance is the request-approve-review-revoke machinery of IGA. In SailPoint, users request roles or entitlements through a self-service catalog, approvers decide, access is provisioned, and it is later reviewed in certifications and removed when no longer needed.

Key takeaways
  • Self-service access request from a catalog
  • Multi-level, policy-aware approvals
  • Provisioning on approval, revocation on review
  • Access history for every identity
  • Ties requests, policy and certification together

Access governance is the discipline of ensuring that access across the enterprise is appropriate, controlled and continuously reviewed. It is the umbrella over roles, certifications, policy and requests, and it is, in a sense, the whole point of SailPoint.

What access governance means

Where provisioning and aggregation move access data, governance is the layer of judgement over it: deciding what access should exist, granting it through controlled processes, reviewing it periodically, and removing what is no longer justified. It turns raw access data into managed, defensible access.

The pillars

  • Roles, express access in business-meaningful terms.
  • Access requests, a controlled channel for granting access.
  • Certifications, periodic review and attestation.
  • Policy (SoD), prevent and detect toxic combinations.
  • Lifecycle automation, keep access aligned to status.

Why it matters

Without governance, access sprawls, audits fail and breaches spread. Access governance is what lets an organisation answer, confidently and with evidence, who has access to what and why, which is exactly what regulators, security teams and boards demand.

Common pitfalls

  • Automating grants but not reviews, so sprawl continues.
  • Governing raw entitlements instead of roles.
  • Treating governance as a project rather than an ongoing programme.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Access governance centres on?

Frequently asked questions

What does the term access governance refer to in SailPoint?
Access governance is the discipline of ensuring that access across the enterprise is appropriate, controlled and continuously reviewed. It is the umbrella over roles, certifications, policy and requests, and it is, in a sense, the whole point of SailPoint.
What do auditors expect from access governance?
Access governance is what lets an organisation answer, confidently and with evidence, who has access to what and why, which is exactly what regulators, security teams and boards demand.
What else is worth knowing about access governance?
Where provisioning and aggregation move access data, governance is the layer of judgement over it: deciding what access should exist, granting it through controlled processes, reviewing it periodically, and removing what is no longer justified.
What tends to go wrong with access governance?
Automating grants but not reviews, so sprawl continues. Governing raw entitlements instead of roles. Treating governance as a project rather than an ongoing programme.
Want this with a live instructor and a lab tenant?
SailPoint IGA training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support