Access governance
Access governance covers how access is requested, approved, reviewed and revoked, the day-to-day machinery of least privilege.
Access governance is the request-approve-review-revoke machinery of IGA. In SailPoint, users request roles or entitlements through a self-service catalog, approvers decide, access is provisioned, and it is later reviewed in certifications and removed when no longer needed.
- Self-service access request from a catalog
- Multi-level, policy-aware approvals
- Provisioning on approval, revocation on review
- Access history for every identity
- Ties requests, policy and certification together
Access governance is the discipline of ensuring that access across the enterprise is appropriate, controlled and continuously reviewed. It is the umbrella over roles, certifications, policy and requests, and it is, in a sense, the whole point of SailPoint.
What access governance means
Where provisioning and aggregation move access data, governance is the layer of judgement over it: deciding what access should exist, granting it through controlled processes, reviewing it periodically, and removing what is no longer justified. It turns raw access data into managed, defensible access.
The pillars
- Roles, express access in business-meaningful terms.
- Access requests, a controlled channel for granting access.
- Certifications, periodic review and attestation.
- Policy (SoD), prevent and detect toxic combinations.
- Lifecycle automation, keep access aligned to status.
Why it matters
Without governance, access sprawls, audits fail and breaches spread. Access governance is what lets an organisation answer, confidently and with evidence, who has access to what and why, which is exactly what regulators, security teams and boards demand.
Common pitfalls
- Automating grants but not reviews, so sprawl continues.
- Governing raw entitlements instead of roles.
- Treating governance as a project rather than an ongoing programme.