Identity governance
Quick answer
Identity governance (IGA) is the set of policies and processes that ensure the right people have the right access to the right resources, for the right reasons, and that you can prove it. SailPoint delivers IGA through the identity lifecycle, access requests, certifications and separation-of-duties policy.
Key takeaways
- IGA answers who has access, should they, and can you prove it
- Built on least privilege and need-to-know
- Combines lifecycle automation with periodic review
- Policy (SoD) prevents toxic access combinations
- Every decision is auditable for compliance
Identity governance is the overarching discipline this entire course is about: ensuring the right people have the right access to the right resources, for the right reasons, and that this can be proven at any time. SailPoint is the platform that operationalises it.
The core question
All of identity governance reduces to answering, continuously and with evidence, who has access to what, why, and whether they should still have it. Every capability, aggregation, roles, certifications, policy, provisioning, exists to answer some part of that question at enterprise scale.
What governance encompasses
- Visibility, a complete, person-centric picture of access.
- Control, granting access through governed, approved processes.
- Review, periodic certification that access is still appropriate.
- Policy, preventing toxic combinations (SoD) and enforcing least privilege.
- Lifecycle, keeping access aligned to each person’s status.
Why organisations invest
Three forces drive it: compliance (provable, reviewed access for SOX, HIPAA and others), security (least privilege and prompt deprovisioning to limit breach impact), and operational efficiency (automating access at scale). Identity governance is where those three meet.
Governance versus administration
Identity administration provisions and manages accounts; identity governance adds the judgement, policy and review over that access. IGA, identity governance and administration, is the combination, and SailPoint is a leading platform for it.
Common pitfalls
- Buying a tool without a programme, process and ownership.
- Provisioning without governing, access grows unchecked.
- Treating governance as one-off rather than continuous.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
Identity governance ensures the right people have?
- A. Continuous loop. Access is granted, used, reviewed and revoked continuously.
- B. Least privilege. Least privilege limits access to what the role requires.
- C. The right access for the right reasons. IGA is about right access, right reasons, and proving it.
Show answer
C. The right access for the right reasons. IGA is about right access, right reasons, and proving it.
The right access for the right reasons. IGA is about right access, right reasons, and proving it.
Giving only the access a role needs is?
- A. Least privilege. Least privilege limits access to what the role requires.
- B. The right access for the right reasons. IGA is about right access, right reasons, and proving it.
- C. Continuous loop. Access is granted, used, reviewed and revoked continuously.
Show answer
A. Least privilege. Least privilege limits access to what the role requires.
Least privilege. Least privilege limits access to what the role requires.
Governance is best described as a?
- A. Least privilege. Least privilege limits access to what the role requires.
- B. The right access for the right reasons. IGA is about right access, right reasons, and proving it.
- C. Continuous loop. Access is granted, used, reviewed and revoked continuously.
Show answer
C. Continuous loop. Access is granted, used, reviewed and revoked continuously.
Continuous loop. Access is granted, used, reviewed and revoked continuously.