Identity governance
Identity governance is the discipline of controlling and proving who has access to what, and why, across an organisation.
Identity governance (IGA) is the set of policies and processes that ensure the right people have the right access to the right resources, for the right reasons, and that you can prove it. SailPoint delivers IGA through the identity lifecycle, access requests, certifications and separation-of-duties policy.
- IGA answers who has access, should they, and can you prove it
- Built on least privilege and need-to-know
- Combines lifecycle automation with periodic review
- Policy (SoD) prevents toxic access combinations
- Every decision is auditable for compliance
Identity governance is the overarching discipline this entire course is about: ensuring the right people have the right access to the right resources, for the right reasons, and that this can be proven at any time. SailPoint is the platform that operationalises it.

The core question
All of identity governance reduces to answering, continuously and with evidence, who has access to what, why, and whether they should still have it. Every capability, aggregation, roles, certifications, policy, provisioning, exists to answer some part of that question at enterprise scale.
What governance encompasses
- Visibility, a complete, person-centric picture of access.
- Control, granting access through governed, approved processes.
- Review, periodic certification that access is still appropriate.
- Policy, preventing toxic combinations (SoD) and enforcing least privilege.
- Lifecycle, keeping access aligned to each person’s status.
Why organisations invest
Three forces drive it: compliance (provable, reviewed access for SOX, HIPAA and others), security (least privilege and prompt deprovisioning to limit breach impact), and operational efficiency (automating access at scale). Identity governance is where those three meet.
Governance versus administration
Identity administration provisions and manages accounts; identity governance adds the judgement, policy and review over that access. IGA, identity governance and administration, is the combination, and SailPoint is a leading platform for it.
Common pitfalls
- Buying a tool without a programme, process and ownership.
- Provisioning without governing, access grows unchecked.
- Treating governance as one-off rather than continuous.
Authoritative sources
- SailPoint IdentityIQ documentation - Governance, certifications and policy reference
- NIST SP 800-53 (AC family) - Access control standards governance maps to