Skip to content
IT Canvass
Getting started · Lesson

Why identity governance

Quick answer

Identity governance exists to answer one question at scale, who has access to what, why, and should they still have it. It replaces spreadsheets and ticket queues with policy, automation and evidence.

Key takeaways

  • IGA answers who-has-access-to-what and whether it is appropriate
  • Drivers are audit/compliance, breach risk and operational cost
  • Manual access management does not scale past a few hundred users
  • SailPoint centralizes access data, policy and provisioning

Identity governance and administration (IGA) exists to answer one deceptively hard question at enterprise scale: who has access to what, why, and should they still have it? Before investing time in SailPoint’s mechanics, it is worth understanding the business forces that make IGA not just useful but, for most large organisations, unavoidable.

The problem IGA solves

In a mid-sized enterprise, a single new hire may need dozens of accounts across AD, email, HR, finance and a long tail of SaaS applications. Done by hand, this is slow, inconsistent and impossible to audit. Worse, access accumulates as people change roles and rarely gets removed, so over time everyone ends up with far more access than they need. Multiply that across thousands of people and you have an unmanageable, high-risk sprawl.

The three forces driving IGA

  • Compliance and audit. SOX, HIPAA, GDPR, ISO 27001 and others all demand provable, controlled, periodically-reviewed access. IGA produces that evidence continuously instead of through pre-audit fire drills.
  • Security and breach risk. Over-privileged and orphaned accounts are prime attack surface; least privilege and prompt deprovisioning shrink the blast-radius of any compromise.
  • Operational cost. Manual access management does not scale, automating onboarding, offboarding and requests saves enormous, ongoing effort.

What governance adds over a directory

A directory stores access; governance layers policy, review and automation over it. Roles define what a job needs, certifications re-check access periodically, SoD rules block toxic combinations, and every grant leaves an audit trail. SailPoint is the control plane that makes all of this happen automatically.

Why it cannot be done with spreadsheets

Manual, spreadsheet-based access management does not scale past a few hundred users, is inconsistent between teams, and produces no reliable audit trail as roles and staff change. The moment access volume and regulatory scrutiny grow, a governance platform becomes the only viable option.

Common pitfalls

  • Treating IGA as a tool purchase rather than a programme with process and ownership.
  • Automating access grants but not removals, so sprawl continues.
  • Ignoring the business/compliance drivers and building technology without purpose.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. What core question does IGA answer?

    • A. Who has access to what, why, and whether they should still have it.
    • B. Compliance and audit pressure, breach and insider risk, and the operational cost of manual access management.
    • C. It does not scale, is inconsistent, and produces no reliable audit trail as roles and staff change.
    Show answer

    A. Who has access to what, why, and whether they should still have it.

    Who has access to what, why, and whether they should still have it.

  2. Why not manage access with spreadsheets?

    • A. It does not scale, is inconsistent, and produces no reliable audit trail as roles and staff change.
    • B. Who has access to what, why, and whether they should still have it.
    • C. Compliance and audit pressure, breach and insider risk, and the operational cost of manual access management.
    Show answer

    A. It does not scale, is inconsistent, and produces no reliable audit trail as roles and staff change.

    It does not scale, is inconsistent, and produces no reliable audit trail as roles and staff change.

  3. What are the main drivers for IGA?

    • A. Who has access to what, why, and whether they should still have it.
    • B. It does not scale, is inconsistent, and produces no reliable audit trail as roles and staff change.
    • C. Compliance and audit pressure, breach and insider risk, and the operational cost of manual access management.
    Show answer

    C. Compliance and audit pressure, breach and insider risk, and the operational cost of manual access management.

    Compliance and audit pressure, breach and insider risk, and the operational cost of manual access management.

Frequently asked questions

What does the term Why identity governance refer to in SailPoint?

Identity governance and administration (IGA) exists to answer one deceptively hard question at enterprise scale: who has access to what, why, and should they still have it?

What do auditors expect from Why identity governance?

Compliance and audit. SOX, HIPAA, GDPR, ISO 27001 and others all demand provable, controlled, periodically-reviewed access. IGA produces that evidence continuously instead of through pre-audit fire drills. Operational cost.

What is another point to note about Why identity governance?

In a mid-sized enterprise, a single new hire may need dozens of accounts across AD, email, HR, finance and a long tail of SaaS applications.

What tends to go wrong with Why identity governance?

Treating IGA as a tool purchase rather than a programme with process and ownership. Automating access grants but not removals, so sprawl continues. Ignoring the business/compliance drivers and building technology without purpose.
CallWhatsAppEnquire