The reference desk / In practice

IGA

Processes and tools for reviewing who should have which access and removing what is no longer justified.

Identity governance and administration

What it means

Identity governance and administration asks who should have access, why they should have it, who approved it, and when it should end. It connects business responsibility to account and permission administration. Request workflows, access reviews, role design, and removal of unjustified access are typical parts of the capability.

The quality of the decision matters more than the number of approvals collected. A reviewer needs to understand what a permission allows and whether it fits the person's current work. Governance becomes effective when an approved removal reaches the target system and someone verifies the result, rather than ending with a checked box.

AN ILLUSTRATIVE SCENARIO

A finance role change

An employee moves from accounts payable to financial planning. Their new duties need budget reports but no longer require changing supplier bank details. A governance review presents those permissions with plain-language descriptions and identifies the application owner. The owner approves removal of the old payment-related access. The administrator applies the change, and a follow-up check confirms the employee can still use budget reports while the old permission is gone. The review also checks inherited access through groups.

Put it to work

  1. Connect identities to an authoritative record of their role, sponsor, and status, including contractors and nonhuman identities with named owners.
  2. Provide reviewers with understandable permissions, recent relevant context, and a clear retain-or-remove decision; prioritize access with significant consequences.
  3. Track each removal through implementation and verification, and revisit role designs that repeatedly grant more access than people need.

How to check your work

Sample a completed review and compare its decisions with current application permissions. You should be able to show that retained access has a reason and removed access is actually unavailable.

Connect the ideas

  • IAM

    The capability for creating identities, authenticating them, authorizing actions, and managing their lifecycle.

  • Privilege creep

    The slow accumulation of standing access after the original job that justified it has ended.

  • Least privilege

    Granting each identity only the actions, objects, and time window required for the current job.

  • PAM

    Controls that broker, record, and constrain powerful administrative identities and sessions.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.