An IGA programme is a structured initiative for Identity Governance and Administration. It focuses on access provisioning, reviews, approvals, role management, and lifecycle controls so organisations can answer who has access, why they have it, and whether that access still makes sense.
Expanded Definition
An IGA programme is the operating model behind identity governance and administration: the policies, workflows, evidence, and ownership structures that keep access decisions explainable and reviewable. It usually spans joiner, mover, and leaver processes, role engineering, access request approvals, periodic recertification, segregation of duties checks, and exception handling. In practice, the programme is less about one tool and more about repeatable control over identities, entitlements, and the business justification for access.
In NHI environments, the same logic extends beyond employees to service accounts, API keys, workload identities, and agentic systems that can act autonomously. That is where definitions vary across vendors, because some platforms treat IGA as human-centric while others extend governance to machine identities and secrets workflows. NHI Management Group treats the broader interpretation as operationally necessary, especially when access is non-interactive and long-lived. The most common misapplication is treating IGA as a quarterly certification exercise, which occurs when organisations focus on review tickets instead of continuously governing entitlement creation, change, and removal.
Examples and Use Cases
Implementing an IGA programme rigorously often introduces process overhead, requiring organisations to weigh stronger governance and auditability against slower access delivery and more coordination across application owners.
- Automating new-hire access so a manager and app owner approve only the minimum roles needed on day one, with explicit expiration for exceptions.
- Running periodic access recertification for privileged users, then revoking stale entitlements that no longer match current job duties or risk posture.
- Extending governance to service accounts by inventorying where credentials are used, who owns them, and whether rotation and offboarding are enforced. NHI Mgmt Group reports that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs.
- Mapping roles to business functions so access requests are approved against a role model rather than granted ad hoc through manual exception paths, a practice aligned with the governance emphasis in NIST Cybersecurity Framework 2.0.
- Embedding segregation-of-duties checks into change workflows so conflicting access combinations are blocked before they become an audit finding or fraud risk.
Why It Matters in NHI Security
IGA programmes matter in NHI security because machine identities accumulate quietly, often with standing access, weak ownership, and poor lifecycle control. That combination creates hidden privilege paths that bypass human-centric review processes. NHI Management Group notes that 97% of NHIs carry excessive privileges, and 80% of identity breaches involve compromised non-human identities such as service accounts and API keys, underscoring how access governance failures become security incidents rather than mere compliance gaps.
The risk is amplified when secrets, certificates, and tokens are issued outside controlled workflows or never retired after use. An effective programme ties entitlement approval to ownership, rotation, revocation, and evidence retention so audit and security teams can answer who has access, why it exists, and when it should end. This is also where alignment with the NIST Cybersecurity Framework 2.0 becomes practical, because governance must be translated into accountable control execution. Organisations typically encounter the full cost of an IGA gap only after a breach, audit failure, or abandoned service account is discovered, at which point the IGA programme becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Governance, inventory, and lifecycle control are core to NHI identity management. |
| NIST CSF 2.0 | PR.AC-1 | Access provisioning and revocation map directly to controlled identity and access processes. |
| NIST Zero Trust (SP 800-207) | Zero Trust requires continuously verified access, which IGA programmes operationalize. | |
| NIST SP 800-63 | IAL2 | Identity proofing and assurance levels inform governance for identity lifecycle decisions. |
| OWASP Agentic AI Top 10 | AGENT-03 | Agentic systems need governed tool access, approval, and revocation like other identities. |
Use IGA evidence and lifecycle controls to continuously validate identity trust and entitlement scope.
Related resources from NHI Mgmt Group
- How should organisations sequence an IGA programme to reduce failure risk?
- How should organisations phase an IGA programme without creating more access drift?
- How do teams know if their IGA programme is actually reducing risk?
- Who should own recertification and access review decisions in an IGA programme?