Best of breed IGA is an identity governance approach that uses a dedicated governance solution rather than relying only on a broader IAM platform. The model is chosen when organisations need stronger lifecycle control, better integration, deeper automation, and more flexible governance across hybrid and third-party environments.
What Best of Breed IGA Means in Practice
Best of breed IGA is not just a vendor preference, it is an architecture choice. The organisation is separating identity governance from the broader IAM layer so governance, reviews, entitlement management, and lifecycle control can be handled by a dedicated platform.
That distinction matters because governance needs often expand faster than core access management needs. A dedicated IGA tool can sit closer to business roles, hybrid applications, and cross-system entitlements, while broader IAM platforms often optimise for authentication and access delivery.
Why Organisations Choose Best of Breed IGA
The usual reason is depth. Best of breed IGA is selected when teams need stronger joiner-mover-leaver automation, better application connectors, more flexible approval workflows, and more complete access review processes than a bundled platform provides.
It is also common where governance must span cloud services, on-prem systems, and third parties. In those environments, a single IAM suite may handle user access well, but still fall short on recertification design, role engineering, or entitlement modelling across varied sources.
For many teams, the decision is less about replacing IAM than about strengthening the governance layer around it. The IAM and IGA Basics guide is useful here because it clarifies where authentication and access delivery end, and where governance begins.
Core Capabilities Behind the Model
Best of breed IGA usually stands out in four areas: lifecycle orchestration, entitlement visibility, access certification, and policy enforcement. Those are the functions that turn identity data into governance decisions rather than just access events.
Lifecycle control is especially important because governance fails when provisioning and deprovisioning lag behind business change. The Joiner-Mover-Leaver (JML) Guide shows why automation matters when access must change quickly and consistently across many systems.
Role design and segregation of duties are also central. A best of breed IGA platform is often chosen to reduce role sprawl, support cleaner entitlement models, and detect toxic combinations before they become control failures. The Role Mining and Role Design Guide and the Segregation of Duties (SoD) Guide both map to those governance needs.
When the Best of Breed Model Becomes the Better Fit
This model tends to make sense when the organisation has many applications, high change volume, or strong audit expectations. It is especially relevant where governance must keep pace with hybrid infrastructure, external partners, and non-standard entitlement structures.
The trade-off is complexity. A best of breed IGA program only works well if identity data, ownership, review workflows, and deprovisioning logic are kept coherent across systems. Without that discipline, the organisation can create a strong governance tool but still leave weak control coverage.
The procurement decision itself is often where teams need the most clarity. The IGA Buyer’s Guide is relevant because it frames the evaluation around lifecycle, connectors, reviews, roles, and governance fit rather than generic feature lists.
Risk and Threat Considerations
Best of breed IGA reduces governance gaps only if it is implemented with strong integration and ownership. If lifecycle feeds are incomplete or review processes are shallow, the organisation can still end up with orphaned access, privilege creep, and stale entitlements across critical systems.
Failure mechanism: control failure usually appears when the dedicated IGA layer has limited visibility into downstream applications, or when provisioning, recertification, and deprovisioning workflows do not keep pace with real identity change.
Impact: the result can be excessive access, failed audits, delayed revocation, and a larger blast radius when accounts, roles, or entitlements are mismanaged across hybrid and third-party environments.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Best of breed IGA governs account lifecycle and access changes across systems. |
| AC-6 — Least Privilege | IGA exists to reduce excessive access and keep entitlements aligned to job need. | |
| IA-5 — Authenticator Management | IGA depends on managing identity lifecycle inputs and credential-related control state. | |
| Recommendation — Use AC-2 to automate account provisioning, modifications, and disabling through governance workflows. Apply AC-6 to limit entitlements and review standing access for excess privilege. Use IA-5 to govern credential lifecycle and remove stale authenticators when access changes. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Best of breed IGA supports the access control policy and entitlement governance layer. |
| A.5.18 — Access rights | IGA operationalises review, approval, and removal of access rights over time. | |
| A.8.2 — Privileged access rights | IGA helps govern privileged entitlements that require stronger oversight and review. | |
| Recommendation — Define access control rules that the IGA platform enforces across applications and users. Review and revoke access rights on a recurring basis through governed certification processes. Track and recertify privileged access rights with tighter ownership and approval. | ||
| NIST CSF 2.0 | PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and audited | Best of breed IGA directly addresses governed identity and access lifecycle management. |
| PR.AA-05 — Access permissions and authorizations are managed | IGA is the control plane for entitlement management and access authorisation governance. | |
| Recommendation — Issue, review, revoke, and audit identities and credentials through governed lifecycle processes. Manage permissions and authorisations through role, entitlement, and certification controls. | ||
| CIS Controls v8 | CIS-5 — Account Management | IGA strengthens centralized account lifecycle control and access review hygiene. |
| Recommendation — Centralize account lifecycle control and remove dormant or inappropriate access promptly. | ||
Practitioner Guidance
Governance implication: the key question is not whether the platform is broader or narrower, but whether it can enforce accountable ownership for access across the systems that matter. Best of breed IGA should be judged on whether it improves entitlement hygiene, review quality, and lifecycle closure in the actual environment.
What to watch for: the strongest signal of fit is whether the organisation needs governance depth that a general IAM suite cannot deliver cleanly, especially for disconnected applications, complex approval paths, or recurring certification cycles.
Practitioner takeaway: best of breed IGA is most defensible when governance complexity, not branding, is the real problem to solve.
Related resources from NHI Mgmt Group
- What is the difference between best-of-breed IGA and a platform play for identity governance?
- Should organisations choose a single IAM platform or separate best-in-breed tools for IGA and related controls?
- What is the difference between platform consolidation and best-of-breed security?
- Should teams keep best-of-breed tools or consolidate around a platform?