CMPs should handle operational orchestration and evidence collection, while IGA should own identity policy, access certification, and lifecycle decisions. That split avoids overloading the cloud platform with governance responsibilities it was not designed to carry. It also keeps human, NHI, and workload access under one governance model even when the cloud estate is distributed.
How CMPs and IGA Should Be Divided
CMPs are strongest when they orchestrate cloud operations, collect evidence, and enforce platform-level settings. IGA should own identity policy, access certification, entitlement governance, and lifecycle decisions. That division keeps the cloud management layer focused on execution while the governance layer remains responsible for who gets access, why, and for how long.
The practical test is ownership of the decision, not the data source. A CMP can surface inventory, logs, policy state, and remediation evidence, but it should not become the system of record for role approvals, recertification outcomes, or joiner-mover-leaver decisions. Those are governance decisions that need consistency across cloud, SaaS, and internal platforms.
This separation matters because cloud estates often span multiple accounts, subscriptions, and providers. If governance lives inside each platform tool, access rules fragment quickly. If IGA owns policy centrally, the organisation can apply one access model across human users, service identities, and machine or workload access without forcing the CMP to become an identity governance engine.
Where the Boundary Should Be Drawn in Practice
Use the CMP for telemetry, orchestration, and remediation workflows that depend on cloud context. Use IGA for identity lifecycle, access requests, approvals, certification campaigns, separation of duties, and policy exceptions that must be reviewed consistently over time. In other words, the CMP can tell you what exists and help change it, while IGA decides whether the access should exist at all.
That boundary also helps with evidence quality. CMP-collected logs and configuration data are valuable inputs, but they do not replace governance records. A certification decision needs an accountable approval trail, not just a snapshot of current entitlements. When access is time-bound, inherited, or role-based, the governance decision should live where it can be audited and re-used across systems.
For cloud-native access, this split is especially important when entitlements move quickly. A CMP may detect drift or misconfiguration faster than a manual review, but IGA should still control the authoritative approval path. That is what prevents operational tooling from quietly becoming the place where policy is defined by accident.
What Good Division of Responsibility Looks Like
A clean operating model usually has three layers. First, the CMP handles provisioning mechanics, evidence collection, and response actions inside the cloud estate. Second, IGA manages identity source data, policies, certification, and lifecycle governance. Third, security or platform teams define the control objectives and exceptions that both systems must satisfy.
When this is working well, cloud teams can move fast without being allowed to self-authorise permanent access. Approvals are traceable, recertification is periodic, and deprovisioning is tied to authoritative lifecycle events rather than local platform cleanup. For distributed estates, that central policy layer is what keeps access decisions aligned across regions, accounts, and providers.
It also reduces governance drift for non-human access. Service accounts, workload identities, and automation credentials need the same decision discipline as human access, even if the CMP is the place where the technical action occurs. The governance question remains the same: who owns it, what can it do, and when should it lose access?
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity & Access Management | CMP and IGA split maps directly to cloud identity and access governance. |
| Recommendation — Use IAM controls to separate cloud execution from authoritative access governance. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | IGA-owned lifecycle decisions include credential and authenticator governance. |
| AC-2 — Account Management | Account lifecycle, approvals, and revocation sit with IGA rather than CMPs. | |
| Recommendation — Manage credential lifecycle centrally and keep cloud tools out of auth control. Route account provisioning and revocation through governed identity workflows. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The split is an access-control design choice between operational and governance systems. |
| A.5.16 — Identity management | IGA should remain the authoritative identity lifecycle and entitlement owner. | |
| A.5.18 — Access rights | Certification and review of rights are core IGA responsibilities in this split. | |
| Recommendation — Define access control ownership so policy decisions stay with the governance layer. Assign identity lifecycle ownership to IGA and keep CMPs as execution systems. Review and certify access rights through IGA, not cloud management tooling. | ||
Practitioner Guidance
What to prioritise: Define the authoritative owner for each decision type before integrating tools. If a decision changes identity status, entitlement, or certification outcome, it belongs in IGA; if it changes cloud configuration or gathers operational evidence, it belongs in the CMP.
What to verify: Check that the CMP can supply evidence without becoming the approval system. The clearest sign of healthy design is that access can be reviewed and revoked centrally even when the cloud team is operating across multiple accounts or providers.
Common mistake: Treating cloud automation as a substitute for governance. Fast provisioning is useful, but if the same tool also becomes the place where access policy is defined, reviewed, and audited, the organisation usually ends up with inconsistent entitlements and weak recertification discipline.
Practitioner takeaway: Let the CMP execute and observe, let IGA decide and govern. If the same platform is doing both, the organisation has probably collapsed operational control and governance into one layer, which is where access sprawl usually starts.
Related resources from NHI Mgmt Group
- How should security teams divide responsibility between IAM and IGA?
- How should organisations divide responsibility between AI-driven correlation and human decision-making in insider risk?
- How should organisations divide responsibility between internal teams and outside experts during a breach?
- How should organisations divide responsibility between SIEM, XDR and ITDR?