By NHI Mgmt Group Editorial TeamBased on Zluri: “6 Key Features of Identity Governance & Administration Tools” (March 12, 2026)

TL;DR: IGA tools only improve security when they combine real-time visibility, automated provisioning and deprovisioning, self-service requests, access certification, and audit reporting, according to Zluri. The deeper issue is that access governance fails when entitlements are scattered across SaaS, shadow IT, and service accounts faster than human review can keep up.


At a glance

What this is: This is a feature-level analysis of IGA tools, showing that access risk falls when visibility, automation, self-service, certification, and reporting work together across SaaS, shadow IT, and service accounts.

Why it matters: It matters because IAM teams cannot govern access they cannot see, and manual workflows break down once entitlement volume and change speed exceed human review capacity.


Context

Identity governance and administration works only when teams can see who has access, decide whether it is appropriate, and remove it when it is no longer needed. In SaaS-heavy environments, that becomes difficult because access spreads across applications, service accounts, shadow IT, and disconnected admin processes.

The article’s core argument is that feature selection matters because control failure often comes from missing coverage rather than missing intent. The practical question for IAM and IGA teams is whether a tool can keep up with entitlement discovery, provisioning, certification, and offboarding at the pace the business actually changes.


Key questions

Q: How should teams decide between identity governance and data security tools?

A: Start with the exposure path, not the product category. If the main gap is who can get access, who approved it, and whether SoD or certifications are enforceable, IGA is the anchor. If the main gap is what sensitive data exists, who touches it, and how behaviour changes at runtime, data security is the anchor. Many programmes need both.

Q: What breaks when access visibility is incomplete in IGA?

A: When visibility is incomplete, every downstream control starts from bad data. Certifications miss applications, deprovisioning misses stale access, and reviewers approve or deny entitlements without seeing the full picture. That creates a false sense of governance while risk continues to accumulate in unmanaged apps and service accounts.

Q: Why does automating access provisioning and deprovisioning matter for compliance programs?

A: Automating access changes matters because compliance depends on evidence that access is granted appropriately and removed promptly when roles change. Manual workflows create lag, inconsistent records, and missed revocations, which weakens control assurance. Automation also improves auditability by creating a repeatable trail for who received access, when it changed, and what triggered the decision.

Q: How do access certification and reporting support audit readiness?

A: Certification shows that access was reviewed, and reporting shows what changed, who approved it, and when. Together they create evidence that governance happened, not just that a workflow exists. That evidence is what auditors and control owners need when they ask how access was validated and enforced.


Technical breakdown

Why access visibility is the first IGA control boundary

Comprehensive visibility is the base layer of identity governance because you cannot govern entitlements you cannot inventory. In this context, visibility means discovering applications, users, permissions, and critical access relationships across SaaS and adjacent systems. The article emphasizes real-time or near-real-time discovery because spreadsheet-driven tracking becomes stale quickly, especially when managed, unmanaged, and shadow IT applications coexist. Without that inventory, every downstream workflow, from review to deprovisioning, inherits incomplete data and weak decision quality.

Practical implication: establish a complete access inventory before expecting certification, approval, or deprovisioning workflows to reduce risk.

How automated provisioning and deprovisioning reduce entitlement drift

Automation matters because access risk grows when joiner, mover, and leaver processes depend on manual tickets and delayed human action. Automated provisioning grants the right access during onboarding and role changes, while automated deprovisioning removes access when people change roles or exit. In practice, this reduces both over-provisioning and lingering access, which are two of the most common governance failures in SaaS-heavy environments. The technical point is not speed alone, but lifecycle consistency across the full entitlement path.

Practical implication: tie provisioning and offboarding to workflow triggers so access state changes follow HR and role events without manual lag.

What access certification and reporting do that raw logs cannot

Access certification closes the governance loop by asking a human reviewer to confirm whether access is still justified. Reporting supports that process by showing who has access, how it changed, and whether exceptions or anomalies exist. The article frames these functions as audit support, but their deeper value is control evidence: they turn access state into something measurable, reviewable, and defensible. That matters because compliance failures often arise when organisations cannot prove who approved access, when it changed, or whether it was ever revalidated.

Practical implication: use certification and reporting together so review decisions produce evidence, not just workflow activity.


NHI Mgmt Group analysis

IGA fails when access governance is treated as a periodic review problem instead of a live control problem. The article’s strongest point is that visibility, provisioning, deprovisioning, self-service, certification, and reporting are not separate features but a control chain. If one link is weak, the others inherit stale or incomplete entitlement data. Practitioners should judge tools by whether they maintain governance continuity across the full access lifecycle, not by isolated feature counts.

Comprehensive visibility is the governance prerequisite, not an optional dashboard. The article correctly shows that SaaS sprawl, shadow IT, and service accounts create an access estate that spreadsheets cannot hold. That is a data quality issue before it is a workflow issue. The practical conclusion is that identity governance programmes need authoritative discovery before they can claim review integrity or least-privilege enforcement.

Automated lifecycle action is what separates administrative convenience from risk reduction. If onboarding, mover events, and offboarding still depend on humans to remember each step, lingering access and over-provisioning will persist. This is especially true where contractors, transient roles, and app-specific entitlements change faster than review cycles. Practitioners should treat lifecycle automation as the mechanism that converts policy into timely revocation.

Access certification only has value when reviewers are deciding against current evidence. A certification workflow that operates on stale ownership data or partial app coverage can produce a compliant-looking record without actually reducing exposure. The article usefully links certification to audit reporting, which is the right pairing: one decides, the other proves. For governance teams, that means the review process must be backed by inventory quality and change traceability.

Identity governance now has to span human users, service accounts, and shadow access paths in one operating model. The article does not frame this as a separate machine identity strategy, but it points to the same governance truth: access risk is system-wide when entitlement sources are fragmented. A mature programme should therefore evaluate whether one governance model can reconcile user access, service-account permissions, and offboarding evidence without manual exception handling.

From our research library:

What this signals

Access governance is shifting from record-keeping to live control execution. The practical lesson for IAM and IGA teams is that governance has to be anchored in current entitlement state, not retrospective cleanup. When discovery, provisioning, certification, and reporting are disconnected, the programme can look mature while access risk still rises faster than review cadence.

Identity governance programmes now need to cover SaaS sprawl, service accounts, and shadow IT in one model. Feature selection should therefore be judged by how well a tool reconciles discovered access with lifecycle changes across the full environment, not by how many workflow screens it exposes. Teams that still rely on partial inventories will continue to certify incomplete access.


For practitioners

  • Map every access source before automating governance Build a complete inventory of SaaS applications, users, permissions, and service-account access so downstream certifications and removals start from current data, not spreadsheet snapshots.
  • Automate joiner-mover-leaver workflows Connect onboarding, role change, and offboarding events to provisioning and deprovisioning workflows so access updates happen as part of the lifecycle rather than through ad hoc tickets.
  • Separate access requests from access approvals Use a self-service request portal for users, but keep approvals tied to app owners, managers, or admins so entitlement decisions remain accountable and traceable.
  • Run certification on authoritative entitlement data Require access reviews to use the same discovered application and identity records that drive provisioning, otherwise reviewers certify stale or incomplete access states.
  • Produce audit evidence from workflow outcomes Generate reports that show who approved, changed, or rejected access so compliance teams can prove governance actions without reconstructing them manually.

Key takeaways

  • IGA tools reduce access risk only when visibility, lifecycle automation, self-service, certification, and reporting operate as a connected control chain.
  • The real failure mode is not the absence of policy, but the gap between how fast access changes and how slowly humans can review it.
  • Identity governance teams should prioritise authoritative discovery and automated offboarding before treating access review as the main control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementThe article focuses on governing user access, approvals, and removal across systems.
Recommendation — Apply CIS-5 to centralise account lifecycle governance and remove stale access automatically.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about managing entitlements and authorisations across SaaS.
Recommendation — Use PR.AA-05 to review and revoke entitlements based on current business need.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article repeatedly points to over-provisioning and lingering access as governance failures.
Recommendation — Enforce AC-6 by limiting entitlements to the minimum required for current job duties.
ISO/IEC 27001:2022A.5.15 — Access ControlThe post is about identity governance controls that define, review, and revoke access.
Recommendation — Implement A.5.15 to define access rules, reviews, and removal procedures across the lifecycle.
SOC 2 (AICPA)CC6.1 — Logical Access ControlsThe article discusses audit trails, access review, and control evidence for governed access.
Recommendation — Use CC6.1 evidence to prove that logical access is authorised, reviewed, and revoked.

Key terms

  • Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Deprovisioning: Deprovisioning is the removal of access when a user changes roles or leaves an organisation. For security teams, it is the point where stale accounts, tokens, and permissions should disappear. Weak deprovisioning leaves residual access that can outlive the business need that created it.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org