TL;DR: Most IGA programmes fail because teams sequence controls poorly, leaving half-implemented systems that auditors do not trust, according to Zluri’s phase-by-phase strategy on access reviews, lifecycle automation, granular entitlement control, identity security, and self-service requests. The practical lesson is that governance must start with visibility and ownership, then tighten access and automation in stages rather than trying to solve everything at once.
At a glance
What this is: This is a phase-by-phase guide to implementing IGA, with the central finding that sequencing matters more than tooling if teams want usable governance and audit trust.
Why it matters: It matters because IAM and IGA teams need a rollout order that builds ownership, visibility, automation, and least privilege without creating a stalled programme that satisfies neither security nor compliance.
Context
IGA implementation fails when teams treat governance as a single rollout instead of a staged operating model. The article argues that the real problem is sequencing: organisations often buy the tooling before they have ownership, visibility, and a reliable identity data foundation.
In practice, that creates a familiar identity governance trap. Access reviews, lifecycle automation, entitlement design, identity security, and self-service all depend on one another, so moving out of order produces partial coverage, audit friction, and manual workarounds that weaken the programme.
Key questions
Q: What breaks when IGA is rolled out before access ownership is clear?
A: When ownership is unclear, reviewers cannot judge whether access is appropriate and remediation tasks stall. The result is a certification process that records opinions instead of decisions. Growing organisations need accountable application, role, and entitlement owners before they ask business teams to approve or reject access.
Q: Why do access reviews fail so often in traditional IGA programmes?
A: They fail because reviewers are asked to judge technical entitlements without enough business context, so approval fatigue sets in and access gets rubber-stamped. The result is weak certification quality, unclear accountability, and audit evidence that is hard to defend when challenged.
Q: How do organisations know whether their IGA programme is actually working?
A: Look for fewer orphaned accounts, fewer unresolved SoD conflicts, and a lower rate of redundant approvals in certification campaigns. If the programme is healthy, access reviews should produce cleaner entitlement data and fewer exceptions over time, not just higher completion percentages.
Q: Should organisations prioritise lifecycle automation before expanding self-service access?
A: Yes. Self-service only works when the access model already has clean role definitions, approval routing, and automated fulfilment behind it. If those foundations are missing, self-service speeds up bad decisions instead of good ones. Lifecycle automation should come first because it reduces drift and makes later request handling reliable.
Technical breakdown
Why access reviews are the right starting point for IGA
Access reviews are point-in-time attestations that answer one narrow question: who should still have access to what? They are often the first practical IGA control because they expose ownership gaps, clean up excess access, and create an immediate compliance artefact. But they do not prevent drift between review cycles, and they work best when the organisation can already identify application owners, sensitive systems, and a trustworthy source of access data.
Practical implication: use reviews to establish visibility and ownership before you automate downstream governance.
How lifecycle automation reduces access drift
Lifecycle automation connects joiner, mover, and leaver events to identity and access changes. Instead of relying on tickets and manual follow-up, the HR record or equivalent source of truth triggers provisioning, role updates, and deprovisioning. That shortens exposure windows and removes one of the biggest causes of privilege creep, which is access that persists after a role change or exit. In IGA terms, this is where governance starts to become continuous rather than periodic.
Practical implication: wire authoritative identity data into provisioning and deprovisioning flows before expanding to more complex controls.
Why entitlement granularity is where least privilege becomes real
Application-level access is too coarse for meaningful least privilege. Real governance happens at the entitlement layer, where roles, profiles, permission sets, channel memberships, and resource permissions determine what a user can actually do inside an application. The implementation challenge is that every platform models permissions differently, so teams need clear application ownership and a consistent way to translate review findings into standard roles. Without that mapping, IGA stays at the level of yes-or-no access and never reaches operational least privilege.
Practical implication: map application-specific entitlements before expecting IGA to enforce least privilege at scale.
NHI Mgmt Group analysis
Phased governance beats tool-first deployment because IGA is a sequencing problem before it is a tooling problem. The article correctly frames implementation as a dependency chain, not a product install. Access reviews create visibility, lifecycle automation removes drift, and entitlement governance tightens precision only after the earlier layers are stable. Practitioners should treat rollout order as a governance control in its own right.
Access reviews are a governance entry point, not a complete control model. They are useful because they surface orphaned access, reveal ownership gaps, and create audit evidence quickly. They are limited because they only show point-in-time state, which means drift, mover risk, and shadow coverage gaps remain unless lifecycle controls follow.
Lifecycle automation is the point where IGA stops being periodic cleanup and starts becoming operating discipline. When joiner-mover-leaver events drive access changes automatically, the programme shifts from reactive remediation to continuous entitlement hygiene. That change matters because most access risk comes from delay, not design. The implication is that identity governance must be built around authoritative data flows, not manual tickets.
Granular access management: This is the stage where entitlement ownership, not application ownership alone, becomes the decisive control boundary. The article shows that real least privilege requires understanding what a user can do inside each application, not merely whether the application is on or off. That is why role definitions, entitlement mapping, and application-specific ownership are central to mature IGA. Practitioners should expect governance failure if they stop at coarse-grained access.
Self-service request workflows only work after the governance backbone exists. If teams expose requests before they have review logic, role mapping, and approval routing in place, they create speed without control. The article’s sequence is right: first define access truth, then automate change, then let business users request what the model can already govern. That is how IGA becomes an enabler rather than a ticket queue.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
What this signals
IGA maturity depends on sequence, not feature count. The fastest way to stall a governance programme is to expose self-service or entitlement complexity before identity data, ownership, and lifecycle flows are reliable. That sequencing problem is why many rollouts feel busy but do not materially change access risk.
Access review cadence is only useful when it feeds downstream change. If review findings are not converted into automation, role clean-up, and ownership decisions, the programme becomes an audit ritual. Mature teams use review output to improve the operating model, not just to pass the next attestation.
For practitioners
- Define application ownership first Assign a named owner to each high-value application so access reviews, approval decisions, and entitlement decisions have accountable humans behind them.
- Start with access reviews on sensitive systems Begin with HR, finance, CRM, and identity platforms because they reveal the fastest compliance wins and the clearest visibility gaps.
- Automate joiner-mover-leaver flows Connect authoritative HR attributes to identity provider provisioning and deprovisioning so role changes and exits update access without ticket delays.
- Map entitlements before expanding least privilege Document how each critical application expresses permissions, then translate review findings into standard roles and governed entitlement sets.
Key takeaways
- IGA fails when teams implement controls in the wrong order and expect tooling to substitute for governance design.
- The article’s core sequence is visibility first, then lifecycle automation, then entitlement granularity, then security controls, then self-service.
- For practitioners, the real test is whether each phase changes the underlying access state rather than simply producing more reporting.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on governing who has access to what across phases. |
| Recommendation — Use PR.AA-05 to structure phased entitlement governance and reduce access drift. | ||
| CIS Controls v8 | CIS-5 — Account Management | IGA implementation here depends on account lifecycle and ownership discipline. |
| Recommendation — Apply CIS-5 to formalise account ownership, reviews, and lifecycle-driven access changes. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Granular access management and role design are direct least-privilege concerns. |
| Recommendation — Enforce AC-6 by translating review findings into role-based, need-to-know access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access Control | The article is fundamentally about staged access governance design. |
| Recommendation — Use A.5.15 to anchor phased access governance and ownership controls. | ||
Key terms
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.
- Entitlement: An entitlement is the permission set that defines what a non-human identity can do after it authenticates. It is usually expressed through roles, policies or access assignments, and unmanaged entitlements are a common reason machine identities become over-privileged over time.
Deepen your knowledge
Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org