TL;DR: Nexis says public Gartner Peer Insights data places its IGA presence at #2 in Insurance and Manufacturing in EMEA and #5 in Telecommunications as of 7 April 2026, pointing to demand for explainable access intelligence in regulated, heterogeneous identity estates. Visibility and decision support, not workflow alone, are becoming the differentiators in complex governance programmes.
At a glance
What this is: This is an analysis of Gartner Peer Insights industry data that shows where Nexis appears in EMEA IGA views, with strongest visibility in Insurance and Manufacturing and a weaker showing in Telecommunications.
Why it matters: For IAM and IGA teams, the signal is that regulated, hybrid estates now demand explainable access intelligence, not just provisioning and certification workflows.
👉 Read Nexis' analysis of Gartner peer data and IGA visibility in EMEA
Context
Identity governance and administration is the discipline that connects accounts, entitlements, roles, approvals, and review processes across systems. In complex EMEA environments, that discipline has to work across legacy platforms, cloud services, and business units with different compliance pressures.
This article is not about product mechanics alone. It is about what public peer data suggests when IGA is evaluated in sectors where access structures are dense, explanation matters, and governance has to survive audits as well as operational change.
Key questions
Q: How should IGA teams handle access governance in complex hybrid estates?
A: Teams should treat hybrid estates as an evidence problem as much as a workflow problem. The priority is to connect identities, entitlements, roles, and risk context across systems so that access decisions are explainable to auditors and owners. If the governance stack cannot reconstruct that context, certifications and approvals will stay shallow.
Q: Why do regulated industries need more than provisioning and certification in IGA?
A: Because provisioning and certification answer only part of the governance question. Regulated sectors need to explain why access exists, how it relates to roles, and whether the entitlement still fits the business need. Without that explanation layer, access reviews become procedural rather than defensible.
Q: What breaks when identity governance only reviews access after it is granted?
A: Access drift becomes invisible between review cycles, which means over-privileged accounts can keep operating long after the business reason for access has changed. That is especially risky for service accounts and tokens because their permissions often persist without a human operator noticing. Governance has to include revocation evidence, not just certification records.
Q: What does explainable access intelligence add to IGA programmes?
A: It adds the ability to present access in context, not as isolated records. That means tying identities to entitlements, roles, risks, and governance relationships so security teams and business owners can make decisions faster and with better evidence. In complex environments, that context is what makes the control usable.
Technical breakdown
Why peer visibility matters in complex IGA markets
Peer listings do not prove product quality on their own, but they do show where a platform is being evaluated and discussed in real operating environments. In identity governance and administration, that matters because adoption signals usually cluster around sectors with difficult entitlement models, regulatory scrutiny, and long-lived application estates. The relevant question is not whether workflow exists, but whether the governance model can handle heterogeneous access structures and still produce an explainable record for review, risk, and audit.
Practical implication: Treat peer data as a directional signal for where your own governance requirements are most likely to be stressed.
Explainable access intelligence versus workflow-only IGA
Traditional IGA often centres on provisioning, certifications, and policy enforcement. That is necessary, but it does not solve the harder problem of making access relationships intelligible across disconnected systems. An identity visibility and intelligence platform consolidates identities, entitlements, roles, and risk signals into a connected view that helps reviewers understand why access exists, not just whether it exists. In regulated estates, explainability is what makes governance scalable across audits, role design, and remediation.
Practical implication: Prioritise governance models that can explain access lineage and entitlement context, not only execute requests.
Why hybrid environments change governance expectations
Hybrid estates complicate IGA because the access story is no longer contained in one directory, one application, or one policy domain. Legacy systems, cloud services, and delegated administration create fragmented evidence, which weakens review quality and slows remediation. The result is that governance teams need better visibility into relationships between identities, roles, and entitlements before they can make defensible access decisions. In that sense, the challenge is less about adding more workflow and more about reducing governance blind spots.
Practical implication: Focus on how your current governance stack reconstructs entitlement context across platforms before expanding review volume.
NHI Mgmt Group analysis
Peer data is a governance signal, not a performance verdict: Public industry listings can help practitioners see where IGA capabilities are being evaluated in environments with real governance pressure. Insurance, manufacturing, and telecommunications are not interesting because they are fashionable sectors, but because they are the places where entitlement sprawl, auditability, and explainable access decisions become operationally expensive. The practitioner takeaway is to read peer visibility as evidence of fit for complex governance conditions, not as a proxy for universal product quality.
Identity visibility and intelligence is becoming the missing layer in IGA: Workflow-centric IGA answers request, approve, and certify, but complex estates need a layer that connects identities, entitlements, roles, risks, and governance relationships. That is the difference between processing access and understanding access. For practitioners, the strategic issue is whether the programme can reconstruct access context fast enough to support reviewers, auditors, and remediation owners.
Explainability is now a control requirement, not a reporting nicety: In regulated environments, access decisions must survive questions from auditors, security teams, and business owners. A governance programme that cannot explain why an entitlement exists will struggle even if it can technically provision or recertify it. The implication is that access intelligence has become part of the control plane for modern IGA, especially where hybrid estates hide the relationships that matter.
Complex sectors are exposing the limits of narrow IGA design: Years of system growth, segmented entitlements, and segregation-of-duties pressure make simple workflow models inadequate in insurance, manufacturing, and telecommunications. The article points to a broader market shift: buyers want connected governance views that can support role design, access review, and remediation in the same place. Practitioners should therefore evaluate whether their governance stack can unify evidence across platforms instead of merely automating approvals.
Access transparency is the new baseline for hybrid identity programmes: The practical bar is no longer just whether access can be granted or reviewed. The real question is whether the programme can show who has access, why they have it, and how that access relates to roles and risk across systems. That is the level at which modern IGA becomes defensible in board, audit, and operational conversations.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: IAM and IGA Basics
What this signals
Access transparency is becoming the deciding factor in complex governance programmes: When identity estates span legacy systems, cloud services, and delegated administration, the real limitation is often not policy design but the ability to reconstruct why access exists. That shifts IGA from a ticketing discipline to an evidence discipline, which is where many programmes still struggle.
Peer visibility is only useful when it is read through operating conditions: The relevant question for practitioners is not which vendor appears in a ranking, but which governance problems consistently surface in regulated, hybrid environments. That lens helps teams separate market signal from procurement theatre and focus on access explainability, review quality, and role traceability.
For practitioners
- Map governance blind spots across hybrid estates Identify where entitlement context is lost between directories, SaaS applications, legacy platforms, and delegated admin paths. Use that map to prioritise the systems where access explanations are weakest.
- Rebuild access review inputs around explainable relationships Make sure reviewers see identities, entitlements, roles, and risk context together rather than as separate extracts. This improves the quality of certification decisions and reduces reflexive approvals.
- Test whether role design can survive audit questions Ask whether a role can be traced back to a business purpose, a system owner, and a review path without manual reconstruction. If not, role design is too opaque for regulated operations.
- Evaluate IGA fit against complex sector conditions Benchmark your current governance stack against environments with legacy systems, regulatory obligations, and segregation-of-duties pressure. The goal is not more workflow, but more defensible governance context.
Key takeaways
- Complex EMEA sectors make identity governance harder because access must remain explainable across legacy, cloud, and delegated systems.
- The article’s signal is less about rankings than about demand for connected visibility into identities, entitlements, roles, and risk.
- Practitioners should test whether their IGA stack can support audit-ready access explanations, not just approvals and certifications.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The article is about governance visibility across identity and access estates in cloud-hybrid environments. |
| Recommendation — Use IAM controls to centralise identity, entitlement, and access relationship visibility across systems. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The core issue is explainable authorization and entitlement governance across heterogeneous environments. |
| Recommendation — Review entitlement models against PR.AA-05 and ensure access decisions remain traceable and justified. | ||
| CIS Controls v8 | CIS-5 — Account Management | IGA programmes depend on accurate account and access governance across the identity estate. |
| Recommendation — Apply account management controls to keep identities, roles, and access paths current and reviewable. | ||
Key terms
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Identity Visibility and Intelligence Platform: An Identity Visibility and Intelligence Platform is a layer that correlates identity data across multiple tools into one risk picture. It does not replace existing controls. It makes them more useful by connecting events, relationships, configuration, and posture so teams can prioritise what matters.
- Explainable Access Administration: Explainable access administration means access decisions can be traced to a policy, a reason, and an accountable owner. This matters because AI-assisted or delegated administration can become opaque unless the programme preserves decision provenance and challengeability.
- Hybrid Identity Estate: A hybrid identity estate combines cloud and on-premises identity systems under one operational environment. For NHIs, this usually means certificates, service principals, and service accounts are distributed across tools and teams, which makes visibility and lifecycle enforcement harder unless controls are centralised.
What's in the full article
Nexis' full analysis covers the operational detail this post intentionally leaves for the source:
- The exact public Gartner Peer Insights industry filters used for the EMEA review
- The broader Hype Cycle context Nexis uses to position identity visibility and intelligence
- The vendor's explanation of why insurance, manufacturing, and telecommunications stand out
- The source links and disclaimers that accompany the public listings review
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org