TL;DR: GRO and Kirk Kapital are taking a majority stake in Omada A/S as the company positions cloud-native, AI-driven IGA and machine identity capabilities for further growth, with the transaction still subject to regulatory approval, according to Omada Identity. The market is now treating identity governance as infrastructure for lifecycle control, compliance, and scale, not just access administration.
At a glance
What this is: Omada Identity’s announcement describes a majority ownership change and frames IGA as a cloud-native, AI-assisted control layer for access, compliance, and lifecycle management.
Why it matters: For IAM and IGA teams, the signal is that governance platforms are being evaluated less as administrative tools and more as operational control planes for hybrid identity estates, including machine identity and automation.
Context
Omada Identity is describing a market transition, not just a financing event. The company says its new ownership structure supports growth, but the operational story is about how identity governance is being positioned as a scalable control layer for complex hybrid environments, including lifecycle management and compliance.
For practitioners, the important shift is that IGA is being pulled closer to cloud architecture, automation, and machine identity management. That changes buying criteria: teams will increasingly judge governance platforms by how well they handle workflow scale, cloud-native deployment, and policy-driven access decisions across human and non-human identities.
Key questions
Q: How should teams govern machine identities when IGA is built for people?
A: Use IGA for human lifecycle controls and add NHIM for service accounts, API keys, tokens, and certificates. Machine identities are often created dynamically by applications, so they need continuous inventory, ownership, rotation, and decommissioning controls that do not depend on HR events or periodic human access reviews.
Q: Why do cloud-native IGA platforms change the way identity governance is designed?
A: Cloud-native IGA shifts the focus from periodic administration to continuous policy enforcement across distributed environments. That matters because access decisions, approvals, and lifecycle events increasingly happen outside traditional perimeter systems. Teams need governance models that can operate at the speed of change in hybrid estates without losing auditability or control consistency.
Q: What are the signs that an IGA programme is not covering the full identity estate?
A: The clearest signs are unowned service accounts, access reviews that exclude workloads or automation, manual exceptions for common identity flows, and certification processes that only cover employees. Those gaps show that governance is still centred on people rather than on the full access graph. The result is incomplete control coverage, not just an administrative backlog.
Q: Should organisations re-evaluate IGA roadmaps after market consolidation in the sector?
A: Yes, because ownership changes often push IGA platforms toward broader cloud and automation capabilities, while practitioners still need strong lifecycle control and compliance coverage. The right question is whether the roadmap still matches your identity estate, your operating model, and your review requirements. Consolidation can simplify procurement, but it can also blur fit for purpose.
Technical breakdown
Why cloud-native IGA now sits closer to identity control planes
Cloud-native, multi-tenant IGA changes the operating model from on-premise administration to continuously managed governance services. That matters because identity workflows are no longer limited to joiner-mover-leaver processes. They now need to support hybrid estates, delegated administration, and policy enforcement across distributed systems without turning every access decision into a manual ticket. In practice, the control plane must be able to keep pace with organisational change rather than merely record it after the fact. The architectural question is no longer whether governance exists, but whether it can be applied consistently across scale, automation, and environment boundaries.
Practical implication: Practitioners should test whether governance controls remain enforceable in cloud-native deployments, not just auditable after the fact.
Why machine identity is becoming part of the IGA scope
Machine identity is moving into the IGA conversation because access governance is no longer only about people. Service accounts, workload identities, and automated system actors create their own lifecycle, ownership, and review problems. If governance models stop at human users, they leave a growing class of access paths outside recertification, offboarding, and policy enforcement. That creates blind spots in environments where automation can create and consume privileges faster than manual review cycles can track. The practical issue is not whether machine identity exists, but whether the governance model treats it as a first-class identity population.
Practical implication: Include machine identities in lifecycle, review, and ownership processes rather than treating them as a separate technical exception.
How AI changes the governance burden rather than replacing it
AI in IGA does not remove governance work. It shifts the burden toward higher-volume decision support, better workflow routing, and faster identification of risky access patterns. AI-assisted governance can help compress review cycles and surface anomalies, but it still depends on policy quality, authoritative identity data, and clear approval boundaries. Without those inputs, automation only accelerates inconsistency. The governance question is therefore not whether AI can manage identity, but whether AI can help enforce existing rules at the speed modern environments require.
Practical implication: Use AI features to accelerate governance decisions only after the underlying identity data and approval rules are reliable.
NHI Mgmt Group analysis
IGA is being repositioned as operational infrastructure, not administrative overhead. This ownership change reflects a broader market view that identity governance must sit closer to cloud operations, lifecycle control, and compliance enforcement. Organisations that still treat IGA as a periodic certification layer will keep missing the control demands of hybrid estates. The practitioner conclusion is that governance maturity is now inseparable from runtime scale and workflow precision.
Machine identity is no longer a side topic inside governance programmes. Omada’s own emphasis on machine identity reflects a category shift: access governance must now account for non-human accounts with their own ownership, review, and revocation problems. That widens the scope of IGA beyond employee access and makes lifecycle discipline the common thread across humans and machines. Practitioners should expect identity governance programmes to be judged on how completely they cover all identity types.
AI changes the economics of governance more than it changes the governance model itself. The value is in scaling decisions, surfacing exceptions, and reducing manual effort, but the control objective remains policy enforcement with accountability. AI can reduce friction in complex environments, yet it does not replace the need for authoritative identity data, access ownership, and approval boundaries. The implication is that AI should be measured as an amplifier of governance, not as a substitute for it.
Private ownership signals category consolidation pressure in IGA. When investors back platforms in this segment, the market usually rewards broader platform scope, cloud delivery, and adjacent identity capabilities. That can accelerate product convergence, but it also raises the bar for practitioners to separate marketing claims from governance depth. The practical conclusion is that teams should re-evaluate whether their IGA roadmap still matches the control scope they actually need.
Cloud-native governance will increasingly be evaluated as a control system for hybrid identity estates. The decisive question is not whether a platform can create workflows, but whether it can consistently enforce identity policy across human, machine, and application access. That makes lifecycle orchestration, review precision, and compliance traceability the real differentiators. Practitioners should judge platforms by control fidelity across identity types, not by interface polish.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: IGA Buyer's Guide
What this signals
Identity governance is becoming a control plane for hybrid estates. The market signal here is that IGA buyers will increasingly be asked to prove coverage across humans, workloads, and automated access paths rather than only produce certification reports. That shifts programme design toward ownership, lifecycle precision, and policy enforcement across every identity type.
Lifecycle governance is the real differentiator behind platform consolidation. When ownership changes happen in IGA, practitioners should pay attention to whether the roadmap is moving toward broader orchestration or simply more workflow volume. The meaningful test is whether the platform can govern access from onboarding through offboarding across both human and non-human identities.
For practitioners
- Reassess IGA scope for machine identities Map service accounts, workloads, tokens, and automated access paths into the same governance inventory used for human identities. If those identities are not owned, reviewed, and revocable, the programme is only partially governing the estate.
- Test cloud-native workflow coverage Validate whether joiner-mover-leaver, approvals, and certifications still work cleanly in multi-tenant and hybrid environments, including delegated administration and distributed policy enforcement.
- Align AI features to policy quality Use automation to accelerate review and routing only where access policies, identity data, and approvers are already authoritative and stable enough to support consistent decisions.
- Rework governance metrics around control coverage Track whether the programme can govern all identity types with the same lifecycle rigor, rather than measuring success only by ticket volume or certification completion.
Key takeaways
- The ownership change shows that identity governance is being framed as operational infrastructure for hybrid environments, not as a narrow access review function.
- Machine identities and AI-assisted workflows are pulling IGA toward broader lifecycle control, ownership, and policy enforcement requirements.
- Practitioners should evaluate governance platforms by how completely they cover the full identity estate, including non-human identities and cloud-native workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Lifecycle governance is central to the article’s discussion of hybrid identity control. |
| NHI-05 — Overprivileged NHI | The article’s machine identity focus makes excess privilege and governance scope directly relevant. | |
| Recommendation — Map offboarding and revocation coverage across all identity types so access does not outlive ownership. Review non-human access scope and reduce entitlements that are not tied to explicit business use. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The piece is about governing access permissions across a growing identity estate. |
| Recommendation — Apply entitlement controls consistently across human and machine identities in hybrid environments. | ||
| CIS Controls v8 | CIS-5 — Account Management | IGA lifecycle control maps directly to account management across human and non-human identities. |
| Recommendation — Centralise account inventory and lifecycle control so all identity types are reviewed and retired on schedule. | ||
Key terms
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Cloud-Native IGA: Cloud-native IGA is an identity governance platform designed to operate as a cloud service rather than as legacy on premises software. It is built for scalability, faster updates, and easier integration across modern environments, which helps reduce infrastructure overhead and support more agile governance processes.
- Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org