TL;DR: Gartner named it a Challenger in the February 2017 Magic Quadrant for Identity Governance and Administration, framing the result around cloud-ready, risk-aware IGA for apps, data, and infrastructure, according to Saviynt. For practitioners, the more useful question is whether identity governance is being measured by feature breadth or by how well it reduces access, certification, and decision risk.
At a glance
What this is: This is a Saviynt press release about Gartner naming the company a Challenger in the February 2017 Magic Quadrant for Identity Governance and Administration, with the central claim that the market was shifting toward cloud-ready, risk-aware IGA.
Why it matters: It matters because IGA teams should treat vendor positioning as a signal about governance scope, certification efficiency, and whether access decisions are tied to actual risk reduction across applications, data, and infrastructure.
Context
Saviynt's article is about identity governance as a market category, not a product feature update. The core issue is how organisations evaluate IGA: by feature breadth, or by whether the programme measurably reduces access risk, decision friction, and certification overhead across business systems.
For IAM and IGA teams, the practical lens is broader than a quadrant placement. The article points to a shift toward cloud-ready governance that spans applications, data, and infrastructure, which is a reminder that identity governance only matters when it can operate across the full access estate.
Key questions
Q: What should teams evaluate before choosing an IGA platform?
A: Teams should evaluate whether the platform can absorb change after deployment without requiring customer-specific code. The key question is how well it handles new applications, new authoritative sources, and changing business rules while preserving governance continuity. That is the real test of architectural flexibility, not initial connector count.
Q: Why does cloud-based IGA matter for access governance maturity?
A: Cloud-based IGA matters because it can make governance more consistent across distributed environments, especially where on-premises processes have become fragmented or heavily customised. The main value is not infrastructure reduction alone. It is the ability to improve coverage, update controls faster, and maintain a more reliable access state across the identity estate.
Q: How do you know if your access certification process is actually reducing access risk?
A: Look for evidence that reviews are producing real decisions, not just approvals. Healthy programs show meaningful revocations, fewer stale entitlements, shorter review cycles, and clearer ownership of access decisions. If almost everything is approved, the process is likely measuring completion rather than control effectiveness. The key signal is whether risky or unnecessary access is actually removed.
Q: What is the difference between access review and access governance?
A: Access review checks whether a permission still looks appropriate. Access governance defines the policy, evidence, and control logic that decides whether access should exist in the first place. In high-value business applications, governance must include SoD, telemetry, and exception handling, not only periodic certification.
Technical breakdown
What cloud-ready IGA changes in access governance
Cloud-ready IGA shifts governance from isolated application reviews to cross-environment access policy enforcement. In practice, that means entitlements, roles, segregation-of-duties rules, and certification evidence must work across SaaS, on-premise systems, and infrastructure-adjacent access paths. The article also points to analytics-supported decision making, which matters because governance collapses when review workflows cannot surface meaningful context fast enough for approvers.
Practical implication: map whether your IGA workflows can govern the same user and entitlement consistently across cloud and on-premise systems.
Why decision quality matters more than feature breadth
Identity governance becomes weak when programme success is measured by module count instead of the quality of access decisions. Features such as access request, certification, role management, and analytics can look comprehensive while still leaving reviewers without enough context to approve, challenge, or revoke access with confidence. The article's emphasis on risk-aware governance reflects a practical reality: decision support is the control, not just a convenience layer.
Practical implication: test whether reviewers can make defensible access decisions, not just whether the platform supports the workflow.
How integrated governance, risk, and access context reduce review fatigue
The article describes a combined approach spanning application governance, data access governance, and risk-based certification. That matters because disconnected tools force teams to cross-check access context manually, which slows reviews and makes exceptions harder to track. Integrated governance is most useful when it turns data sensitivity, application criticality, and role risk into a single certification conversation rather than separate administrative tasks.
Practical implication: consolidate evidence feeds so access reviews incorporate data, application, and role context in one workflow.
NHI Mgmt Group analysis
IGA market positioning is increasingly about governance quality, not inventory size. A Challenger placement only matters to practitioners if it reflects better access decisioning, stronger certification outcomes, and more usable governance across environments. The market signal is that feature parity is no longer enough; programme teams now need proof that the platform reduces review noise and decision delay.
Cloud-ready IGA is now a governance expectation, not a differentiator. When applications, data, and infrastructure are all in scope, identity governance has to work across mixed estates and mixed operating models. That means practitioners should judge whether a programme can certify and remediate access consistently without fragmenting controls by hosting model.
Integrated governance context: The article's real value is its reminder that access request, role management, SOD, and certification only become meaningful when they share the same risk context. Separating those functions creates administrative motion without governance clarity, so teams should evaluate how much decision context is actually preserved through the workflow.
Risk-aware IGA is the discipline that converts visibility into action. Analytics and persona-based workflows matter because they shorten the gap between identifying risky access and changing it. The practitioner takeaway is straightforward: if the programme cannot translate evidence into faster, better access decisions, it is reporting on governance rather than enforcing it.
What this signals
Governance programmes should be measured by decision quality, not by how many review cycles they can complete. If approvers do not have enough context to make defensible choices, certification becomes a compliance ritual rather than a control. That is the real test for IGA maturity.
Cloud-ready governance is now the minimum expectation for mixed estates. Identity teams need access policy, role design, and certification logic that can operate across SaaS and on-premise systems without splitting the control model. Otherwise, governance fragments as environments proliferate.
For practitioners
- Assess cross-environment governance coverage Verify that one governance model can handle SaaS, on-premise, and infrastructure-adjacent access without forcing separate review processes for each estate.
- Test certification decision quality Sample recent access reviews and check whether approvers had enough risk, role, and application context to make defensible decisions.
- Map role and SOD logic to current business systems Review whether role definitions and segregation-of-duties rules still match the applications and data domains currently in use.
- Reduce manual evidence stitching Connect application, data, and usage analytics so reviewers do not have to assemble access context from separate tools or spreadsheets.
Key takeaways
- The article is best read as a governance signal, not a product story, because it centres on whether IGA can improve access decisions rather than merely add features.
- A cloud-ready IGA programme has to govern applications, data, and infrastructure consistently, or certification and remediation will remain fragmented.
- Practitioners should evaluate whether their access reviews produce better decisions with less manual effort, because that is what turns identity governance into a control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing entitlements and certification decisions across systems. |
| Recommendation — Use PR.AA-05 to align access approvals, reviews, and revocation with governed entitlements. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The governance theme is reducing excess access and making access decisions risk-aware. |
| Recommendation — Apply AC-6 to minimise standing access and keep entitlements tied to job need. | ||
| CIS Controls v8 | CIS-5 — Account Management | IGA programmes operationalise lifecycle control over accounts, roles, and access reviews. |
| Recommendation — Use CIS-5 to enforce account review, approval, and removal processes across the estate. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The article discusses governance scope and access control across cloud and on-premise systems. |
| Recommendation — Map access governance processes to A.5.15 and keep policy coverage consistent across environments. | ||
Key terms
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
- Role Management: The process of designing, maintaining, and reviewing access roles so they reflect real business duties and do not accumulate unnecessary privilege. Good role management limits sprawl, improves review quality, and makes governance more consistent across applications.
Deepen your knowledge
NHI governance, IAM, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org