TL;DR: Demand for access entitlement control, separation of duties enforcement, and hybrid identity visibility across cloud and on-prem environments is highlighted by Saviynt’s recognition as Overall Leader in KuppingerCole’s Identity as a Service - IGA Leadership Compass, according to Saviynt and KuppingerCole. The signal for practitioners is that governance scope is widening beyond classic IGA into cloud privileged access and risk-based access decisions.
At a glance
What this is: This is a Saviynt press release about KuppingerCole naming the vendor an Overall Leader in IGA, with the core finding that IGA evaluation is converging around entitlements, separation of duties, and hybrid access visibility.
Why it matters: It matters because IAM and IGA teams are being pushed to govern entitlements, privileged access, and compliance decisions as one operating problem rather than separate control silos.
Context
IGA programmes are no longer assessed only on joiner-mover-leaver hygiene or certification cadence. The market is now asking whether governance can follow access entitlements, separation of duties, and risk across cloud and on-prem environments without losing sight of who can do what.
For identity teams, that shift matters because the control boundary has widened. Cloud privileged access, application GRC, and cross-environment visibility are increasingly part of the IGA conversation, which changes how practitioners evaluate programme scope, tooling overlap, and operating ownership.
Key questions
Q: How should organisations govern access when identity controls are spread across IGA, AM, and PAM?
A: They should treat governance as one continuous workflow, not three separate teams. Access should be approved, provisioned, reviewed, elevated, and revoked through linked controls that produce evidence of completion. For NHIs, that workflow must also cover secrets, certificates, service accounts, and automation paths, or the governance model will leave hidden access behind.
Q: When does separation of duties fail in hybrid identity environments?
A: It fails when the policy exists only at design time and is not re-evaluated against inherited permissions, delegated access, and exception paths. In hybrid estates, the role model can look clean while the effective entitlement graph still creates toxic combinations.
Q: What should security teams do first when cloud privileged access sits outside IGA?
A: Bring privileged cloud roles into the same inventory and review cycle as business entitlements. If elevated access is certified in a separate workflow, the organisation will keep producing incomplete governance evidence and miss the highest-risk access paths.
Q: Why do hybrid identity programmes need a single view of effective access?
A: Because governance decisions depend on what an identity can actually do across environments, not on where the entitlement was created. A single view exposes cross-platform privilege accumulation, makes SOD review defensible, and reduces the gap between approved and real access.
Technical breakdown
Entitlement governance across hybrid environments
Identity governance in hybrid estates depends on maintaining an accurate view of entitlements across applications, infrastructure, and SaaS platforms. The technical challenge is not only provisioning and deprovisioning, but also knowing the effective access state after role nesting, inherited permissions, and platform-specific exceptions. When cloud and on-prem systems are governed together, the quality of entitlement inventory becomes the real control surface. Without that inventory, access review and policy enforcement turn into partial visibility exercises rather than defensible governance.
Practical implication: validate whether your entitlement data model can represent cloud and on-prem access in one governance view.
Separation of duties as a continuous control
Separation of duties, or SOD, is only effective when toxic combinations are evaluated against current access, not static role design. In modern environments, users accumulate access through multiple pathways, so SOD checks need to run against effective permissions and business context. That is why IGA platforms increasingly bundle policy evaluation, entitlement intelligence, and access risk scoring. The control fails when SOD exists as a design-time rule but is not enforced against real entitlements after changes, exceptions, and cross-application access grants.
Practical implication: test SOD rules against effective entitlements, not only against role definitions or approval workflows.
Cloud privileged access inside the IGA perimeter
Cloud privileged access management extends governance into accounts and roles that can change infrastructure, security settings, or business-critical data paths. In practice, this means the IGA layer has to understand elevated access in the same way it understands application entitlements, especially where access is granted through cloud roles, ephemeral privileges, or delegated administration. The technical issue is scope alignment: if privileged cloud access sits outside governance, the organisation can certify ordinary access while leaving high-risk access unreviewed. That creates a blind spot in the control chain.
Practical implication: bring cloud privileged access into governance reporting and certification scope, not just into a separate PAM workflow.
Breaches seen in the wild
- BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
IGA convergence is becoming a scope question, not a product category question. The market is moving toward governance platforms that can see entitlements, SOD, and privileged access in the same decision loop. That is less about feature bundling and more about whether identity teams can still answer a basic question: who has effective access, under what risk, and across which environments? Practitioners should treat convergence as a programme-design decision, not a procurement label.
Cloud privileged access now belongs inside governance, not beside it. Cloud environments blur the line between standard entitlement and high-risk privilege because the same identity can both read data and alter infrastructure. That makes access governance incomplete if it stops at application roles. The practical consequence is that cloud PAM and IGA can no longer be evaluated as separate control domains when the objective is defensible access oversight.
Separation of duties only works when it follows the identity, not the org chart. Static policy design assumes a clean mapping between role and risk, but hybrid estates create inherited permissions, delegated access, and exception paths that change the effective control state. This is where governance programmes fail in practice: the SoD rule exists, but the access path escapes the rule. Practitioners need to inspect effective entitlements, not just policy intent.
Hybrid identity visibility is the real control plane for modern governance. The article points to a broader direction in the market: identity governance is being measured by its ability to unify cloud and on-prem access state. That aligns with NHI governance patterns as well, because privileged machine access and human access now share the same risk surface in many estates. Identity leaders should expect procurement decisions to favour platforms that reduce governance fragmentation.
Entitlement drift is the hidden cost of fragmented governance. When certification, privilege review, and SOD enforcement sit in separate tools, each one sees only a slice of the identity state. The result is not just inefficiency but control drift, where the approved state and the effective state diverge over time. For practitioners, the signal is clear: governance architecture has to be designed around the effective access graph.
From our research library:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Entitlement visibility is becoming the anchor point for governance maturity. The stronger signal in this market is not whether an IGA platform can issue approvals, but whether it can keep the effective access model current across cloud and on-prem systems. That is the difference between audit support and actual control.
Cloud privileged access is collapsing into governance oversight. As organisations move more operational authority into cloud roles, identity teams will be judged on whether privileged access is reviewed, certified, and risk-scored alongside ordinary entitlements. The boundary between IGA and PAM is no longer stable.
Identity programmes that cannot model effective access will struggle to prove control. Static role definitions do not survive exceptions, nesting, and delegated administration. Practitioners should expect future governance assessments to focus on the quality of the access graph, not just the presence of policy.
For practitioners
- Map the effective access graph Build a single inventory of application entitlements, cloud roles, and privileged paths so governance decisions are based on effective access rather than disconnected role records.
- Extend certification into privileged access Include cloud privileged access and administrative roles in recertification cycles so elevated access is reviewed with the same rigor as ordinary business access.
- Re-test separation of duties rules Run SoD checks against current entitlements after exceptions, role nesting, and cross-application grants, not only against the original role design.
- Align governance ownership across IAM and PAM Assign a clear control owner for hybrid identity decisions where access governance and privileged access overlap, so audit evidence and remediation paths do not split across teams.
Key takeaways
- IGA is being judged less as a certification workflow and more as a hybrid access governance layer that must account for entitlements, SOD, and privileged access together.
- A single entitlement model becomes the practical difference between visible control and fragmented oversight across cloud and on-prem estates.
- Practitioners should expect the governance boundary to keep shifting toward effective access, where cloud privilege and ordinary entitlement review are part of the same decision process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Cloud privileged access and entitlement scope are central to the governance convergence described here. |
| Recommendation — Review high-risk identities for overprivileged access and fold them into governance and certification workflows. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centers on entitlement governance across hybrid environments. |
| Recommendation — Validate access permissions and entitlements against current business need across cloud and on-prem systems. | ||
| CIS Controls v8 | CIS-5 — Account Management | Hybrid governance depends on disciplined account and access lifecycle management. |
| Recommendation — Centralise account management so review and remediation cover all active access paths. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | The article's cloud PAM angle maps directly to privileged access governance. |
| Recommendation — Apply privileged access rights controls to administrative cloud roles and review them with the rest of IGA. | ||
Key terms
- Entitlement Governance: Entitlement governance is the discipline of deciding who or what should have access, for how long, and under what business justification. It spans human users, non-human identities, and automated workflows, making it a core control layer for SaaS, cloud infrastructure, and lifecycle management.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
- Cloud Privileged Access: Cloud privileged access is the ability to perform high-impact administrative actions in cloud environments. It covers permissions that can create, change, delete, or expose infrastructure, identities, data, and security controls. These rights often exist through console roles, API permissions, service accounts, and temporary credentials, so they require tight governance, monitoring, and review.
- Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org