TL;DR: Identity governance becomes manageable when leaders translate guidance into outcomes, automation, and broad integration rather than treating IGA as an abstract framework, according to Fischer Identity. The core message is that governance programs fail when they are built around jargon and customization instead of business alignment, measurable risk reduction, and sustainable operations.
NHIMG editorial — based on content published by Fischer Identity: The Beginning of the Journey, Turning Insight into Action
Questions worth separating out
Q: How should organisations turn identity governance guidance into action?
A: Start with business outcomes, then map governance workflows to those outcomes in a fixed order.
Q: Why do identity governance programmes fail when they rely on custom code?
A: Custom code makes governance logic fragile.
Q: What should teams prioritise first in a modern IGA programme?
A: Prioritise integration and authoritative data sources before widening the scope of reviews or automation.
Practitioner guidance
- Define governance outcomes before selecting workflow scope Set explicit 12-month and 36-month objectives for risk reduction, onboarding speed, compliance evidence, and operating cost.
- Reduce custom code in identity workflows Prioritise configuration-first implementations for joiner, mover, leaver, certification, and exception handling processes.
- Map authoritative identity sources early Identify the systems that own identity attributes, entitlement data, and business context before expanding certification or provisioning automation.
What's in the full article
Fischer Identity's full blog covers the operational detail this post intentionally leaves for the source:
- The series recap showing how each earlier IGA guidance topic connects to a practical programme decision.
- The vendor's own examples of configuration-first governance and where it reduces custom implementation effort.
- The executive questions Fischer Identity recommends asking before modernising an IAM or IGA programme.
- The broader series list for readers who want to trace the guidance from modern IGA through business value.
👉 Read Fischer Identity's series recap on turning IGA guidance into action →
IGA guidance and program design: what should leaders do next?
Explore further
Configuration-first IGA is a governance discipline, not a product preference. The article’s central claim is that sustainable identity governance depends on preserving control logic in configuration rather than embedding it in brittle custom code. That matters because lifecycle, policy, and audit requirements all change over time, while custom implementation debt tends to outlive the original design assumptions. Practitioners should treat maintainability as a control requirement, not a deployment convenience.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
- Only 13% of security leaders feel extremely prepared for the reality of agentic AI, according to the same survey.
A question worth separating out:
Q: How do organisations know whether their IGA programme is actually working?
A: Look for fewer orphaned accounts, fewer unresolved SoD conflicts, and a lower rate of redundant approvals in certification campaigns. If the programme is healthy, access reviews should produce cleaner entitlement data and fewer exceptions over time, not just higher completion percentages.
👉 Read our full editorial: IGA guidance turns useful when leaders map insight to action