Join our Newsletter — 33% off our NHI Course

IGA Challenger status: what it means for governance teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Gartner named it a Challenger in the February 2017 Magic Quadrant for Identity Governance and Administration, framing the result around cloud-ready, risk-aware IGA for apps, data, and infrastructure, according to Saviynt. For practitioners, the more useful question is whether identity governance is being measured by feature breadth or by how well it reduces access, certification, and decision risk.

Editorial analysis by NHI Mgmt Group, based on content published by Saviynt: “Press Releases”.

Key questions

Q: What should teams evaluate before choosing an IGA platform?

A: Teams should evaluate whether the platform can absorb change after deployment without requiring customer-specific code.

Q: Why does cloud-based IGA matter for access governance maturity?

A: Cloud-based IGA matters because it can make governance more consistent across distributed environments, especially where on-premises processes have become fragmented or heavily customised.

Q: How do you know if your access certification process is actually reducing access risk?

A: Look for evidence that reviews are producing real decisions, not just approvals.

Practitioner guidance

  • Assess cross-environment governance coverage Verify that one governance model can handle SaaS, on-premise, and infrastructure-adjacent access without forcing separate review processes for each estate.
  • Test certification decision quality Sample recent access reviews and check whether approvers had enough risk, role, and application context to make defensible decisions.
  • Map role and SOD logic to current business systems Review whether role definitions and segregation-of-duties rules still match the applications and data domains currently in use.

Bottom line: The article is best read as a governance signal, not a product story, because it centres on whether IGA can improve access decisions rather than merely add features.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group
This topic was modified 2 days ago 2 times by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

IGA market positioning is increasingly about governance quality, not inventory size. A Challenger placement only matters to practitioners if it reflects better access decisioning, stronger certification outcomes, and more usable governance across environments. The market signal is that feature parity is no longer enough; programme teams now need proof that the platform reduces review noise and decision delay.

A question worth separating out:

Q: What is the difference between access review and access governance?

A: Access review checks whether a permission still looks appropriate. Access governance defines the policy, evidence, and control logic that decides whether access should exist in the first place. In high-value business applications, governance must include SoD, telemetry, and exception handling, not only periodic certification.

👉 Read our full editorial: Saviynt’s Challenger placement and what it means for IGA governance


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.