TL;DR: GRO and Kirk Kapital are taking a majority stake in Omada A/S as the company positions cloud-native, AI-driven IGA and machine identity capabilities for further growth, with the transaction still subject to regulatory approval, according to Omada Identity. The market is now treating identity governance as infrastructure for lifecycle control, compliance, and scale, not just access administration.
Editorial analysis by NHI Mgmt Group, based on content published by Omada Identity: “Omada kündigt Investition von GRO und Kirk Kapital an, um die nächste Wachstums- und Innovationsphase im Bereich Identity Governance voranzutreiben”.
Key questions
Q: How should teams govern machine identities when IGA is built for people?
A: Use IGA for human lifecycle controls and add NHIM for service accounts, API keys, tokens, and certificates.
Q: Why do cloud-native IGA platforms change the way identity governance is designed?
A: Cloud-native IGA shifts the focus from periodic administration to continuous policy enforcement across distributed environments.
Q: What are the signs that an IGA programme is not covering the full identity estate?
A: The clearest signs are unowned service accounts, access reviews that exclude workloads or automation, manual exceptions for common identity flows, and certification processes that only cover employees.
Practitioner guidance
- Reassess IGA scope for machine identities Map service accounts, workloads, tokens, and automated access paths into the same governance inventory used for human identities.
- Test cloud-native workflow coverage Validate whether joiner-mover-leaver, approvals, and certifications still work cleanly in multi-tenant and hybrid environments, including delegated administration and distributed policy enforcement.
- Align AI features to policy quality Use automation to accelerate review and routing only where access policies, identity data, and approvers are already authoritative and stable enough to support consistent decisions.
Bottom line: The ownership change shows that identity governance is being framed as operational infrastructure for hybrid environments, not as a narrow access review function.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
IGA is being repositioned as operational infrastructure, not administrative overhead. This ownership change reflects a broader market view that identity governance must sit closer to cloud operations, lifecycle control, and compliance enforcement. Organisations that still treat IGA as a periodic certification layer will keep missing the control demands of hybrid estates. The practitioner conclusion is that governance maturity is now inseparable from runtime scale and workflow precision.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: Should organisations re-evaluate IGA roadmaps after market consolidation in the sector?
A: Yes, because ownership changes often push IGA platforms toward broader cloud and automation capabilities, while practitioners still need strong lifecycle control and compliance coverage. The right question is whether the roadmap still matches your identity estate, your operating model, and your review requirements. Consolidation can simplify procurement, but it can also blur fit for purpose.
👉 Read our full editorial: Omada ownership change signals a new phase for identity governance