TL;DR: Traditional IGA programs fail when they try to govern cloud, SaaS, contractors, and machine access through one large transformation, because static roles and manual reviews age faster than the environment they are meant to control, according to RSA Security. The practical answer is phased governance focused on the highest-risk access first, not a single enterprise-wide redesign.
Editorial analysis by NHI Mgmt Group, based on content published by RSA Security: “Why Traditional IGA Breaks in Modern Environments—And How a More Focused Approach Can Fix It”.
Key questions
Q: What breaks when traditional IGA is forced to cover too much at once?
A: The programme usually breaks at the point where design ambition outruns operational change.
Q: Why do static IGA models lose value in cloud and SaaS environments?
A: Because the access environment changes faster than the model can be kept current.
Practitioner guidance
- Define one high-risk governance use case Start with a single application, entitlement set, or review problem where exposure is obvious and success can be measured quickly.
- Prioritise the riskiest access first Rank accounts and entitlements by business impact, privilege level, and change frequency, then govern the top slice before expanding coverage.
- Replace static role assumptions with living access data Use current access evidence to validate whether roles still reflect how people, contractors, and machines actually work.
Bottom line: Traditional IGA fails when it is treated as a single transformation programme for a moving environment.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Big-bang IGA is a governance assumption failure, not just a delivery problem. The model assumes the estate will stay stable long enough for design, build, and rollout to finish before risk changes materially. In cloud, SaaS, and mixed human-plus-machine environments, that assumption fails because access patterns shift continuously. The implication is that identity governance must be designed for ongoing adaptation, not one-time completion.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: How do teams know if automated access reviews are actually working?
A: Automated reviews are working when exception rates fall, reviewer overrides become rare, and access decisions are grounded in clean role definitions rather than ad hoc exceptions. If certifications keep surfacing the same noisy entitlements, the problem is usually role design, not reviewer effort. Effective automation should reduce ambiguity, not scale it.
👉 Read our full editorial: Traditional IGA breaks at scale in modern environments