Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that an access platform…
Governance, Ownership & Risk

What are the signs that an access platform is not true IGA?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

The usual signs are weak SoD enforcement, limited hybrid reach, no native privileged access coverage, and audit outputs that look like activity logs rather than control evidence. If the platform can approve access but cannot prove why access was appropriate, it is operating as access workflow tooling rather than governance.

How to Tell Access Workflow from True IGA

A genuine IGA platform proves governance decisions, not just routes requests. If the product mainly moves approvals through a workflow engine, but cannot show authoritative ownership, role logic, entitlement context, or evidence of periodic access review, it is closer to access orchestration than identity governance. The difference matters most when you need durable control over people, systems, and non-human accounts across the lifecycle.

One practical test is whether the platform can explain an access decision in governance terms. If it only records who clicked approve, but cannot tie that approval to policy, role model, SoD rules, or lifecycle state, then it is missing the control layer that makes IGA useful in audits and operations. For a baseline comparison of IGA capabilities, see IAM and IGA Basics and the IGA Buyer’s Guide.

Another marker is depth of lifecycle handling. True IGA connects joiner, mover, and leaver events to provisioning, deprovisioning, role change, and recertification. If the tool handles requests but does not reliably remove outdated access, retire stale entitlements, or close the loop after review, it is not governing identity in a meaningful sense. That is why lifecycle guidance such as Joiner-Mover-Leaver (JML) Guide and Access Reviews and Certification Guide sits at the core of the distinction.

What Weak SoD, Narrow Coverage, and Missing Privileged Access Reveal

Weak segregation of duties is one of the clearest tells. If the platform cannot model toxic combinations, detect conflicts, or enforce compensating controls before access is granted, then it is not governing separation of powers, it is merely routing requests. The same is true if it only works for a narrow set of business apps and misses hybrid estates, cloud resources, or critical non-human access paths.

Coverage also matters. A true IGA program needs usable reach across HR-fed provisioning, enterprise apps, cloud services, and privileged workflows. If privileged access lives outside the platform, or the product cannot govern service accounts and similar non-human identities, then governance is incomplete even if the request screen looks polished. The more a platform depends on manual exceptions, the more it behaves like process automation rather than control enforcement. For a buying lens on these gaps, Role Mining and Role Design Guide and Segregation of Duties (SoD) Guide show what mature governance has to support.

Auditability is the final separator. If exports look like activity logs, ticket trails, or ticket status snapshots instead of control evidence, the platform is not proving whether access was appropriate at the time it was granted and maintained. That is a serious limitation because governance depends on context, entitlement state, reviewer action, and remediation, not just transaction history. Access visibility tools can help, but they are not a substitute for control ownership. See also Identity Visibility and Intelligence Platforms (IVIP) Guide for the difference between visibility and governance.

How to Evaluate Whether a Platform Is Actually Governing Access

A simple evaluation sequence helps separate real IGA from workflow tooling. First, test whether the platform can model roles, entitlements, and SoD constraints in a way that changes approval outcomes. Second, check whether it can certify access against business context and remove access when the answer is no. Third, verify whether it can govern privileged and non-human access without pushing those cases into a separate toolchain.

Top 10 NHI Issues is useful here because governance gaps often show up first in service accounts, shared accounts, and stale credentials. If the platform cannot see those identities, cannot recertify them, or cannot drive timely offboarding, then it may still be useful software, but it is not the governance system the buyer thinks it is.

Practitioner Guidance: What to verify is whether the platform changes decisions, not whether it speeds up approvals. Ask for proof that SoD logic blocks or escalates risky combinations, that recertification results in actual removals, and that privileged and non-human access are in scope for the same control model as workforce access. When those three tests fail, treat the product as access workflow support, not true IGA.

Practitioner takeaway: True IGA is measured by enforced governance and closed-loop remediation, not by how many access requests the platform can route.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementTrue IGA must provision, review, and revoke access over the lifecycle.
AC-5 — Separation of DutiesThe question centers on weak SoD enforcement as a sign of poor governance.
AU-6 — Audit Review, Analysis, and ReportingIGA should produce evidence of why access was appropriate, not just logs.
Recommendation — Implement account lifecycle controls that tie approvals to provisioning, review, and revocation. Enforce separation of duties rules and block conflicting access combinations. Generate audit evidence that shows access rationale, reviewer action, and remediation.
CIS Controls v8CIS-5 — Account ManagementAccess governance is directly tied to account and entitlement lifecycle control.
Recommendation — Centralize account and entitlement management with timely review and removal.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org