The usual signs are weak SoD enforcement, limited hybrid reach, no native privileged access coverage, and audit outputs that look like activity logs rather than control evidence. If the platform can approve access but cannot prove why access was appropriate, it is operating as access workflow tooling rather than governance.
How to Tell Access Workflow from True IGA
A genuine IGA platform proves governance decisions, not just routes requests. If the product mainly moves approvals through a workflow engine, but cannot show authoritative ownership, role logic, entitlement context, or evidence of periodic access review, it is closer to access orchestration than identity governance. The difference matters most when you need durable control over people, systems, and non-human accounts across the lifecycle.
One practical test is whether the platform can explain an access decision in governance terms. If it only records who clicked approve, but cannot tie that approval to policy, role model, SoD rules, or lifecycle state, then it is missing the control layer that makes IGA useful in audits and operations. For a baseline comparison of IGA capabilities, see IAM and IGA Basics and the IGA Buyer’s Guide.
Another marker is depth of lifecycle handling. True IGA connects joiner, mover, and leaver events to provisioning, deprovisioning, role change, and recertification. If the tool handles requests but does not reliably remove outdated access, retire stale entitlements, or close the loop after review, it is not governing identity in a meaningful sense. That is why lifecycle guidance such as Joiner-Mover-Leaver (JML) Guide and Access Reviews and Certification Guide sits at the core of the distinction.
What Weak SoD, Narrow Coverage, and Missing Privileged Access Reveal
Weak segregation of duties is one of the clearest tells. If the platform cannot model toxic combinations, detect conflicts, or enforce compensating controls before access is granted, then it is not governing separation of powers, it is merely routing requests. The same is true if it only works for a narrow set of business apps and misses hybrid estates, cloud resources, or critical non-human access paths.
Coverage also matters. A true IGA program needs usable reach across HR-fed provisioning, enterprise apps, cloud services, and privileged workflows. If privileged access lives outside the platform, or the product cannot govern service accounts and similar non-human identities, then governance is incomplete even if the request screen looks polished. The more a platform depends on manual exceptions, the more it behaves like process automation rather than control enforcement. For a buying lens on these gaps, Role Mining and Role Design Guide and Segregation of Duties (SoD) Guide show what mature governance has to support.
Auditability is the final separator. If exports look like activity logs, ticket trails, or ticket status snapshots instead of control evidence, the platform is not proving whether access was appropriate at the time it was granted and maintained. That is a serious limitation because governance depends on context, entitlement state, reviewer action, and remediation, not just transaction history. Access visibility tools can help, but they are not a substitute for control ownership. See also Identity Visibility and Intelligence Platforms (IVIP) Guide for the difference between visibility and governance.
How to Evaluate Whether a Platform Is Actually Governing Access
A simple evaluation sequence helps separate real IGA from workflow tooling. First, test whether the platform can model roles, entitlements, and SoD constraints in a way that changes approval outcomes. Second, check whether it can certify access against business context and remove access when the answer is no. Third, verify whether it can govern privileged and non-human access without pushing those cases into a separate toolchain.
Top 10 NHI Issues is useful here because governance gaps often show up first in service accounts, shared accounts, and stale credentials. If the platform cannot see those identities, cannot recertify them, or cannot drive timely offboarding, then it may still be useful software, but it is not the governance system the buyer thinks it is.
Practitioner Guidance: What to verify is whether the platform changes decisions, not whether it speeds up approvals. Ask for proof that SoD logic blocks or escalates risky combinations, that recertification results in actual removals, and that privileged and non-human access are in scope for the same control model as workforce access. When those three tests fail, treat the product as access workflow support, not true IGA.
Practitioner takeaway: True IGA is measured by enforced governance and closed-loop remediation, not by how many access requests the platform can route.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | True IGA must provision, review, and revoke access over the lifecycle. |
| AC-5 — Separation of Duties | The question centers on weak SoD enforcement as a sign of poor governance. | |
| AU-6 — Audit Review, Analysis, and Reporting | IGA should produce evidence of why access was appropriate, not just logs. | |
| Recommendation — Implement account lifecycle controls that tie approvals to provisioning, review, and revocation. Enforce separation of duties rules and block conflicting access combinations. Generate audit evidence that shows access rationale, reviewer action, and remediation. | ||
| CIS Controls v8 | CIS-5 — Account Management | Access governance is directly tied to account and entitlement lifecycle control. |
| Recommendation — Centralize account and entitlement management with timely review and removal. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org