Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Cloud-private IGA
Governance, Ownership & Risk

Cloud-private IGA

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

A cloud deployment model where the identity governance platform runs in a customer-owned cloud tenant rather than a shared vendor tenant. It preserves cloud delivery while shifting control over environment ownership, data residency, and administrative scope back to the customer.

What Cloud-private IGA Actually Changes

Cloud-private IGA keeps the IGA function in a customer-controlled cloud tenant, so the customer owns the environment boundary, administrative scope, and operational controls. The practical change is not the IGA logic itself, but where governance authority, tenancy separation, and data handling are anchored.

That distinction matters because IGA is not just a software category, it is a control plane for lifecycle, access review, entitlement governance, and policy enforcement. For that reason, cloud-private IGA often sits closer to enterprise ownership expectations than a shared vendor-hosted model.

How Cloud-private IGA Shapes Governance and Control

Cloud-private IGA is most often chosen when organisations want cloud delivery without surrendering tenancy control. The customer can align the platform with internal cloud guardrails, segment administrative access, and connect the service to enterprise identity and access processes more directly.

That makes the deployment model especially relevant for organisations that treat identity governance as a core control function rather than a convenience layer. A private tenant can make it easier to reflect internal approval chains, segregation requirements, and data residency expectations in the operating model.

In governance terms, cloud-private IGA also helps clarify ownership. The customer is not merely consuming a service, it is operating a governed platform inside a managed cloud boundary, which changes how responsibilities for configuration, logging, backup, and access administration should be assigned.

What Belongs in a Cloud-private IGA Architecture

A cloud-private design should preserve the normal IGA capabilities, such as provisioning, access reviews, role management, and entitlement lifecycle controls, while adding stronger tenant scoping and environment isolation. Those controls are what make the deployment model materially different from a generic hosted SaaS arrangement.

Customers should expect the architecture to support integration with authoritative sources, downstream target systems, and audit evidence flows without blurring tenant boundaries. The point is to keep the platform modern and cloud-native while still making the customer the clear operational owner of the governance environment.

For a deeper foundation on the control model behind this architecture, IAM and IGA Basics explains how identity governance differs from access administration, and IGA Buyer's Guide shows the platform capabilities buyers should validate.

Where Cloud-private IGA Fits in the Broader Identity Lifecycle

Cloud-private IGA is usually part of a broader lifecycle model that includes joiner, mover, leaver handling, access recertification, and entitlement cleanup. The deployment model does not change those objectives, but it can make them easier to govern when the customer wants tighter control over the execution environment.

That is especially relevant when lifecycle decisions must be auditable across people, contractors, privileged users, and automation. The environment can also help when teams want clearer segregation between governance data, operational administration, and the systems being governed.

Identity lifecycle discipline is still the real control objective, so the platform should be evaluated on whether it supports that discipline cleanly inside a customer-owned tenant. Joiner-Mover-Leaver (JML) Guide and Access Reviews and Certification Guide are useful reference points for those lifecycle controls.

Deployment Trade-offs and Operating Expectations

Cloud-private IGA reduces some tenancy and data-scope concerns, but it shifts more responsibility back to the customer. The platform may feel SaaS-like, yet the customer still needs disciplined administration, governance oversight, and integration management to avoid recreating the complexity of self-hosted IGA in a cloud wrapper.

This model also places more weight on environment design choices such as tenant isolation, connector management, and role assignment for platform administrators. If those choices are weak, the private tenant can still become a governance bottleneck, even if the deployment is technically cloud-based.

A useful operational check is whether the customer can explain who owns the tenant, who can administer it, what data lives there, and how access changes are reviewed. That is the difference between a cloud deployment and a cloud-private governance platform.

Risk and Threat Considerations

Cloud-private IGA lowers some exposure by reducing shared-tenant dependence, but it also concentrates sensitive governance data and administrative control inside one customer-owned environment. If that tenant is over-permissioned, weakly segmented, or poorly monitored, the control plane for identity governance can become a high-value target.

Failure mechanism: Excessive admin privilege, connector abuse, or poor tenant isolation can expose governance records, change approval paths, and lifecycle actions, which then affects the integrity of downstream identity decisions.

Impact: An attacker or insider who reaches the tenant can tamper with access governance, suppress reviews, alter provisioning behaviour, or use the platform to scale unauthorized access across connected systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeCloud-private IGA depends on tightly scoped tenant and admin access.
IA-5 — Authenticator ManagementIGA tenants rely on credentials and secrets for administrative and connector access.
AU-2 — Event LoggingIGA governance decisions and admin actions need auditable records.
Recommendation — Limit IGA tenant administration to the minimum necessary privileges. Manage platform credentials with rotation, protection, and lifecycle controls. Log tenant administration, workflow changes, and provisioning events.
CSA Cloud Controls MatrixIAM — Identity & Access ManagementCloud-private IGA is an IAM governance platform deployed in a customer cloud tenant.
Recommendation — Align tenant ownership, access governance, and lifecycle controls to IAM requirements.
ISO/IEC 27001:2022A.5.15 — Access controlThe model is defined by who can administer the customer-owned governance tenant.
Recommendation — Define and enforce access control responsibilities for the private tenant.

Practitioner Guidance

Governance implication: Treat cloud-private IGA as an owned control environment, not just a hosted application. The operating model should clearly assign responsibility for tenant administration, access to the IGA platform, connector trust, and audit evidence retention.

What to watch for: Pay close attention to whether the deployment preserves meaningful tenant separation, supports lifecycle and review workflows cleanly, and keeps administrative access narrowly scoped. If the answer is no, the environment may be cloud-hosted but not truly cloud-private in governance terms.

When the model is implemented well, it gives organisations a practical middle ground between SaaS convenience and self-managed control, while keeping identity governance close to enterprise policy and audit needs.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org