Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

IGA Coverage

← Back to Glossary
By NHI Mgmt Group Updated October 7, 2026 Domain: Governance, Ownership & Risk

IGA coverage is the portion of an application estate whose access, entitlement, and review processes are controlled by an identity governance platform. For custom apps, coverage is often the limiting factor, because unsupported integrations leave organisations with manual work and weaker assurance over who has access to what.

What IGA coverage means in practice

IGA coverage is not just whether an organisation owns an identity governance tool, it is how much of the application estate the tool can actually control. The practical test is whether access requests, entitlement visibility, and periodic review workflows are enforced in the system itself rather than handled outside it.

Coverage matters because the control boundary is rarely uniform. Core business applications, SaaS platforms, custom apps, and legacy systems often sit at different levels of integration, so the effective governance model is usually a mix of automated enforcement and manual exception handling.

Where coverage is high, the organisation can treat access governance as a repeatable control. Where coverage is thin, the programme may still exist on paper, but assurance depends on spreadsheets, tickets, or local app owners.

Why coverage becomes the limiting factor

Coverage is often the constraint that determines whether IGA reduces risk or only documents it. A platform can manage roles and reviews well for connected systems, yet leave the hardest-to-govern applications outside its reach, which creates blind spots in entitlement ownership and recertification.

That is why unsupported or partially supported integrations are so consequential, especially in estates with many custom apps. When an app cannot speak the governance platform’s native language, the organisation loses scale and consistency, and the process drifts toward manual control. The distinction is visible in IAM and IGA Basics, which frames identity governance as the control layer for provisioning, reviews, and entitlement oversight.

Coverage also affects how confidently teams can answer basic questions such as who has access, why they have it, and whether that access is still appropriate. If the answer depends on separate records for different application classes, governance quality becomes uneven even when the policy is sound.

How coverage changes identity governance outcomes

Coverage changes the output of the whole programme, not just its admin burden. Access reviews are only as trustworthy as the systems they include, role models are only as useful as the applications they map to, and joiner-mover-leaver processes are only as complete as the applications they can provision and deprovision.

It also changes whether governance can support change at scale. In a well-covered estate, entitlement review, request approval, and lifecycle actions are consistent enough to support auditability and least-privilege decisions. In a fragmented estate, the same control objectives may still exist, but they rely on local workarounds and ad hoc evidence. For implementation tradeoffs, the IGA Buyer's Guide is a useful reference for evaluating connectors, workflows, and application fit.

Coverage is therefore a measure of control reach, not platform brand strength. An enterprise can buy a mature IGA tool and still have weak governance if a large share of the app estate remains outside automated entitlement and review processes.

Coverage, custom apps, and operational trade-offs

Custom applications are where coverage gaps usually show up first because they rarely match standard connectors or prebuilt review models. The result is a practical trade-off between moving fast and maintaining evidence-backed control over entitlements.

That trade-off affects how organisations design governance boundaries. If the app estate includes many bespoke systems, teams need a clear policy for which applications are governed natively, which are integrated through custom connectors, and which remain on manual controls until coverage improves. For that reason, the lifecycle view in NHI Lifecycle Management Guide is relevant here as a model for how control maturity depends on discovery, ownership, and decommissioning discipline.

Coverage should also be understood as a living metric. As application portfolios change, a once-good integration can become stale, and a once-manual workaround can become permanent. The governance question is not whether the platform exists, but whether its reach still reflects the real estate it is supposed to control.

Risk and Threat Considerations

Low IGA coverage creates control gaps that can leave accounts, entitlements, and review evidence outside formal governance. The result is weaker assurance over excessive access, delayed removal of obsolete permissions, and reduced visibility into who can do what across the application estate.

Failure mechanism: Unsupported applications, custom integrations, or manual fallbacks bypass automated provisioning, review, and certification workflows, so access decisions persist without central oversight.

Impact: The organisation can accumulate privilege creep, orphaned access, audit findings, and higher exposure from accounts that were never reviewed or revoked on time.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementIGA coverage determines whether account provisioning and review are enforced across apps.
AC-6 — Least PrivilegeCoverage affects whether entitlement governance can actually constrain access rights.
IA-5 — Authenticator ManagementCoverage often depends on lifecycle handling for credentials and tokens linked to governed access.
Recommendation — Extend account lifecycle controls to every integrated application and close manual gaps. Use least-privilege reviews to reduce excess access in covered and custom apps. Track credential lifecycle dependencies where unmanaged apps weaken governance coverage.
CIS Controls v8CIS-5 — Account ManagementIGA coverage is an account-management problem across the application estate.
CIS-6 — Access Control ManagementCoverage measures how broadly access control is enforced and reviewed.
Recommendation — Map every application to an account-management path and eliminate unsupported blind spots. Apply access-control governance consistently across all applications with elevated access risk.

Practitioner Guidance

Governance implication: Treat coverage as a control-design metric, not a deployment metric. The useful question is whether the applications that matter most to access risk are actually inside the governed boundary, including custom apps and other systems that would otherwise stay manual.

Practitioner takeaway: When coverage is uneven, prioritise the applications whose unmanaged access would create the largest governance and assurance gap, rather than assuming the platform’s global rollout tells the whole story.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org