Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Phase One IGA
Governance, Ownership & Risk

Phase One IGA

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

A limited identity governance rollout that covers only a small set of high-priority applications first. The approach is useful for early progress, but it becomes a risk when the rest of the application estate is left outside enforceable lifecycle and certification controls.

Why Phase One IGA Exists

Phase One IGA is a pragmatic rollout pattern, not a weakened governance model. It lets teams establish the core identity governance motions first, such as ownership, entitlement visibility, access reviews, and lifecycle control for the most important applications, before expanding to the rest of the estate.

The value is sequencing: the organisation gets measurable progress without waiting for a perfect enterprise-wide programme. That can reduce implementation friction, accelerate audit readiness, and prove that governance workflows actually work in production.

What Phase One IGA Covers, and What It Deliberately Leaves Out

A phase-one rollout usually focuses on high-value systems, sensitive data platforms, or applications with the clearest entitlement structure. In practice, that means prioritising the systems where overprovisioning, dormant access, and weak joiner-mover-leaver handling create the biggest exposure.

The trade-off is scope. When the rollout stops at a small application set, the rest of the environment can remain outside enforceable provisioning, certification, and deprovisioning controls. IAM and IGA Basics is a useful companion for understanding how governance, authorisation, and lifecycle control fit together.

That limited coverage is not a flaw by itself. It becomes one only when the phase-one boundary is treated as the final governance state rather than the start of a wider operating model.

How Phase One IGA Changes Governance Work

Phase One IGA changes the way teams prioritise reviews, role design, and provisioning rules. Instead of trying to normalise every entitlement on day one, practitioners define a governed core, stabilise the operating process, and use that first scope to refine policies, ownership, and exception handling.

This approach is often paired with targeted access recertification and clearer lifecycle triggers. Access Reviews and Certification Guide supports the review side of that model, while Joiner-Mover-Leaver (JML) Guide maps the lifecycle side of the same governance problem.

Role structure also matters early. If the first phase starts with messy roles or duplicated entitlements, the programme can automate inconsistency faster than it automates control. Role Mining and Role Design Guide is relevant because a narrow rollout still needs a role model that can scale cleanly.

Common Failure Patterns in a Phase One Rollout

Phase One IGA fails when leaders mistake pilot success for programme completion. A controlled first set of applications can look healthy while shadow access, stale entitlements, and manual exceptions continue everywhere else.

Another common failure is using the pilot to prove tooling rather than governance. If the programme only automates a few workflows but does not establish ownership, review cadence, exception handling, and deprovisioning discipline, it may create a polished demonstration without reducing enterprise risk.

That is why initial scope should be chosen for governance value, not just implementation convenience. Where the first phase includes the highest-risk systems, the organisation learns whether Segregation of Duties (SoD) Guide and access certification can actually hold up under real operational pressure.

Risk and Threat Considerations

Phase One IGA creates a governance gap if the “phase one” boundary becomes a standing exception. The main risk is uneven control coverage, because attackers and insiders do not need the governed applications if other systems still allow persistent access, stale accounts, or weak entitlement oversight.

Failure mechanism: Partial rollout leaves parts of the estate outside enforceable lifecycle and certification control, so access creep, dormant permissions, and orphaned access can accumulate unchecked in the uncovered population.

Impact: Privilege misuse, delayed revocation, audit findings, and broader identity exposure become more likely, especially when the unchecked applications still connect to sensitive data or downstream admin paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementPhase one IGA governs account and entitlement lifecycle for in-scope applications.
IA-5 — Authenticator ManagementIGA rollouts often control credentials and lifecycle steps tied to access governance.
AC-6 — Least PrivilegePhase one IGA is about constraining access to high-priority systems before broad expansion.
Recommendation — Apply AC-2 to ensure accounts are provisioned, reviewed, and removed under defined ownership. Apply IA-5 to manage credential lifecycle and reduce lingering access after phase-one rollout. Apply AC-6 to keep initial application access limited to the minimum required privileges.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlPhase one IGA is an identity governance control rollout that establishes access control discipline.
GV.OC-03 — Understanding Organizational Role and ResponsibilityPhase one IGA depends on clear ownership for application access decisions and certification.
Recommendation — Use PR.AA-05 to formalize access governance for the first application set. Use GV.OC-03 to assign accountable owners for the governed application scope.
ISO/IEC 27001:2022A.5.15 — Access controlPhase one IGA implements controlled access decisions for a limited application population.
A.5.16 — Identity managementIGA rollout depends on managed identities, entitlement ownership, and lifecycle control.
A.5.18 — Access rightsPhase one IGA is often centered on granting, reviewing, and revoking application access rights.
Recommendation — Use A.5.15 to define access rules and governance boundaries for the first rollout phase. Use A.5.16 to anchor identity ownership and lifecycle governance in the pilot scope. Use A.5.18 to govern access rights reviews and removals for in-scope systems.

Practitioner Guidance

Why practitioners should care: Phase One IGA should be managed as a governed starting point, not a permanent subset. The practical question is whether the first scope is designed to prove a repeatable operating model that can extend to the rest of the estate.

Practitioner takeaway: Treat phase one as the control blueprint, then use the lessons from the first applications to define the next expansion wave, not to justify stopping there.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org