Identity governance and administration (IGA) platforms manage who has access to what, why and for how long: lifecycle automation, access requests, reviews, roles and segregation of duties. The market ranges from long-established suites with deep customisation to newer cloud-native products that promise faster deployment, plus governance features built into identity providers and SaaS management tools. Many IGA programmes have struggled with long implementations and limited application coverage. This vendor-neutral buyer's guide helps you define requirements, compare options, test the hard parts and avoid common pitfalls.
Key takeaways
- The biggest cost and risk in IGA is usually application integration, not the platform itself. Test connectors for your hardest applications.
- Look for strength in lifecycle automation, access requests, reviews with context, role management and SoD, and assess how well each works in practice, not just whether it exists.
- Check how the platform governs non-human identities and AI agents, which many IGA tools were not designed for.
- Weigh time to value and operating effort against flexibility; heavy customisation is expensive to maintain.
Define requirements
- Populations: employees, contractors, partners, service accounts, AI agents.
- Authoritative sources: HR, non-employee systems.
- Applications: how many, which have standard connectors (SCIM, directory, major SaaS), which are custom or on-premises?
- Compliance drivers: SOX, PCI DSS, HIPAA, DORA and others. See the Identity Security Regulatory Map.
- Current maturity and pain points: slow onboarding, failed audits, orphaned accounts, review fatigue.
Capability areas
| Area | What to look for |
|---|---|
| Lifecycle (JML) | HR-driven joiners, movers and leavers; birthright rules; mover access removal. See the JML Guide |
| Access requests | User-friendly catalogue; approval routing; time-bound access; policy checks |
| Access reviews | Context (usage, peer comparison, risk); micro-certifications; rubber-stamp detection; closed-loop revocation. See the Access Reviews Guide |
| Roles | Role mining, modelling and lifecycle. See the Role Design Guide |
| SoD | Cross-application rulesets; preventive and detective checks; mitigation tracking. See the SoD Guide |
| Connectors and provisioning | Breadth and depth of connectors; SCIM; handling of disconnected apps; reconciliation |
| Non-human identities | Inventory and ownership of service accounts, OAuth apps and agents; reviews for NHIs; integration with NHI platforms |
| Analytics and AI | Outlier detection, recommendations, natural-language access requests, with explainability |
| Reporting and audit | Evidence for auditors; history of who approved what and why |
Questions to ask vendors
- How would you integrate our three hardest applications, and how long would it take?
- What happens to requested access when someone changes role?
- Show a review campaign with usage data and peer comparison, and how revocations are executed and verified.
- How do you govern service accounts, OAuth apps and AI agents, including ownership and reviews?
- What customisations will we need, and how do upgrades affect them?
- What are typical implementation timelines for organisations like ours, and can we speak to references?
Red flags
- Connector claims that turn out to be "build it yourself" frameworks.
- Reviews that show only entitlement names without context.
- No path for disconnected applications other than manual spreadsheets.
- NHI support limited to importing accounts with no ownership or lifecycle.
- Implementation estimates that depend heavily on professional services.
Proof of concept
- Connect HR and three to five applications, including at least one difficult one.
- Run joiner, mover and leaver scenarios end to end.
- Run a small review campaign with real reviewers and measure revocation rate and time.
- Test an SoD rule preventing a conflicting request.
- Import service accounts and OAuth apps and test ownership and review.
How NHI Mgmt Group can help
We provide independent requirements, RFP and evaluation support for IGA and NHI governance programmes. Browse vendors in our products directory or contact us.
Related NHI Mgmt Group resources: IAM and IGA Basics · NHI Security Platform Buyer's Guide · PAM Buyer's Guide · IVIP and ISPM Buyer's Guide