What is IGA? Identity Governance & Administration
Identity Governance and Administration (IGA) is the discipline that focuses on the policies and management of digital identities and their access rights across an organisation. Where IAM ensures users get the right access, IGA ensures that access remains appropriate over time, aligns with broader organisational policy, and can be verified and audited at any point. IGA also provides the tools to identify where identity management can be improved.
The Difference Between IGA and IAM
There is no single universally accepted definition of IGA, and most vendors, analysts, and specialists use their own descriptions. The boundaries between IGA and IAM are rarely drawn in exactly the same place twice.
Gartner draws a useful distinction: IGA differs from IAM in that it enables organisations not only to define and enforce access policy, but also to connect those IAM functions to meet audit and compliance requirements. In other words, IAM is the operational layer, and IGA is the governance layer that verifies the operational layer is working as it should.
Some analysts treat IGA as an extension of IAM. Others position it as a progression path, where an organisation moves from administering identities to actively governing them. Tools4ever takes the latter view. IAM gets you in control of who has access to what. IGA keeps you in control as your organisation evolves.
IAM Consists of Two Functions
IAM traditionally combines Identity Management (IM) and Access Management (AM). Identity management covers the provisioning and administration of digital identities and their associated rights. Access management covers the technology layer that secures access: Single Sign-On (SSO), Multi-Factor Authentication (MFA), and related capabilities.
In practice, the access management component is increasingly handled by mainstream platforms such as Active Directory and Entra ID. Many HelloID customers use Entra ID for access management. The HelloID Access Management module remains available and is used primarily for specific scenarios where the Microsoft stack is unavailable or unsuitable.
The identity management component is where the progression toward IGA becomes most relevant, and where HelloID continues to invest.
Evolving from IAM to IGA
HelloID is continuously developing its identity management functionality toward a full IGA environment. This means going beyond the operational provisioning of accounts and rights to include attribute-based access control, reporting, reconciliation, and audit capabilities.
The goal is control across the entire identity lifecycle. HelloID provisions users with the correct accounts and rights when they join, adjusts those rights automatically when they change role or department, and removes access promptly when they leave. This keeps identity management aligned with business policy in real time and supports ongoing compliance with applicable regulations.
Much of this functionality already exists within the HelloID Provisioning and Service Automation modules. The governance layer adds further capabilities on top, described below.
Why IGA Matters Now
IAM began as an IT operations discipline: provision the right access, manage it efficiently, keep the helpdesk load manageable. For a long time, it remained an internal IT matter.
That has changed. Most organisations today are almost entirely digital, which means identity management is a primary business process. If users cannot access their systems, operations stop. At the same time, demonstrable compliance with privacy legislation and information security standards is no longer optional.
UK organisations operating under UK GDPR, ISO 27001, the UK NIS Regulations, and sector-specific frameworks such as the NHS Data Security and Protection (DSP) Toolkit face real consequences for non-compliance. Fines under UK GDPR can reach £17.5 million or 4% of global annual turnover, whichever is higher. ISO 27001 certification requires documented, auditable access controls. The forthcoming Cyber Security and Resilience Bill will extend those obligations further.
For the CIO and IT Director, identity and access management has moved from an operational concern to a governance priority. That shift is what drives the transition from IAM to IGA.
The HelloID Governance Module
A useful way to think about the distinction: IAM turns off the tap; IGA keeps it off. With IAM, you operate according to policy, enforce your processes, and prevent unnecessary access from being issued. With IGA, you verify continuously that those controls are working, catch what slips through, and keep your access landscape aligned with current business operations and regulatory requirements.
The HelloID Governance module delivers this ongoing control through a growing set of capabilities.
Governance Features in HelloID
Feature | What it does |
|---|---|
Reconciliation | Compares the target state (the desired configuration within HelloID) against the actual state in connected target systems, surfacing and resolving discrepancies |
Toxic Rules Management | Automatically detects and prevents conflicting access rights from being issued; resolves conflicts according to configured rules |
Integrated Role Mining | Identifies patterns in source data and issued rights, enabling continuous optimisation of business rules |
Advanced Role Model | Streamlines the management of complex business rule sets, keeping identity management manageable at scale |
Recertification | Periodically reviews rights previously granted through self-service requests to verify they are still required and compliant with current policy |
Product Suggestions | Makes self-service access requests more user-friendly and efficient for employees and their managers |
Advanced Approval Workflows | Enables more intelligent, configurable workflows for complex or high-risk access requests |
These capabilities are on an active development roadmap and will continue to expand.
Benefits of IGA
Better compliance with laws and regulations. Reconciliation gives you the ability to demonstrate at any point that the access rights registered in your system have actually been implemented correctly in every connected target system. That kind of auditable evidence is what ISO 27001 auditors and UK GDPR supervisors require.
Continuous optimisation of your access structure. Toxic Rules Management, Role Mining, and the Advanced Role Model work together to improve the existing rights structure progressively and keep it aligned with business operations as they evolve. Over time, your access model becomes more accurate, not just more up to date.
Improved service processes. Recertification ensures that rights are granted only when genuinely necessary. Product Suggestions and Advanced Approval Workflows make self-service more efficient and more controlled at the same time, removing the tension between usability and security.