openskills.info
Course Preview

Identity Governance and Administration

Identity governance and administration, or IGA, is the discipline of deciding, granting, reviewing, and removing access to systems and data. It connects business roles and policies to the accounts, permissions, approvals, and evidence that enforce them.

itIdentity, access, and cryptography

Don't Panic — Identity Governance and Administration

Identity governance and administration, or IGA, is the part of access control that refuses to let a permission become a fossil. It connects a business decision to a technical grant, then keeps enough evidence to explain the grant later. That sounds bureaucratic because it is partly bureaucracy, but bureaucracy with a useful habit: it asks who owns access and when it stops.

The important distinction is between access management and governance. Access management answers whether an identity can act now. IGA asks whether it should have that access, who made that call, and whether the reason still exists. The difference is a small word, should, which has a remarkable ability to generate work.

The machinery is a control loop. A person joins, changes duties, finishes a contract, or requests elevated access. Policy and an accountable owner decide what fits. Administration changes the account, group, role, or entitlement in the target system. Evidence records the request, approval, and result. A later review checks that the permission has not wandered off to start a second career.

Two ideas keep the loop honest. A role bundles entitlements for a job or task, which makes repeated access easier to understand. A direct grant can still be necessary, but needs an owner, reason, and end condition. And least privilege means access is limited to a defined task, scope, and period. It is not a decorative label applied after the groups have multiplied.

The surprise is that a completed review is not the finish line. A reviewer can revoke access on paper while the target system keeps it. The useful question is therefore not only did someone decide, but did the account, role, or entitlement actually change? Evidence has to follow the decision all the way to the system that enforces it.

Read the Intro for the full control loop and the boundary between governance and administration. Use the Slides for the relationships among identity, owner, entitlement, target, and review. Keep the Cheatsheet nearby when comparing lifecycle events, reviews, roles, exceptions, and separation of duties. The Exercise turns the loop into a synthetic access review, where no production system receives an alarming surprise.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources