CydentiCydenti
NHI Glossary

What Is IGA (Identity Governance & Administration)?

Identity Governance & Administration (IGA) is the discipline of overseeing who — or what — has access to which systems, ensuring that access remains appropriate over time, and producing the audit evidence regulators and auditors expect. IGA typically includes access certification campaigns (periodically confirming access is still needed), role-based access modeling, segregation-of-duties checks, and workflow-driven provisioning and deprovisioning. Where IAM handles the mechanics of authenticating and authorizing identities day to day, IGA sits above it as a governance layer, answering the recurring question 'should this identity still have this access?' IGA programs were built primarily around human employees and their manager-driven review cycles.

Why It Matters

IGA's core mechanism — periodic access certification by a human manager — assumes there's a person who understands what access is needed and why. Non-human identities break that assumption: a service account or API key has no manager to certify it, and the engineer who created it may have left the company or forgotten it exists. As a result, most IGA programs simply exclude NHIs from certification scope, even though they can outnumber human employees 45 to 1 and a typical 100-person company runs 2,000+ of them. That gap is a compliance liability, not just a technical one: OWASP's NHI Top 10 (2025) found 80% of identity breaches involve a non-human identity, and NIS2 — enforced from October 1, 2026, with ANSSI's ReCyF Objective 13 specifically covering service accounts and machine credentials — expects organizations to govern these identities with the same rigor as human access, not leave them outside the audit trail.

How Cydenti Helps

Cydenti fills the gap traditional IGA programs leave open by giving non-human identities an owner, a risk profile, and a reviewable access history — the missing ingredients for certifying them meaningfully. Instead of excluding service accounts and API keys from governance because there's no obvious human to sign off, Cydenti surfaces who actually created and uses each credential, making certification and audit evidence possible for the identity population IGA has historically ignored. See how Cydenti supports audit-ready compliance reporting for non-human identities.

Explore →

Frequently Asked Questions

Why do traditional IGA programs struggle with non-human identities?

IGA access certification relies on a manager or resource owner periodically confirming that access is still needed. Service accounts, API keys, and other non-human identities often have no clear human owner to perform that review, so most IGA programs exclude them from certification scope entirely, leaving a large share of an organization's actual access unreviewed.

Is IGA the same as IAM?

No. IAM handles the operational mechanics of authenticating and authorizing identities in real time. IGA is the governance layer built on top of IAM, focused on periodically reviewing whether existing access is still appropriate, modeling roles, and producing audit evidence — it's about oversight and compliance rather than day-to-day access enforcement.

Ready to secure your future?

Discover the machine identities you didn't know you had — in 27 minutes, for free.

NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.

No commitment • No credit card • Data hosted in Europe • Response within 24h

What Is IGA (Identity Governance & Admin)? | Cydenti