NCC Group’s expanded collaboration with SailPoint highlights how identity security is becoming a broader operating discipline rather than a narrow access-management function. For organisations managing complex workforces, contractors, applications and automated processes, the partnership points to a practical need: identity governance must connect policy, implementation and ongoing assurance.
The challenge is that identity risk rarely sits in one system. Joiners, movers and leavers may be handled by HR, access requests by an IGA platform, privileged permissions by a separate control, and application ownership by individual business teams. Without coordination, an organisation can have strong controls on paper while retaining excessive or outdated access in production.
From an IGA perspective, a collaboration between a security consultancy and a major identity platform matters because governance depends on execution. Policy design is only useful when access models reflect real business roles, approval paths are understood, and certification campaigns produce decisions that administrators can act on. Implementation expertise can help organisations translate broad governance goals into connected identity lifecycle management processes.
The first priority is role and entitlement visibility. Security teams need to understand which identities can reach sensitive applications, what privileges are inherited through groups, and where access has accumulated outside formal workflows. That visibility supports more meaningful access reviews and helps reduce the common problem of reviewers approving permissions they cannot interpret.
The second is lifecycle consistency. When a person changes department or responsibility, access should be recalculated from authoritative attributes rather than relying on manual tickets. Automated provisioning and deprovisioning reduce delays, but they also need exception handling, ownership and evidence. IGA teams should measure not only whether an account was created, but whether the resulting access matched policy.
A third consideration is integration with risk operations. Identity signals can strengthen investigations by showing who approved access, when it changed and whether the permission was used. Conversely, security findings can inform governance decisions, such as prioritising high-risk entitlements for review or requiring stronger approval for sensitive systems.
For CISOs, the commercial announcement is therefore less important than the operating model it represents. Successful identity governance administration requires platform capability, reliable data, process ownership and specialist knowledge working together. Buyers assessing similar programmes should examine how vendors will improve entitlement quality, lifecycle automation, review completion and audit evidence—not simply how many connectors are listed on a product sheet.