Identity governance and administration is becoming a central security discipline as organisations add cloud services, automation and artificial intelligence. The question is no longer simply who has access, but whether access is justified, current, observable and accountable throughout the identity lifecycle.
That creates a practical problem for security teams. Identity data is distributed across directories, SaaS platforms, infrastructure and specialist tools, while access decisions still need to be made quickly. Manual reviews and disconnected provisioning create entitlement drift, orphaned accounts and audit friction.
Extending governance beyond human users
Identity governance must increasingly control software agents, service accounts and automated workflows. These identities can initiate actions at scale without a conventional employee behind every transaction.
The governance problem is accountability. Organisations need to know who owns an agent, what it may do, which data it can reach and when access expires.
Lifecycle controls for AI identities
Registration should record purpose, sponsor, dependencies, permitted tools and environments. Changes to an agent’s function should trigger policy evaluation. Runtime controls and IGA approval workflows must be connected so a review can affect live permissions.