Megatrend · Cybersecurity & Digital Trust

Who can access what, should they, and can you prove it?

In a big company with tens of thousands of employees and thousands of apps, everyone holds dozens of "digital keys" — to email, to payroll, to the customer database. But ask an executive a simple question: "Right now, who holds which keys, and should they?" Most can't answer on the spot. This is the problem IGA (Identity Governance & Administration) was built to solve — a system that constantly answers three questions: who can access what · should they really have that right · and can you prove it to an auditor. It isn't glamorous, but it's required by law, and it's where a lot of money is flowing in.

Category Cybersecurity Level Specific topic Layer platform Read time ~12 min
A single employee stands before a wall hung with hundreds of keys, while a librarian with a register walks down the line, checking key by key who should hold each one.
ภาพประกอบ (hero.webp)
The key ledger for the whole organization. IGA is the "librarian" that records who holds which key, takes them back when they're not used, and proves every key is correct.

01What it is

Picture a big company as a building with hundreds of thousands of doors — each door is one access right: into the accounting system, into the contracts folder, into the customer database, into the payment system. Each employee gets a ring of keys, and a single ring might hold 50–100 of them. The question is, who keeps the ledger of which key is in whose hand? Who takes them back when that person changes departments or quits? And if one day an auditor walks in and asks, "Show me proof that everyone who can reach the financial data has a real reason to," how do you answer?

That's the job of IGA — it doesn't "open the door" (that's the login system's job); it governs and administers the entire key ledger. Its full name says exactly what it does: Governance (oversight — who should have what right, reviewed in cycles) plus Administration (the hands-on part — creating, changing, and revoking rights automatically). In one sentence, IGA always answers three questions: who can access what · should they · can you prove it.

On the megatrend map, this node is a branch under Identity & Access Management (IAM) in the big trend Cybersecurity & Digital Trust, with two siblings that work alongside it — Workforce & Customer IAM (SSO/MFA), which handles "proving who you are at login," and Privileged Access Management (PAM), which handles "the admin's privileged accounts." If SSO is "the guard checking your badge at the door" and PAM is "the safe that holds the master keys," then IGA is "the librarian who keeps the building's entire key ledger."

Key terms
Entitlement · Provisioning · Certification

Entitlement = one piece of access (e.g., "can read the payroll folder") — a single key on the ring · Provisioning = automatically "granting" access to various systems when someone joins, and Deprovisioning = "taking it back" when they leave or move · Access Certification (or access review) = having managers periodically review whether "your people should still hold these keys" and sign off — the evidence auditors want.

02Why it matters — keys nobody takes back

The problem IGA solves has a nickname: "access creep" (rights piling up). Picture an employee who's been at the company 10 years — started in sales, moved to marketing, then ran projects. Every time they moved, they got a new set of keys — but almost no one ever took back the old set. In the end, their key ring swells with the rights of every role they've ever held, not just the current one. This is the most dangerous hole, because if their account is hacked, the attacker gets the whole ring too.

Worse still is the orphaned account — the account of someone who's left that no one closed. In reality, "cutting access the moment someone leaves" is harder than it sounds, because the rights are scattered across dozens of systems. Verizon's 2025 report found that about 22% of data breaches involved insiders, part of it from delayed offboarding. And Ponemon estimates that insider threats cost an organization an average of ~$16.2 million a year.

$16.2M average annual cost of "insider" threats per organization (Ponemon) — up ~40% in three years, mostly from accounts with too many rights or not closed when people left

But the biggest force driving this market isn't just security — it's law and auditing. Public companies in the U.S. must pass SOX (Sarbanes-Oxley), which requires them to prove who can access financial systems, to separate duties (so one person can't both create and approve a payment), and to keep complete records. If they can't, a company may be flagged as having a "material weakness" in internal controls — and the stock usually drops 2–5% the moment it's announced. In the past year, about 64% of material weaknesses disclosed came from "people and weak access controls." So IGA is a tool that automatically produces "audit-ready evidence."

IGA doesn't just sell security — it sells "passing the audit"
The events that turned access control into a balance-sheet-level risk (figures from multiple sources)
Source: Verizon DBIR 2025; Moss Adams / SEC data 2025; midpoint of several firms
An employee walks through the organization with a key ring that drags along the floor and swells bigger each time they change departments, with no one taking the old keys back.
ภาพประกอบ (access-creep.webp)
The key ring that won't stop swelling. Every time someone moves jobs they get a new set of keys, but almost no one takes back the old set — this is the access creep IGA was born to fix.

This is why IGA is a "must-have," not a "nice-to-have" — every public company, every bank, every hospital (HIPAA), every company that takes credit cards (PCI DSS) is pushed by law to prove its access controls. So this market grows on "the practical necessity of compliance," not just fear of cyberattacks.

03How it works (the joiner–mover–leaver cycle)

The heart of how IGA works is watching over the "identity lifecycle" at work, which boils down to three beats called joiner – mover – leaver — people who join, people who move roles, people who leave — with one key checkpoint in between, access certification, which reviews whether the keys in everyone's hands should "still be there."

IGA's joiner mover leaver cycle When an employee joins, the HR system signals IGA to grant rights automatically. When they move roles, old rights are removed and new ones added. There's a periodic review of rights by managers, and when they leave, all rights are cut immediately, with evidence recorded at every step. HR system (source) 1 JOINER · joins grant rights automatically by role (provision) 2 MOVER · changes roles remove old rights add new rights ACCESS CERTIFICATION manager reviews + signs off each cycle 3 LEAVER · leaves cut all rights immediately (deprovision) record evidence at every step → send to the auditor (audit)
Keys granted, taken back, and reviewed in cycles. Every time an identity changes state, IGA handles the rights automatically, then keeps a record as evidence — the point that makes you pass the audit is "access certification" in the middle.

What makes this system powerful is that it's tied to the HR system as the source — when HR records a new hire, IGA automatically sets up a bundle of rights by "role" in minutes (instead of waiting weeks for IT to open one system at a time). And when HR records a departure, every right is cut in a single beat, leaving no orphaned account. Meanwhile, access certification forces every department's managers to sit down periodically (say, every quarter) and review which keys each of their people should still hold. What the system quietly keeps at every step is the audit trail — a record of who granted access to whom, when, who approved it, who reviewed it. That's exactly the "audit-ready evidence" the law requires.

04Where it sits in the security world

IGA is the "governance layer" of identity. It doesn't work alone — it's the piece that makes IAM whole. Let's look at how it connects to its neighbors.

  • Paired with Workforce IAM (SSO/MFA): SSO/MFA proves "you are you" at login, while IGA answers the next question — "what should you be able to access?" A verified identity still needs someone to govern its rights, or you just log in and walk anywhere you like
  • Complementing PAM (privileged accounts): PAM guards the admin's most dangerous master keys, IGA guards the keys of "everyone across the organization" — together they cover both ordinary and special users. That's why many big players try to sell both on one platform
  • The foundation of zero trust: for the principle "trust no one automatically, verify every access" to hold, the system has to know first who should access what — which is the rights database IGA maintains. Without IGA setting "what should really be," zero trust has nothing to check against
  • Accelerated by Cloud & Digital Infrastructure and AI: the more an organization moves to the cloud and uses hundreds of SaaS apps, the more the number of "keys" explodes — and AI is creating vast numbers of new "machine identities" that also need governing. IGA's demand grows with this complexity
Perspective An easy way to remember the three IAM siblings: SSO/MFA = "who are you?" (on the way in) · PAM = "the dangerous master keys" (the admin's) · IGA = "who should hold which key, and can you prove it?" (everyone's) — IGA is the piece the auditor asks for. So it's where the compliance team and the IT team meet.

05Where it stands now

The IGA market today is worth about $8.4–9.3 billion in 2025 and is expected to reach $17–33 billion by early next decade — steady growth of about 13–15% a year, because it's driven by laws that aren't going away (every public company has to do this), not just a tech fad.

The IGA market keeps growing double-digit because the law requires it
global market size ($ billions) — 2030 is a projection, midpoint of several firms (CAGR ~13–15%)
Source: Mordor Intelligence, Fortune Business Insights, SkyQuest (midpoint; projection range $17–33B by 2030–2034)

The biggest story in this space lately is the return of the market leader SailPoint — the company regarded as the "pioneer" of IGA for large enterprises. It was taken private by Thoma Bravo (a private equity fund) in 2022 for $6.9 billion, then brought back to the stock market in early 2025 at a valuation of about $12.8 billion, raising $1.38 billion. In its filing, the company revealed ARR of about $813 million, growing ~30% a year, with net retention of 114% (existing customers spend more every year) — a sign that the dull-looking IGA is actually a business where money flows in steadily.

$12.8B SailPoint's valuation when it returned to the stock market in early 2025 — reflecting how highly the market prices a "pure-play IGA leader," while ARR of $813M grows ~30% a year

The key challenger is Saviynt, which just raised $700 million in a Series B in late 2025 at a valuation of about $3 billion to accelerate AI-driven IGA. Meanwhile Denmark's Omada pitches "deployed in 12 weeks" against legacy systems that drag on for years, and Okta is expanding from its SSO base to sell Identity Governance as an add-on module.

But the biggest shadow over this market is Microsoft — with Entra ID Governance sold as an add-on at about $7 per user per month, tied to the Microsoft 365 E5 package many organizations already have. So Microsoft is both a major player and a pricing pressure on every pure-play. The game becomes "the deeper, specialized player" versus "the giant that throws it in with something the customer already owns."

Key players in this field
SailPointSAIL · US
United States · pure-play IGA leader
The pioneer of IGA for large enterprises. Taken private by Thoma Bravo in 2022 ($6.9B), then brought back to the stock market in early 2025 at about $12.8B — ARR around $813M growing ~30% a year, net retention 114%, focused on AI-driven identity security.
core · market leader
MicrosoftMSFT · US
United States · the giant that comes bundled with E5
Sells Entra ID Governance as an add-on at about $7 per user per month, tied to the Microsoft 365 E5 package many organizations already pay for — both a major player and the biggest pricing pressure on every pure-play.
core · challenger by bundling
Saviyntprivate
United States · the AI-route challenger (private)
A key rival that just raised ~$700M in a Series B in late 2025 at about $3B to accelerate AI-driven IGA — strong in organizations that need fine-grained control of ERP-system rights.
secondary · AI challenger
OktaOKTA · US
United States · expanding from an SSO base
The SSO/identity market leader expanding into selling Identity Governance as an add-on module — bundling lifecycle management, workflows, and access governance on the same platform as the original Okta.
secondary · building on SSO
CyberArkCYBR · US
United States · the PAM leader moving into governance
The privileged-account (PAM) market leader expanding into identity governance, including the exploding world of machine/non-human identity — an example of trying to sell both PAM and governance on one platform.
secondary · from PAM to governance
Omadaprivate
Denmark · fast deployment as its selling point (private)
A European cloud-based IGA platform pitching "deployed in 12 weeks" against legacy systems that drag on for years — strong on automation and faster rollout.
secondary · fast deployment
United Kingdom · the specialist
A UK specialist in managing identities and high-security digital credentials — an example of a small specialized player in the identity-governance ecosystem outside the U.S.
core · specialist

06What's ahead — AI deciding access rights, and identity for machines

The first direction is AI stepping into access decisions. The classic problem with access certification is "rubber stamping" — a manager who has to review hundreds of items of a subordinate's rights tends to approve them all in one click without really looking. AI is now helping point out, "this key your report hasn't used in 6 months — should it be removed?" or "this person's rights are abnormal compared with peers in the same role" — turning the review from a meaningless ritual into a data-backed decision.

A single manager faces a huge pile of access-request paperwork to sign off, while a smart machine assistant filters them and flags only the suspicious items to look at.
ภาพประกอบ (ai-review.webp)
From one-click approval to data-backed decisions. AI sifts through huge volumes of access requests, then points the human to only the items that are genuinely abnormal.

The second direction is a tsunami changing the very meaning of the word "identity" — machine identity. Today it's not just "people" that need rights, but bots, scripts, API keys, and lately AI agents working on people's behalf — each one needing access to systems like any employee. The problem is they appear fast and in huge numbers. Several 2025 reports show that machine identities outnumber human ones by 45-to-1, even up to 144-to-1 depending on the organization, growing ~44% in a single year.

"Machine" identities overwhelm "human" ones by a landslide
the ratio of machine identities to human ones in a modern organization (range from several 2025 reports)
Source: Rubrik Zero Labs, Entro Labs, CyberArk (2025 reports; the ratio varies by organization)

This is IGA's biggest new arena — because most machine identities have no clear owner. There's no HR to tell you they've "left," and there are reports that ~68% of organizations still have no access controls for AI at all. Whoever can automate the governance of machine and AI-agent identities first will be the winner of the next generation of IGA.

07Challenges & risks

The first risk is Microsoft's shadow. When Entra ID Governance is sold as a cheap add-on tied to the Microsoft 365 E5 that many organizations already pay for, some customers may pick "good enough and cheaper" over paying extra to a pure-play, even if the specialized product is deeper. This pricing pressure is a direct risk to specialists' revenue — though the specialists argue that organizations with complex systems or apps outside the Microsoft world still need a dedicated platform anyway.

The second risk is deployment complexity. IGA is notorious for projects that drag on for years and budgets that balloon, because you have to connect to dozens or hundreds of legacy systems and define "who should have what right" correctly from the start. Get the foundation wrong and the system just "automates the same chaos, faster." This is why a new-generation player like Omada uses "fast deployment" as a selling point, and it's the hurdle that makes customers hesitate.

The third risk is identity sprawl and machine identity growing faster than the tools can keep up. When AI agents and machine identities multiply to 45–144 times the number of humans, governing all of it becomes an ever-harder problem — fall behind, and new holes open faster than governance can close them. And because the product is "the credibility of proof" itself, if the IGA system fails, it becomes the single point that breaks and takes the whole organization down with it.

The bottom line for investors IGA is the "key ledger" of the whole organization — slow-growing but solid because the law requires it, with subscription revenue customers find hard to drop. Three keys: (1) who handles the wave of machine identity + AI agents first (the biggest arena ahead) · (2) can pure-plays like SailPoint/Saviynt keep the depth that beats Microsoft · (3) who can truly turn access review from a ritual into AI-driven decisions — the real value is in "a platform embedded so deep in the customer's compliance process that it can't be removed," not just one standout feature.

In short: this node is the story of a question that sounds ordinary but is the hardest to answer in any digital-age organization — "who can access what, should they, and can you prove it?" — a question the law requires you to answer, where enormous economic risk hides, and which keeps getting harder now that "identity" is no longer just people.

Explore this theme — live data, stocks & news →