Knowledge Center
Glossary
Identity governance definitions from A to Z. Select a letter to jump to matching terms.
Looking for side-by-side explainers? See comparisons.
A18 terms
Access Certification
Access certification is the formal process in which an authorized reviewer confirms, changes or revokes a person's or non-human identity's access.
Access Governance
Access control is the combination of policies and mechanisms that permits or denies an identity's requested action on a resource.
Access Control
Access control is the combination of policies and mechanisms that permits or denies an identity's requested action on a resource.
Access Intelligence
Access intelligence is the use of normalized identity, account, entitlement, activity and risk data to explain access and improve decisions.
Access Policy
An access policy is a documented rule that defines the conditions under which access may be granted, retained, used or revoked.
Access Request
An access request is a recorded request to grant, change, extend or remove access for an identity.
Access Review
An access review is a periodic, event-driven or continuous evaluation of whether assigned access remains appropriate.
Access Risk
Access risk is the potential harm created by excessive, inappropriate, conflicting or unmanaged access to systems and data.
Account Aggregation
Account Aggregation is the collection of accounts, entitlements, groups and selected activity data from target systems into an IGA repository.
Account Correlation
Account Correlation is the process of matching an account in a target system to the correct enterprise identity.
Account Lifecycle
The account lifecycle is the sequence through which a target-system account is created, enabled, modified, suspended, disabled, retained and deleted.
Application Onboarding
Application Onboarding is the process of bringing a system under identity governance.
Approval Workflow
An approval workflow is a defined sequence of decision steps for an access request or governance action.
Attestation
Attestation is a recorded statement by an accountable person that access, a control or a set of information is accurate and appropriate at a point in time.
Attribute Based Access Control (ABAC)
ABAC is an authorization model that evaluates attributes of the subject, resource, requested action and environment against policy rules before granting or denying access.
Audit Evidence
Audit Evidence in IGA is the verifiable record showing that identity controls were designed and operated as intended.
Authentication
Authentication is the process of verifying that a person, device or workload is the identity it claims to be.
Authorization
Authorization is the decision to permit or deny an authenticated identity's requested action on a resource.
B2 terms
Birthright Access
Birthright Access is baseline access automatically granted because an identity meets defined criteria, such as being an active employee in a particular location or department.
Break-glass Access
Break-glass Access is exceptional, tightly controlled access used during an emergency when normal access methods are unavailable or too slow.
C7 terms
Certification Campaign
A Certification Campaign is a managed collection of access-review tasks launched for a defined population, application, entitlement or risk area.
Cloud IGA
Cloud IGA is identity governance and administration delivered as a cloud service or designed to govern access across cloud, SaaS and hybrid environments.
Compensating Control
A Compensating Control is an alternative safeguard used when the preferred control cannot be implemented fully or immediately.
Conditional Access
Conditional Access is runtime authorization that uses context - such as identity, device security, location, network, application sensitivity or risk- to allow, block or restrict access.
Connected Application
A Connected Application is a target system integrated with IGA so that identity, account and entitlement data can be exchanged automatically.
Continuous Access Evaluation
Continuous Access Evaluation is the reassessment of access when relevant identity, device, session, threat or policy conditions change, rather than waiting for a session to expire or a periodic review.
Continuous Controls Monitoring (CCM)
Continuous Controls Monitoring (CCM) is the automated, ongoing testing of control conditions and evidence.
D9 terms
Data Access Governance (DAG)
Data access governance (DAG) is the discovery, classification, ownership, policy and review of access to structured and unstructured data.
Data Owner
A data owner is the business role accountable for a dataset's classification, permitted use, access requirements, retention and protection.
Delegated Administration
Delegated administration assigns limited identity-management responsibilities to authorized business or technical teams.
Deprovisioning
Deprovisioning is the removal, disabling or reduction of access when it is no longer needed.
Detective Control
A detective control identifies an undesired condition after it exists.
Digital Identity
A digital identity is a representation of a person, organization, device, application, service or workload in an information system.
Disconnected Application
A Disconnected Application is a system that is governed by IGA without a direct automated connector for reading or changing access.
Dormant Account
A dormant account is an account that remains enabled but has not been used for a defined period.
Dynamic Separation of Duties
Dynamic separation of duties (DSD) prevents conflicting actions within a transaction, session or defined period, even if a person is eligible for both roles.
E5 terms
Effective Access
Effective access is the total access an identity can exercise after direct, inherited, role-based and policy-based permissions are resolved.
Entitlement
An entitlement is a discrete access right, such as a group membership, application role, permission or API scope.
Entitlement Catalog
An entitlement catalog is a governed inventory of access items that can be requested, assigned, reviewed or analyzed.
Entitlement Owner
An entitlement owner is accountable for an access right's purpose, eligibility, risk, approvals and review policy.
Excessive Privilege
Excessive privilege is access beyond what an identity currently needs for authorized duties.
F2 terms
G3 terms
Governance Policy
A governance policy is an approved statement of required behavior and accountability for identities and access.
Governance, Risk and Compliance (GRC)
GRC coordinates how an organization sets direction, manages uncertainty and meets internal and external obligations.
Group
A group is a collection of identities or accounts used to simplify access assignment, communication or administration.
H1 term
I11 terms
Identity Analytics
Identity analytics is the analysis of identity, access, activity, peer, policy and risk data to identify patterns and improve governance decisions.
Identity And Access Management (IAM)
Identity and access management (IAM) is the broad discipline for managing digital identities and controlling their access to systems and data.
Identity Attribute
An identity attribute is a governed characteristic—such as department, job code or worker type—used in identity decisions.
Identity Cube
An identity cube is a consolidated IGA record linking an identity to its attributes, accounts, entitlements, roles, risk and history.
Identity Governance and Administration (IGA)
IGA manages identity lifecycles and governs who receives, retains and loses access across an organization.
Identity Lifecycle Management
Identity lifecycle management is the controlled creation, maintenance, suspension and retirement of a digital identity and its associated access.
Identity Proofing
Identity proofing verifies evidence to establish that an applicant is the real-world person they claim to be.
Identity Provider (IdP)
An identity provider (IdP) is a system that authenticates a subject and provides identity information to a relying application or service.
Identity Repository
An identity repository consolidates identities, accounts, entitlements, roles, policies, ownership, risk and governance history.
Identity Security Posture Management (ISPM)
ISPM continuously discovers and assesses identity-related exposure, misconfiguration, risky privilege and control gaps.
Identity Source
An identity source is a system that supplies identity records or attributes to IGA.
J2 terms
L2 terms
M3 terms
Machine Identity
A machine identity represents a workload, application, device, script or automated process that authenticates and acts on systems.
Manager Certification
Manager certification is an access review in which managers evaluate the access held by their direct or indirect reports.
Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) verifies an identity using more than one distinct authentication factor, commonly knowledge, possession or inherence.
N1 term
O3 terms
OAuth 2.0
OAuth 2.0 is an authorization framework that gives clients limited, token-based access to protected resources.
OpenID Connect (OIDC)
OpenID Connect (OIDC) is an identity layer built on OAuth 2.0 that allows a client to verify an end user's authentication and receive identity claims.
Orphaned Account
An orphaned account is an account that cannot be reliably linked to a current, accountable owner or enterprise identity.
P7 terms
Policy-Based Access Control
Policy-based access control is an approach in which centrally defined rules determine whether access should be granted or retained.
Policy Exception
A policy exception is a formally approved, time-bound deviation from an access or governance rule.
Preventive Control
A preventive control stops an inappropriate action before it occurs.
Privilege
A privilege is an authorized right to perform an action.
Privilege Creep
Privilege creep is the gradual accumulation of access that is no longer required.
Privileged Access Management (PAM)
Privileged access management (PAM) protects and controls high-impact administrative and service access.
Provisioning
Provisioning is the creation or modification of accounts, entitlements, roles and related identity data in target systems.
R16 terms
Recertification
Recertification is the repeat confirmation that existing access remains appropriate.
Reconciliation
Reconciliation is the comparison of the intended identity or access state in IGA with the actual state in a target system.
Relationship-Based Access Control (ReBAC)
Relationship-based access control (ReBAC) determines access from the relationship between a subject and a resource or between connected entities.
Requestable Role
A requestable role is a role published in an access catalog so eligible users can request it through a governed workflow.
Resource Owner
A resource owner is accountable for the acceptable use, protection and access requirements of a system, application or dataset.
Revocation in IGA
Revocation in IGA is the withdrawal of an account, entitlement, role, credential, session or authorization.
Risk-Based Access
Risk-based access adapts access decisions or controls to the assessed risk of the identity, resource, requested action and context.
Risk-Based Access Certification
Risk-based certification uses entitlement sensitivity, policy, usage, peer and identity signals to prioritize access reviews.
Risk Owner
A risk owner is accountable for decisions about a defined risk, including its treatment, acceptance, monitoring and escalation.
Role in IGA
A role in IGA is a managed collection of access rights associated with a job function, responsibility or technical purpose.
Role-Based Access Control (RBAC)
Role-based access control (RBAC) assigns permissions to roles and roles to users, allowing access to be managed according to job functions or responsibilities.
Role Engineering
Role engineering is the disciplined design, implementation and maintenance of roles.
Role Explosion
Role explosion is the uncontrolled growth of roles, often caused by creating a separate role for every small variation in access.
Role Hierarchy
A role hierarchy is a structure in which one role inherits permissions from another.
Role Mining
Role mining analyzes existing access and identity attributes to find patterns that may become governed roles.
Role Model
A role model defines an organization's roles, relationships, hierarchies, ownership, assignment rules and constraints.
S10 terms
SaaS Application
A software-as-a-service (SaaS) application is software operated by a provider and accessed over a network, commonly through a subscription.
SoD
Segregation of Duties
Security Assertion Markup Language (SAML)
SAML is an XML-based standard for exchanging authentication, attribute and authorization information between trusted parties.
Separation of Duties (SoD)
Separation of duties (SoD) is the principle that no single identity should control enough conflicting steps or privileges to misuse a process without detection.
Service Account
A service account is an account used by an application, service, script or automated process rather than by a person for ordinary interactive work.
Shared Account
A shared account is an account used by more than one person.
Single Sign-On (SSO)
SSO lets users authenticate through a common identity service and reach multiple applications without separate sign-ins.
Source of Truth
A source of truth is the system designated as authoritative for a defined identity record or attribute.
Stale Access
Stale access is access that remains assigned despite no longer being needed, used or supported by current identity and business context.
System for Cross-Domain Identity Management (SCIM)
SCIM is an IETF standard for creating, reading, updating, deleting and searching user and group resources across domains.
T2 terms
U2 terms
Unstructured Data Access Governance
Unstructured data access governance controls access to files, folders, collaboration sites, messages and similar content.
User Access Review (UAR)
A user access review (UAR) is a control in which accountable reviewers verify that users' accounts and permissions remain appropriate.