Access control is the combination of policies and mechanisms that permits or denies an identity's requested action on a resource. It answers questions such as who may view a record, change a configuration, approve a payment or invoke an API.
IGA governs how access should be requested, approved, assigned and reviewed; enforcement points in applications, directories, operating systems and cloud platforms apply those decisions.