Authorization is the decision to permit or deny an authenticated identity's requested action on a resource. The decision may use roles, attributes, relationships, policy, risk and environmental context.
IGA governs the assignment and continuing appropriateness of the roles, attributes and entitlements that feed authorization decisions; the target system or policy engine usually enforces them at runtime.