Privileged access is any entitlement that can change systems, identities, or money at scale: cloud root, domain admin, production deploy, break-glass, and powerful SaaS admin roles.
IGA decides who may be eligible, tracks ownership, runs SoD against privileged roles, and certifies them. PAM vaults credentials, brokers sessions, records activity, and prefers just-in-time elevation over standing privilege.
Governance checklist:
- Inventory privileged entitlements across cloud, SaaS, and on-prem.
- Remove standing shared passwords; require checkout with MFA.
- Tie eligibility to roles + manager/security approval with short TTL.
- Certify privileged access more frequently than standard business roles.
- Alert on unused privileged grants and emergency access use.
Next: how to prove all of this to auditors without a spreadsheet scramble.