Foundations lessons

Foundations · Lesson 1

What is IAM vs IGA vs PAM?

Three related disciplines — authentication, governance, and privileged access — often confused as one.

Identity and Access Management (IAM) answers “who are you?” and “can you sign in right now?” It covers directories, authentication, MFA, and runtime access enforcement.

Identity Governance and Administration (IGA) answers “who should have access?” It covers lifecycle (joiner–mover–leaver), access requests, certifications, roles, and audit evidence. IGA sits above day-to-day login — it designs and proves entitlement policy.

Privileged Access Management (PAM) focuses on powerful accounts: admins, root, service accounts, and break-glass access. PAM vaults credentials, records sessions, and reduces standing privilege.

In a healthy architecture, IAM authenticates, IGA governs who gets what and why, and PAM constrains high-risk access. Teams that only buy an IdP often discover later that certifications, SoD, and offboarding still need a governance layer.

For Citadel Identity 360, IGA is the product focus: continuous governance across cloud, SaaS, and on-prem so least privilege and compliance are operational — not quarterly fire drills.

IAM vs IGA vs PAM

IAM, IGA, and PAM — who does what?

How authentication, governance, and privileged access fit together in a modern identity stack. Columns: IAM (Authenticate); IGA (Govern); PAM (Constrain).

  • IAMAuthenticate users and enforce sign-in
  • IGADecide who should have access and prove it
  • PAMConstrain high-privilege accounts

Learn more: Open related lesson →

Interactive check

No game on this lesson — try Access Request Flow or Spot the SoD Conflict.

Mark complete

Save progress on this device. Track completion unlocks badges in a later release.