Identity Governance
Overview
Identity governance manages who has access, why, and whether that access is still appropriate — including access reviews and privileged access management for the most powerful accounts.
Key concepts
- Access reviews
- Privileged Access Management (PAM)
- Just-in-time access
How it works
Identity governance is the process of managing who has access to resources, why they have access, and whether that access is still appropriate — helping ensure permissions match job responsibilities, policies, compliance requirements, and security needs. It focuses on access visibility, approval workflows, access reviews, and identity lifecycle management.
Access reviews
Access reviews are regular checks confirming users still need their assigned permissions. Managers and resource owners review accounts, group memberships, administrator privileges, and access to sensitive systems.
Privileged Access Management (PAM)
PAM controls and monitors powerful accounts — domain administrators, cloud administrators, database administrators, security administrators. Privileged accounts should be protected with strong MFA, separate administrator accounts, logging, and limited access duration.
| Term | Meaning |
|---|---|
| Just-in-time access | Gives users temporary elevated privileges only when needed for a specific task. |
| Privileged access review frequency | Should be reviewed more often than standard access, since these accounts can cause significant damage if compromised. |
Examples
A new help desk employee receives access to the ticketing system and basic account-management tools, but not domain administrator rights. An employee transferring from Finance to Marketing loses payroll-system access and receives access to marketing applications instead.