The traditional approach of organizations deploying Identity Governance and Administration (IGA) to automate Joiner, Mover, and Leaver (JML) processes, satisfy auditors, and demonstrate that users only had access to the systems they needed is slowly becoming outdated. This shift is captured in our latest Leadership Compass on Identity Governance and Administration where the vendors best positioned are the ones treating correlation, reconciliation, and NHI governance as core emerging capabilities, not peripheral add-ons.

Figure 1: KuppingerCole Reference Architecture highlighting IGA-related capabilities
Modern enterprise environments are dynamic, context-driven and seek almost real-time governance capabilities. Also, organizations now manage identities across complex hybrid environments such as cloud platforms, Software as a Service (SaaS) applications, business systems, and developer environments. Workforce represents only one category of current landscape of identities. Contractors, partners, and Non-Human Identities (NHIs) such as APIs, service accounts, bots, and Artificial Intelligence (AI) agents are increasingly becoming an integral part of business processes.
The scale of this shift is easy to underestimate until it is made concrete. Rubrik Zero Labs' 2025 research puts the ratio of non-human to human identities at 82 to 1 in the modern enterprise, and the same research found that 89% of organizations have already fully or partially incorporated AI agents into their identity infrastructure, with another 10% planning to.
In other words, the NHI-heavy environment is not an edge case reserved for cloud-native shops; it is close to universal. When machine identities outnumber people by that margin, "who has access to what" stops being a JML question and becomes a continuous data-correlation problem.
Identity Data Correlation and Continuous Reconciliation
Most modern organizations understand that access should be governed consistently even when identity information originates from multiple authoritative sources. The difficult part is establishing a reliable picture of “who has access to what” or “who granted that access”, across the entire IT environment.
The challenge has expanded from provisioning users into application to correlating thousands of accounts, resolving ownership, reconciling entitlements, and maintaining an accurate inventory as environments continuously change. Governance decisions can become increasingly complex when handling these different scenarios at the same time. Access reviews require context, lifecycle automation needs to be consistent, and risk assessments need complete information for optimal decision making.
This is why modern IGA platforms increasingly position identity correlation and continuous reconciliation as core capabilities rather than background processes.
Lifecycle management needs to cover wide range of identity types
The concept of identity lifecycle management has expanded well beyond employees. While workforce identities still follow relatively predictable onboarding and offboarding processes, NHIs such as service accounts, APIs, containers, automation scripts, and AI agents are created through development pipelines and infrastructure automation rather than HR systems. The identities are ephemeral and need constant governance.
The cost of getting this wrong compounds over time. GitGuardian's 2026 research on exposed credentials found that 64% of secrets that were valid in 2022 remain exploitable today, nearly four years later. Ungoverned NHIs do not just accumulate; they persist, quietly, long after anyone remembers why they were created.
As a result, traditional workforce-centric lifecycle models are no longer sufficient. Organizations increasingly expect IGA platforms to govern both human and NHIs consistently through flexible lifecycle policies, continuous reconciliation, and clear ownership models. The focus is shifting to applying a unified governance model across all identities.
Governance is shifting to continuous evaluation
Access certifications remain an essential governance control, particularly for regulated industries. However, reviewing thousands of entitlements is difficult to justify when access changes every day. Instead of certifying every entitlement equally, reviews increasingly focus on higher-risk scenarios, unusual access patterns, privileged permissions, or changes triggered by lifecycle events.
Rather than relying exclusively on scheduled certification campaigns, organizations increasingly expect continuous monitoring, event-driven reviews, and policy enforcement that reacts to changes as they occur. This continuous, event-driven posture echoes the logic underpinning Zero Trust architectures: access is not a status to certify periodically, it is a condition to verify constantly.
Access intelligence is becoming the real differentiator
Provisioning, approval workflows, and role management have become mature capabilities across the IGA market. So, the area where vendors increasingly differentiate themselves is access intelligence. The goal is not replacing governance decisions with AI. Instead, analytics provides additional evidence that allows reviewers, administrators, and auditors to make more informed decisions while reducing unnecessary manual effort.
Organizations want governance decisions supported by context rather than static policies alone. Machine learning (ML) models are now being applied to identify dormant accounts, detect anomalous access, recommend entitlements, optimize role models, and highlight unusual permission combinations. These capabilities are particularly valuable because entitlement structures continue to grow more complex. Access intelligence is gradually moving from optional enhancement to expected functionality.
What’s next for IGA
The next generation of IGA is gradually evolving toward continuous reconciliation, event-driven lifecycle management, contextual risk analysis, and governance that extends equally across human identities and NHIs.
This episode of the Analyst Chat dives into a deeper discussion of these dynamics:
