Modern enterprises depend on thousands of users, roles, applications, and entitlements, yet many access governance programs still rely on periodic reviews, manual approvals, and scattered audit evidence. This creates blind spots, approval fatigue, privilege creep, and unnecessary compliance exposure. The 2026 Leadership Compass on IAG provides a comprehensive analysis of the market, emerging capabilities, and strategic trends shaping the future of access governance.
Nitish Deshpande, Senior Analyst at KuppingerCole Analysts, will present key findings from the 2026 Leadership Compass on IAG, offering an independent perspective on the current market landscape. He will discuss evaluation criteria and leadership positioning and provide guidance on how organizations can align their access governance strategies with business and security priorities.
Who should attend:
This webinar is ideal for IAM and IGA leaders, security architects, CISOs, GRC professionals, and IT decision-makers looking to strengthen access governance, reduce compliance risk, and evaluate the latest market-leading IAG solutions.
So, hello everyone. Welcome to today's KuppingerCole webinar. My name is Nitish Deshpande. I'm a Senior Analyst at KuppingerCole Analysts. And today's webinar follows up our Identity & Access Governance Leadership Compass report, which went live a couple of months back. So in today's webinar, we will share our findings. We will also share the results from that Leadership Compass. So stay tuned towards the end. We will share the diagram about the leaders and what are the key trends that we observed when doing this report. A few housekeeping rules, as always. So you all are centrally muted.
You don't need to mute or unmute yourself. We will also run a few polls in this webinar. We want to keep these webinars more interactive. And so I request everyone attending this webinar to participate in these polls and provide your inputs using the control panel. And we would love to discuss the results of these polls in the final Q&A session. So if you have any questions, even throughout the webinar, you can enter those questions using the control panel. And I'll try to answer as many questions as possible towards the end of the webinar session. And finally, we are recording the slides.
So the recording and the presentation deck will be made available for download in the coming days. Now, without further ado, let's quickly take a look at the agenda. It's a short one, quick one to the point. We will be focusing mainly on our findings from this LISP-Compose report with also a few our insights as well from what we believe are the challenges in this market and what were the top drivers for acquiring these IAG solutions. And then we'll have the quick Q&A session towards the end.
But before I begin, I would like to invite everyone who is attending to participate in the first poll of today's webinar. And that is, what is the biggest challenge your organization faces in managing access? Is it first, over entitlement of users? Is it second, segregation of duties violations? Is it third, lack of centralized governance visibility? Or is it fourth, managing access for external users? You can select your option which you prefer using the control panel and look forward to seeing the results in the final Q&A session.
Now, identity and access governance. What is identity and access governance? What is IAG? And we get these questions a few, several times, especially around, you have your IGA. What is the difference between this and IAG? Access governance comes up again and again as one of the most important parts about identity and access management. And the reason for that is, these questions you need to ask is that, who provided the access? When was the access granted? Who approved the access? And for how long this access was given?
And this is not just limited to your particular, your employee, workforce, contractor identities. It is now extending much more towards the non-humanities of your service accounts or API keys, your certificates, bots. So it's extending in that direction as well.
So, another part is excessive privileges and SOD violations, dormant accounts, or fund entitlements. So, these are another risks which we try to cover as capabilities when evaluating an IAG solution. These risks, they show up in breach reports or in findings and regulatory fines over and over.
So, put simply, IAG is today covering all the various types of identities, answering these four questions. It's focusing a bit less on the lifecycle management part of the solution, of an IAG solution, if we take that into example. And finally, I would like to leave you with this, is that it's just not your compliance checkbox right now. It's also a foundational piece of Zero Trust. It enables continuous verification, and it's what lets organizations move away from static, extending access towards something more dynamic, policy-driven, continuous verification.
And with this foundation, I think we can start now to shift towards sharing with you what are our key findings when doing the IAG report in 2026. The first one is certification-focused governance is evolving into intelligence-driven continuous models. And for years, you had your access governance meant periodic certification campaigns. You had your reviewers doing manual reviews, server stamping. And that model is now giving way to continuous intelligence-driven governance where analytics and automation surface real risk in real time.
And so, not just during the review, you get shown the risk, but it's now shown continuously in real time. Second is the governance scope is expanding, not just towards your workforce accounts, but towards your NHIs as well. And that includes your service accounts, APIs, other NHIs. And this has been another theme of this year is the support has been extended a lot towards NHIs because unmanaged NHIs create today some of the biggest risks, mainly because of the visibility part.
So, with the IAG solutions and access governance, we try to evaluate how does the solution also provide visibility into all types of entities. Also, AI and machine learning are aware that there are differentiating factors when you look at this report. Vendors are using them for various use cases, such as you have your pooled mining, vulnerability detection, risk-based recommendations. They're also helping reviewers focus on what matters, actually, instead of just doing low-risk routine tasks, administrative tasks.
Flexible SOD management, policy governance, and adaptive access is also one of the core requirements right now, based on what organizations are asking for. So, SOD hasn't gone away.
In fact, it has become a crucial part of IAG solutions. And it's also gotten even harder as roles multiply across your cloud and SaaS systems.
So, organizations still need flexible SOD policies and adaptive risk and access reviews that adjust review frequency and depth based on the actual exposure. Finally, the fifth key finding, you can say, is the deeper integration with SaaS, CIM, ITSM. You have these governance platforms that are expected to be now plugged directly into your SaaS applications, CIM, ITSM tools, rather than them operating independently.
So, that deeper integration combined with growing automation and delegated administration is what has defined this IAG market in 2026. But there are also still some challenges in the IAG market. There are a few. We have to highlight some of the four major ones. The first one being the higher total cost of ownership and complex customization.
So, one of the biggest complaints you can say that we hear is the cost. Managing many access governance platforms carry a high total cost of ownership, and bring them for an organization's role and applications.
Often, you have your lengthy, expensive customization work that is beyond your initial licensing. Second is poor role definition and role maintenance.
So, roles are, you can say, organizations are still struggling to define the roles correctly. You have your role models that drift out of, that are outdated. You have business changes happen, entitlements pile up, and underneath all this are outdated roles.
So, defining proper role definition, who owns these roles, and keeping them accurate is a challenge. Access review, that is the third one. Reviewers prefer to move away from your manual robust running reviews to more continuous reviews, automated reviews, you can say. And finally, it's unclear access ownership. When nobody is clearly accountable for a given entitlement, certifications can become a formality.
So, business owners often don't understand what a role function actually runs, so they approve access rather than making an informed decision. So, there are a few challenges that we have.
So, there are, of course, many more challenges, but we'd like to highlight the main ones here. Talking about the top drivers for acquiring IAG solutions, we asked vendors and customers, what are they looking for in IAG solutions? And this is organizations of various sizes across different verticals, and the top one remains regulatory compliance and audit readiness. Surprise! Compliance continues to be one of the strongest drivers for IAG adoption, particularly in your highly regulated industries.
Organizations of different sizes now need to demonstrate who has access to what, who granted access, and other questions around this topic. So, the modern IAG solution, you can call them, they help in automate certifications and processes, and provide audit-ready documentation for regulations, such as NISTO, DORA, GDPRF, and others. Second is operational efficiency.
This is, again, about access to reviews. Organizations are looking to eliminate certification processes and review activities.
So, automated processes where you can do public reviews are more preferred. Human intervention is only being desired at only for critical reviews.
So, this improves overall operational efficiency. Third one is access to risk management and entitlement control. As your IT environments become more complex, users often accumulate excessive permissions over time. Organizations that want IAG solutions that can continuously identify this high-risk access and pose least privilege and detect SOD conflicts. Increasingly, also, access intelligence, access analytics, is also being highly prioritized, especially in high-risk entitlements, rather than relying solely on critical reviews.
Finally, it's the consistent governance across a wide range of identity types. So, as I mentioned, the requirement for having unified governance is expanding from your workforce, contractors, partners, to now your different types of NHIs. Organizations are looking for the same level of guardrails, same level of ownership, lifecycle management, for every type of identity. What are a few more, let's say, particular capabilities that customers are also asking for is the overall governance for now AI agents, and agentic AI is also increasingly being requested.
Also, it is also nearly every vendor's roadmap that we have evaluated the support for AI agent governance, often by MCP integrations. Broad NHI governance, again, goes back to providing more unified governance for all types of NHIs. Third is the continuous access visibility and event-driven governance. Organizations prefer more continuous. We have these platforms called as IVIP, Identity, Visibility, and Intelligence platforms.
So, shared signals, framework adoption, and continuous assurance of compliance monitoring. All of these signals customers are pushing. That is the third requirement. AI ML-driven access intelligence. Number one, it includes different use cases for your role mining, risk scoring, predictable and explainable recommendations, and anomaly detection. And finally, it's the convergence with adjacent identity security domains. Customers want one platform rather than having five different vendors providing different capabilities.
So, there is definitely a requirement for moving towards a more single unified platform that provides your governance capabilities, lifecycle management, visibility, and all in one rather than having different vendors. Now, we can move on to sharing with you some of the results and methodology also that will be used for evaluating the vendors in this leadership composed for identity and access governance. The leadership composed process is quite extensive. It starts with first test research.
We identify the vendors and send out the questionnaires and supporting documents around the topic to all these vendors. Then we conduct briefings with all the vendors. And after the briefings, we move towards the rating and the draft creation. Then it goes towards the fact-check process where the vendors have the possibility to go through the document. Usually what happens when the first process of test research and briefings towards fact-check, it takes at least a month or two months. In that time, vendors have added new capabilities.
So, our aim is to publish a report with the latest capabilities. We use this fact-check process to identify the latest capabilities from the vendors and also include them. And finally, we publish it on our website. But if we talk about especially the IAG report, we had several categories that were used to evaluate the vendors. The first one is access governance and certification.
In this category, we evaluated the platform's ability to govern identities, roles, accounts, and entitlements across enterprise systems including role management, entitlement management, access reviews, certification campaigns, orphan account management, and also support for NHIS evaluation. It also included support for road modeling, road discovery, event-driven certifications, entitlement reconciliation, and similar other capabilities that fall under the governance and certification frame. The other one that's quite important is SOD controls.
In this category, we evaluated the capabilities for identifying, analyzing, and preventing and remediating your SOD conflicts and access risks across different types of identities, roles, and entitlements. The assessment also included SOD analysis and simulation, continuous SOD validation, risk-based scoring, entitlement conflict detection, and similar other SOD-related capabilities. Analytics and access intelligence is another important capability and one of the things that differentiates when we are speaking to so many vendors in the current space.
In this capability, we evaluated the platform's ability to provide visibility, intelligence, and insights into different identities. Evaluation also included your identity analytics, access intelligence, behavioral analytics, risk scoring, road recommendations, and several other AI and MLJ support capabilities. Audit reporting compliance, target system support, and deployment flexibility were some of the other capabilities that we evaluated in this report.
For audit monitoring compliance, we evaluated the platform's ability to provide auditing reporting compliance, auditing trails, foreign capabilities, dashboards, compliance controls, support for providing out-of-the-box reports for different types of major compliance frameworks like GDPR and others. We also looked at same integration, access to logs, and audit data. It's a very extensive list for audit monitoring compliance.
As we saw, the top driver for acquiring IAG solutions is related to improving your compliance. Policy management is not mentioned here, but we also evaluated the vendor's capabilities on defining, managing, enforcing, and governing the access policies. We also looked at what kind of different access control models the vendor supports. It also included other capabilities such as policy simulation, policy authoring, delegated policy management, policy integration with also third-party systems, and automated policy-driven decisions.
High-risk access governance was another capability not mentioned here, but something which was added in this year's report. This category evaluates controls for governing your privileged, sensitive, and high-risk access across your enterprise environments. Access management also included your system-time provisioning, system-time access, and time-bound access, privileged access request, risk-triggered remediation, temporary access management, and integration with other privileged access technology. We also looked at how the solution is for an end-user, how is the usability for it.
We also evaluated the user experience, for example, for managing and tracking access and related resources. We also included how access is governed when you have different items added into your shopping cart. Is the SOD control also being done for addition to the shopping cart? We also see how access can be approved. Is there support for providing access approval using mobile interface as well as web interface? We also take a look at administrative governance and delegation capabilities as well.
This category includes your delegated administration capabilities, policy management, final-disk authorization controls, time-bound delegation, approval governance, and different types of authentication methods supported, including such as step-up authentication. We also look at role-based administration and governance controls over deleted access and responsibilities. We also have a few more categories on which we rate the vendor, such as we call them security, functionality, unit units, and deployment. So those are other capabilities.
So it's a large – there are several categories that are used to evaluate the vendor. It's a very thorough process. In the next slides, I will show an example of how it exactly looks like. But before we go there, here's a quick snapshot of all the vendors that were in this report. As you can see, it's a wide range of vendors, long list as well. It includes your traditional IAM vendors. It includes specialists as well, and vendors supporting different sizes of organizations as well.
So I think when you do all the evaluation for all these vendors, you get this final picture of how all the vendors stack into this overall data diagram. So this overall leadership rating is a combination of three factors. It's product, innovation, and market leadership. In the product leadership, we evaluate the main capabilities of the product. And this is, again, all the categories which I mentioned in the previous slide. So those all are evaluated in a separate product leadership category.
We also have an innovation leadership diagram where we evaluate the innovativeness of the vendor, how they are delivering the solutions, what is in the roadmap, which new features have been added, how are the basic functions being executed as well. And then we have the market leadership diagram as well where we evaluate the size of the vendor, how many customers they have, in which geographical regions they are operating, how many system integrator partners they have. So it's a wide range of parameters that are included when evaluating all these three capabilities.
And when you take the picture and compile it together, you get this one final view of how the vendors stack up against each other. So I'll just skip this slide for a moment for everyone to have a look at it. In the bottom of the diagram, you will see the legends for market leader. The size of the bubble defines whether the vendor is an entrant, emerging, is a contender, challenger, or the leader in that segment. The x-axis is about the product leader capabilities, and the y-axis is about innovation leader capabilities. And now I'll show you how do we evaluate each vendor.
This is a sample vendor spider chart. We take a vendor for example, and we can see all the categories which I mentioned earlier have been mapped on this spider diagram and how the vendor stacks up against each of the capability. We do this for all the vendors. It's an extensive process. You can go into details about each vendor and how each capability is rated. It's in our Leadership Compose report. And I think that's it. But before we go into the next section, here is one more poll question for you all. What were the top drivers for you for acquiring an IAG solution in your organization?
Is it first regulatory compliance? Is it second, enhancing security? Is it third, improved user experience? Or is it fourth, automation? You can again use the Livestorm Control Panel to provide your input. And I look forward to seeing the results of the polls very soon.
In fact, we can maybe check the results of the first poll already. Okay, the first question was here. So yes. First question was, what is the biggest challenge your organization faces in managing access? And 50% of you have selected for lack of centralized governance visibility. 36% have gone with over-entitlement of users. While 7% is each for SOE violations and managing access for external users. And this aligns with all findings as well. The challenge many organizations are facing is just not having proper visibility.
And this is becoming more and more important when you take into account governing your NHIs. The first question we get is, how do we govern NHIs?
Well, you have to first start with discovering these NHIs and proper visibility in these NHIs. And if you don't have the proper visibility, you cannot govern them. So you have to start first with visibility. Then you have to move towards the inventory. And once you have a list of all the NHIs you have, then you can move towards the governance part about certifications, reviews, ownership, lifecycle management. So definitely, yes, having visibility is important. And that is a major challenge.
The second question that we asked right now, not enough time, I guess, for everyone to answer, but I hope we have some votes already. What were the top drivers for acquiring an IAG solution in your organization? And to our surprise, 50% of you have clicked on regulatory compliance, while 17% each has gone to enhancing security, improved user experience and automation. And I think everyone has gone with these votes. Regulatory compliance being the most important driver for acquiring an IAG solution, again, is also aligned with our findings as well.
So thank you for everyone participating in these votes. Let's check if we can see we have some. We have a couple of minutes left.
Okay, so the first question that we have is how to govern service accounts, APIs and AI agents and other NHIs. And this, again, goes back to what I just mentioned earlier, is you can only govern these NHIs if you have proper visibility. So you need to start with discovering the NHIs in your systems, making a correct inventory of these NHIs, and then you move towards the lifecycle management of these NHIs. You have your governance, you have your posture management, you have your lease privilege enforcement, and then finally moving towards decommissioning as well.
So, yes, you can govern them, but first you need to start with the visibility. Second is we have challenges always there in IAG market. What is the best solution or perfect tool to overcome these challenges? I think as we went through those slides earlier, the market is evolving at a rapid pace. There are challenges, definitely.
But, sorry, screens flicker, we have different questions. So, yes, so the solution, the perfect tool, difficult to point to one tool, but it's always, but you can definitely refer to our report, which went live on this topic. We have tried to cover extensive number of vendors in that report. We have really tried to evaluate each vendor in great detail.
Hopefully, with that information, you can find a solution which matches your requirements and requirements. So I think we are just, we are right on time, so we have to hurry a bit. Before we leave, here's one, here's a quick slide about where you can find all the research around this topic of identity and access governance. You can go on our website and search the leadership composite reports, biased composite reports on this topic. We also provide several other services, including events and webinars and advisory.
Make sure to also check out different events that are going to happen in our webinar that we'll be managing. So I think that's it for me. Thank you so much for everyone's time and attention and look forward to seeing you in the next webinar. Thank you so much.
See All Locations
See All Locations