Software Buyer Brief
Identity Governance Software Checklist Before Rollout
Short answer: roll out identity governance software only if it can connect HR and directory sources, automate joiner-mover-leaver changes, run access reviews, detect orphan and overprivileged accounts, govern service accounts, enforce separation of duties, and export evidence that auditors can trace back to owners and approvals.

NIST SP 800-63-4 is now the current Digital Identity Guidelines suite as of August 1, 2025. For software buyers, the practical lesson is that identity programs need lifecycle controls, authentication context, federation awareness, and risk-based decisions rather than one-time account creation.
NIST SP 800-53 Rev. 5 also includes access-control expectations such as account management and least privilege. CISA’s Zero Trust Maturity Model makes identity one of the core pillars. Identity governance software should help prove those controls are working, not just collect user lists.
Start With Lifecycle Sources
Ask how the tool connects to HR systems, directories, identity providers, SaaS apps, cloud platforms, ticketing systems, and privileged access tools. Joiner, mover, and leaver workflows are only as good as the source data.
The demo should show a new employee being provisioned, a department transfer changing access, and a terminated user being deprovisioned across connected systems.
Test Access Reviews With Real Owners
Access reviews should support application owners, managers, data owners, privileged access owners, and risk-based campaigns. Ask how reviewers see context: last login, role, department, entitlement description, privileged status, and related accounts.
If reviewers only receive a long spreadsheet of cryptic entitlements, certification fatigue will produce rubber-stamp approvals.
Find Orphan And Overprivileged Accounts
The product should detect users without active HR records, accounts with no manager, stale accounts, shared accounts, dormant privileged access, risky role combinations, and service accounts without owners.
Ask the vendor to show remediation routing. Finding risky access is not enough if no one owns the cleanup task.
Review Role Mining And Policy Design
Role mining can help reduce one-off permissions, but it can also automate old messes. Ask whether suggested roles are based on business function, application owner approval, separation-of-duties rules, and least-privilege review.
Good IGA software lets teams simulate role changes before enforcing them.
Govern Non-Human And Service Accounts
Modern identity is not only employees. Ask how the tool handles service accounts, machine identities, API clients, bots, contractors, partners, and break-glass accounts.
Each non-human account should have an owner, purpose, credential rotation path, expiry or review date, and activity evidence.
Identity Governance Software Review Table
| Requirement | Demo question | Buying signal |
|---|---|---|
| Lifecycle | Can HR changes trigger provisioning and removal? | Access follows employment status. |
| Reviews | Can owners certify access with useful context? | Reviews become meaningful, not rubber stamps. |
| Risk | Can it flag orphan, stale, privileged, and toxic access? | Cleanup work is prioritized. |
| Policy | Can roles and SoD rules be tested before enforcement? | Governance avoids breaking operations. |
| Evidence | Can approvals, removals, exceptions, and campaign results export cleanly? | Audit trails are defensible. |
Questions To Ask Before Rollout
- Which HR, directory, SaaS, cloud, and PAM systems are connected natively?
- Can access changes trigger automatically from employee lifecycle events?
- How are application owners and entitlement descriptions maintained?
- Can reviewers see last activity, risk level, and business justification?
- How are orphan, dormant, shared, and service accounts detected?
- Can separation-of-duties rules block or flag risky combinations?
- How do exceptions expire and return for review?
- Can audit exports show request, approval, fulfillment, review, and removal history?
Red Flags In An IGA Demo
- The tool cannot connect to the systems that actually hold access.
- Reviewers see entitlement codes with no plain-language description.
- Service accounts and contractors are treated as out of scope.
- Deprovisioning evidence is limited to a ticket comment.
- Role mining suggestions cannot be simulated safely.
- Exceptions do not expire or require reapproval.
Demo move: use one real employee transfer, one terminated contractor, one privileged admin, and one service account. Ask the vendor to prove lifecycle action, review context, risk flags, and audit evidence for all four.
Source Links
- NIST SP 800-63-4: Digital Identity Guidelines
- NIST SP 800-63-4 Online Guidelines
- NIST SP 800-53 Rev. 5: Security and Privacy Controls
- CISA: Zero Trust Maturity Model
- IDManagement.gov: FICAM and Zero Trust
FAQ
Is identity governance the same as SSO?
No. SSO controls login paths. Identity governance controls who should have access, why, who approved it, when it is reviewed, and when it is removed.
What is an access review campaign?
It is a structured review where owners certify, remove, or justify user access for applications, roles, data, or privileged entitlements.
Should service accounts be included?
Yes. Service accounts often hold powerful access and should have owners, purpose, rotation, review dates, and activity evidence.
What is separation of duties?
It is a control that prevents risky combinations, such as the same person approving vendors and issuing payments without review.
What evidence should auditors receive?
Request records, approvals, fulfillment timestamps, review decisions, removals, exceptions, owner assignments, and campaign results.