Identity governance and administration
Identity governance and administration (IGA) is the discipline of controlling who has access to what across an organisation's systems (granting it, reviewing it, and removing it), with a record of why every grant exists.
Identity governance and administration covers the full life of an access grant: how someone gets access when they join or change role, how that access is checked while they hold it, and how it is removed when they no longer need it. The "administration" half is the doing: provisioning and deprovisioning accounts and entitlements. The "governance" half is the deciding and proving: policies that say who should have what, reviews that check reality against those policies, and an audit trail that shows both happened.
Why it exists
Every system of any size accumulates access faster than it removes it. Without governance, the gap between who has access and who should have access widens quietly until an audit, an incident, or a leaver with live credentials exposes it. IGA is the practice of keeping that gap measured and closed.
What changed recently
Legacy IGA tools assumed a company small enough to model by hand: connectors were custom work, reviews were quarterly campaigns, and the policy model lived in consultants' heads. Modern platforms invert this: pre-built integrations discover the estate, policies are written against what was found, and AI does the reading work humans used to batch into spreadsheets. That is the model Ploy is built on, with Luna doing the reading.