Capability library
Everything expected of IGA.
One model underneath.
Enter through the customer journey when you are exploring. Use this library when you need to verify scope, boundaries and how each capability actually works.
Use the library as a reference. Use the four-step journey when you want the story.
Connect & understand
Establish what is true.
Systems & connectors
Connect the systems you have—not the ones a template expects.
Explore capability 02 · One governed vocabularyData model & authority
Make authority explicit before automation makes assumptions.
Explore capability 03 · Explainable attentionRisk & posture analytics
Know where human attention matters—and why.
Explore capability 04 · One person, every accountIdentity correlation & resolution
Resolve who an account belongs to before governing its access.
Explore capability 05 · Machines need owners tooNon-human identities
Govern service accounts, bots and agents by why they exist.
Explore capability 06 · Contractors, partners and guestsExternal identity management
Onboard every external identity through a sponsor-owned path—with access and exit decided up front.
Explore capabilityModel & govern
Turn reality into owned intent.
Identity lifecycle
Let employment events drive access—not a ticket checklist.
Explore capability 02 · One governed inboxSelf-service access & approvals
Make access decisions in business language.
Explore capability 03 · Govern close to the businessDelegated administration
Delegate work without delegating away accountability.
Explore capability 04 · Patterns become owned modelsRoles & role mining
Find useful roles without turning the organisation into a workshop.
Explore capability 05 · Model what can be governedApplications & entitlements
Turn technical access into applications people recognise.
Explore capability 06 · Expected access, stated plainlyAccess policies
Preview who gains and loses access before a rule becomes real.
Explore capability 07 · Govern the elevationPrivileged & emergency access
Make powerful access temporary, visible and reviewable.
Explore capability 08 · Autonomy needs accountabilityAI-agent governance
Treat an AI agent as a governed identity—not an integration footnote.
Explore capabilityProve & operate
Keep intent and reality aligned.
Access certification & reviews
Certify access by campaign, by time, by event or when a live signal changes the answer.
Explore capability 02 · Toxic combinations across systemsSegregation of duties
Declare a conflict once and find it wherever it occurs.
Explore capability 03 · Expected versus actualReconciliation & provisioning
Know whether every approved change really landed.
Explore capability 04 · Evidence while governance happensAudit packs, dashboards & compliance
Generate evidence from live controls—not a quarterly reconstruction.
Explore capabilityOne connected system