Applied IAM
Services — IGA implementation

IGA implementation is a program, not a project

Phase one go-live usually lands around month four or five, or ten to twelve months on legacy estates. Application onboarding runs another six to twelve months after that, and a mature identity governance and administration program takes two to three years. Here is what each stage involves and what it asks of your team.

The shape of it

The IGA implementation timeline, stage by stage

The most common misunderstanding about identity governance is that go-live is the end. It sits about a quarter of the way through.

Month 0

The question nobody can answer

Usually from an auditor, sometimes an insurer or a board member: who has access to what, and who approved it? In most organizations, finding out takes weeks of spreadsheets across several departments. That is where an IGA program starts.

Months 0–510–12 on legacy estates

Assessment and planning

The least glamorous stage, and the one most often cut short. Cutting it is the surest way to spend a year building the wrong role model, because everything later inherits these decisions.

Define the scope

Which identities, which applications, which populations. Drawing this line honestly is harder than it sounds.

Set the metrics

What success is measured against, agreed before the build. This protects the program when it runs long.

Choose the platform

SailPoint, Saviynt or Microsoft Entra ID, chosen against your estate. A wrong choice is expensive to unwind at month eight. Here is how SailPoint and Saviynt compare.

Run sample work

A slice built end to end and tested until it produces the right result every time. Nothing scales until this does.

Agree what a role means

The part that is not technical. Each department has its own idea of who should hold what, and people have to reconcile them. Role mining finds the patterns but does not make the decisions. The model you pick matters too: RBAC, ABAC or PBAC.

Month 4–5The quarter mark, not the finish

Phase one go-live

Three things, working across the applications in phase one scope, not across everything:

Automated identity lifecycle management

Joiner, mover and leaver changes run from HR data instead of tickets, so access appears on day one and disappears on the last day.

A governance dashboard

One place that answers who has access to what, and who approved it.

Audit-ready evidence

Produced by the process itself, not assembled each time someone asks.

Where budgets go wrong

Budgets get set against phase one because that is the number quoted. Then application onboarding needs another six to twelve months nobody planned for, and a program running to schedule gets called a failure.

Plus 6–12 months

Application onboarding, the long middle

One connector and one owner at a time. It is not technically hard. Its pace is set almost entirely by how fast application owners respond, and systems with no clear owner are where it stalls. Connectors to HR, ITSM and cloud systems are core IAM integration work.

OngoingFrom go-live onwards

Keeping it honest

The platform rarely breaks. The discipline around it does.

Automated defaults

The lifecycle doing most of the work untouched.

Monthly access reviews

Reviews that get read. Once managers approve everything unread, the program quietly stops working. See what makes access reviews hold up.

Exception handling

Exceptions granted with an expiry. The ones granted for a migration two years ago are the ones auditors find.

Connector health

Syncs break quietly when source systems change. Nobody notices until an access review comes back empty.

Role model upkeep

Departments reorganize. Left alone for a year, the model stops describing the organization.

If you would rather not carry this, we run it as part of our managed IAM services.

Years 2–3

Program maturity

Governance runs in the background instead of as a project with a steering committee. Reviews are routine, onboarding an application is a known process, and "who has access to what" takes minutes to answer.

Your side of it

What it asks of your team

This is where identity governance differs most from PAM implementation. IGA touches business rules, security policy and technical connections at once, so it needs a matrixed team, with one person whose job is bridging them.

RoleWhy it mattersTime
A single communicatorThe bridge between departments, and the role that decides whether this succeeds50–100%
HR directorLifecycle automation is only as good as the HR data behind it15–20%
Department decision-makersManagers who decide who gets what, in short bursts throughout5–10%
Executive sponsorUnblocks departments that will not engageWeekly or biweekly update
The honest answer

Budgeted as a project, or as a program

Budgeted as a projectusually gets canceled
  • budget set against phase one, the number that was quoted
  • go-live treated as the finish
  • nobody whose job is bridging departments
Budgeted as a programusually succeeds
  • budget covers onboarding and upkeep, not just phase one
  • go-live treated as the point the work becomes visible
  • a real communicator in place

The ones that fail almost never fail on technology.

If an audit finding is driving this, start with a compliance readiness assessment.

Why Applied IAM

Why teams choose us for IGA

Certified, and they have shipped it

SailPoint-certified engineers and CISSP holders who have run real implementations.

Roles people will accept

Governance designed around how your teams actually work, so adoption does not stall after launch.

Assessment to managed service, one team

No handoff between a consultancy and an operator.

Built for the auditor’s questions

Roles, reviews and reporting mapped to SOX, HIPAA, PCI-DSS and GDPR from the first design session.

Measured on outcomes

Access removed and conflicts closed, not reports generated.

Identity is our core practice

Governance sits at the center of it, not on the edge.

Proof & credentials

What stands behind the work

Certifications our engineers hold

  • SailPoint Certified IdentityIQ Engineer
  • SailPoint Certified IdentityNow Engineer
  • IdentityNow Security Engineer
  • IdentityNow Cloud Engineer
  • ISC2 CISSP

Certifications held by individual engineers.

What you should expect

  • Access reviews that finish on schedule
  • Access removed at offboarding, every time
  • Separation-of-duties conflicts caught before an auditor finds them
  • New starters with the access they need on day one

In practice

Insurance, 20,000+ employees. Facing a SOX deadline, our engineers deployed a unified onboarding framework and integrated 470 databases across six complex types in six weeks, against a six-month baseline, with the certification pipeline streamlined and self-service onboarding in place afterwards.

By sector

Where IGA implementation gets hardest

Lifecycle churn and outside identities make governance harder in some sectors: whole student cohorts joining and leaving at once in identity security for education, independent agents and brokers in identity security for insurance, and clinician and contractor turnover in identity security for healthcare.

IGA FAQ

Questions worth asking first

Phase one go-live is usually around month four or five, and ten to twelve months on legacy estates. Application onboarding then runs another six to twelve months, and program maturity takes two to three years. A single number for identity governance usually describes phase one only.

PAM is mostly about accounts and infrastructure. Identity governance touches business rules: every application has an owner who has to agree what a role means and who should hold it. That is a series of conversations across departments, and conversations do not compress the way technical work does.

A matrixed team, not one person:

  • a communicator bridging departments at 50 to 100% of their time
  • an HR director at 15 to 20%
  • managers who decide access at 5 to 10%
  • an executive sponsor at a weekly or biweekly update

Usually automated joiner-mover-leaver processes, one governance dashboard and audit-ready reporting, across the applications in phase one scope. What you will not have yet is every application onboarded. That is the next, longer stage.

Yes. We start with what is live: which lifecycles run, which connectors work, and where reviews have become a rubber stamp. Then we decide with you whether to repair the current platform or move, and plan it so access keeps working throughout.

Automated defaults doing most of the work, monthly access reviews, exception handling and healthy application and partner syncs. The usual failure is not the platform breaking. It is reviews becoming a rubber stamp and exceptions never being revoked.

Free consultation

Get an honest range for your program

A free consultation is 30 minutes with a certified engineer on your estate, your HR data and your application list. You get the findings in writing: a realistic phase one range, what it would need from your team, and where the hard parts are. No obligation to work with us.

Free consultation

Findings in writing afterwards, whether or not you work with us.