Implementation guide
Treat an IGA implementation as a sequence of evidence gates. Each phase should produce something a customer owner can inspect before the next phase gains more authority.
Phase 1 — establish the boundary
Document the tenant, environments, identity sources, target systems, accountable owners and deployment mode. Record the required data region and hosting constraints before treating a provider as selected. For hybrid deployments, agree what stays in the customer network and how the agent is enrolled. Check hosting and deployment status rather than assuming a target architecture or future enterprise option is available today.
Exit evidence: approved system inventory, named owners, selected deployment mode, hosting requirements and an environment plan.
Phase 2 — read and classify
Connect sources with read-only credentials. Discover object types, map fields, declare correlation keys and configure account types. Run imports until totals, correlation and classification are stable across two runs.
Exit evidence: successful imports, explained deltas and no unexplained unclassified population.
Phase 3 — model governance
Add lifecycle defaults, access policies, roles, approval chains, separation-of- duties rules and ownership resolution. Use previews before saving broad rules. Review a sample of Expected-versus-Actual explanations with business owners.
Exit evidence: approved governance rules, real reviewer resolution and traceable Expected-state explanations.
Phase 4 — prove review mode
Keep provisioning in review mode. Exercise joiner, mover, leaver, request, certification and drift cases without allowing an automatic write. Confirm that failures and unresolved owners remain visible.
Exit evidence: signed-off scenario results, known gaps and an agreed exception process.
Phase 5 — enable narrow writes
Configure safety limits, confirm read/write parity, and enable one operation type for a small non-production scope. Observe the job, re-import the target and prove convergence.
Rollback: disable the operation capability, pause provisioning, cancel or hold queued work, apply the target-system compensating action, then re-import. Never retry repeatedly before the original outcome is known.
Phase 6 — expand and operate
Widen capabilities by system and operation, not with one global switch. Put failed jobs, platform health, ownership gaps, expiring credentials and review coverage into the operating rhythm.
Exit evidence: production acceptance, operational owners, alert routes, recovery steps and a dated limitation register.
Change control
For every material rule, mapping or connector change:
- make it in a non-production environment;
- inspect the impact preview;
- obtain the required approval;
- promote the same reviewed configuration;
- verify the first run and its evidence;
- record any rollback or exception.
See environments and staged configuration for the promotion model.