Identity Governance and Administration (IGA) is a core IAM capability, but it remains difficult for both businesses and users because identity data is spread across silos, key tasks are operationally inefficient, and decisions are made with too little context. Organizations struggle to understand where access occurs, provide consistent entitlement experiences (roles, groups, requests, reviews), and perform meaningful analytics across disconnected environments. As a result, overprivileged access becomes common, permissions accumulate beyond what is required, orphaned accounts persist, and visibility and accountability suffer—raising security, audit, and regulatory compliance risks.
Traditional conceptual approaches like role mining and role engineering have not reliably solved these problems, especially as businesses require agility due to cloud adoption, remote work shifts during the COVID-19 pandemic, and rapidly changing collaboration and operating models. IGA must adapt quickly rather than inhibit change, yet many current implementations rely on static entitlement models, complex role structures, and highly manual processes such as recertification campaigns that encourage “rubber stamping.”
AI and ML augmentation is positioned as a practical way to reduce complexity and improve outcomes, provided it is implemented carefully. AI can identify entitlement patterns and outliers, propose likely entitlements to request, recommend approvals or revocations during reviews, and help focus “micro certifications” on what matters most. Success depends on focused outputs (avoiding overload), accurate recommendations, sufficient data volume and variety (including usage data), and explainable, predictable, reproducible results.
ForgeRock Autonomous Identity is presented as an AI-driven identity analytics overlay that ingests and normalizes broad identity data from ForgeRock and third-party systems, builds historical models of access change, produces confidence scores with justification, and pushes actionable recommendations for remediation, provisioning, deprovisioning, and role definitions via APIs and an integrated UI.
See All Locations
See All Locations