3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Provide your out-of-the-box connector list mapped against our [in-scope application list], showing for each connector which account and entitlement operations it supports (read, create, update, disable, delete).
Why it matters. Connector gaps found after contract signing become custom builds. These delay application onboarding and add maintenance cost the buyer did not budget for.
Good answer
- Each listed application is marked as native connector, generic connector configuration, or custom build
- Operations are listed per connector, with read-only and write support shown separately
- Entitlement types ingested are named per connector rather than stated as "groups" only
Red flags
- A list of application logos with no operation detail
- Targets marked "supported" that actually require undisclosed partner or custom work
- No distinction between account-level and entitlement-level ingestion
2. Can your product build identity records from more than one authoritative source at the same time, such as [HR system] for employees and [contractor management system] for contractors?
Why it matters. Workforce populations are often held in separate systems. A product limited to one source forces the buyer to merge the sources outside the product, which creates a data pipeline that the product does not govern.
3. Can your product assign birthright access automatically through rules evaluated on identity attributes, such as department, location, job code or worker type?
Why it matters. If birthright access can only be granted through manually maintained lists or custom scripts, new hires start without the access they need or receive access copied from a peer. The buyer then cannot show auditors the rule behind each grant.
Capability areas
Connectors & Entitlement Aggregation (15)
Out-of-the-box and custom connectors to target systems (ERP, directories, mainframe, ITSM, SaaS, homegrown apps), fine-grained entitlement ingestion, aggregation scheduling, reconciliation and delta handling, and the effort to build and maintain connectors for non-standard applications. Generic public APIs, SDKs and webhooks are covered by the integration module.
Identity Data Model & Authoritative Sources (11)
How the product builds the identity record from one or more HR and non-HR authoritative sources, correlates accounts to identities, handles contractors and other non-employee populations, and detects and remediates orphan, dormant and mismatched accounts before governance runs. Lifecycle event processing is covered under JML.
Joiner-Mover-Leaver Lifecycle Automation (12)
HR-event-driven provisioning and deprovisioning, including birthright access, mover handling of access no longer needed, leaver timing, rehires, future-dated and back-dated events, and fulfillment to connected and disconnected (ticket-based) targets. Self-service requests are covered under ARQ. Attribute- and rule-based birthright policies are in scope here; role definitions are covered under ROL.
Access Request & Approval (11)
Self-service access catalog, requests for self and others, policy-aware approval routing, time-bound and just-in-time access, request-time risk and eligibility checks, and expiry handling. Request-time SoD rule logic is covered under SOD.
Access Certification Campaign Design (12)
Campaign types (user, manager, application, role, entitlement, account), event-driven and micro-certifications, scoping and scheduling, reviewer assignment, delegation, reassignment, escalation and campaign closure rules. Reviewer decision aids and revocation fulfillment are covered under REV.
Reviewer Decision Support & Closed-Loop Remediation (10)
Business context, last-used data, peer-group comparison and risk scoring shown to reviewers, recommendations, detection of rubber-stamp review behavior, and closed-loop revocation that removes access in the target system and confirms the removal. Generic AI oversight controls are covered by the ai-human-oversight module. Population-wide outlier and access-risk analytics outside a campaign are in scope here; posture signals from identity threat tools are covered under CNV.
Role Modeling & Role Mining (10)
Business and technical role models, role mining from entitlement and HR attribute data, role definition approval, role versioning and change impact analysis, role ownership and role certification. SoD rules applied to roles are covered under SOD.
Segregation of Duties & Access Policy (13)
Cross-application SoD rule definition, toxic-combination detection at the fine-grained entitlement level, preventive (request-time) and detective enforcement, prebuilt ERP rule sets, mitigating-control assignment and expiry, and emergency or elevated access governance in ERP systems.
Audit Evidence & Compliance Reporting (9)
Tamper-evident history of requests, approvals, certifications, provisioning and revocations; evidence packages for auditors; mapping of controls to our compliance frameworks; and point-in-time reporting of who had access to what. Vendor attestations and certifications are covered by the compliance-certifications module.
Identity-Security Convergence (11)
Governance of cloud entitlements across public cloud providers, non-human and machine identities (service accounts, API keys, workload identities), ownership of those identities, integration with privileged access tooling, and use of identity threat detection and posture signals in governance decisions. It also covers whether these functions share one data model and console or are separate modules.
Program Operability & Incumbent Migration (10)
Configuration versus custom code, promotion of configuration between environments, upgrade impact on customizations and connectors, admin and analyst skills needed to run campaigns and policies, and migration of roles, policies and certification history from an incumbent IGA product run in parallel by application tier. Professional-services scope and contract-level exit terms are covered by the implementation-onboarding and migration-exit modules.
Questions about this package
How many Identity Governance & Administration (IGA) RFP questions are there?
124 solution questions in 11 capability areas: 25 for the RFI, 67 for the RFP and 32 deep-dive questions for the finalists. The workbook adds 90 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.