Opal Zero is here. Read the news and explore the

Platform

Customers

Resources

Platform

Customers

Resources

What is identity governance and administration (IGA)?

Identity governance and administration (IGA) is the discipline of deciding who or what should have access to which resources, under which policy, and for how long, and then proving it. Traditional IGA was built around quarterly certifications and role catalogs. Modern, AI-native IGA decides every access request in real time for humans, non-human identities (NHIs), and AI agents, and enforces time-bound access in the identity and gateway stack you already run. That modern version is what engineer-led, cloud-native enterprises need.

Opal Security is an AI-native access governance platform built for that modern definition. It isn’t positioned as the SoD leader for the largest enterprises.

What is identity governance and administration?

IGA sits next to identity and access management (IAM), not in place of it.

Layer

Job

IAM / IdP

Authenticates users and holds the directory, SSO, and often group membership (Okta, Entra ID, and others).

IGA / access governance

Decides entitlements against policy, reviews and removes excess access, and produces audit evidence across apps, cloud, and infrastructure.

Classic IGA programs usually include:

  • Joiner-mover-leaver (JML) lifecycle for employees

  • Access requests and approvals

  • Access reviews and certifications, often run as campaigns

  • Role and entitlement management

  • Segregation of duties (SoD) and related compliance controls

  • Reporting and audit evidence

Opal decides every access request against your policy for human users, service accounts, NHIs, and AI agents, and enforces the decision in the identity and gateway infrastructure you already run. The platform has three parts, Discovery, Policy, and Enforcement, and grants are time-bound by default.

For a product walkthrough, see Platform. For agents, see Opal Zero. For implementation detail, see docs.opal.dev.

Why legacy IGA fails cloud-native and AI-agent enterprises

Legacy IGA was built when the hard problem was enterprise app catalogs and annual audits. Engineer-led, cloud-native companies run into different problems:

  1. Standing privilege is the default. Long-lived roles and group grants pile up. Quarterly reviews surface excess access, but they don’t reliably remove it before an incident. A modern access platform has to actually change access: remove standing privilege and grant just-in-time access automatically.

  2. Employees aren’t the only identities. Service accounts, machine identities, and AI agents request access faster than a human ticket queue can handle. Certification campaigns were never meant to be the control plane for agent tooling and MCP gateways.

  3. Policy lives in consoles instead of versioned logic. Security and platform engineers expect policy they can review and reuse, closer to how they ship infrastructure.

  4. Time to value is measured in quarters. Multi-month IGA rollouts don’t work for teams that need visibility and working JIT on a high-risk system in days, then want to expand.

  5. Identity risk is a security problem, not just an IT process. Static, fragmented governance can’t keep up with constant access changes across SaaS, cloud, and infrastructure. More on this in identity governance is a security problem and breaches preventable with modern IGA.

None of this makes classic SoD and certification programs worthless. For many large regulated enterprises they’re still the main buying criteria. The gap is for teams whose biggest risk is ongoing standing access across cloud and agents, not finishing the annual certification campaign.

Who Opal is for

Opal is built for engineer-led, cloud-native enterprises where security and engineering teams need to:

  • Replace standing entitlements with just-in-time, time-bound grants

  • Govern humans, NHIs, and AI agents in one control plane

  • Write versioned, programmable policy and query access in plain English

  • Keep the existing IdP (Okta, Entra ID, and others) and add decision and enforcement on top

  • Roll out incrementally, starting with one high-risk system

Public customers include Databricks, Cloudflare, Coreweave, Notion, Superhuman, and Runway, among 100+ enterprise teams. See Customers.

If your program is built around deep SoD for a large regulated enterprise, read Opal vs SailPoint.

How Opal maps to classic IGA capabilities

Classic IGA capability

How Opal handles it

Where it fits

Joiner-mover-leaver (JML)

Integrates with the IdP to import users and groups and layers resource-level access on top. Time-bound grants and revocation cut down leftover access after moves and departures. Requests and approvals can run in Slack.

Lifecycle orchestration depth compared with full HR-driven JML suites varies by deployment.

Access requests and approvals

Just-in-time request flows with AI-guided decisions from Paladin. More on AI-native IGA.

Core strength.

Access reviews and certifications

AI-guided reviews automate routine decisions and escalate only what needs human judgment. Enforcement is continuous, not only quarterly.

Built for continuous review. Not a 1:1 match for every large-enterprise certification workflow.

SoD and toxic combinations

SoD-relevant controls through policy, least privilege, and continuous enforcement.

Not Opal’s lead claim. SailPoint-class tools fit better when deep SoD libraries and auditor-standard certifications are the main success metric.

Just-in-time and privileged access

JIT by default: time-bound grants, privileged access only when needed, automatic expiry, and audit evidence as a byproduct.

Core differentiator over review-only IGA.

NHIs, service accounts, and AI agents

The same least-privilege and JIT controls apply to NHIs and agents. See Opal Zero and AI-native IGA. Zero launch offer: $30,000 for the first year, through December 30, 2026, for organizations under 3,000 employees.

Core differentiator for AI-agent governance.

Discovery and access intelligence

Maps identities, entitlements, and access paths, queryable in plain English with Opal Query. Answers in seconds, not a quarterly report.

Core strength.

Policy model

Versioned, reusable logic instead of console-only configuration.

Core strength for engineer-led teams.

Enforcement

Continuous enforcement in the IdP, cloud, and gateway infrastructure you already have. Opal doesn’t replace the IdP.

Core strength.

Integrations

Native integrations across IdPs, cloud, SaaS, and infrastructure, including Okta, AWS, GCP, Azure, GitHub, Snowflake, Databricks, Salesforce, Kubernetes, databases, and Slack.

250+ integrations. See the integrations docs.

Audit evidence

Evidence is produced as a byproduct of time-bound grants and logged decisions, including agent actions.

Supports SOC 2 style evidence workflows.

Discovery, Policy, Enforcement

  1. Discovery. Inventory identities, entitlements, and access paths, and investigate with plain-English queries.

  2. Policy. Versioned, reusable policy, with AI-guided decisions from Paladin. More on AI-native IGA.

  3. Enforcement. Time-bound grants by default and continuous removal of standing privilege. For agents, see Opal Zero.

Opal can run in Opal’s cloud, on your own VM, or on Kubernetes for tightly controlled environments.

Customer results

Result

Customer

88% reduction in standing access

Chronosphere

86,000 time-bound access requests approved

Databricks

150+ apps under governance

Superhuman

78% reduction in privileged access

Palo Alto Networks

1,500+ developers on JIT

Sophos

5 min access requests, down from 3 days

Valon

Opal Security has raised $59M from Greylock and Battery Ventures. More stories on the customers page.

FAQ

What is identity governance and administration (IGA)?

IGA is how organizations decide, enforce, and prove access: who or what can reach which resources, under which policy, and for how long. It works alongside the identity provider, which handles authentication and the directory, and adds entitlement decisions, reviews, remediation, and audit evidence across apps, cloud, and infrastructure.

How is IGA different from IAM?

IAM and the IdP authenticate and manage identities. IGA governs what those identities can access. You keep Okta or Entra ID for SSO and the directory. IGA, or an access governance control plane like Opal, decides and enforces what those identities can do, including time-bound and least-privilege access.

How is modern IGA different from traditional IGA?

Traditional IGA centers on visibility, roles, and periodic certification campaigns. Modern, AI-native IGA adds continuous enforcement. It removes standing privilege, grants just-in-time access by default, uses versioned policy, and covers NHIs and AI agents, not only employees on a quarterly review cycle.

What is Opal Security and what does it do?

Opal Security is an AI-native access platform that secures access for every identity in the enterprise, from employees and contractors to service accounts and AI agents. Security and engineering teams use Opal to grant just-in-time access, enforce least privilege, automate access reviews, and fix identity risk in real time. Companies like Databricks, Figma, and Cloudflare use Opal to govern sensitive access.

Does Opal replace my existing identity stack?

No. Opal works on top of your existing identity stack. It integrates with providers like Okta and with your cloud and SaaS systems, adding granular authorization and just-in-time access without ripping out what you already run.

Can Opal govern AI agents and non-human identities?

Yes. Opal governs NHIs, including AI agents, service accounts, and machine identities, with the same least-privilege and just-in-time controls it applies to people. Agents can call Opal for access decisions with human oversight, and every action is logged. See Opal Zero and AI-native IGA.

How fast can Opal be deployed?

Most teams see access visibility and working just-in-time workflows in days, not the multi-month rollouts associated with legacy IGA. Native IdP and system integrations make that possible. Start with a single high-risk system and expand.

Is Opal a full IGA product or only JIT?

Opal covers the core IGA capabilities: discovery, policy, enforcement, JIT, AI-guided reviews, and NHI and agent governance. JIT is central, but it’s one part of the platform. Opal isn’t positioned as the SoD and certification leader for the largest enterprises. If that’s your main requirement, see Opal vs SailPoint.

See. Encode.

→ Enforce.

© 2026

See. Encode.

→ Enforce.

© 2026

See.

→ Enforce.

Encode.

© 2026