Meet Fischer Identity at the EDUCAUSE Annual Conference in Denver, CO | September 28 – October 1, 2026

BLOG

The Future of IGA Looks Familiar: Gartner’s 2026 Market Direction and the Fischer Identity Approach

Discover how Gartner’s 2026 Identity Governance and Administration (IGA) market direction aligns with principles Fischer Identity has championed for years, from continuous governance and dynamic access to AI-agent accountability and reduced reliance on custom code.

Published: September 16, 2026

Author photo

Fischer Editorial Team

The identity governance market is changing quickly.

Artificial intelligence is introducing entirely new classes of identities. Organizations are managing more applications, more cloud services, more external users, more automation, and more non-human identities than ever before. At the same time, security teams are being asked to make access decisions faster, demonstrate compliance continuously, and reduce the amount of manual work required to keep identity environments secure.

Gartner’s recently released 2026 Market Guide for Identity Governance and Administration reflects many of these changes. Fischer Identity was included among Gartner’s Representative Full-Suite Vendors in IGA.

We are pleased to be included.

But the more interesting story is not simply that Fischer Identity appears in the Market Guide.

It is how familiar Gartner’s description of the evolving IGA market sounds.

For years, Fischer Identity has advocated for identity governance that is continuous rather than periodic, policy-driven rather than dependent on static roles, capable of governing complex identity populations, responsive to real-time identity changes, and configurable without requiring organizations to maintain customized IAM code.

Increasingly, those same principles are becoming central to the broader industry conversation.

IGA Is Moving Beyond Periodic Governance

Traditional identity governance has often revolved around scheduled events.

Run an access certification every quarter. Review accounts periodically. Reconcile systems overnight. Generate reports before the auditors arrive.

That model made sense when identity environments changed relatively slowly.

They do not anymore.

Gartner describes the market as evolving away from legacy quarterly cycles toward an autonomous, continuous and outcome-driven process encompassing both access certification and provisioning.

That distinction matters.

A user can change jobs today.

A contractor can reach the end of an engagement this afternoon.

A student can become an employee while remaining a student.

An account can become orphaned immediately.

An elevated entitlement can become unnecessary the moment a project ends.

Waiting weeks or months for the next governance exercise is increasingly difficult to justify.

Fischer Identity has long approached identity as a continuously changing state. Changes from authoritative systems can trigger provisioning, deprovisioning, policy evaluation, role changes, notifications, approvals, expiration rules and other governance actions as those changes occur.

This is visible in real-world implementations. At the University of Virginia, for example, Fischer Identity supports automated provisioning and deprovisioning, dynamic RBAC, ABAC and PBAC policies, identity reconciliation and real-time synchronization across a highly complex university and healthcare environment.

Continuous identity governance is not simply about processing things faster.

It is about reducing the amount of time during which identity reality and access reality disagree.

The Identity Population Is Getting Much Bigger

One of the most important changes in the 2026 Market Guide is Gartner’s expanded view of what IGA must govern.

IGA is no longer only about employees.

Gartner describes IGA as managing identities and entitlements for both workforce and workloads, explicitly including AI agents.

We believe that is an important evolution.

Organizations have always had identities that existed outside traditional HR systems: contractors, volunteers, visiting scholars, service accounts, application identities, vendors, affiliates, partners and other external populations.

AI agents add another layer of complexity, but the fundamental governance questions remain surprisingly familiar:

  • Who owns this identity?
  • Why does it exist?
  • What is it authorized to do?
  • Who approved that authority?
  • How long should the access remain?
  • What happens when its purpose changes?
  • Who is accountable for its actions?
  • And when should the identity cease to exist?

Those are IGA questions.

Fischer Identity has long supported identity populations that do not fit neatly into the traditional employee model. Our approach to external identities, for example, includes sponsorship, lifecycle ownership, expiration, renewal, identity matching, policy-driven access and automated deprovisioning.

AI agents may be technologically different from contractors and affiliates, but good governance still begins with ownership, purpose, authority and lifecycle.

AI Does Not Eliminate the Need for Governance

There is considerable attention today around using AI inside identity platforms.

AI can certainly improve analytics, identify patterns, help detect unusual activity and reduce administrative effort.

But AI does not change a fundamental principle of identity governance:

Automation still needs authority.

Gartner’s Market Guide emphasizes accountability for AI agents and calls for clarity around business sponsorship, technical ownership, security responsibility and IGA lifecycle management.

That is an important distinction.

Knowing that an agent performed an action is not the same as knowing whether the agent should have been authorized to perform it.

Runtime security can detect behavior. IGA establishes authority. The two are complementary, but they are not interchangeable.

The same applies when AI-powered source systems generate risk information or identity changes. Fischer Identity can consume information from connected systems and use those changes to drive lifecycle and governance decisions. Our previous work around AI-enabled identity sources has focused on exactly this relationship: using changing identity and risk information to trigger policy, provisioning and remediation actions while maintaining governance around those decisions.

Static Roles Cannot Carry the Entire Load

RBAC remains extremely useful. But anyone who has operated a mature IAM program knows what happens when every business exception becomes another role. Eventually, there are hundreds or thousands of them. Roles overlap. Exceptions accumulate. Nobody remembers why certain roles exist. And the access model becomes harder to govern than the access it was intended to simplify.

Fischer Identity has consistently supported a blended approach using RBAC, ABAC and PBAC, allowing organizations to base access decisions on roles, attributes, policies, organizational context and changing identity state rather than forcing every access scenario into a static role structure.

Gartner’s direction toward contextual certification, policy orchestration and dynamically adjusted access reflects the same underlying reality: modern identity environments require more than static role assignment.

The goal is not to eliminate roles. The goal is to use them where they make sense and use policy where roles stop making sense.

Identity Data Still Determines Whether Any of This Works

There is another part of the identity conversation that receives far less attention than AI but is arguably more important.

Data.

IAM cannot make consistently good access decisions using consistently bad identity data. If HR has the wrong employment status, the IAM platform receives the wrong employment status. If a Student Information System does not properly represent a role transition, IAM cannot magically know what the institution intended.

If the same individual arrives from several authoritative systems and cannot be reliably matched, duplicate identities and fragmented access can result.

We have written extensively about this because it remains one of the most common causes of IAM complexity. Identity governance should not become a place where organizations hide broken upstream business processes.

The better approach is to establish reliable authoritative data, strong identity matching, clear lifecycle events and well-defined policy.

This becomes even more important as Gartner describes IGA moving toward real-time synchronization, correlation and dynamic policy decisions.

Faster bad data does not create better governance. It simply creates bad decisions faster.

Complexity Does Not Have to Mean Custom Code

Perhaps one of the most important distinctions in Fischer Identity’s approach is something we have been saying for many years:

Complex identity requirements do not inherently require customized IAM software.

There is a difference between a product being highly configurable and an organization having to modify the product.

Fischer Identity customers can configure complex lifecycle logic, identity policies, role models, workflows, access requests, approvals, certifications and integrations without modifying the Fischer Identity product code.

That distinction has significant long-term consequences. Custom code often works quite well on the day it is written. The challenge comes three years later when the original developer is gone, the business process has changed, the underlying application has been upgraded and the organization discovers that its IAM platform has quietly become a custom software development project.

Fischer Identity has spent more than 20 years solving highly complex IAM and IGA requirements without requiring customers to customize the core platform. Our cloud and on-premises offerings retain the same fundamental product capabilities, allowing organizations to support hybrid environments while avoiding separate product architectures and unnecessary development dependencies.

Gartner now identifies low-code orchestration, faster integration and reduced dependency on professional services as important areas of market advancement.

The terminology may evolve. The principle has been part of Fischer Identity for a long time.

Compliance Is Becoming Continuous Too

The traditional approach to compliance frequently looks something like this:

An audit is coming.

  • Reports are generated.
  • Access is reviewed.
  • Problems are discovered.
  • Remediation begins.
  • Then everyone repeats the process next year.

Modern identity environments require something better.

Gartner describes automated audit trails, real-time compliance reporting and continuous audit readiness as increasingly important capabilities within IGA.

We agree. Good governance should create the evidence required for compliance as part of normal operations.

  • Provisioning should be traceable.
  • Approvals should be attributable.
  • Temporary access should expire.
  • Identity changes should be recorded.
  • Access should reflect current policy.
  • Deprovisioning should occur when the underlying authority disappears.

Certification then becomes another governance mechanism rather than the mechanism an organization depends upon to discover months of accumulated access problems.

Recognition Is Welcome. Market Alignment Is More Interesting.

Gartner’s inclusion of Fischer Identity among its Representative Full-Suite Vendors in IGA is meaningful, and we appreciate the recognition.

We also want to be precise about what it means.

A Gartner Market Guide is not a ranking, an award or a declaration that one vendor is better than another. Gartner explicitly describes the vendor list as representative rather than exhaustive.

For us, the more compelling part of the report is the direction Gartner sees the IGA market moving:

  • Continuous identity governance.
  • Workforce and workload governance.
  • AI-agent accountability.
  • Policy orchestration.
  • Dynamic access.
  • Real-time identity information.
  • Continuous compliance.
  • Reduced dependency on manual processes.

Those ideas sound familiar because many of them have guided Fischer Identity’s product architecture and customer implementations for years.

Fischer Identity has never tried to become the loudest IAM company in the market. We do not spend millions trying to manufacture market visibility. We have invested instead in the platform, our customers, our people and solving complicated identity problems that organizations actually have.

That approach has sometimes made Fischer Identity something of an underdog in a market dominated by very large technology companies and heavily funded vendors.

But identity governance ultimately has to work after the presentation ends.

  • It has to provision the account.
  • It has to recognize that the employee is also a student.
  • It has to know when an affiliation ends.
  • It has to revoke temporary access.
  • It has to reconcile the account nobody knew existed.
  • It has to understand the authoritative data.
  • It has to govern the AI agent.

And it needs to do those things without requiring the customer to build and maintain another software product around the IGA platform.

More than 20 years into our journey, that remains our focus.

As the identity governance market continues to evolve, we are encouraged to see the broader industry conversation moving toward many of the same principles.

Sometimes the future does not require starting over.

Sometimes it means recognizing that the right architecture was already pointing in the right direction.

 

more blog posts

Interested in Learning More? Let's Connect!

Ready to Get Started?

We’ll tailor your demo to meet your specific needs, showcasing how the Fischer Identity solution:

  • Provides full life cycle management and a complete compliance framework.
  • Utilizes configuration-based setups with pre-built workflows and integrations.
  • Reduces help desk calls by utilizing an intuitive and user-friendly interface.
  • Handles complex IAM requirements without custom coding.

"We’ve been able to achieve our security and IAM-related goals and SLAs, plus accelerate the introduction of new services to our constituents due to the operational efficiencies afforded by Fischer.”

Jon Allen
CIO & CISO at Baylor University