Identifying the Stakeholders in Access Governance

Information security is about the question who can have access to what and why. Identity and Access Management (IAM) is considered the capability to help answer that question.

Note: the paper shared on this page is revised with minor changes and republished in September 2026. The original paper dates to February 2022. A broader revision and update expected late 2026 / early 2027.

Perspective on Identity & Access Management

We believe otherwise. Managing identities and managing access cover lots of ground in different domains.

Identity Management

Identity management is all about automating joiner, mover, and leaver processes in an identity lifecycle. It is about workforce management, customers and consumers, things, every single object or service that may need to get access to whatever needs to be secured.

Access Management

Access management is all about handing out the keys to the castle. But who is allowed to hand out the keys, and to what part of the castle? And why would anyone hand out the keys?

Importance of the ‘Why’

The ‘Why’ part in essence, is overlooked. Managing identities by implementing an Identity Governance and Administration solution can help manage the Who. And such a solution can also manage authorizations in roles, taking care of the What.

A challenge for Access Governance

Why does someone get a role or an authorization? “Why does a role contain an authorization”, is a question that cannot easily be answered, leave alone that there is a person who can answer the question. This is the access governance issue that needs to be managed.

Identifying Accountability

In our whitepaper Identifying the Stakeholders in Access Governance we do not present the answers to the questions, but we present a method to identify the persons who should be held accountable for answering the questions.

Enjoy the read and if you like to comment, feel free to do so!

About SonicBee

YOUR IAM, OUR PRIORITY: FROM PROJECTS THAT LAUNCH TO IAM THAT LASTS | Identity & Access Management (IAM) is of increasing strategic importance and plays a part in the safety of our world. SonicBee, with teams in the Netherlands and Germany, helps organisations with continued control on IAM, security and privacy. From strategy to implementation, from operations to optimisation, from business adoption to training and workshops, all geared towards moving people, processes and technology securely in the same direction.