Governance
Identity Manager not only gives the right entitlements to the right identities, but also makes sure that, over time, every assignment still complies with the configured policy.
Enforcing the Policy
By reading entitlement data from the managed systems, Identity Manager builds an exhaustive list of existing assignments for all identities in all managed systems.
Rules and roles define a policy. By definition, assignments not supported by a rule don't comply with the policy. These assignments are identified as non-conforming to be acted upon by knowledgeable users who can decide whether the assignment is warranted, such as security officers.

A non-conforming assignment must be reviewed in Identity Manager by a knowledgeable user, and is therefore:
- either removed if Identity Manager correctly spotted it and the owner should indeed not possess this permission;
- or kept as an exception if the configured rules don't apply to this particular case.
Other Governance Tools
Identity Manager provides a set of governance tools to help enforce the policy, like access certification campaigns, risk management or reporting.
Next Steps
Let's read some Use Case Stories.
Related Resources
See the Governance topic for more information.
See how to Generate Reports.
See the Perform Access Certification topic for more information.
See how to Manage Risks.