Govern Every Identity.
Enforce Every Policy.
Prove It to Any Auditor.

RSA® Governance & Lifecycle automates the full identity lifecycle—from provisioning to deprovisioning—while delivering continuous, AI-driven access governance across cloud, hybrid, and on-premises environments.

A complete identity governance and administration platform for government, finance, and 
high-assurance organizations. 

Surpass compliance with continuous governance across cloud, hybrid, and on-premises environments.

TELECOMMUNICATIONS

RSA Governance & Lifecycle was pivotal to ensuring Sorenson Communications’ data, security, and mission.

Steve Yeo, Sorenson Communications IT Director – IT Security

Watch Now

The identity governance standard.

The tools that financial services organizations, government agencies, and other high-assurance organizations need to answer the hardest questions.

Govern everyone

RSA Governance & Lifecycles answers the fundamental questions organizations must be able to answer at any moment: who has access? How did they get it? Should they still have it?

Automated Access reviews

Reduce reviewer fatigue with automated reviews and certifications, backed by gamification that keeps reviewers engaged and speeds up cycle times.

Segregation of duties (SoD) detection

Stop violations before they become audit findings.

Customizable compliance reports

Manage reporting for CJIS, HIPAA, IRS 1075, SOX, 23 NYCRR 500, PCI-DSS, NIST 800-53, FISMA, and more.

COMPLETE AUDIT TRAILS

Maintain a full historical record of every access request, approval, and change so you can answer any auditor’s question in minutes, not weeks.

Lifecycle automation

RSA Governance & Lifecycle automates identity provisioning and deprovisioning across the full joiner-mover-leaver workflow, ensuring all users have the right access at the right time—and nothing more.

Automated JML

Automate onboarding, role change, and offboarding workflows.

Role-based access controls (RBAC)

Align access requests, approval, and fulfillment workflows to business process.

Every identity, everywhere

Manage employee, contractor, and non-human identities across environments from a single platform.

Closed Loop Validation

Confirm that scheduled actions completed. When a connector removes access or provisions an account, the next collection cycle verifies it happened correctly.

Risk insights

RSA’s AI-driven risk analytics continuously evaluate entitlements across every connected system. Discover anomalous access patterns, excessive permissions, toxic combinations, and access drift in real time, not during an audit.

The right thing—not everything

Apply AI-powered entitlement analytics to identify high-risk combinations and anomalous access patterns.

Risk trends

Use advanced dashboards to measure governance efficacy and surface risk trends.

Always-on visibility

Maintain continuous visibility into identities, roles, and entitlements across on-premises and cloud environments.

Move to Zero Trust

Enforce least-privilege enforcement across all environments.

Deployed where your mission operates. Governing what your risk demands.

Discover RSA Governance & Lifecycle

Take the product tour to see how RSA Governance & Lifecycle manages your risk surface, simplifies compliance, reviews Zero Trust posture, and completes access reviews:

Frequently asked questions

How does RSA Governance & Lifecycle use AI?
RSA Governance & Lifecycle applies AI-driven analytics to continuously evaluate entitlements and access patterns across connected systems. The platform identifies high-risk entitlement combinations, surfaces anomalous access behavior, and provides contextual guidance during access reviews—helping reviewers focus on what matters rather than approving access they lack the context to evaluate. Risk insights are surfaced in dynamic dashboards with actionable recommendations.
What deployment models does RSA Governance & Lifecycle support?
RSA Governance & Lifecycle supports on-premises, air-gapped and classified, private cloud, and hybrid (cloud and on-premises) deployment models. This range of deployment options makes it suitable for federal agencies and financial institutions operating in environments where cloud-only solutions are not viable.
How does RSA Governance & Lifecycle govern third-party and contractor identities?
RSA Governance & Lifecycle governs third-party, contractor, and partner identities within the same platform and policies as full-time employees. Automated workflows trigger deprovisioning when engagements end, eliminating the orphaned accounts that represent a persistent risk in organizations relying on a complex mix of internal and external workers.

SURPASS COMPLIANCE.

Close the gap between policy and reality.