The statement is too absolute. Identity Governance and Administration platforms substantially automate and streamline access governance processes, but they do not necessarily eliminate human judgment or fully automate every review, approval, and audit activity.
For example, an IGA platform can automatically generate access certification campaigns, identify the access requiring review, notify reviewers, record their decisions, perform supported remediation, and produce audit evidence. However, designated managers, application owners, source owners, or other certifiers are still commonly required to decide whether individual access should be retained or revoked. SailPoint describes certifications as processes in which designated certifiers review users' access and explicitly approve or revoke it.
Similarly, approval workflows automate routing and enforcement but can still require human authorization. Audit functionality generates searchable events, reports, and evidence, while auditors and compliance professionals still assess whether the organization's controls satisfy applicable requirements.
SailPoint describes IGA as streamlining certification and audit processes by automating reviews, notifications, and audit-ready reporting—not as eliminating every human governance decision.
Study Guide Reference: General knowledge for Identity Security Administrators — Identity Governance and Administration, Access Reviews, Approvals, Audit and Governance Automation.
===============