
SailPoint (NASDAQ:SAIL) outlined how identity governance and administration systems could help government organizations manage machinery-of-government changes, or MOGs, which the company described as the public-sector equivalent of corporate reorganizations.
In the first of a four-part government-focused webinar series, Identity Strategist Will Harrington said MOG events can follow elections, ministerial portfolio changes, policy shifts and the creation or restructuring of government departments. Such changes can affect job titles, managers, HR records, email domains, departmental assignments and access to applications and data for employees, contractors and other users.
Manual processes can create access risks
Based on conversations with public-sector employees at Public Sector Network events, Harrington said spreadsheet-based processes remain common for handling MOG changes. These spreadsheets may contain names, roles and instructions to add or remove access, which service-desk personnel then process manually across systems such as Active Directory, SaaS applications and databases.
He said this approach can be operationally inefficient and prone to errors, including missed access removals, incorrect data entry and delays in deprovisioning accounts. Script-based approaches can automate some work, Harrington said, but may create questions about auditability, code ownership and maintenance when the original developers leave an organization.
Harrington also cited a public case study involving a New South Wales government department that used an identity-management system to identify roughly 800 active accounts associated with terminated HR records. He said dormant and orphaned accounts can create exposure if attackers gain access to them and use them for lateral movement.
Other risks associated with manual MOG processes include privilege creep, insufficient audit evidence, interruptions to operations and potential data-privacy issues when staff retain access to information from their former departments, Harrington said.
Identity governance approach
Harrington described identity governance as a process to “connect, correlate, govern, automate” and provide proof of access decisions. Under this approach, an organization connects HR systems and target applications, correlates accounts to an individual identity, applies policies and roles, automates account changes, and records audit evidence.
He said the model should extend beyond employees to include contractors, service accounts, bots, agents and other non-human identities. In the case of agents and service accounts, Harrington said organizations should establish human ownership and succession plans, particularly when accountable individuals move between departments.
The identity model can combine HR attributes—such as department, manager, cost center, job title, employment status and start or end dates—with account and entitlement data from applications. Harrington said this enables organizations to identify, for example, terminated workers with active accounts or employees whose entitlements no longer fit their departmental assignment.
- Lifecycle management: Workflows can trigger when employees join, move or leave an organization, including changes in department, manager or job title.
- Role-based access controls: Roles can bundle entitlements associated with specific job functions, allowing access to be removed and reassigned as HR attributes change.
- Requests and approvals: Workers can request additional access through a central portal, with approvals creating an auditable control point.
- Policies and separation of duties: Organizations can define conflicting access combinations or prevent users in one department from holding entitlements belonging to another.
- User access reviews: Managers can review employee access before and after a MOG event to identify unnecessary permissions.
Harrington said a department transfer could be treated as a termination-and-rehire process, with prior access removed and new access recalculated based on the employee’s updated HR data. This approach, he said, could reduce permission accumulation and avoid placing additional workload on service desks when systems can provision directly to target environments.
MOG events as a business-case opportunity
Harrington said MOG changes can be framed as an opportunity to improve security, reduce manual work and support a business case for identity-governance investment. He cited a Victorian Public Service report published by Helen Silver as evidence that employees affected by departmental movements may wait six to eight weeks to regain access to systems.
Organizations could estimate the cost of this downtime by considering the number of affected employees, time without required access and employee costs, Harrington said. They could also quantify service-desk ticket volumes, manual provisioning work, audit and compliance effort, and software-license reclamation from accounts and applications no longer required.
He also pointed to the potential cost of security incidents, referencing IBM’s annual breach-cost report and high-profile Australian breaches involving Medibank, Latitude and Optus. While MOGs can be operationally burdensome, Harrington said they also create an opportunity to remove outdated access, improve accountability for non-human accounts and preserve public trust in government digital services.
About SailPoint (NASDAQ:SAIL)
SailPoint Technologies Holdings, Inc (NASDAQ: SAIL) is a leading provider of enterprise identity governance solutions that enable organizations to manage and secure user access across on-premises, cloud and hybrid IT environments. Its software automates identity lifecycle management, access certifications, policy enforcement and privileged account governance, helping enterprises reduce security risks, maintain regulatory compliance and streamline IT operations. The company’s flagship offerings include IdentityIQ, a comprehensive on-premises platform, and IdentityNow, a cloud-native identity governance-as-a-service solution.
Founded in 2005 by industry veterans Mark McClain and Kevin Cunningham, SailPoint is headquartered in Austin, Texas.
