Access policy without an owner becomes whatever is convenient this week.
MFA, single sign-on, and Conditional Access are usually rolled out as a project. Someone picks the tool, sets the initial rules, and moves on. What happens next - a legacy application needs a bypass, a senior executive wants a waiver, a contractor keeps standing access weeks after the contract ends - rarely has an owner at all.
Each exception is granted for a specific, defensible reason in the moment. None of them are revisited as a set. Eighteen months later, the actual policy is not the one written down; it is the accumulated pile of exceptions nobody has re-tested.
Identity governance separates the tool decision from the ownership decision: who can approve an exception, who reviews standing access on a schedule, and what should trigger a policy change - independent of which platform enforces it.