Organisations should build the agenda around shared operating problems, not product pitches. Focus sessions on access governance, privileged access, workforce and vendor access, device access, and compliance workflows. The best event formats bring identity, security, audit, and operations teams into the same room so they can compare controls, identify gaps, and agree on practical next steps.
Why This Matters for Security Teams
An identity and access event only works when it helps teams resolve real control failures, not when it becomes a catalogue of tools. Access governance, privileged access, secrets handling, and third-party exposure all intersect across identity, security operations, audit, and infrastructure teams. The agenda should force those functions to compare how access is granted, monitored, and revoked, especially where the scale of non-human identities outpaces human oversight. Current guidance also aligns with the control structure in NIST SP 800-53 Rev 5 Security and Privacy Controls, which makes the event most useful when it maps discussion to clear operational ownership. The strongest agendas surface the gaps that matter: stale privileges, incomplete visibility, weak offboarding, and exceptions that never get closed. In practice, many teams only discover those failures after an audit finding, a leaked secret, or a vendor access incident has already created pressure to act.
How It Works in Practice
A practical agenda starts with problem statements, then builds sessions around the systems and workflows that create those problems. For example, identity teams can walk through how entitlements are approved, security can challenge where logging stops, and operations can show which access requests are handled manually. A session on non-human identities should not be theoretical; it should use a live control map, the current service account inventory, and the access paths that matter most. The OWASP Non-Human Identity Top 10 is useful here because it frames recurring failure modes such as exposed secrets, over-privilege, and weak lifecycle management. NHIMG research reinforces why that matters: the Ultimate Guide to NHIs shows how often organisations still lack visibility, rotation, and offboarding discipline.
A well-designed event agenda usually includes:
- Access governance, with a review of approval paths, periodic recertification, and exception handling.
- Privileged access, including where PAM is used, where it is bypassed, and where JIT is still manual.
- Workforce and vendor access, especially where third-party access is indirect or only partially visible.
- Device and workload access, with a focus on trust boundaries, certificate use, and secrets storage.
- Compliance workflows, so audit evidence, remediation, and ownership are discussed together rather than separately.
The most effective format pairs short briefings with working sessions, so teams leave with a backlog of control fixes, named owners, and dates for follow-up. These controls tend to break down when the event is framed around vendor demos instead of the actual identity systems, because the hardest problems sit in cross-team exceptions and undocumented workarounds.
Common Variations and Edge Cases
Tighter agenda control often increases planning overhead, requiring organisers to balance broad participation against the risk of unfocused discussion. Some environments need a split agenda because workforce identity, vendor access, and non-human identity governance are operationally different even if they share the same platform. Current guidance suggests that the event should still converge on a single control language, but there is no universal standard for structuring the sessions yet.
A useful edge case is regulated environments where audit and compliance teams need evidence, not exploration. In those settings, the agenda should include control mapping, evidence collection, and remediation tracking, rather than long product walkthroughs. Another common variation is the large enterprise with multiple identity platforms. Here, the agenda should emphasise interoperability, ownership boundaries, and where policy decisions are made, especially across IAM, PAM, and secrets management. For teams dealing with NHIs at scale, the Top 10 NHI Issues is a strong discussion starter, and the 52 NHI Breaches Analysis is useful when participants need concrete failure patterns rather than abstract risk language. The best agendas leave room for those realities while still forcing decisions on ownership, prioritisation, and next steps.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Agenda topics should expose NHI inventory, lifecycle, and access gaps. |
| OWASP Agentic AI Top 10 | Agentic systems create access events that need runtime governance and shared review. | |
| CSA MAESTRO | MAESTRO-3 | MAESTRO emphasizes governance and orchestration across identity, access, and runtime controls. |
| NIST AI RMF | AI RMF supports accountable risk discussion for automated and agent-driven access flows. | |
| NIST CSF 2.0 | PR.AC-1 | Access control reviews align directly to identity and authorization governance. |
Structure the agenda around governance checkpoints that connect policy, operations, and exception handling.
Related resources from NHI Mgmt Group
- How should security teams handle identity and access challenges at scale in modern enterprises?
- What do security teams get wrong about event based identity coordination?
- Why do distributed supply chains increase identity and access risk for security teams?
- How should security teams migrate identity governance from on premises platforms to cloud based identity security without disrupting access controls?