Yes, when the two domains support different operating rhythms and user goals. Identity governance teams need access reviews, access requests, and workflows, while SaaS management teams focus on spend, contracts, and optimisation. Separate workspaces can reduce distraction, improve task clarity, and make it easier for each group to find the controls and data it uses most.
Why This Matters for Security Teams
The question is less about user interface preference and more about operating model. Identity governance and SaaS management pull teams toward different decisions: one is control-heavy, approval-driven, and audit-oriented, while the other is cost-, adoption-, and contract-oriented. When both workflows sit in one workspace, users often inherit too much context switching and miss the signals that matter most for their role.
That matters because identity work is already high stakes. NHI-related compromise remains common, and the research in The State of Non-Human Identity Security shows how often organisations still struggle with basic visibility and response discipline. The practical lesson aligns with NIST Cybersecurity Framework 2.0: governance succeeds when people can reliably find the right control, the right data, and the right workflow without noise. In practice, many security teams discover workspace design flaws only after reviews stall, SaaS sprawl grows, or access exceptions start bypassing normal oversight.
How It Works in Practice
Separate workspaces usually work best when the platform supports shared identity data but distinct operating views. Identity governance teams need access certifications, policy exceptions, role cleanup, and lifecycle workflows. SaaS management teams need licence optimisation, vendor inventory, contract dates, and application usage trends. If both groups are forced into one flat workspace, the platform may still be technically usable, but it becomes harder to maintain focus and harder to explain accountability.
A practical split does not mean duplicating the source of truth. It means separating the experience layer while keeping governance consistent underneath. For example, one workspace can expose access review queues, ownership mapping, and approval routing, while another highlights unused licences, app spend, and renewal risk. That approach is consistent with the control intent behind NIST SP 800-53 Rev 5 Security and Privacy Controls, which emphasise accountability, access control, and auditability.
- Use shared identity records, but tailor dashboards and navigation to each team’s tasks.
- Keep entitlement data, approvals, and recertification workflows in the governance workspace.
- Keep SaaS inventory, spend analytics, and renewal workflows in the SaaS workspace.
- Apply consistent role-based permissions underneath both views so separation does not create control drift.
This pattern fits the lifecycle view in NHI Lifecycle Management Guide and the broader operational guidance in Ultimate Guide to NHIs, where the issue is not just what is managed, but how consistently teams can execute the work. These controls tend to break down when workspace separation is added on top of unclear ownership, because users then do the wrong work in the right tool.
Common Variations and Edge Cases
Tighter workspace separation often increases administration overhead, requiring organisations to balance clarity against governance consistency. That tradeoff becomes more visible in smaller teams, where the same administrator may need to review both identity events and SaaS spend, or in companies that are still maturing their identity data model. In those environments, a single workspace with strong role-based views may be more efficient than full separation.
Best practice is evolving around whether separation should be hard or soft. There is no universal standard for this yet. Some organisations use one platform tenant with two dedicated workspaces, while others rely on one workspace with role-specific dashboards and navigation. The right answer depends on how different the operating rhythms are, how much overlap exists in the users, and whether audit evidence must be partitioned for different audiences. The NHIMG research on 52 NHI Breaches Analysis is useful here because it shows how quickly weak operational boundaries can create security exposure when ownership is blurred.
As a rule, split workspaces when the teams measure success differently and need different control surfaces. Keep them unified when the organisation is early in maturity, the same people own both functions, or the platform cannot preserve consistent policy underneath separate views.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Workspace design should support clear governance oversight and accountability. |
| NIST SP 800-63 | Identity assurance and access decisions depend on clear role separation and context. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Separating workspaces can reduce misuse of shared non-human identity controls. |
| CSA MAESTRO | GOV-2 | Agent and SaaS workflows need governance boundaries that match operational goals. |
| NIST AI RMF | The question reflects governance design choices around clear accountability and measurement. |
Apply AI RMF governance principles to assign ownership and monitor workspace effectiveness.
Related resources from NHI Mgmt Group
- Why do organisations struggle to fund identity governance without SaaS management data?
- Why do organisations need separate rules for user identity and user-to-app relationships in SaaS governance?
- Why do SaaS-heavy environments make identity governance harder than older perimeter-based models?
- Why do organisations struggle to govern access effectively as identity estates grow across SaaS and hybrid systems?