Join our Newsletter — 33% off our NHI Course

What is the difference between a workshop format and an unconference format in an identity security event?

A workshop format is structured and instructor-led, with attendees staying in the selected session for the full duration. An unconference is participant-driven, where attendees propose and lead discussion topics on the spot. In practice, workshops suit guided learning and skill building, while unconferences are better for open exchange, problem solving, and peer-generated priorities.

Why This Matters for Security Teams

In identity security events, the format shapes what practitioners learn, how candidly they share failures, and whether the session produces reusable guidance or only broad discussion. Workshops are best for teaching a defined method, while unconferences are better for surfacing current pain points, local patterns, and unresolved questions. The distinction matters because NHI risk is operational, not theoretical, and teams often need either guided execution or peer comparison.

For NHI programs, that difference is especially important when the agenda involves lifecycle controls, secrets rotation, offboarding, or visibility gaps. NHI Management Group research shows that 68% of organisations do not know how to fully address NHI risks, while 71% of NHIs are not rotated within recommended time frames in the Ultimate Guide to NHIs. A workshop can teach the mechanics of a control; an unconference can expose why that control still fails in practice. Current guidance suggests choosing the format based on the outcome needed, not on preference for structure alone. In practice, many security teams discover the format mismatch only after the session ends and the real decision work has not happened.

How It Works in Practice

A workshop format is facilitator-led and usually follows a planned sequence: short instruction, demonstration, exercise, review, and questions. In an identity security event, that structure works well for topics such as privileged access workflows, secrets hygiene, or reviewing evidence against a framework like the NIST Cybersecurity Framework 2.0. The attendees remain in the same session, which helps if the objective is to leave with a repeatable skill, checklist, or implementation pattern.

An unconference is more fluid. Participants propose topics at the start or even during the event, and the group sets the agenda around the issues that matter most at that moment. That can be valuable in NHI security because the hardest problems are often cross-functional: service account ownership, API key sprawl, third-party exposure, and audit evidence. In that setting, the conversation can benefit from real incidents and operational lessons, including research such as The State of Non-Human Identity Security, which highlights the confidence gap and visibility weaknesses many programs still face.

  • Use workshops when the goal is consistent instruction, shared terminology, and hands-on practice.
  • Use unconferences when the goal is discovery, peer exchange, and surfacing unresolved blockers.
  • Choose workshop tracks for control design, then unconference sessions for implementation friction and operating model gaps.
  • For identity security specifically, unconferences often surface missing owners, weak rotation processes, and unclear accountability faster than formal presentations.

Practically, a good event may use both formats: workshops for depth, unconferences for breadth. That combination lets attendees learn the “how” and then pressure-test the “why now” and “what breaks next.” These controls tend to break down when the event is trying to cover too many identity topics in one room because neither format gets enough time to deliver value.

Common Variations and Edge Cases

Tighter session design often increases planning overhead, requiring organisers to balance learning depth against participant autonomy. That tradeoff is real in identity security events because some topics need structure, while others only become useful when the room can steer itself. A workshop on NHI offboarding or secrets rotation usually needs a clear sequence and a defined artifact. An unconference on third-party OAuth exposure or service account ownership may be more productive because the answers are highly environment-specific.

Best practice is evolving around hybrid agendas. Some events open with a short workshop to establish baseline concepts, then move into unconference-style breakouts to collect practitioner problems. That approach works especially well when attendees vary in maturity, since early-stage teams need vocabulary and advanced teams need peer comparison. It also aligns with the reality that the most useful identity sessions are often the ones that turn abstract guidance into operational decisions.

There is no universal standard for which format is “better.” The right choice depends on whether the session must teach, diagnose, compare, or prioritise. If the audience includes both operators and leaders, a mixed format usually performs better than a pure lecture or a fully open agenda. For deeper background on why identity programs need this kind of practical tailoring, see the Top 10 NHI Issues and the broader Ultimate Guide to NHIs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV Event format choice affects how teams evaluate and share identity risk lessons.
OWASP Non-Human Identity Top 10 NHI-07 Identity events often focus on lifecycle and operational gaps covered by NHI guidance.
CSA MAESTRO M1 Agentic and identity sessions benefit from structured versus peer-led operating models.
NIST AI RMF GOVERN Governance framing helps determine when structured learning or open discussion is appropriate.
OWASP Agentic AI Top 10 A08 Autonomous systems need the right collaboration format to surface operational failure modes.

Use governance and oversight sessions to turn workshop outputs into repeatable identity-risk decisions.