The platform may appear inexpensive, but the organisation is quietly paying for missing capability with staff time. Manual reviewer reminders, spreadsheet correlation, ticket creation, deprovisioning, and evidence assembly all turn into ongoing labour costs. That approach also slows governance outcomes, because access decisions and remediation depend on people moving files instead of automated workflows.
Why Manual “Savings” Usually Just Move the Bill
IGA programmes look cheaper when the software line item is low, but the hidden cost is that people become the workflow engine. Reviewer chasing, exception follow-up, spreadsheet reconciliation, ticket handoffs, deprovisioning checks, and evidence assembly all consume recurring labour, which turns a supposed platform saving into an operating expense. The result is often slower access governance, not leaner governance. A common pattern is that teams buy tooling to reduce effort, then recreate the missing automation with email and spreadsheets.
That tradeoff matters because governance work is time-sensitive: access changes lose value when they sit in queues, and control evidence becomes less reliable when it is assembled manually after the fact. In practice, manual work often survives as “temporary” process glue long after the platform is live.
How the Workload Shows Up in Practice
The strongest sign of disguised manual work is that the platform creates alerts and tickets but does not complete the decision path. Reviewers still need reminders, approvers still chase context, and operators still copy data between systems to answer basic questions such as who has access, why they have it, and whether it was removed on time. That means the organisation is paying twice, once for the platform and once for the labour needed to make the platform usable.
- Review campaigns may be launched automatically but closed by spreadsheet comparison and manual exception handling.
- Access removals may require a human to open, route, and verify tickets instead of triggering a controlled workflow.
- Evidence for audits may be reconstructed from email, screenshots, and exports rather than produced by the system of record.
- Role or entitlement clean-up may depend on analysts mapping mismatched records across HR, directory, cloud, and application systems.
For identity-heavy programmes, the labour burden scales with the number of accounts and access edges, not with the number of licences purchased. NHIMG data shows how often that burden lands on weak visibility, with Ultimate Guide to NHIs reporting that only 5.7% of organisations have full visibility into their service accounts. Even when the immediate question is about IGA economics, poor visibility is what turns “automation” into repeated manual triage.
These controls tend to break down when identity data is fragmented across legacy systems, SaaS apps, and custom entitlements because the platform cannot reliably decide without human cleanup.
Where the Savings Claim Breaks Down
Tighter automation often increases upfront implementation effort, so organisations have to balance lower steady-state labour against higher design and integration work. The savings claim fails when the programme is measured by licence cost alone instead of by the cost of operating the control over time.
The main edge case is partial automation: if the platform handles requests but not approvals, or approvals but not downstream enforcement, the manual residue becomes the real system. Another common issue is that teams accept low-quality entitlement data because cleansing feels expensive, only to pay that cost repeatedly in every review cycle. Guidance is evolving here, but the practical rule is simple, use software to remove recurring decision and routing work, not just to formalise it.
When a programme still needs humans to discover, correlate, approve, deprovision, and prove the outcome for every cycle, the organisation has not bought efficiency, it has purchased a more organised manual process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 5 — Account Management | IGA work centers on managing access lifecycle and reviews. |
| Recommendation — Automate account review and removal workflows to reduce manual governance labour. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | Access governance effectiveness depends on timely identity and entitlement control. |
| GV.OV — Oversight | Manual-heavy IGA programs often hide operating cost behind licence savings. | |
| Recommendation — Implement access governance controls that reduce manual review and remediation work. Track operating effort and control completion, not just software cost. | ||
| ISO/IEC 42001:2023 | AI governance system | Only applicable if IGA work is being automated with AI decision support. |
| Recommendation — Govern automated decision support so human review is reserved for exceptions. | ||
Practitioner Guidance
What to prioritise: Separate “workflow completed by the system” from “workflow tracked by the system.” If reviewers, approvers, or operators still have to move data between tools, the platform is not reducing labour in the part of the process that usually dominates cost.
What to verify: Check whether the programme can produce access decisions, removals, and audit evidence from system-generated records alone. If success depends on exports, reconciliations, or inbox chasing, count that as operating labour, not automation.
Decision rule: If a control still needs repeated human follow-up to finish, treat the manual step as a core dependency and include it in the business case, staffing plan, and risk assessment.
Practitioner takeaway: The real question is not whether the platform is inexpensive, but whether it eliminates recurring human effort at the exact points where governance work must be timely, accurate, and provable.
Related resources from NHI Mgmt Group
- How should organisations build a credible IGA ROI case before buying software?
- What breaks when organisations try to model IGA savings as full automation?
- What happens when legacy and new IGA platforms both stay authoritative during migration?
- What does the 144:1 NHI-to-human ratio mean for IAM governance programmes?