Join our Newsletter — 33% off our NHI Course

What should organisations do first to make IT more valuable in a modern, decentralised workplace?

The first step is visibility. Organisations need a clear picture of which apps are used, who approves access, and how identity changes move through the business. Once that baseline exists, IT can support self-service access, reduce manual work, discover shadow IT, and connect security, compliance, and cost management around the same operational truth.

Why visibility comes before decentralised self-service

In a decentralised workplace, IT creates value first by knowing what is actually in use, who has authority over access, and where identity changes occur. Without that baseline, every improvement is partial: automation can speed up the wrong process, shadow IT stays hidden, and finance, security, and operations keep working from different facts.

Visibility is not just asset discovery. It is the operational map that connects applications, approvers, access paths, and ownership so teams can decide what should be standardised, delegated, or removed. That is what makes IT useful as a business enabler rather than only a support function.

When visibility is strong, organisations can connect the practical controls that matter most in distributed environments, such as access requests, app approval workflows, and offboarding logic. It also makes it easier to spot duplicated tools, unmanaged SaaS usage, and access patterns that no one formally owns. For a broader identity baseline, NHI Mgmt Group’s Ultimate Guide to NHIs, What are Non-Human Identities is useful because it frames visibility as a lifecycle and governance problem, not just an inventory exercise.

What changes once the baseline exists

Once organisations can see the real operating picture, IT can move from gatekeeping to service design. Self-service access becomes safer because approvals are tied to known apps and known owners, manual fulfilment drops because standard requests can be routed consistently, and exceptions become visible enough to challenge. The practical shift is from reacting to tickets to managing a controlled access model.

That baseline also exposes where the organisation is spending time on low-value administration. If access requests are repeatedly approved through email, if app ownership is unclear, or if different business units buy overlapping tools, IT can rationalise those patterns around a common source of truth. In modern workplaces, that common truth is what allows security, compliance, and cost management to line up instead of competing.

  • Use visibility to define which applications are sanctioned, which are tolerated, and which should be retired.
  • Use approver and owner data to remove ambiguous approval chains that slow down access decisions.
  • Use identity-change tracking to find where joiner, mover, and leaver processes break down.

A practical example of why this matters is that decentralised tool use often hides third-party and SaaS access paths until something goes wrong. NHIMG’s Klue OAuth Supply Chain Breach is a good reminder that visibility is also about knowing which integrations can move trust, data, and permissions across systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS Control 1 — Inventory and Control of Enterprise Assets Visibility starts with knowing which apps and assets are in use.
CIS Control 6 — Access Control Management The question centers on who approves access and how it is governed.
Recommendation — Inventory all enterprise assets and sanctioned applications before standardising access workflows. Define access approval ownership and enforce consistent access-control processes.
NIST CSF 2.0 GV.AM — Asset Management A reliable operating baseline depends on understanding apps, ownership, and usage.
PR.AA — Identity Management, Authentication, and Access Control Visibility into access approvals and identity change flows directly supports access governance.
Recommendation — Maintain an accurate asset and application inventory to support governance decisions. Align access request and approval workflows to managed identity and access controls.
OWASP Non-Human Identity Top 10 NHI-01 — Secret Discovery and Inventory A visibility baseline in modern workplaces also includes identities and access material behind apps and integrations.
NHI-02 — Secret Rotation and Lifecycle Management Visibility is needed to understand where access material changes and who owns its lifecycle.
Recommendation — Discover and inventory identity-bearing secrets and access paths before automating operations. Map ownership and lifecycle for access material so rotation and revocation are reliable.

Practitioner Guidance

What to prioritise: Start with application and access visibility before you redesign service delivery. If you cannot explain who uses an app, who approves access, and what identity changes trigger downstream action, you do not yet have a stable operating model.

What to verify: Check whether the organisation can produce a trustworthy list of sanctioned apps, approval owners, and access paths without manual reconstruction. If that evidence only exists in scattered tickets, spreadsheets, or local knowledge, the visibility layer is still immature.

Common mistake: Teams often automate self-service too early. That can make a broken process faster, harder to audit, and more expensive to unwind. The better sequence is baseline first, then standardisation, then automation.

What good looks like: Requests are routed through known owners, unused or duplicate tools are visible, and identity changes are reflected quickly enough that security, compliance, and cost decisions all use the same operational record.

Practitioner takeaway: The first value-creating move for IT is not adding more tooling, it is establishing enough visibility that the organisation can govern access, spend, and support from one shared truth.