Common signs include high click counts, repeated help requests, inconsistent execution of routine tasks, slow access requests, and users relying on informal cheat sheets. If people can only complete basic governance actions by memorizing special steps, the experience is too brittle. A strong signal is when routine work becomes dependent on support or tribal knowledge.
Why Everyday Users Struggle When Governance Feels Like a Specialist Task
Identity governance should feel like routine administration, not an obstacle course. If everyday users need to pause, ask for help, or remember special handling steps just to complete ordinary access reviews, role changes, or approvals, the experience is too complex. That usually means the workflow is carrying too much policy detail, too many exceptions, or too much hidden state for normal use.
A practical way to judge this is whether the user can complete the task correctly on the first try without external memory aids. If the answer depends on tribal knowledge, the experience has shifted from governance support to governance burden. That is where adoption drops and shadow processes begin to appear.
- High click counts or deep navigation for basic actions usually indicate the interface is forcing users to think like administrators.
- Repeated help requests for the same routine task suggest the workflow is not self-evident.
- Inconsistent execution, where two users handle the same action differently, points to unclear decision paths or missing cues.
The broader governance lesson is that complexity is not just a usability issue. It becomes a control issue when users bypass the intended process, delay action, or rely on unofficial instructions to get work done. In that state, the governance model may still exist on paper, but it is no longer dependable in day-to-day use.
What Complexity Looks Like in Real User Behaviour
The clearest signal is friction around routine tasks. If ordinary actions such as approving access, completing certifications, or updating entitlements require repeated training, users are compensating for the design instead of following it naturally. That is usually visible in support volume, completion time, and the number of steps needed to finish a task that should be straightforward.
Another warning sign is workflow fragility. When a process only works if users remember an exception path, a hidden rule, or a sequence that is not visible in the interface, the experience is brittle. A governance journey should tolerate normal variation in user behaviour; if it does not, the system is too dependent on memory and too weakly guided by the interface itself.
- Ultimate Guide to NHIs is useful background for the governance and lifecycle patterns that become difficult when control journeys are overcomplicated.
- NHI Lifecycle Management Guide helps frame how provisioning, review, and revocation work when ownership and process clarity are weak.
- Ultimate Guide to NHIs, Key Challenges and Risks is relevant where complexity shows up as visibility gaps, over-privilege, and unmanaged governance paths.
If users need informal cheat sheets to remember the right sequence, that is often a stronger signal than a single complaint. Cheat sheets can be a symptom of a design that is too dependent on memorisation, especially when the correct path is not obvious from the interface, the labels, or the approval logic.
Risk and Threat Considerations
Overly complex governance experiences create operational risk because people stop using the intended path consistently. That can lead to delayed approvals, incomplete reviews, inconsistent entitlement changes, and ad hoc workarounds that weaken accountability. Where governance is tied to access decisions, complexity can also increase the chance that risky access persists longer than it should.
Failure mechanism: users cannot reliably follow the intended process, so they resort to support tickets, shortcuts, or memory-based steps. That produces inconsistent outcomes, obscures ownership, and makes control execution dependent on individual familiarity rather than a repeatable workflow.
Impact: the organisation gets lower control reliability, slower decision cycles, and more room for bypass, error, or unreviewed exceptions. Over time, that can reduce trust in the governance process itself and make remediation harder because the real workflow has shifted outside the designed control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Complex governance workflows undermine reliable access control execution. |
| Recommendation — Simplify access-review and approval paths so users can complete routine control actions consistently. | ||
| NIST CSF 2.0 | GV.PO-01 — Policy Establishment | Clear policy translation into usable workflows is central to governance usability. |
| PR.AA-05 — Identity Proofing, Authentication, and Access Rights Management | User friction often reflects poorly designed access-rights workflows and review steps. | |
| Recommendation — Translate governance policy into simple, repeatable user workflows. Streamline access-rights processes so users can complete routine actions without support. | ||
Practitioner Guidance
What to verify: look at whether a first-time user can complete the top three routine governance actions without help, documentation, or backtracking. If they cannot, simplify the workflow before adding more policy detail, because more guidance usually does not fix a confusing path.
What to measure: track task completion time, help requests per task, and repeat correction rates. A governance experience is usually too complex when support demand stays high even after users have been trained, because that means the problem is structural rather than educational.
Common mistake: teams often treat every user error as a training gap. If the same task keeps generating confusion across different users, the interface or process design is usually the real issue.
Practitioner takeaway: Everyday governance should be executable from the interface itself, if users need memory aids to do routine work, the control has become too fragile to rely on at scale.
Related resources from NHI Mgmt Group
- What breaks when identity governance is too complex for cloud and contractor access?
- What happens when privileged users are not monitored in identity governance workflows?
- What are the signs that identity security UX is not working for end users?
- Why do overly complex access request flows create risk for identity governance teams?