A Lean time savings study is a process-improvement method that measures how much time a workflow consumes before and after a change. It turns wasted minutes into operational evidence, helping teams estimate staffing impact, productivity gains, and process efficiency. In identity projects, it can show how access friction affects clinical work.
What a Lean Time Savings Study Measures
A lean time savings study measures how much time a workflow uses before and after a process change. The goal is to turn observed delay, rework, and handoff friction into evidence that can support staffing, productivity, and process-design decisions.
The study is not just a before-and-after stopwatch exercise. It is most useful when the workflow is repeated, the task boundaries are clear, and the team can separate actual work from waiting, searching, re-entering data, or recovering from avoidable access friction.
How the Method Works in Practice
The usual pattern is to observe a task, define the same task after a change, and compare elapsed time across a meaningful sample. The comparison can be simple, but the measurement needs consistent start and stop points, otherwise the result becomes easy to dispute.
Good studies distinguish between process time and queue time, because a change may reduce one while leaving the other untouched. In clinical and operational settings, that distinction matters: a faster login or access step may shorten the workflow, but a downstream approval or verification step can still dominate the total elapsed time.
When the workflow is tied to access, the study can reveal whether security controls are creating legitimate delay or unnecessary friction. That makes the method useful in identity-heavy environments, where the business question is often not only whether a control works, but whether it slows work enough to affect adoption or workarounds.
Why It Matters for Security, Operations, and Identity Work
Lean time savings studies help teams quantify trade-offs instead of arguing them abstractly. They can show when a control improves safety with little operational cost, and they can also expose when poorly designed access steps push people toward manual bypasses, duplicate entry, or informal exceptions.
In identity projects, the study is often valuable because access friction is not merely a user-experience issue, it can become a governance issue. If clinicians, analysts, or technicians spend repeated time waiting on access, teams may understate the staffing burden, overestimate the benefit of a control, or miss the operational pressure that leads to exceptions.
Used well, the method gives leaders a practical way to discuss process efficiency without losing sight of control integrity. It does not prove that a change is secure, but it can show whether the change makes the secure path realistic enough to use consistently.
What Good Evidence Looks Like
A credible study ties the measured time savings to a clearly defined workflow, a known baseline, and a specific change. The strongest studies compare the same task under comparable conditions, document assumptions, and avoid mixing unrelated work into the measurement.
Evidence is strongest when the study can explain both the measured delta and the mechanism behind it. For example, a reduction in time might come from fewer handoffs, less re-entry, better access routing, or fewer interruptions, and each of those has a different operational meaning.
For teams evaluating access-related changes, it helps to interpret the result alongside the control design rather than in isolation. A time saving that comes from removing a control is not the same thing as a time saving that comes from making the control faster to complete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | CM-2 — Baseline Configuration | Time studies often benchmark a workflow before and after a controlled process change. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Lean studies rely on evidence from observed workflow performance and change impact. | |
| Recommendation — Establish a stable baseline before measuring workflow time savings. Review workflow evidence to confirm the measured change is real. | ||
| ISO/IEC 27001:2022 | A.8.15 — Logging | Process timing studies often depend on logged events to establish before-and-after performance. |
| Recommendation — Use event logs to support reliable before-and-after timing comparisons. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Audit trails can provide the timing evidence needed to validate workflow improvements. |
| Recommendation — Preserve logs that substantiate the time-savings measurement. | ||
Practitioner Guidance
Why practitioners should care: A time savings study is most useful when it supports a specific operational decision, such as whether a workflow redesign, access change, or automation effort actually reduces burden enough to matter. If the measurement cannot be tied to a real decision, it usually becomes a vanity metric.
What to watch for: The most common failure is measuring a narrow step while ignoring rework, exception handling, or downstream delay. That can make a change look better than it is, especially when the workflow contains security or approval steps that shift time rather than remove it.
Practitioner takeaway: Treat the result as decision evidence, not proof of improvement by itself, and always ask whether the saved time reflects real work removed or simply work moved somewhere else.