Join our Newsletter — 33% off our NHI Course

What should organisations do when they need to grow identity capability across new and experienced practitioners?

Organisations should invest in structured learning, peer exchange, and recognised credentials that validate practical experience. They should also create pathways for participation that welcome newcomers, not just veterans. That combination builds continuity, improves retention of knowledge, and helps the identity function mature beyond isolated subject matter experts.

Why growing identity capability needs a learning pathway, not just hiring

Identity teams often stall when capability lives in one or two experienced specialists. New practitioners need structured learning so they can understand the operating model, while experienced practitioners need a way to keep that knowledge current and transferable. The goal is not only staffing, it is building a repeatable capability that survives turnover, change, and scale.

That is why programmes that combine formal learning, peer exchange, and practical exposure usually outperform ad hoc mentoring alone. They help organisations move from isolated expertise to a shared discipline, which is especially important when access decisions, lifecycle changes, and governance work must be consistent across many systems.

Identity capability also improves when learning is connected to real operating work. People retain more when they can see how lifecycle management, privileged access, and authentication choices affect daily operations. NHIMG’s Identity Security Programme Guide is a useful reference for structuring that broader operating model around people, process, and governance.

How to welcome both newcomers and experienced practitioners into the same function

A healthy identity function should create multiple entry points. Newcomers need lower-risk work, clear terminology, and access to peer support. Experienced practitioners need advanced responsibilities, space to share patterns, and enough autonomy to improve standards rather than only execute tickets. If everyone is forced into the same path, the function either slows down or becomes dependent on a few veterans.

That balance matters because identity work spans administration, policy, engineering, and stakeholder coordination. Peer exchange, labs, reviews, and rotations help practitioners learn how decisions are made, not just what the policy says. It also makes the team more resilient when a key person leaves or when the environment expands into new platforms, cloud services, or non-human identities. NHIMG’s NHI Lifecycle Management Guide is a useful example of how lifecycle thinking supports that kind of structured capability building.

Recognised credentials can add value when they validate practical competence rather than substituting for it. Used well, they give organisations a shared baseline for screening, progression, and role design. Used badly, they become a proxy for ability and can exclude strong operators who have experience but not formal certification.

How to make capability growth durable instead of personality-dependent

The most durable identity functions turn individual know-how into repeatable artefacts: playbooks, onboarding paths, review checklists, and decision records. That reduces dependence on informal memory and makes it easier to bring in new practitioners without diluting standards. It also helps senior people shift from being the sole problem-solvers to being mentors, reviewers, and design authorities.

Capability growth should therefore be measured by the team’s ability to handle common identity work consistently, not by how often one expert is interrupted. If only veterans can explain entitlement models, offboarding, or authentication dependencies, the organisation has not built capability, it has concentrated it. NHIMG’s Top 10 NHI Issues is a useful reminder that lifecycle and ownership gaps become more visible when identity practice matures.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Identity capability growth depends on defining the function’s role and stakeholders.
Recommendation — Define the identity programme’s operating context and responsibilities before expanding roles or training paths.
NIST SP 800-53 Rev 5 AT-2 — Awareness Training Structured learning and onboarding are central to building repeatable identity capability.
PL-1 — Policy and Procedures Playbooks and documented procedures turn expert knowledge into reusable identity practice.
Recommendation — Provide role-based training that equips practitioners for identity tasks they will actually perform. Document identity procedures so new practitioners can learn from standardised operating guidance.
CIS Controls v8 CIS-14 — Security Awareness and Skills Training Capability growth relies on training pathways and ongoing knowledge transfer.
Recommendation — Run continuous training and skills development for identity staff, not one-off onboarding only.
ISO/IEC 27001:2022 A.6.3 — Information security awareness, education and training The topic is about building practitioner capability through structured learning and participation.
Recommendation — Provide targeted education and training that supports identity roles at different experience levels.

Practitioner Guidance

What to prioritise: Build a role-based learning path for newcomers, a peer forum for shared problem-solving, and a progression path that rewards practical judgement, not just tenure.

What to verify: Check whether the function can onboard someone new into common identity tasks without relying on a single expert to explain every exception. If not, capability is still trapped in individuals.

What practitioners underestimate: Recognition matters, but it works best when it validates real operating experience and reinforces shared standards across the team.

Practitioner takeaway: The objective is to create an identity function that can teach itself, so growth in headcount also grows continuity, consistency, and resilience.