Centralised administration simplifies account and policy management in one place, while full identity governance proves that access is authorised, reviewed, and revocable across every system that matters. A single portal can improve usability without covering all entitlements. Full governance requires lifecycle and certification control beyond the directory boundary.
Why centralised administration is narrower than full governance
Centralised identity administration is mainly about operational convenience. It gives you one place to create accounts, assign roles, reset access, and apply policy, which reduces duplication and makes administration faster. Full identity governance is broader: it must show that every entitlement is justified, approved, reviewed on schedule, and removed when it should be.
The practical difference is scope. A central portal can manage identities in a directory or core platform without proving that access is still appropriate in the applications, databases, cloud services, and business systems where real risk lives. Governance adds control over the lifecycle of access, not just the place where requests are processed.
This is why a centralised team can be efficient without being governance-complete. If the process stops at provisioning, you may know who received access, but not whether the access still matches job need, segregation rules, or recertification expectations. Governance is the evidence layer that turns administration into accountable access control.
What full identity governance adds beyond a single portal
Full identity governance connects request, approval, provisioning, review, and revocation into one accountable loop. It covers joiner, mover, and leaver changes, entitlement ownership, periodic certification, exception handling, and proof that access can be removed across connected systems. IAM and IGA Basics is a useful reference point for the distinction between administration and governance.
That broader model matters because access is rarely confined to one directory. A person or non-human actor may have roles in HR, finance, engineering, cloud platforms, SaaS tools, and local applications. Full governance must inventory those entitlements, identify the owner of each one, and make review decisions that reflect actual business risk rather than directory convenience.
Centralised administration can still be a strong foundation, especially when it standardises provisioning and reduces drift. But it only becomes governance when it also supports evidence of least privilege, segregation of duties, access certification, and timely removal of stale access. Access Reviews and Certification Guide shows why review quality, not just review volume, determines whether governance is real.
How to recognise the boundary in practice
The boundary is easy to test. If the system can create or change an account but cannot prove who owns the entitlement, when it was last reviewed, and whether revocation actually reached every target application, you have administration, not full governance. If the system can also track those outcomes end to end, you are operating in governance territory.
Another useful test is whether the process can survive exceptions. Central administration often handles requests cleanly when they are standard. Governance must also handle non-standard access, temporary elevation, shared or inherited roles, and orphaned permissions that accumulate outside the main workflow. That is why role design, review design, and separation of duties matter as much as provisioning speed. Role Mining and Role Design Guide and Segregation of Duties (SoD) Guide both support that operational boundary.
Where many programs go wrong is confusing a single pane of glass with control coverage. A unified dashboard is helpful, but if disconnected applications, manual grants, or weak offboarding still exist, the organisation has central visibility without reliable governance. IGA Buyer’s Guide is relevant here because platform selection often determines whether review, entitlement discovery, and revocation are truly integrated.
Risk and Threat Considerations
Centralised administration can create a false sense of control. The main risk is that teams believe the directory is authoritative even when entitlements in downstream systems are stale, excessive, or never re-certified. That leaves privilege creep, orphaned access, and weak offboarding hidden behind a clean administrative front end.
Failure mechanism: Access is provisioned centrally, but review and revocation are incomplete across all systems, so old entitlements persist after role changes, departures, or exceptions.
Impact: Excess access can be abused for insider misuse, account takeover, audit failure, or lateral movement, and the organisation may be unable to prove that access decisions were authorised and reversible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Central admin and governance both depend on account lifecycle control. |
| AC-6 — Least Privilege | Governance must keep entitlements limited to what each role needs. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Governance needs evidence that access decisions and removals were verified. | |
| Recommendation — Enforce AC-2 to provision, review, and disable accounts across all systems. Apply AC-6 to restrict entitlements to the minimum required access. Use AU-6 to review access activity and support entitlement recertification. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | The question turns on managing and reviewing access rights beyond administration. |
| Recommendation — Review access rights periodically and remove those no longer justified. | ||
| CIS Controls v8 | CIS-5 — Account Management | Central administration and governance differ mainly in account lifecycle enforcement. |
| Recommendation — Implement CIS-5 to manage account creation, review, and removal consistently. | ||
Practitioner Guidance
What to verify: Check whether entitlement ownership, review cadence, and revocation coverage exist for every connected system, not just the primary directory. If you cannot produce evidence that a grant was reviewed and removed everywhere it existed, the control is administrative rather than governed.
Decision rule: Treat “single portal” as an operating model improvement, not a governance claim, unless it also closes the loop on inventory, certification, exceptions, and deprovisioning. If disconnected applications remain outside that loop, prioritise coverage before adding more workflow polish.
What practitioners underestimate: Governance is less about where requests are submitted and more about whether access can be justified, reviewed, and revoked at scale across the real application estate. The strongest programmes use central administration to reduce friction, then add governance to prove control over every entitlement that matters.
Practitioner takeaway: Centralised administration improves efficiency; full identity governance improves assurance. If the organisation cannot demonstrate review and revocation beyond the core directory, it has streamlined access management but not yet achieved governance.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?
- What is the difference between patching a vulnerability and reducing identity blast radius?