Join our Newsletter — 33% off our NHI Course

Should identity leaders prioritise process removal or new control features first?

Prioritise the workflows that most directly slow business activity, especially high-volume approvals and repetitive administration. New controls matter, but if the organisation still relies on manual handoffs for standard access, the programme will continue to tax speed. Remove friction where it blocks delivery, then harden the controls around it.

Why process removal usually comes before new control features

The first question for identity leaders is not which new feature looks strongest, but where the organisation is losing time to avoidable workflow friction. If standard access still depends on manual approvals, exception handling, or repeated rework, the programme is paying a hidden tax on every request. Process removal is often the faster path to measurable improvement because it eliminates waste before adding more governance layers.

That matters most in high-volume, low-risk activity where the control objective is routine assurance rather than bespoke review. In those cases, the real design choice is whether the control model can be simplified without weakening accountability. Mature teams treat friction as a signal: if a workflow exists mainly to compensate for poor ownership, unclear policy, or missing data, fixing the process can unlock more value than introducing another gate.

For NHI-heavy environments, the same logic applies to repetitive credential and lifecycle work. The NHI Lifecycle Management Guide is useful because it frames provisioning, rotation, and offboarding as lifecycle problems, not just control checkboxes. Where those steps are manual, the best first move is usually to remove unnecessary handoffs, then automate the remaining controls around a cleaner workflow.

When new controls should still come first

Process removal is not a licence to delay control investment indefinitely. If a workflow is slow because it lacks basic safeguards, is poorly segmented, or cannot prove who approved what, a new control feature may be the correct first step. The test is whether the control gap itself is the blocker, or whether the organisation is simply using control complexity to compensate for an inefficient process.

New controls matter most when the underlying risk is not just speed, but exposure. For example, the Top 10 NHI Issues highlights how overprivilege, secret sprawl, and poor lifecycle discipline create security debt that process simplification alone will not solve. In that situation, the right sequence is to remove redundant steps where possible, but also introduce the minimum control needed to stop unsafe access paths from being normalised.

The practical decision rule is straightforward: if a control feature reduces a known failure mode, implement it; if it mainly adds a new approval path around an already clumsy process, simplify first. The point is not to choose speed over security, but to stop buying security with bureaucracy when a cleaner workflow would give you both.

How to sequence the change without losing governance

The strongest sequencing model is usually remove, stabilise, then harden. Start by mapping where work slows down, identify which steps are pure administration, and remove those that do not materially improve access decisions, auditability, or risk containment. Then reintroduce controls only where they answer a specific question: who owns the access, what was approved, how long it lasts, and how it is revoked.

That sequence is especially important when identity and access work spans provisioning, review, and deprovisioning. Identity Security Programme Guide is relevant here because it treats roadmap, governance, and operating model as connected decisions rather than separate projects. Leaders who try to harden everything first often end up preserving broken process logic inside a more complicated toolset.

Good sequencing also means using standards to keep simplification safe. The CIS Controls v8 emphasise account management, access control, and audit logging, which are the minimum guardrails you want preserved while workflow friction is reduced. The aim is not to strip controls away indiscriminately, but to make sure the remaining ones are deliberate, observable, and proportionate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Prioritisation here turns on account and access workflow overhead.
Recommendation — Streamline account workflows and retain only controls that preserve traceability.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Manual access processes often reflect weak credential lifecycle handling.
AC-6 — Least Privilege Process simplification must not expand standing access beyond what users need.
Recommendation — Automate credential lifecycle steps that slow standard access without improving assurance. Remove redundant approval steps while enforcing least-privilege access.
ISO/IEC 27001:2022 A.5.15 — Access control The question is about balancing access friction with control strength.
Recommendation — Review access workflows and eliminate controls that do not reduce access risk.
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Lifecycle cleanup is a core reason process removal and control hardening must be sequenced.
Recommendation — Shorten offboarding paths while keeping revocation checkpoints intact.

Practitioner Guidance

What to prioritise: Start with the workflows that consume the most human effort for the least risk reduction, usually standard approvals, repetitive access requests, and manual reconciliation. If removing a step does not weaken accountability or evidence, remove it before investing in a new feature.

What to verify: Before adding any new control, verify whether the current delay is caused by policy ambiguity, missing ownership, or tool limitation. If the slowdown is mainly governance theatre, a feature will not fix it; the process needs redesign first.

Decision rule: If the organisation can still answer “who approved, for what, and for how long” after simplification, the change is probably safe. If it cannot, keep or add the minimum control needed to preserve traceability before removing more friction.

Practitioner takeaway: The best sequence is rarely “more control first” or “remove everything first”, it is to eliminate avoidable friction where it does not improve risk decisions, then harden only the steps that actually prevent unsafe access or failed accountability.