Common signs include pending requests that sit untouched, senior approvers who rarely complete reviews on time, and mobile users who wait until they are back at a laptop. Those symptoms usually point to workflow friction, not policy failure. If people cannot act quickly, governance will drift.
When approvers are struggling, what does the workflow tell you?
The clearest signal is not usually a policy exception, it is a path people avoid. If requests linger in queues, approvers defer action until they have more time, or they only complete reviews when they are already at a desktop, the process is asking for more attention than the business can reliably give. That is a usability problem in governance, not a disagreement with the policy.
In practice, overloaded approvers start to create a shadow process: they batch approvals, delegate informally, or approve without context just to clear the queue. Those behaviours are important because identity governance only works when the review step is quick enough to fit real work patterns.
A useful comparison is the difference between a control that is technically correct and one that is operationally usable. An access review that requires too many clicks, too much context switching, or too much manual decision-making may still look compliant on paper, but it will not survive day-to-day use.
Which signs show the approver experience is too heavy?
The most reliable signs are behavioural. People stop responding promptly, review cycles slip past their due dates, and certain approver groups become chronic bottlenecks because they are difficult to reach or too busy to complete every request. When this happens repeatedly, the problem is usually not lack of intent, it is too much friction at the point of decision.
Another sign is channel mismatch. If mobile users consistently wait for a laptop, if managers need multiple tabs to understand one request, or if approvers cannot make sense of the context from the notification alone, the workflow is not aligned to how decisions are actually made. The stronger the friction, the more likely people are to postpone the decision or treat it as routine noise.
Over time, that creates governance drift. Approval becomes something that happens late, inconsistently, or with limited scrutiny, and the quality of the control falls even when the policy text remains unchanged.
What usually causes that friction in identity governance?
Friction usually comes from one of four places: too much context, too many decisions, too little time, or too many handoffs. Approvers may be asked to judge entitlements they do not understand, compare requests against role structures that are hard to interpret, or validate access across systems that do not present a single clear view.
Workflows also become hard to use when they combine high-volume review with low-value detail. If approvers must inspect every request individually but receive little risk context, they cannot separate routine items from genuinely sensitive ones. That is where access reviews and certification design matter, because review quality depends on both decision speed and decision quality.
At the governance layer, the same friction often appears when role design, segregation rules, or lifecycle handling are too complex for the audience doing the approving. A process that only specialists can use is not scalable governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Delayed approvals need monitoring and review signals to spot control drift. |
| AC-2 — Account Management | Approver friction directly affects account and entitlement governance workflows. | |
| Recommendation — Track approval latency and escalate repeated review delays as a control effectiveness issue. Streamline account and entitlement approval paths so reviews finish within operational deadlines. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Identity governance approvals are part of access control execution and oversight. |
| Recommendation — Reduce approval friction so access control decisions remain timely and enforceable. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account approval delays weaken operational control over user and privileged access. |
| Recommendation — Simplify approval workflows and monitor queues for repeated bottlenecks. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access decisions must be governable in practice, not just documented in policy. |
| Recommendation — Ensure approval processes are usable enough to support consistent access control decisions. | ||
Practitioner Guidance
What to prioritise: Start with the approval path that blocks the most business activity, then look at where approvers most often stall. Measure time to approve, abandonment, and late completion by approver group so you can separate rare exceptions from structural friction.
What to verify: Check whether approvers can decide from the notification itself, whether the request carries enough business context, and whether the approval action works on the devices people actually use. If the answer is no, usability is already weakening control performance.
Common mistake: Teams often respond to slow approvals by adding more reminders or stricter deadlines. That can increase pressure, but it does not remove the underlying friction that caused the delay.
Practitioner takeaway: Treat repeated approval delay as a control-design signal. If the workflow is hard enough that approvers consistently defer it, the governance model is too complex for the operating rhythm it is meant to support.
Related resources from NHI Mgmt Group
- What are the signs that identity governance workflows are becoming too hard for administrators to use effectively?
- What are the signs that a digital identity process for creators is becoming too hard to use?
- What are the signs that identity data is too stale for governance use?
- Why is it important to integrate identity and data governance?