Join our Newsletter — 33% off our NHI Course

When should organisations prioritise access redesign over adding more digital capability?

When existing systems are already deployed but clinicians still struggle to use them efficiently. If the problem is access friction rather than missing functionality, more technology will not fix the underlying issue. Redesigning identity flows is the faster route to usable maturity.

When access redesign should come before more capability

Prioritise access redesign when the current barrier is not a missing feature, but a broken path to using what already exists. In practice, that means clinicians can reach the system, but the login flow, role setup, approval steps, or session handling make routine work slow, error-prone, or avoidable. Adding functionality in that state usually increases complexity before it improves care.

What access friction is really telling you

Access friction is often a signal that the organisation has outgrown its identity model, not its software catalogue. If users must juggle too many steps, shared accounts, repeated prompts, or inconsistent permissions, the issue is usually how access is being granted and governed, not whether another module should be purchased. The strongest fix is to remove friction at the point of authentication and authorization, then measure whether people can complete the intended task with fewer workarounds.

That distinction matters because digital capability and usable access are not the same thing. A system can be feature-rich and still underperform if the access path is slow, fragmented, or misaligned to real work. When the access layer is the bottleneck, redesign tends to produce faster gains than more development, because it improves the experience of every existing capability at once.

Why access redesign beats capability expansion in mature deployments

Where the platform is already deployed, capability expansion only helps if the current process is functionally incomplete. If the day-to-day complaint is “we have the system, but it is hard to use,” then the better question is whether users can be provisioned, authenticated, and authorized in a way that matches the operational workflow. In these cases, redesigning roles, permissions, sign-on journeys, and escalation paths usually delivers more usable maturity than adding another feature set.

That is especially true in regulated or high-tempo environments, where delay creates shadow processes. People will route around friction by sharing access, storing credentials badly, or relying on informal approvals. A cleaner access design reduces those pressures and improves both adoption and governance.

Risk and Threat Considerations

When access is awkward, users create workarounds, and those workarounds often become the real control surface. Shared credentials, overbroad roles, excessive exceptions, and delayed removal of access all increase exposure, even if the underlying application is secure.

Failure mechanism: Friction pushes people toward shortcuts, such as password sharing, standing access, or ad hoc privilege grants. Over time, those shortcuts weaken accountability, expand blast radius, and make it harder to tell whether access is still appropriate.

Impact: The organisation inherits both operational inefficiency and avoidable security risk. Access redesign reduces that risk by making the secure path the easiest path, which is often more effective than layering additional controls on top of a broken user journey.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-01 — Identity Management, Authentication, and Access Control Access redesign here centers on how users get and use access.
Recommendation — Redesign identity and access flows so the easiest path is the approved one.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Clinical users must authenticate cleanly before they can use deployed systems.
Recommendation — Simplify organizational user authentication without weakening assurance.
ISO/IEC 27001:2022 A.5.15 — Access control The question is about redesigning how access is granted and managed.
Recommendation — Review and restructure access control rules around actual workflow needs.
CIS Controls v8 CIS-5 — Account Management Access friction often reflects poor account lifecycle and role management.
Recommendation — Tighten account management so users get the right access at the right time.

Practitioner Guidance

What to prioritise: Start with the access path that blocks routine work most often, not the feature gap that is easiest to budget for. If the same task repeatedly requires overrides, manual approvals, or repeated sign-ins, that is a redesign problem before it is a capability problem.

What to verify: Confirm whether the issue sits in identity proofing, role design, permission scope, session timeouts, or device and network constraints. If the workflow fails only after authentication succeeds, the remedy is usually authorization and journey design rather than more functionality.

Decision rule: If current systems already cover the clinical task, but users cannot access them smoothly enough to work at pace, redesign access first. If the workflow truly lacks a needed clinical function, then capability expansion remains the right investment.

Practitioner takeaway: Improve the path to existing capability before adding more capability to a path people already avoid. Usability, adoption, and control quality usually improve together when access is redesigned around real work.