Join our Newsletter — 33% off our NHI Course

OKR

An OKR is a goal-setting framework that pairs a desired objective with measurable key results. In identity governance, it is best used for change programmes where the team needs to move a process, behaviour, or control outcome over a defined cycle.

What OKRs Are For in Identity Governance

OKRs are a planning and measurement system, not a control framework. In identity governance, they are most useful when a team is trying to change how consistently a process runs, how quickly a control improves, or how widely a new operating model is adopted.

The value of OKRs is that they force a clear distinction between the outcome you want and the indicators that prove progress. That makes them well suited to change programmes, but less suited to steady-state control design where success is measured by whether a requirement is met every time.

How OKRs Differ from Policies, Controls, and Metrics

An objective states the intended change in plain language, while key results define measurable signals that show whether the change is happening. In security work, that can mean moving from ambiguous improvement goals to concrete, time-bound outcomes.

This differs from policy, which sets the rule, and from a control, which enforces or evidences the rule. It also differs from an operational metric, which may describe performance but not necessarily express the target state the team is trying to reach. The framework becomes most useful when those distinctions are kept clean.

Where OKRs Fit in Identity Governance Work

OKRs fit best at the programme level, where a team is coordinating multiple workstreams such as entitlement cleanup, access review quality, role design, or approval process redesign. They help leadership and practitioners align on what meaningful progress looks like over a quarter or other defined cycle.

Used well, an OKR can connect business change to identity governance outcomes, for example reducing manual exceptions, increasing review completion quality, or shortening the time it takes to remove access after a role change. The structure is especially helpful when the work spans people, process, and tooling.

They are less useful when the goal is to express a permanent requirement. A mature access control should not need OKRs to explain that it exists; it needs operational ownership, consistent enforcement, and evidence of execution.

Common Misuses and Practical Boundaries

OKRs are often misused when teams write activity goals instead of outcome goals, or when they confuse ambition with measurement. A statement like “complete more access reviews” is weaker than a result that shows the governance process is actually improving in quality or timeliness.

They also fail when they are used to manage every control equally. Some security and governance measures need stable, repeatable execution rather than quarterly experimentation, so OKRs should sit above the control layer instead of replacing it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.PO-01 — Policy OKRs support governance planning by turning change goals into measurable outcomes.
GV.OC-01 — Organizational Context OKRs are used to align change goals with the organisation's operating context.
GV.RM-01 — Risk Management Strategy OKRs are often set to drive planned risk reduction over a defined cycle.
Recommendation — Use OKRs to define measurable governance outcomes for the identity programme. Align OKRs with the identity governance context and business priorities. Set OKRs that track progress against the agreed identity risk strategy.
ISO/IEC 27001:2022 A.5.4 — Management responsibilities OKRs can clarify ownership for security governance improvement work.
A.5.36 — Compliance with policies, rules and standards for information security OKRs can measure whether policy-driven governance improvements are taking hold.
Recommendation — Assign OKRs to accountable owners for each identity governance improvement. Use OKRs to measure adoption of policy-aligned identity governance changes.

Practitioner Guidance

Governance implication: Use OKRs to manage change where the target is a better state, not to redefine the control itself. The objective should describe the business or risk outcome, while the key results should show whether the governance process is becoming more effective, more reliable, or more scalable.

Practitioner note: If a proposed OKR cannot be measured without vague language, it is probably tracking activity rather than progress. In identity governance, the best OKRs usually connect process change to an observable control outcome.