Subscribe to the Non-Human & AI Identity Journal

Why do IGA programmes look mature but still leave major gaps?

Because maturity models often score capabilities inside the platform rather than the applications the platform can actually reach. A team may have workflows, roles, and certifications while still governing only a narrow slice of the environment. The gap appears when integration coverage is low and manual processing fills the rest.

Why This Matters for Security Teams

IGA programmes often look mature because they score well on workflow design, certifications, and role catalogues, yet those controls can still cover only a fraction of the identities and systems that matter. The real risk is not whether the platform has features, but whether it can govern the applications, service accounts, API keys, and privileged access paths that create exposure. NHI Mgmt Group has shown how often organisations lack full visibility into their non-human estate in the Ultimate Guide to NHIs, which is a useful warning sign for any identity programme.

This gap matters because maturity models can reward internal process completeness while ignoring integration coverage and enforcement outside the tool. A programme can have strong approvals and quarterly reviews, yet still leave manual exceptions, unmanaged apps, and orphaned entitlements outside policy. That creates a false sense of control, especially in environments where the identity surface is larger than the IAM team expects. The NIST Cybersecurity Framework 2.0 is useful here because it pushes organisations to measure outcomes, not just capability presence. In practice, many security teams discover the gap only after an audit exception, a breach, or a painful app onboarding review has already exposed the blind spot.

How It Works in Practice

A mature-looking IGA programme usually has three visible layers: access request workflows, certification campaigns, and role governance. The hidden question is whether those controls connect to the actual systems where access is granted and removed. If integration is shallow, the platform becomes a reporting layer over a partially governed estate rather than a real enforcement point. That is why the best programmes start by mapping coverage, not just cataloguing features. The Ultimate Guide to NHIs highlights how quickly identity risk grows when visibility is incomplete and credentials live outside managed controls.

In practice, teams should test maturity against the full lifecycle:

  • Which applications support automated provisioning and deprovisioning?
  • Which systems still depend on manual tickets, spreadsheets, or email approvals?
  • Which entitlements are reviewed on paper but never actually revoked?
  • Which identities sit outside the IGA boundary, including NHIs, shared accounts, and emergency access?

This is where NIST Cybersecurity Framework 2.0 helps operationally, because it encourages organisations to measure protect and respond capabilities against real assets and real business processes. A programme is materially stronger when it can show reach across critical applications, measurable deprovisioning outcomes, and exception handling that is time-bound rather than indefinite. These controls tend to break down in large, federated, or legacy-heavy environments because ownership is split across business units and the identity platform cannot enforce policy end to end.

Common Variations and Edge Cases

Tighter IGA coverage often increases integration and governance overhead, requiring organisations to balance control depth against platform sprawl and delivery speed. That tradeoff becomes sharper when merger activity, SaaS adoption, or developer-managed infrastructure expands the identity surface faster than the IGA roadmap.

Current guidance suggests the biggest maturity illusion appears when programmes optimise for standard employee access while leaving contractors, privileged users, and NHIs under-governed. This is especially true where the identity model was built for human joiner-mover-leaver processes and only later extended to service identities. NHIMG data shows how severe that blind spot can be, with only a small share of organisations reporting full visibility into service accounts in the Ultimate Guide to NHIs.

There is no universal standard for “mature” IGA coverage yet, so teams should judge whether the programme measures enforcement, not just administration. If a dashboard looks strong but the organisation still relies on manual approvals, spreadsheet reconciliations, or partial connectors for key systems, the maturity score is overstated. The practical test is simple: can the programme revoke access everywhere it claims to govern, and can it prove that revocation happened?

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 IGA maturity should reflect real coverage of assets and business context.
OWASP Non-Human Identity Top 10 NHI-01 Unmanaged service accounts and API keys often sit outside mature-looking IGA.
OWASP Agentic AI Top 10 A01 Autonomous workloads expose why identity controls must work beyond human-centric IGA models.
CSA MAESTRO IAM-2 Agentic and workload identities need lifecycle governance across dynamic tool access.

Use runtime identity and policy controls for autonomous workloads instead of assuming fixed human-style access patterns.