By NHI Mgmt Group Editorial TeamBased on SecurEnds: “The Future of Identity Governance: AI and Automation in IGA” (October 30, 2025)

TL;DR: Manual access reviews, spreadsheet-driven approvals, and delayed joiner-mover-leaver updates no longer scale across hybrid estates, and the article argues that AI and automation can reduce review cycles, surface anomalies, and keep governance closer to real time, according to SecurEnds. The deeper issue is that governance models built for quarterly checkpoints now collide with continuously changing identities and entitlements, so the control assumption itself is outdated.


At a glance

What this is: This article argues that AI-assisted identity governance is becoming necessary because manual IGA processes cannot keep up with hybrid estates, frequent access changes, and audit-driven review cycles.

Why it matters: IAM and IGA teams need to rethink governance cadence, review workflows, and entitlement cleanup when access changes faster than manual certification can verify it.


Context

Identity governance is the set of controls that decide who should have access, when that access changes, and how teams prove it stayed appropriate. In hybrid enterprises, those decisions are increasingly made against incomplete, stale, or scattered data, which makes manual certification cycles slow and unreliable.

The article’s core problem is not that governance disappeared, but that the operating model was built for slower environments. When entitlements change continuously across cloud, legacy, and temporary-user populations, quarterly reviews become a lagging control rather than a reliable check on access state.


Key questions

Q: What breaks when governance relies only on quarterly access reviews?

A: Quarterly reviews miss the day-to-day drift that accumulates between certification cycles. By the time the review happens, the access graph may already have changed, so the programme validates yesterday’s state rather than today’s risk. That makes certification useful for assurance, but weak as a primary control.

Q: How do organisations know whether AI-driven IGA is actually improving control?

A: They should measure whether access changes are converging faster, whether exceptions are shrinking, and whether review queues are limited to truly risky cases. If the system is only speeding up paperwork without reducing stale access, it is automating administration, not governance.

Q: What do organisations get wrong about automating identity governance?

A: They often automate the workflow without hardening the policy. That scales inconsistency, because the system will grant or certify access according to whatever rules exist, even if those rules are incomplete or too permissive. The real work is policy design, not simply workflow acceleration.

Q: How should security teams implement IGA for IT operations in a way that reduces manual work without losing control?

A: Start with the highest-volume access workflows, then standardise request forms, approval routing, and lifecycle events for joiners, movers, and leavers. Keep business owners in the approval chain, automate reminders, and track remediation to closure. The goal is to reduce tickets while preserving evidence for every access decision, removal, and exception.


Technical breakdown

Why manual access reviews stop scaling

Manual certification depends on people reviewing lists that are already stale by the time they are approved. In large estates, that means managers rubber-stamp safe-looking access, while risky entitlements stay buried in a growing queue. The technical failure is not only volume. It is the mismatch between review cadence and entitlement volatility. Once access is changing daily across SaaS, cloud, and legacy systems, the review process becomes a snapshot of a moving target, not a current control state.

Practical implication: shorten the distance between entitlement change and review evidence, or the certification program becomes bookkeeping instead of governance.

How AI changes entitlement decisioning

AI in IGA is being used to score risk, identify unusual combinations of access, and separate routine approvals from exceptions. That changes the control from human-per-every-request to policy-plus-model evaluation, where low-risk patterns can be handled automatically and suspicious ones escalate for review. The important technical shift is that the system is learning from prior decisions and access patterns, not applying a fixed role rule alone. That makes the control adaptive, but also dependent on data quality and model tuning.

Practical implication: validate the quality of identity and entitlement data before trusting AI-driven recommendations in production.

Continuous governance versus quarterly certification

Continuous governance is not just faster certification. It is a different operating assumption, where provisioning, review, and revocation are tied to live identity signals rather than audit calendars. In the article’s model, automation closes the delay between HR changes, role changes, and access updates, while AI helps prioritise what deserves human attention. That is materially different from a quarterly access review campaign, because the control is no longer waiting for the next scheduled checkpoint to detect drift.

Practical implication: move high-churn access paths to continuous enforcement and reserve periodic reviews for exceptions, not the whole estate.


NHI Mgmt Group analysis

Quarterly governance is the wrong unit of control for hybrid identity estates. The article describes an access environment where users, vendors, bots, and temporary accounts change faster than review cycles can close. That is not a tooling problem alone, it is a governance timing problem. Identity governance now has to operate against live entitlement drift, not a static attestation calendar.

AI-driven identity governance exposes the limits of review-centric IGA. Traditional programs assume the review is the control, but in this operating model the review is already late. The control has to shift toward issuance, change detection, and automated cleanup, because waiting for managers to certify stale data creates the very risk the review is supposed to prevent.

Governance latency is the new entitlement risk surface. Excess permissions, orphan accounts, and delayed deprovisioning grow in the gap between business change and identity change. That gap is where manual IGA breaks down first, and it is where continuous automation earns its value. Practitioners should measure control effectiveness by how quickly access state converges, not by how many campaigns were completed.

Identity governance needs a new operating concept: control at the speed of change. The article’s strongest implication is that enterprise access cannot be governed as a quarterly administrative exercise anymore. That applies across human users, temporary workers, and machine-like operational identities that move through the same entitlement estate. The discipline now is continuous governance with exception handling, not periodic cleanup.

Autonomous identity governance widens the question from efficiency to accountability. If systems begin to make routine access decisions automatically, practitioners must treat decision provenance, policy boundaries, and exception ownership as first-class governance requirements. The practical conclusion is that automation only scales when accountability still scales with it.

From our research library:

What this signals

Governance latency is now an access risk, not just an operations issue. When entitlement state changes faster than certification cycles, the control is effectively blind between checkpoints. IAM teams need to treat time-to-convergence as a governance metric, not an implementation detail.

Continuous identity governance is becoming the practical baseline for hybrid estates. The real question is no longer whether automation belongs in IGA, but whether the programme can still prove control without it. That shifts priority toward lifecycle-linked revocation, risk-based review, and exception handling.

AI-assisted IGA changes the governance conversation from volume to judgement. Human reviewers should spend less time approving obvious access and more time resolving edge cases, policy conflicts, and outlier entitlements. That is where automation supports, rather than replaces, control.


For practitioners

  • Define the access state you will govern continuously Identify which applications, roles, and user populations change too quickly for quarterly review to remain credible. Prioritise the high-churn entitlements first so automation is applied where governance lag is greatest.
  • Replace spreadsheet certifications with risk-prioritised reviews Use automated scoring to push routine approvals through and surface only exceptions that need human judgment. That reduces review fatigue and keeps reviewers focused on genuinely risky access.
  • Automate deprovisioning for stale and temporary access Tie joiner-mover-leaver events to entitlement removal so departing users, contractors, and short-term project accounts do not linger with unused access after role changes or offboarding.
  • Measure governance by convergence time Track how long it takes for access changes, removals, and exceptions to appear in the governed state after the business event occurs. If the lag is still measured in weeks, manual control remains the bottleneck.

Key takeaways

  • Manual IGA breaks down when review cycles lag behind identity and entitlement change across hybrid estates.
  • AI and automation shift governance from campaign-based administration toward continuous exception handling and faster access convergence.
  • Practitioners should measure success by how quickly stale access is removed, not by how many review rounds were completed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on entitlement governance and review cycles across hybrid estates.
Recommendation — Apply PR.AA-05 to continuously validate entitlements and remove access that no longer matches role need.
CIS Controls v8CIS-5 — Account ManagementThe article centers on lifecycle-driven provisioning, deprovisioning, and stale account cleanup.
Recommendation — Use CIS-5 to govern account provisioning, revocation, and recertification across connected systems.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeExcess permissions and delayed cleanup are the main control failure described in the article.
IA-5 — Authenticator ManagementAutomated governance depends on timely credential and access lifecycle control.
Recommendation — Enforce AC-6 to reduce standing access and constrain permissions to current business need. Apply IA-5 to manage credential lifecycle changes alongside entitlement revocation.
ISO/IEC 27001:2022A.5.15 — Access controlThe article is about governance of access decisions and their operational enforcement.
Recommendation — Implement A.5.15 to make access approval, review, and removal consistent across the identity estate.

Key terms

  • Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Joiner Mover Leaver: Joiner Mover Leaver is the identity lifecycle process for creating, changing, and removing access as people enter, change roles, or leave an organization. It governs provisioning, modification, and deprovisioning across systems, ensuring access matches current job needs and reducing orphaned accounts, privilege creep, and residual access risk.
  • Continuous governance: An identity governance model that checks and enforces policy as activity happens rather than on a schedule. It is designed to catch drift, misuse, and orphaned access while the identity is still active, which matters when risk unfolds in minutes instead of review cycles.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org