By NHI Mgmt Group Editorial TeamBased on 1Password: “How to lead with confidence in the AI era: a conversation with Nancy Wang, VP, Engineering” (August 21, 2025)

TL;DR: AI should absorb repetitive work while human judgment, empathy, and trust-building stay central to decisions that affect people and culture, according to 1Password. The real governance issue is not AI capability, but where organisations draw the line between augmentation and authority.


At a glance

What this is: This is 1Password's view on using AI to remove toil while keeping people-led judgment in decisions that affect teams, trust, and culture.

Why it matters: For IAM practitioners, it reinforces that AI should support identity operations and decision-making, but not replace human accountability in sensitive governance calls.


Context

This article is about the boundary between AI augmentation and human authority. In identity programmes, that boundary matters because the wrong tasks can be automated without changing the governance model, while the wrong decisions cannot.

1Password argues that AI can handle repetitive work such as summarising notes, drafting documents, and surfacing patterns. The harder governance question is which decisions should remain human because they shape trust, team dynamics, or culture.

For IAM, PAM, and identity governance teams, this is less about AI tooling and more about decision rights. The article is best read as a leadership view on where human judgment remains the control point in an AI-assisted operating model.


Key questions

Q: How should IAM teams balance AI-assisted approvals with accountability?

A: IAM teams should use AI agents as a first-pass decision aid, not as an accountability substitute. Policy owners still need final authority over exceptions, high-risk entitlements, and unclear cases. Every recommendation should carry an explanation and audit trail so the decision can be reviewed, challenged, and improved over time.

Q: Why do judgment and empathy matter in AI-enabled identity governance?

A: Judgment and empathy matter because identity decisions often involve ambiguity, exceptions, and business context that policy rules cannot fully capture. AI can accelerate the workflow, but it cannot interpret intent, weigh competing human impacts, or preserve trust when the decision is consequential. That makes human review part of the control model, not a courtesy.

Q: What are the signs that an AI application has too much authority?

A: A common sign is that a single model response can write to databases, send messages, start workflows, or spend resources without a separate check. Another indicator is when the same identity can reach multiple systems even though the task only needs one narrow permission set.

Q: What is the difference between AI augmentation and delegated authority in identity programmes?

A: AI augmentation speeds up work while leaving the final judgement and accountability with people. Delegated authority means the system can decide and act without a human interpreting each outcome. In identity governance, that difference determines whether AI is a productivity tool or part of the control plane.


Technical breakdown

Where AI belongs in the identity operating model

AI is most defensible when it helps teams compress mechanical work, such as summarising information, drafting first passes, or surfacing patterns across large sets of material. In an identity programme, that maps to support functions around review preparation, documentation, and signal triage, not final authority. The important distinction is between assistance and autonomy. A system that accelerates analysis still leaves decision ownership with people, which is very different from a system that decides, acts, and closes the loop on its own.

Practical implication: use AI to reduce toil in identity operations, but keep approval and accountability with human owners.

Why trust, empathy and judgment remain identity controls

The article treats trust, empathy, and judgment as leadership skills that cannot be outsourced. In governance terms, those are the capabilities that let teams interpret ambiguous situations, handle exceptions, and make decisions that affect people fairly. Identity programmes routinely encounter edge cases in access, role changes, and collaboration patterns where policy alone is not enough. Human judgment is what resolves those cases without over-automating the relationship between access and authority.

Practical implication: preserve human review where identity decisions have people impact, especially for exceptions and sensitive access changes.

How AI changes leadership without replacing it

AI changes the speed and surface area of leadership work, but not the underlying responsibility to set direction, create clarity, and build confidence. The article points to a leadership style that is honest about uncertainty, encourages experimentation, and normalises learning in public. That is relevant to identity teams because AI adoption often fails when leaders treat novelty as certainty or hide unresolved risk. The technical stack may change, but the governance expectation does not: humans still own the outcome.

Practical implication: build AI adoption norms that allow experimentation without surrendering human accountability.


NHI Mgmt Group analysis

Human judgment remains the control point in AI-assisted identity governance: AI can compress repetitive work, but it does not own the consequences of access decisions. In IAM terms, the programme still needs a named human owner for ambiguity, exceptions, and value-laden decisions. The practitioner lesson is to automate tasks, not authority.

This article exposes a governance boundary, not a tooling debate: The meaningful question is where organisations draw the line between augmentation and delegated authority. That line matters across human identity, NHI, and autonomous systems because the control model changes once a system can act without a human to interpret the outcome. Identity leaders should define that boundary before AI becomes embedded in routine workflows.

Trust is an operational requirement, not a soft skill: The article correctly treats trust-building as part of leadership, because distributed teams and AI-assisted workflows both increase the cost of uncertainty. When trust erodes, review quality, escalation paths, and exception handling all become weaker. Practitioners should treat trust as part of governance design, not just culture.

Inclusive AI governance improves the quality of identity decisions: Bringing different disciplines and lived experiences into AI design makes the resulting systems more resilient and easier to govern. That matters in identity security because poor assumptions about users, workflows, and edge cases are a common source of access friction and control failure. The practical outcome is better decision-making, not just better optics.

Leadership in AI-enabled organisations now includes deciding what must stay human: The article's strongest point is that capability and control are not the same thing. Teams that blur that distinction will eventually delegate decisions that depend on context, judgement, or empathy. IAM and security leaders should preserve human authority where the decision changes relationships, not just records.

What this signals

Leadership teams need explicit boundaries for AI-assisted identity work: The programme risk is not that AI is present, but that teams let it drift from support into authority without a decision framework. That boundary should be written into access governance, review workflows, and escalation paths before the operating model hardens.

Human control stays relevant even as automation expands: Identity leaders should expect AI to absorb documentation and analysis work, but they should not expect it to replace the judgment required for exceptions, trust-sensitive calls, or people-impacting decisions. That separation is the difference between efficiency and governance drift.


For practitioners

  • Define the human decision boundary Map which identity, access, and governance decisions may be AI-assisted and which must remain human-owned because they affect people, teams, or culture.
  • Use AI to reduce review toil Apply AI to summarising evidence, drafting notes, and surfacing patterns so reviewers spend more time on exceptions and higher-risk cases.
  • Keep escalation paths explicit Document when a human must override AI-generated output, and make that handoff clear in access review and approval workflows.
  • Run low-stakes experiments Create controlled spaces for teams to test AI use cases, share imperfect outputs, and learn without turning early experiments into production governance decisions.

Key takeaways

  • AI is best used to remove repetitive work from identity and security teams, not to replace the human judgment behind sensitive decisions.
  • The article frames empathy, trust-building, and judgment as governance capabilities, not soft extras, because they shape how teams handle ambiguity and exceptions.
  • Identity leaders should define which decisions can be assisted by AI and which must stay human-owned before AI becomes embedded in routine workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about who retains authority when AI is used in leadership and operational work.
Recommendation — Establish governance that keeps accountability with humans when AI supports decisions and workflows.
NIST CSF 2.0GV.RR-01 — Roles, Responsibilities, and AuthoritiesThe post centres on defining which decisions stay human and how responsibility is assigned.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe identity angle is about preserving human control over consequential access decisions.
Recommendation — Assign clear decision rights for AI-assisted identity work and keep human ownership explicit. Review access decisions so AI can assist preparation without becoming the approval authority.
ISO/IEC 42001:20234.1 — Understanding the organisation and its contextThe article frames AI adoption as an organisational leadership and context-setting issue.
Recommendation — Define the organisational context for AI use before embedding it into identity workflows.

Key terms

  • Tool Augmentation: Tool augmentation is the practice of giving an AI system explicit access to external tools such as SIEMs, identity platforms, threat intelligence feeds, or endpoint APIs. The model outputs structured calls rather than free text, allowing it to gather evidence and execute bounded tasks under policy control.
  • Delegation authority: Delegation authority is the right for one identity to act on behalf of another within a defined scope. For agents, it must be explicit, time-bound, and auditable because the system may initiate actions independently once granted access.
  • Decision boundary: The point in a workflow where a machine may inform a decision but may not make it final. In security operations, this boundary is critical because it preserves accountability, auditability, and human challenge rights when AI output is uncertain or incomplete.
  • Trust Building: Trust building is the process of earning credibility through consistency, directness, listening, and follow through. In security leadership, trust makes it easier to influence other teams, discuss risk honestly, and secure cooperation when policies or controls require changes in behaviour.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org