By NHI Mgmt Group Editorial TeamBased on C1.ai: “From Manual to Intelligent: Using AI to Mature Your IGA Program” (September 12, 2025)

TL;DR: C1.ai argues that as organisations add more applications, distributed teams and non-human identities, manual reviews, static policies and human-driven approvals no longer scale, especially as AI identities are expected to outnumber human users 25:1. Governance is shifting from review-heavy administration to policy-driven, AI-assisted decisioning because the bottleneck is now the control model itself.


At a glance

What this is: This blog says IGA programmes need AI-assisted governance because manual reviews and static approval models cannot keep pace with growing numbers of applications, distributed users, and non-human identities.

Why it matters: It matters because identity teams have to govern human, NHI, and autonomous access at a scale that makes manual certification and approval workflows increasingly ineffective.

👉 Read C1.ai's analysis of AI maturity in IGA and manual review limits


Context

As organisations add more applications, distributed teams, and non-human identities, traditional identity governance starts to break under volume and inconsistency. Manual reviews assume humans can inspect each request, certification, and exception at a pace that matches growth, but that assumption no longer holds in modern environments.

The core governance issue is not only throughput. It is whether identity programmes can make consistent decisions across service accounts, AI agents, and employee access without turning reviews into bottlenecks that delay access, reduce audit quality, and miss risk signals.

This article frames AI as a governance accelerant inside IGA, not as a replacement for identity controls. The practical question for teams is how to use automation to keep policy enforcement defensible as identity estates grow faster than review capacity.


Key questions

Q: How should security teams use AI in identity governance without weakening controls?

A: Use AI as a triage and interface layer, not as a control replacement. Keep policy enforcement, approval authority, and audit logging in the underlying IGA process. If a model can surface issues faster but cannot explain, version, or constrain the resulting decision path, it is helping operations, not governing identity.

Q: What breaks when manual access reviews are used for growing NHI estates?

A: Manual reviews break when the number and pace of access decisions exceed what humans can inspect consistently. Service accounts and AI agents can outgrow employee-style certification cycles, leaving governance reliant on stale context, delayed decisions, and uneven reviewer judgment. The result is weaker control, not simply slower administration.

Q: How do you know if AI-assisted IGA is actually improving governance?

A: Look for fewer inconsistent outcomes on similar requests, clearer exception handling, and stronger auditability of why a request was approved or denied. If AI only shortens queue times but does not improve decision quality or policy consistency, the programme has automated workload without improving governance.

Q: Why do service accounts and AI agents need different controls from human users?

A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.


Technical breakdown

Why manual IGA reviews stop scaling

Manual governance works when the number of access decisions is low enough for humans to review each one with context. That model weakens as applications, entitlements, and identities multiply, because reviewers are forced to approve based on incomplete information and uneven judgment. In practice, the control becomes a queue management problem rather than an access-control problem. When the review surface expands across employees, service accounts, and AI agents, static certification cycles cannot keep pace with change, and the governance result is delay, inconsistency, and blind spots.

Practical implication: treat manual review as a limited-control backstop, not the primary governance layer for a growing identity estate.

How AI changes access request and certification workflows

AI-assisted governance changes the workflow by enriching requests with context, applying policy consistently, and recommending outcomes based on entitlement, risk, and historical patterns. In the article, that includes using signals such as requestor context, entitlement risk, login behaviour, and approver availability to inform a decision. The important architectural shift is that AI is not just speeding up existing review steps. It is moving the decision point closer to the policy itself, so governance can be more deterministic and less dependent on human memory or availability.

Practical implication: design AI-assisted workflows so the policy decision remains auditable, explainable, and tied to explicit entitlement criteria.

Why non-human identities force a different governance model

Non-human identities change IGA because they expand the population that must be governed without adding human-style review capacity. Service accounts and AI agents do not fit neatly into workflows built around employee managers and periodic certification. Their access is often more dynamic, more frequent, and more operationally embedded than human access. That means the real governance problem is lifecycle and policy enforcement across identity types, not simply automating approvals for the existing process. A programme that only scales human review does not solve NHI governance.

Practical implication: extend governance rules to service accounts and AI agents explicitly, rather than inheriting human review patterns by default.


NHI Mgmt Group analysis

Manual review is becoming a governance bottleneck, not a governance strategy. Review-based IGA assumes people can inspect enough context, fast enough, to keep pace with identity growth. That assumption fails when applications, entitlements, and non-human identities expand faster than human approvers can reason about them. The implication is that governance must move closer to policy enforcement and decision automation.

AI-assisted IGA is shifting the control point from people to policy. When requests are enriched with entitlement context, behavioural signals, and risk indicators, the programme stops relying on memory and guesswork. That matters because consistency is a control property, not a convenience feature. Practitioners should treat decision quality as the primary outcome, not just cycle-time reduction.

Non-human identity growth exposes the limits of human-centric certification models. Service accounts and AI agents are not exceptional edge cases anymore; they are part of the mainstream identity estate. Access review cadences designed for employees do not naturally map to identities that act continuously or outside normal business hours. The governance implication is that NHI and human identity controls now need shared policy logic but different operational handling.

Identity blast radius: the more identities and entitlements an organisation owns, the more governance must reduce decision variance across every access grant. This article shows that blast radius is now a governance issue as much as an access issue. When review quality varies by approver, team, or workload, the organisation creates its own inconsistency at scale. Practitioners should focus on narrowing decision variance before they focus on adding more review volume.

AI in IGA is not the end-state; it is the acknowledgement that manual governance has hit its economic ceiling. The real signal is that identity teams cannot staff their way out of growth in applications, users, and machine identities. That reality pushes programmes toward policy-centric automation, with human judgment reserved for exceptions. The practical conclusion is that governance maturity now depends on where humans remain in the loop, not on how often they are asked to click approve.

From our research library:

What this signals

Identity blast radius: governance teams now have to reduce decision variance across humans, service accounts, and AI agents, because scale exposes inconsistency faster than manual review can correct it.

The operational shift is away from people as the primary control and toward policy as the primary control, with human reviewers reserved for exceptions and high-risk edge cases. That is a maturity change, not just an automation change.


For practitioners

  • Define which access decisions can be policy-driven Separate routine approvals from exception cases so AI-assisted workflows only automate decisions that are already governed by clear entitlement rules.
  • Enrich review workflows with contextual signals Feed requestor context, entitlement sensitivity, login anomalies, and approver status into certification and request decisions so reviewers see risk before they approve.
  • Extend governance to non-human identities Create explicit review and approval paths for service accounts and AI agents instead of forcing them through employee-centric certification cadences.
  • Measure decision consistency, not just cycle time Track how often similar requests receive different outcomes across approvers, teams, or business units to identify where governance is still subjective.

Key takeaways

  • Manual reviews are no longer a reliable primary control when identity estates expand across people, machine accounts, and AI-driven access paths.
  • The article’s own logic points to scale pressure as the real problem, with AI identities expected to reach a 25:1 ratio against human users.
  • Practitioners should measure whether AI-assisted governance improves decision consistency and exception handling, not just workflow speed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on governing access scope for service accounts and AI agents at scale.
NHI-10 — Human Use of NHIThe post discusses human reviewers and approvals governing machine identities through IGA workflows.
Recommendation — Apply NHI-05 to constrain machine and AI access to the minimum entitlement needed for each workflow. Separate human approval duties from NHI execution rights so machine access is not governed as if it were employee access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about scaling entitlement governance and access review quality.
Recommendation — Use PR.AA-05 to standardise entitlement decisions and reduce variance across approvals and certifications.
CIS Controls v8CIS-5 — Account ManagementThe article addresses lifecycle control over accounts, approvals, and review processes.
Recommendation — Apply CIS-5 to keep account governance current as identities, workflows, and approval paths expand.
NIST AI RMFGOVERN — AI Governance and AccountabilityAI is being used to make governance decisions, so accountability and oversight are central.
Recommendation — Use GOVERN to assign accountability for AI-assisted access decisions and review outcomes.

Key terms

  • AI-Driven Identity Governance: AI-driven identity governance uses machine analysis to process large volumes of identity data, identify anomalies, and prioritize risky access for human review. It does not replace governance owners. It helps them act on the data they already have by adding pattern recognition, contextual scoring, and decision support at scale.
  • Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
  • Decision Consistency: The extent to which similar cases receive similar outcomes when reviewed by managers, approvers, or governance teams. In identity operations, consistency is a control property because it affects approvals, exceptions, certifications, and the reliability of access decisions.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

What's in the full article

C1.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • Thomas request-enrichment logic for access approvals and review tasks
  • Copilot workflow examples for bulk certifications, policy building, and helpdesk intake
  • Context signals used in governance decisions, including login activity and approver availability
  • Operational distinctions between automated recommendations, routed approvals, and escalations

👉 The full C1.ai post covers Thomas, Copilot, and the governance workflows they change.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org