TL;DR: Cloud management platforms centralize orchestration, cost, monitoring, and security controls across hybrid environments, but the source article shows that identity, governance, and compliance remain only one part of the stack according to Zluri. The practical issue is that cloud control planes can simplify operations without solving who or what should hold access, how that access is reviewed, or when it should be revoked.
At a glance
What this is: This is a Zluri overview of cloud management platforms that concludes they improve cloud operations but still leave identity governance, compliance, and access control uneven across environments.
Why it matters: IAM and IGA teams should treat cloud management platforms as operational control planes, not substitutes for lifecycle governance over human, NHI, or workload access.
Context
Cloud management platforms are designed to unify monitoring, orchestration, cost controls, and security across public, private, and hybrid environments. In practice, that makes them useful for managing cloud sprawl, but not sufficient for deciding who should have access, how that access is governed, or when it should end.
The identity gap matters because cloud operations and identity governance are often treated as adjacent problems when they are tightly linked. A platform can centralize infrastructure workflows while still leaving role assignment, certification, offboarding, and compliance evidence scattered across separate tools and teams.
Key questions
Q: What breaks when cloud identities are not centrally governed?
A: Shadow accounts, orphaned credentials and inconsistent role definitions emerge because no single process can see the whole access picture. That breaks least privilege, complicates incident response and makes compliance evidence harder to prove, especially when workforce and service identities are managed separately.
Q: Why do cloud management platforms still leave access risk in place?
A: Because automation changes how quickly access is created, but not who is accountable for it. If provisioning is fast and revocation is slow, stale entitlements accumulate across clouds, service accounts, and application roles. The risk is highest when teams rely on platform policy checks without a separate governance workflow to confirm whether access still has a valid purpose.
Q: How can security teams know if cloud identity governance is actually working?
A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review. If teams still spend days reconstructing access state, governance is not operating continuously. Effective programmes can show current MFA coverage, role scope, and credential age on demand.
Q: How should organisations divide responsibility between CMPs and IGA?
A: CMPs should handle operational orchestration and evidence collection, while IGA should own identity policy, access certification, and lifecycle decisions. That split avoids overloading the cloud platform with governance responsibilities it was not designed to carry. It also keeps human, NHI, and workload access under one governance model even when the cloud estate is distributed.
Technical breakdown
Why cloud management platforms stop short of identity governance
Cloud management platforms aggregate operational control across cloud resources, but they are not designed to own identity lifecycle decisions. They typically expose RBAC, policy checks, audit logs, and provisioning workflows, yet those controls sit at the platform layer, not the governance layer. That distinction matters because access can be granted through a cloud control plane without a corresponding view of entitlement purpose, review cadence, or offboarding trigger. The result is governance by surface area rather than by lifecycle, especially when multiple clouds and business units are involved.
Practical implication: Treat CMP access controls as enforcement points, and keep lifecycle ownership in IAM and IGA.
Why cloud orchestration does not solve entitlement sprawl
Orchestration speeds up deployment, but it can also multiply access paths if entitlements are not normalized across clouds, applications, and service accounts. The more a platform automates provisioning, the more important it becomes to know which identities were created, which permissions they inherited, and which ones are still active after the work is done. In identity terms, speed without governance widens the gap between provisioning and revocation. That is especially relevant in hybrid environments where a single operational request can touch several control planes and several identity stores.
Practical implication: Map automated provisioning flows to entitlement owners and revoke stale access on a defined lifecycle trigger.
Where security and compliance features still leave gaps
Many cloud management platforms advertise security and compliance features such as access control, logging, encryption, and reporting. Those capabilities help evidence activity, but evidence is not the same as governance. Logging tells you what happened; it does not guarantee the right identity was granted the right privilege for the right duration. Compliance reporting can also become fragmented when policy checks are embedded in one platform while recertification, exception handling, and audit response live elsewhere. That split is where governance debt accumulates.
Practical implication: Use platform logs as audit inputs, not as a substitute for access reviews or policy ownership.
NHI Mgmt Group analysis
Cloud management platforms create a control plane, not an identity authority. The article shows how these platforms concentrate monitoring, orchestration, and security operations, but that concentration should not be mistaken for governance maturity. Identity decisions still need a separate source of truth for ownership, review, and revocation. The practitioner lesson is to distinguish operational centralization from access governance.
Identity governance is still the missing integration point in cloud operations. CMPs can expose RBAC, logging, and compliance checks, yet the article implicitly shows that those features remain fragmented across the broader stack. That fragmentation matters because governance depends on consistent entitlement policy across cloud, application, and workload identities. The implication is that cloud control planes must be evaluated for how they connect to IGA processes, not just how many resources they manage.
Lifecycle control matters more than platform breadth. The article’s feature list spans provisioning, cost, security, and user experience, which is exactly why access governance gets diluted inside platform comparisons. Broad functionality can hide the fact that access still needs joiner-mover-leaver discipline, certification, and offboarding outside the CMP. Practitioners should judge cloud platforms by how cleanly they hand identity events into governance workflows.
Cloud governance and identity governance are converging, but they are not the same discipline. The CMP category is moving toward broader operational consolidation, yet access ownership, privilege scope, and compliance evidence still require identity-native controls. That is true for human users, but it also matters for service accounts and workload identities created by cloud automation. The practical conclusion is to govern the identities behind the cloud before assuming the cloud platform has already done it.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: Access Reviews and Certification Guide
What this signals
Cloud management platforms are becoming the control surface, but not the governance source of truth. The practical risk is that teams may confuse orchestration with authority and assume a centralized dashboard equals centralized entitlement control. In identity programmes, that usually means access is easier to provision than to justify, certify, or retire.
Identity governance has to follow the automation path, not sit beside it. When cloud platforms create resources, roles, and service accounts on demand, the real governance question is whether those identities are owned, reviewable, and revocable in the same workflow. If not, the cloud platform is accelerating entitlement sprawl rather than reducing it.
For practitioners
- Define the governance boundary for CMPs Document which access decisions belong to the cloud management platform and which must remain in IAM or IGA, especially for provisioning, approvals, and revocation.
- Tie cloud provisioning to lifecycle ownership Require every automated resource or entitlement flow to map to an owner, a business purpose, and a revocation trigger so access does not outlive the work.
- Separate audit evidence from governance Use CMP logs and compliance reports as evidence sources, but keep access review, exception handling, and offboarding in a governance process that can certify entitlements.
- Review workload and service account access paths Check whether cloud automation creates service accounts, tokens, or role bindings that bypass the review and offboarding processes used for human access.
Key takeaways
- Cloud management platforms help consolidate cloud operations, but they do not by themselves resolve who should hold access or when that access should end.
- The main governance gap is the separation between platform-level controls and identity lifecycle ownership across cloud, workload, and human access.
- Practitioners should anchor cloud automation to IGA processes so provisioning, review, and revocation stay connected.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centers on cloud access governance and entitlement control gaps. |
| Recommendation — Apply PR.AA-05 to govern cloud entitlements through reviewable authorization rules. | ||
| CIS Controls v8 | CIS-5 — Account Management | CMPs create and manage accounts and roles that need lifecycle oversight. |
| Recommendation — Use CIS-5 to keep cloud-created accounts tied to ownership, review, and removal. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Cloud platform access must still be constrained to the minimum required permissions. |
| Recommendation — Enforce AC-6 across cloud roles so platform automation cannot expand privilege unnecessarily. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Cloud automation often creates service and workload identities with excessive privileges. |
| Recommendation — Audit cloud-generated non-human identities for overprivileged access and reduce their scope. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud governance and access control are central to the CSA cloud control domain IAM. |
| Recommendation — Map cloud platform governance to CSA-CCM IAM controls and close entitlement ownership gaps. | ||
Key terms
- Cloud Management Platform: A cloud management platform is a control layer that helps organisations provision, monitor, and govern resources across cloud environments. It centralises operational tasks, but the underlying identity model still determines who or what can act, which permissions persist, and how access is retired.
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Entitlement Sprawl: The gradual accumulation of too many discrete permissions, often with overlapping access and unclear ownership. It makes access review noisy and offboarding fragile. Grouping entitlements into profiles is one way to reduce that sprawl, provided the groups are designed around real work patterns.
- Lifecycle Ownership: Lifecycle ownership is the assignment of responsibility for creating, changing, reviewing, and retiring an identity or its access. For customer and non-human identities, weak lifecycle ownership usually shows up as orphaned access, inconsistent policy enforcement, and unclear accountability during change.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org