TL;DR: Confidence in identity governance is high while proof of execution remains thin, according to Omada Identity’s State of Identity Governance 2026, based on nearly 600 U.S. enterprise professionals, with reporting still centered on activity and non-human identities growing faster than ownership. The real control gap is not belief but continuous, measurable governance at machine speed.
At a glance
What this is: This blog argues that identity governance programmes often look strong in executive reporting even when they cannot prove risk reduction, especially as non-human identities and automation expand faster than ownership and measurement.
Why it matters: It matters because IAM, IGA, PAM, and NHI teams need evidence of control effectiveness, not just confidence in the programme, if they want to govern human, machine, and autonomous access credibly.
By the numbers:
- More than 80% of leaders report concern about every major identity threat category.
Context
Identity governance is supposed to show whether access is controlled, explainable, and continuously aligned to risk. In this article, that promise breaks down because many programmes still prove activity more easily than they prove reduced risk, which matters most once governance has to operate at machine speed across NHI and AI-driven workflows.
The gap is not a lack of intent. The article says leaders see identity as a critical control, yet reporting, ownership, and evidence quality have not kept pace with more dynamic environments. That makes the governance problem less about awareness and more about whether the control surface can support continuous execution across human, non-human, and emerging autonomous identities.
As a result, executive confidence can mask weak operational proof. The article’s central claim is that identity governance is moving from a periodic function to a continuous operating layer, but many enterprises are still measuring throughput instead of control effectiveness.
Key questions
Q: What breaks when identity governance only reports activity instead of risk?
A: You get a programme that can show work completed but cannot prove exposure reduced. That is how provisioning timeliness, audit readiness, and incident counts become a substitute for control effectiveness. The result is confidence without evidence, which leaves privileged access, orphaned accounts, and delayed revocation hidden from decision-makers.
Q: Why do Zero Trust programmes fail when identity data stays fragmented?
A: Zero Trust depends on continuous evaluation across systems, so fragmented APIs, weak documentation, and inconsistent data exchange prevent the organisation from proving a shared access state. Local enforcement may still work, but the enterprise cannot demonstrate that the same policy is being applied coherently across platforms.
Q: How should teams assign ownership to non-human identities?
A: Teams should assign one accountable owner and one technical steward to every non-human identity, then require both to be recorded before production access is approved. Ownership should be tied to the identity lifecycle, including review, rotation, and retirement, so accountability survives staffing changes and application handoffs.
Q: How should organisations measure whether identity governance is actually working?
A: Organisations should measure whether governance reduces incident cost, manual workload, and time to detect or contain risky access. If the only visible improvement is fewer tools, the programme may not be effective. Strong governance shows up in faster policy enforcement, clearer ownership, and fewer unreviewed access paths.
Technical breakdown
Why activity reporting can hide identity risk
Executive dashboards often track what identity teams did, such as provisioning speed, deprovisioning speed, incident counts, and audit readiness. Those metrics are useful, but they measure throughput, not whether access decisions are continuously reducing exposure. When organisations rely on activity indicators, they can appear mature while still missing orphaned accounts, delayed revocation, and privileged access accumulation. The technical problem is that risk moves through state changes in identity, while reporting often captures only completed transactions. In a machine-paced environment, that lag matters because the control surface must answer whether access is still justified now, not whether a ticket was closed last week.
Practical implication: measure governance outcomes and exposure states, not just operational completion rates.
Zero Trust needs shared identity data, not isolated enforcement
Zero Trust is an operating model that depends on continuous evaluation across systems, not a one-time policy decision. The article points to inconsistent APIs, weak documentation, and limited shared standards as barriers to that model because each system may enforce its own rules correctly while leadership still lacks a unified view. That creates a technical split between local enforcement and enterprise assurance. Identity governance fails here when policy evidence cannot move cleanly across platforms, so risk decisions become fragmented by tool and team. The issue is not whether a control exists somewhere, but whether the organisation can prove that the control is functioning coherently across the stack.
Practical implication: standardise identity data exchange so Zero Trust decisions can be verified across platforms.
Non-human identity ownership breaks when accountability is shared by everyone
Non-human identities now outnumber human identities in most enterprises, but ownership is often split across security, IAM, DevOps, and other functions. That fragmentation creates an identity estate that is governed in pieces, with no single team responsible for the full lifecycle of service accounts, tokens, and agent credentials. The technical challenge is not just inventory; it is control coherence across creation, use, revocation, and review. As automation expands, static credentials and shared accounts become harder to defend because the environment changes faster than periodic governance routines can follow. Without a single accountable owner, the system can report coverage while leaving real access paths ambiguous.
Practical implication: assign lifecycle ownership for every non-human identity and tie it to revocation, review, and exception handling.
NHI Mgmt Group analysis
Identity governance has become a control surface, not a reporting function. The article shows that confidence in identity programmes is rising while evidence of execution remains weak, which means the discipline is being judged on belief rather than proof. Reporting that tracks throughput can look healthy even when access decisions are not continuously defensible. The implication is that governance teams must be measured on control effectiveness, not on whether the dashboard is active.
Fragmented identity ownership is now a governance failure mode, not just an operating inconvenience. When non-human identities outnumber humans and no single team owns them, the estate is effectively governed in fragments. That breaks the assumption that identity can be managed cleanly by separate platform teams without a shared lifecycle view. The practical consequence is that accountability must be designed as part of the identity operating model, not discovered after a control gap appears.
Zero Trust execution depends on evidence continuity, not policy alignment. The article’s point about inconsistent APIs and limited shared standards is important because Zero Trust only works when identity, security, and governance systems can prove the same state at the same time. A local success does not equal enterprise execution if the evidence cannot be correlated. Practitioners should treat interoperability as an assurance requirement, not a convenience issue.
Machine-paced governance exposes the limits of periodic review models. As GenAI and agentic AI are used to automate lifecycle work, identity decision-making is moving faster than human review cadences were designed to handle. That does not make the control obsolete, but it does make the old evidence model too slow to describe current risk. The implication is that governance programmes need continuous measurement aligned to runtime identity behaviour.
Continuous governance is the named concept this market now needs. The article effectively describes a shift from periodic control to a continuous operating layer, where access must be measured as it changes rather than after the fact. That is the right frame for human, NHI, and AI-driven identity estates because the same control cannot be assumed to hold across all three at review time. Practitioners should build for continuous assurance, or accept that their evidence will always lag reality.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Standards
What this signals
Identity governance teams should treat reporting as an assurance layer, not a proxy for control. When leaders can cite throughput but not exposure reduction, the programme is measuring activity rather than whether access decisions are defensible at the point of use.
Continuous governance: the shift from periodic review to ongoing verification is the core design change this article points to. The pressure comes from machine-paced identity environments, where 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
For identity teams, the practical consequence is that ownership and evidence must travel together. If no single function can see the full identity estate, then even strong local controls will not add up to enterprise-grade governance.
For practitioners
- Redesign identity dashboards around risk indicators Replace throughput-only reporting with measures that show whether access remains justified, including privileged access coverage, revocation delay, and orphaned account exposure.
- Map identity data flows across governance platforms Document where identity state is created, updated, and consumed so Zero Trust decisions can be evaluated across systems instead of inside one tool boundary.
- Assign lifecycle ownership for every non-human identity Name a responsible owner for each service account, token, and agent credential, then tie that owner to offboarding, review, and exception handling.
- Move review cycles closer to runtime change Shorten the gap between identity change and governance validation so automation and AI-driven access decisions do not outrun human oversight.
Key takeaways
- The article’s central warning is that confidence in identity governance can be high even when organisations cannot prove that access risk is falling.
- This gap shows up most clearly in executive reporting, where operational activity is tracked more often than privileged access exposure, orphaned accounts, or revocation delays.
- Continuous governance, shared identity data, and explicit lifecycle ownership are the controls that turn identity security from belief into evidence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article highlights unmanaged and fragmented machine access that can linger without continuous oversight. |
| NHI-09 — NHI Reuse | Shared or reused machine credentials undermine accountability when ownership is fragmented. | |
| Recommendation — Continuously trim non-human entitlements to the minimum access each identity still needs. Eliminate credential reuse for NHIs and tie each credential to a unique owner and purpose. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The core issue is whether access decisions remain defensible as conditions change. |
| Recommendation — Review entitlements continuously and revoke access that no longer matches current risk. | ||
| NIST Zero Trust (SP 800-207) | Continuous verification | Zero Trust is central to the article's argument about moving from periodic review to ongoing assurance. |
| Recommendation — Use continuous verification to confirm that access remains justified across systems. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article discusses GenAI and agentic AI as part of identity operations and oversight. |
| Recommendation — Set governance and accountability for AI-driven identity decisions before automating them. | ||
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Execution evidence: Execution evidence is the proof that a governance control worked in practice, not just that a workflow ran. It includes measurable signals such as risky access removal, revocation timing, and reduced entitlement drift, which are more useful than activity counts alone when environments are dynamic.
- Continuous governance: An identity governance model that checks and enforces policy as activity happens rather than on a schedule. It is designed to catch drift, misuse, and orphaned access while the identity is still active, which matters when risk unfolds in minutes instead of review cycles.
- Non-Human Identity Ownership: Non-Human Identity Ownership is the assignment of clear accountability for every machine identity used by software, services, or AI systems. It defines who creates, approves, rotates, monitors, and retires credentials such as keys, tokens, certificates, and service accounts, so each identity has a responsible human or team throughout its lifecycle.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 3, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org