TL;DR: Periodic access reviews, nightly feeds, and manual exceptions cannot keep pace with constantly changing roles and entitlements, according to Fischer Identity. The control model now has to recompute identity state, enforce policy outcomes, and preserve audit evidence as conditions change, not after the fact.
At a glance
What this is: This is an argument for continuous identity as a closed-loop governance model, with the key finding that periodic IGA processes break when identity state changes faster than review cycles.
Why it matters: It matters because IAM, IGA, and PAM teams need governance that keeps pace with movers, leavers, contractors, and cloud entitlements without relying on stale snapshots.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 68% of organisations do not know how to fully address NHI risks.
Context
Continuous identity governance is the idea that identity state should be recomputed and enforced as conditions change, rather than waiting for a scheduled review cycle. In practice, that is a direct challenge to periodic IGA, because roles, affiliations, and access entitlements now change continuously across human identity, NHI, and hybrid lifecycle processes.
The article argues that nightly feeds, yearly access reviews, and manual exceptions no longer provide dependable governance in dynamic environments. That problem is especially visible in higher education and other complex organisations, where movers, leavers, contractors, researchers, and vendors all create overlapping identity states that traditional snapshots struggle to represent accurately.
Key questions
Q: How should organisations move from periodic access reviews to continuous identity governance?
A: Start by treating certification campaigns as validation, not detection. Then connect entitlement changes, exceptions, and revocations to real-time policy checks so the programme can prove enforcement at the moment access changes. That shift matters most where service accounts, tokens, and privileged roles can drift faster than a review cadence.
Q: Why do nightly feeds and scheduled reconciliations fail in modern IAM programmes?
A: They fail because they observe change after it has already created risk. In volatile environments, identity state can shift several times before a batch job runs, so the programme spends time reconciling stale truth. Continuous governance closes that gap by making enforcement follow state changes instead of reporting them later.
Q: What signals show that an identity programme is continuous rather than just automated?
A: Look for three signals: policy recomputation at the moment of change, direct enforcement that alters access without manual intervention, and audit evidence that explains the decision path. If the system only moves data faster or sends tickets to people, it is automated administration, not continuous governance.
Q: Who is accountable when identity governance is still based on manual exceptions and delayed reviews?
A: Accountability stays with the organisation that allowed the control gap to persist, because delayed review is a governance design choice, not an unavoidable limitation. In regulated environments, control owners, IAM leaders, and business approvers all need to accept that stale entitlement state is a programme failure, not an administrative inconvenience.
Technical breakdown
Closed-loop identity governance and continuous computation
Continuous Identity is a control loop, not a data integration pattern. Signals from authoritative sources and operational systems update identity state, policy engines recalculate eligibility and entitlement posture, enforcement changes access, and evidence is recorded for audit. The technical distinction matters: a platform can ingest data frequently and still fail if it does not recompute the effective identity state and drive decisions from that computation. In other words, streaming feeds without policy-driven enforcement remain observational, not governing.
Practical implication: Treat any IAM or IGA claim that stops at sync frequency as incomplete unless it also recomputes state and enforces policy outcomes.
Why periodic reviews fail in fast-changing lifecycle states
Periodic governance assumes the identity relationship is stable long enough to be reviewed later. That assumption breaks when a person changes role, gains a new affiliation, or leaves and re-enters through another relationship, because the entitlement truth can drift multiple times before the next certification cycle. The same pattern applies to service accounts and other non-human identities when provisioning, deprovisioning, or exception handling lags behind operational change. The control failure is not just delay. It is mismatch between governance cadence and identity volatility.
Practical implication: Use lifecycle events, not calendar reviews alone, as the trigger for access recalculation and entitlement removal.
Audit-grade evidence as part of the control plane
Continuous governance only holds up if every state change leaves a verifiable trail of what changed, when it changed, why it changed, and which policy caused the action. Without that evidence, organisations may automate access changes but still struggle to prove control effectiveness during audit, incident review, or compliance testing. This is why evidence generation is not a reporting layer bolted on after the fact. It is part of the governance mechanism itself, because control without proof is operationally fragile.
Practical implication: Design identity workflows so enforcement and evidence are produced together, not reconstructed later from logs.
NHI Mgmt Group analysis
Continuous Identity is a control model, not a faster feed. The article is right to separate frequent ingestion from actual governance. A platform that only moves data faster can still leave entitlement decisions stale, while a continuous model recomputes identity posture and enforces outcomes in step with change. For IAM and IGA teams, the practical conclusion is that refresh speed alone is not a governance metric.
Periodic certification is structurally misaligned with volatile identity state. Access review programmes assume entitlement truth is stable long enough to be sampled later. That assumption fails in environments where movers, leavers, contractors, and time-bound affiliations alter identity relationships multiple times inside a review window. The implication is that governance must be tied to lifecycle events and state recomputation, not calendar-driven clean-up.
Continuous evidence is now part of the compliance control, not an afterthought. The article’s emphasis on audit-grade evidence reflects a wider shift in identity governance: enforcement that cannot be proven will not survive scrutiny from auditors, regulators, or internal control owners. That makes evidence generation a first-class design requirement for modern IGA and PAM programmes. Organisations should treat traceability as part of the control, not a report generated after the fact.
Relationship-aware identity is the named concept teams should operationalise. The article describes identity as a changing relationship among people, systems, and eligibility states rather than a fixed account record. That framing is especially useful in higher education, healthcare, and hybrid enterprises where one person can hold multiple roles and access paths at once. Practitioners should govern the relationship, not just the account, if they want access decisions to remain accurate.
Continuous governance exposes the weakness of custom-heavy identity programmes. When policy logic depends on brittle code, every change in source systems or business structure turns governance into a maintenance project. The article’s no-code emphasis points to a deeper operational truth: durable identity control requires configuration-led adaptation, not custom engineering that degrades over time. Teams should evaluate whether their current model can survive organisational churn without rework.
From our research:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- That is why Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs remains the right next step for teams aligning governance with lifecycle reality.
What this signals
Relationship-aware governance is becoming the practical dividing line between mature IAM programmes and administrative tooling. Organisations that still depend on batch reconciliations will keep discovering that access drift is a lifecycle problem, not a reporting problem. The more volatile the identity ecosystem, the more governance has to move from periodic review to continuous policy enforcement.
With 97% of NHIs carrying excessive privileges, according to the Ultimate Guide to NHIs, identity teams cannot afford to treat entitlement excess as a rare exception. The same logic applies when human and machine lifecycle states overlap, because the blast radius grows whenever access lags reality.
Continuous Identity should be read as a control design pattern rather than a product feature. For practitioners, the next step is to test whether your IAM, IGA, and PAM workflows can recompute state, enforce outcome, and leave evidence in one motion. If they cannot, you have automation, but not continuous governance.
For practitioners
- Rebuild governance around lifecycle-triggered recalculation Map mover, leaver, affiliation, and source-record correction events to automatic entitlement recomputation instead of waiting for the next access review cycle.
- Separate streaming from continuous enforcement Test whether your platform only ingests identity changes or actually changes access, workflow outcomes, and exceptions when policy state changes.
- Make audit evidence part of the workflow Require each entitlement change to record what changed, why it changed, and which policy produced the action so evidence is generated at the point of enforcement.
- Reduce dependence on brittle customisation Inventory custom code, scripts, and one-off workflows that would block policy recalculation when source systems or organisational structures change.
Key takeaways
- Periodic reviews and nightly feeds are too slow for identity environments where roles, affiliations, and access states change continuously.
- Continuous governance means recomputing identity state, enforcing policy outcomes, and recording evidence as part of the same control loop.
- Teams should treat lifecycle-triggered enforcement and audit-grade traceability as core requirements, not optional enhancements.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Continuous identity governance maps to access management and entitlement control. |
| NIST SP 800-53 Rev 5 | AC-2 | Lifecycle-based account management fits this article's emphasis on continuous enforcement. |
| NIST Zero Trust (SP 800-207) | Zero trust depends on continuous verification as identity state changes. | |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance and policy enforcement are central to the article. |
Use continuous identity to keep authorization decisions aligned with current identity state.
Key terms
- Continuous Identity: A governance model that turns identity data into live access decisions. Instead of relying on static approvals and periodic reviews, continuous identity reevaluates whether access should still exist based on current context such as risk, device state, ticket status, or business need.
- Identity State: Identity state is the live condition of an account, token, certificate, or permission set at a given moment. It matters because a task can be complete while the real access remains active, stale, or overprivileged. Security teams should validate identity state rather than relying only on process completion.
- Audit-Ready Evidence: Audit-ready evidence is access proof that can be retrieved directly from the control system without manual reconstruction. It should show who approved access, what policy they used, when the decision occurred, and whether any exceptions or compensating controls were applied.
- Lifecycle-Triggered Enforcement: Access control that reacts to joiner, mover, leaver, or correction events instead of waiting for a scheduled review cycle. This approach reduces drift because the governance action is tied to the change that created the risk.
What's in the full article
Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:
- The article expands the five capability areas that distinguish streaming from true continuous governance, including signal ingestion and continuous enforcement.
- It gives concrete lifecycle scenarios for movers, leavers, and source-record corrections that show how policy recomputation should behave.
- It explains why no-code configuration matters for long-term sustainability when identity sources and organisational structures keep changing.
- It describes the author’s position on Continuous Identity as a durable operating model rather than a rebranding of periodic IGA.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org