By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Fischer IdentityPublished August 6, 2026

TL;DR: Traditional IGA metrics still assume access is corrected at checkpoints, but modern identity states change continuously across people, projects, contracts, risk signals, and non-human identities, according to Fischer Identity. That makes delayed certification a control gap, not a governance model, because stale access can remain active long before review begins.


At a glance

What this is: This is an analysis of continuous identity governance, arguing that access should be recalculated when business conditions change rather than corrected during periodic reviews.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes all depend on whether access can change as fast as the underlying identity condition, not just whether it can be certified later.

By the numbers:

👉 Read Fischer Identity's analysis of continuous identity governance and lifecycle control


Context

Continuous identity governance means the system recalculates access when authoritative business conditions change, rather than waiting for a quarterly or annual review. In this article, Fischer Identity argues that checkpoint-based IGA is too slow for modern enterprises where workforce status, project assignments, contracts, risk signals, and non-human identities shift continuously.

The primary IAM issue is governance lag: access remains valid after the condition that justified it has changed. That gap matters across human IAM, NHI lifecycle management, and AI-adjacent governance because delayed correction turns policy into after-the-fact cleanup instead of an active control.

For practitioners, the question is not whether certifications still matter, but whether they are being used as the engine of governance when they should be a validation layer. If the target state is not continuously reconciled, the organisation only learns about stale access when the next review cycle finally runs.


Key questions

Q: How should organisations govern access when business conditions change continuously?

A: They should shift from periodic attestation to event-driven policy evaluation. Access should be recalculated when source systems report a relevant change, then reconciled against the target state. That makes certifications a validation layer, not the primary mechanism for discovering stale access that should already have been removed.

Q: Why do periodic access reviews fail as the main governance control?

A: Because they assume access can remain in place until the next review without creating meaningful risk. In modern environments, job changes, risk signals, contracts, and project assignments can invalidate access long before the review occurs. The review may confirm the problem, but it does not prevent the exposure window.

Q: What breaks when device lifecycle management is not tied to identity governance?

A: When device lifecycle management is isolated from identity governance, organisations lose the ability to prove who used the device, what access it carried, and whether retirement actually removed trust. That creates residual access risk through cached credentials, retained software permissions, and incomplete offboarding. The control failure is usually not the asset record itself, but the missing link between device state and identity state.

Q: How should teams use certification if continuous governance is already in place?

A: Use certification to validate policy ownership, confirm exceptions, and provide human judgment where rules are incomplete. Do not use it as the engine for routine lifecycle change. If the platform is healthy, certification should explain exceptions, not discover every basic access change.


Technical breakdown

Why checkpoint-based IGA creates governance lag

Traditional IGA assumes access is granted, then later reviewed, then eventually corrected. That sequence works only when identity conditions change slowly and source systems sync in batches. In practice, business relationships now change continuously, so the architecture can leave entitlements active long after the underlying condition has changed. The result is not simply slow reporting. It is a control model that treats review as detection, rather than recalculation of the intended state.

Practical implication: replace campaign-first thinking with event-driven policy evaluation tied to authoritative source changes.

Continuous identity lifecycle as a closed-loop control system

A continuous model treats identity governance as a control loop: source event, correlation, policy evaluation, access decision, provisioning or revocation, target reconciliation, and audit evidence. The critical shift is that access is no longer a static grant waiting for attestation. It is an outcome that must be repeatedly validated against current business context. That is what makes lifecycle management, reconciliation, and certification distinct functions, not interchangeable ones.

Practical implication: instrument each step in the loop so delays can be isolated to source, workflow, connector, or target system.

Why non-human identities need lifecycle governance too

The article’s broader point applies to NHIs as well as people. A service account, API key, or AI-linked workload still has an owner, purpose, duration, entitlement set, and retirement condition. If those lifecycle attributes are not continuously evaluated, the identity becomes harder to reconcile than a human account because its usage is often more persistent and less visible. Continuous governance is therefore a lifecycle discipline, not just a workforce process.

Practical implication: govern NHI access by owner, purpose, expiration, and reconciliation status, not by periodic review alone.


NHI Mgmt Group analysis

Checkpoint-oriented IGA is a lagging control, not a governance model. The article correctly exposes the assumption that access can be granted once and safely revisited later. That assumption was designed for slower identity change and batch-oriented systems, not for continuous business events. The implication is that governance programmes must stop treating certification as the primary control for access correctness.

Continuous governance is the same discipline across humans, NHIs, and autonomous systems, but the evidence surface differs. A person, service account, and AI-linked workload all require ownership, purpose, duration, and retirement conditions. What changes is the speed and observability of the lifecycle, which is why the review model must adapt to the actor type. Practitioners should align lifecycle enforcement to the identity subject, not the campaign calendar.

Identity blast radius becomes the real control metric when access state can drift between reviews. The more time an entitlement can remain active after the business condition changes, the larger the exposure window becomes. That exposure is not just a compliance problem. It is a design problem in entitlement propagation, reconciliation, and revocation timing. Practitioners should measure how much stale access can exist before the next control action.

Continuous reconciliation matters more than better certification commentary. The article makes a strong case that richer review workflows do not fix stale access if the target system is still out of sync. That is the governance failure mode many programmes miss. The right conclusion is not that reviews are obsolete, but that they cannot compensate for weak lifecycle enforcement.

Policy-derived access only stays governed when the underlying business condition is still true. That premise is central to modern IGA and becomes even more important as organisations adopt more third-party, project-based, and machine-mediated access models. Once the condition changes, entitlement legitimacy changes with it. Practitioners should treat stale-condition access as a lifecycle failure, not a reviewer failure.

From our research:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which helps explain why lifecycle drift persists even when governance teams believe controls are working.
  • For a broader lifecycle lens, the NHI Lifecycle Management Guide shows how provisioning, rotation, and offboarding need to be managed as one continuous control loop.

What this signals

Identity governance is moving toward event-driven enforcement, not review-led correction. As business systems produce more real-time signals, programmes that still depend on quarterly attestation will keep finding problems after they have already created exposure. That is especially true for service accounts and workloads where access can outlive the business reason that justified it.

Continuous reconciliation is now a programme design requirement, not an optimisation. The practical question is whether the identity platform can prove that target state matches intended state after every meaningful change. If it cannot, then the organisation is not governing access continuously, regardless of how sophisticated the review workflow appears.

Entitlement drift is increasingly an architecture problem. The shift toward policy-based governance means practitioners should examine whether access is tied to current business condition or merely recorded in a campaign history. For a deeper lifecycle perspective, the Ultimate Guide to NHIs remains a useful reference point, especially where NHI and workforce governance intersect.


For practitioners

  • Map access to authoritative business events Identify which source events should trigger recalculation of access, including job changes, contract end dates, project closure, sponsorship lapse, and risk signals. Use those events to drive policy evaluation before the next certification campaign begins.
  • Measure governance lag end to end Break the control loop into source ingestion, identity correlation, policy evaluation, provisioning, target reconciliation, and evidence confirmation. That lets you see whether stale access is caused by delayed data, workflow friction, or target-system latency.
  • Separate certification from lifecycle enforcement Use access reviews to validate ownership, exceptions, and policy fit, but do not rely on them to discover routine changes that should already have been enforced. Certifications should confirm the control system, not replace it.
  • Extend lifecycle rules to NHIs and workload identities Give service accounts, API keys, and workload credentials the same governance basics as human identities: owner, purpose, expiration, revocation path, and reconciliation checks. Continuous governance breaks down quickly when machine identities are left outside the lifecycle model.

Key takeaways

  • Continuous identity governance replaces delayed correction with recalculation tied to business events.
  • The main weakness in checkpoint-based IGA is governance lag, not a lack of review effort.
  • Practitioners should treat certifications as validation, while lifecycle enforcement and reconciliation do the real control work.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4The article focuses on access lifecycle enforcement and least-privilege continuity.
NIST SP 800-53 Rev 5IA-5Continuous identity governance depends on managing authenticators and related lifecycle changes.
NIST Zero Trust (SP 800-207)The article aligns with continuous verification and access decisions in a zero-trust model.
OWASP Non-Human Identity Top 10NHI-03NHI lifecycle drift and stale machine credentials are central to the governance gap discussed.

Map access changes to PR.AC-4 and ensure revocation is triggered by authoritative business events.


Key terms

  • Continuous Identity Governance: An operating model where access decisions, lifecycle changes, and risk signals are handled as an ongoing process rather than a periodic campaign. It uses authoritative events, telemetry, and policy automation to keep access aligned with current business and security conditions.
  • Governance Latency: Governance latency is the delay between a change in risk, relationship, or access need and the point at which the control model reflects that change. In API environments, high governance latency turns simple access management into a bottleneck and increases residual exposure.
  • Target State Reconciliation: The process of comparing intended access against what actually exists in the destination system. It is the control that confirms whether provisioning, revocation, and entitlement changes really took effect, rather than merely being requested or logged.
  • Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.

What's in the full article

Fischer Identity's full article covers the operational detail this post intentionally leaves for the source:

  • The source article walks through the continuous control-loop model from authoritative event to reconciliation.
  • It explains how policy-driven lifecycle management differs from campaign-centric certification in day-to-day operation.
  • It outlines how organisations can classify access as birthright, exception, dynamic, or orphaned in practical governance terms.
  • It gives a programme-level view of how continuous governance applies to people, contractors, and non-human identities.

👉 The full Fischer Identity article expands on policy evaluation, reconciliation, and the limits of certification-led governance.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org