TL;DR: Lifecycle events still anchor identity administration, but modern environments need continuous identity state to keep access aligned with current relationships, ownership, policy, and risk, according to Fischer Identity. Event-only models leave drift between reviews and changes, making governance continuous rather than periodic the decisive control.
At a glance
What this is: This is an analysis of why event-based identity administration no longer fully governs modern IAM, and the key finding is that continuous identity state is needed to keep access aligned with real-time relationships and risk.
Why it matters: It matters because IAM, IGA, and NHI programmes all fail when access is only corrected at discrete lifecycle moments instead of continuously aligned to current business relationships.
👉 Read Fischer Identity's analysis of lifecycle events versus continuous identity state
Context
Identity lifecycle management is no longer just a hire, transfer, and leave process. In the primary topic area of IAM, the gap is that many identities now exist in overlapping, temporary, or non-human relationships that do not fit a simple event-driven model.
Fischer Identity argues that lifecycle events remain important, but they are not sufficient on their own. The operational issue is identity drift: access, ownership, and policy can become misaligned between formal events, which creates governance gaps for human identities, service accounts, workloads, bots, and AI agents.
Key questions
Q: How should organisations govern identities when lifecycle events are not enough?
A: They should move from event-only administration to relationship-based governance. That means using joiner-mover-leaver events as triggers, but continuously checking whether access still matches the current relationship, ownership, and policy. The goal is not just faster processing, but lower drift between what the business says and what the directory still allows.
Q: Why do quarterly access reviews miss identity risk?
A: Quarterly reviews miss risk because entitlement abuse can happen and finish long before the next certification cycle. A clean audit trail only proves that someone reviewed access later. It does not show whether the access was safe during the interval when an attacker or insider could use it.
Q: What breaks when identity state is not continuously aligned to relationships?
A: Ownership becomes unclear, access outlives the business need, and governance reacts to stale records rather than present conditions. In practice, that creates hidden privilege, orphaned accounts, and approval trails that look correct on paper but no longer reflect reality.
Q: How can IAM teams decide whether to prioritise continuous identity state?
A: Prioritise it when your environment has overlapping populations, temporary access, frequent role changes, or non-human identities that do not follow a simple hire-to-retire pattern. Those conditions create drift faster than lifecycle processes can reliably clean up.
Technical breakdown
Why event-based identity management drifts
Event-based identity management assumes a discrete trigger will produce the correct access state and that the next lifecycle event will capture any later change. That works when relationships are simple and stable. It breaks when identities have multiple sponsors, temporary access, overlapping roles, or non-human ownership patterns. Between events, access can remain valid after the relationship changes, and the system has no inherent reason to notice. The technical failure is not provisioning itself, but the absence of a continuous comparison between current relationship state and current access state.
Practical implication: treat lifecycle events as inputs to governance, not as proof that access remains correct.
What continuous identity state changes in governance
Continuous identity state treats identity as a governed condition rather than a sequence of isolated tasks. The model continuously evaluates relationship, ownership, policy, and risk so that access can change when the underlying justification changes. This is especially relevant in IGA, where periodic certifications can miss drift that appears and disappears between review cycles. In practice, the architecture depends on authoritative signals from HR, student systems, contractor records, directories, and security tools, then applies policy to produce actions such as approval, review, or removal.
Practical implication: design governance rules around state changes, not just scheduled certification windows.
Relationship state is the control plane
A relationship-aware IAM model makes the current business relationship the source of truth for access. Employee, contractor, student, vendor, service account, and AI agent relationships each justify different scopes, durations, and ownership rules. When the relationship changes, access should change with it. That shift matters because identity risk often comes from long-lived access that still looks legitimate in a directory but no longer matches the business context. Continuous control means the system must know not only who or what the identity is, but also what relationship currently authorises it.
Practical implication: map each identity population to a clear relationship model before expanding automation or governance rules.
NHI Mgmt Group analysis
Continuous identity state is a governance model, not a workflow refinement. Lifecycle event processing is designed for discrete administrative moments, but modern identity risk emerges between those moments. The discipline shifts from processing joiner-mover-leaver events to continuously validating whether current access still matches current relationships, ownership, and policy. For IAM and IGA teams, the practical conclusion is that periodic operations alone cannot be treated as governance.
Event-only identity administration creates identity drift as a structural failure mode. Drift is what happens when a contractor, student, vendor, service account, or AI agent retains access after the relationship that justified it has changed. That is not just a control gap, it is a broken assumption that the last lifecycle event fully represents the present state. The implication is that access reviews and offboarding controls must be tied to live relationship state, not historical records.
Continuous identity state gives lifecycle governance a broader operating boundary. The article correctly extends IAM beyond workforce-only thinking by including students, partners, service accounts, workloads, bots, and AI agents. That broader scope matters because the same governance discipline has to work across human IAM, NHI, and emerging autonomous identity programmes. Practitioners should stop designing lifecycle controls around one population and start designing them around relationship types and state transitions.
Identity accuracy becomes the real control objective. When current access no longer reflects current reality, the programme has already lost the governance race. Continuous state management shifts the target from faster administration to accurate identity representation, which is a more defensible objective for auditors, security teams, and business owners alike. The practical conclusion is that identity programmes should be measured by alignment, not just completion of workflow tasks.
What this signals
Continuous identity state: the next governance problem is not whether lifecycle events exist, but whether the programme can keep pace with identities whose relationships change faster than review cadences. For teams managing human IAM, NHI, and AI-enabled access, the operating question is alignment over time, not one-time provisioning.
The shift also changes how leaders should think about governance investment. If access can drift between scheduled events, then certification, offboarding, and sponsorship controls need live signals and policy logic that can react before stale access becomes a finding.
For practitioners
- Define relationship-based access rules Classify identities by the relationship that justifies access, such as employee, contractor, student, vendor, service account, or AI agent, and use that classification to drive entitlement scope and duration.
- Trigger governance from state changes Route review, approval, or removal actions when sponsorship ends, ownership changes, role changes, or policy exceptions occur, rather than waiting for the next periodic certification cycle.
- Build continuous signal ingestion Pull authoritative signals from HR, student, contractor, directory, ticketing, and security sources so that access state is recalculated when the underlying relationship changes.
- Reduce dependence on custom code Use configurable policy and workflow logic for lifecycle transitions so that new relationship types, exceptions, and governance triggers do not require brittle point-to-point development.
- Track identity drift as a control metric Measure how often access remains active after the relationship that justified it has ended, and use that figure to prioritise cleanup and lifecycle automation.
Key takeaways
- Lifecycle events are necessary, but they are no longer enough to govern modern identity populations.
- The central risk is identity drift, where current access no longer matches the current business relationship.
- IAM and IGA teams need continuous state validation so governance follows reality instead of stale snapshots.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Continuous access validation maps to maintaining appropriate access rights over time. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central to lifecycle and state-driven identity governance. |
| NIST SP 800-63 | SP 800-63C | Federation and assertion handling matter when relationships span systems and sponsors. |
| NIST Zero Trust (SP 800-207) | Zero Trust reinforces continuous verification rather than one-time trust decisions. |
Align identity governance with continuous verification instead of relying on initial approval alone.
Key terms
- Continuous Identity: A governance model that turns identity data into live access decisions. Instead of relying on static approvals and periodic reviews, continuous identity reevaluates whether access should still exist based on current context such as risk, device state, ticket status, or business need.
- Identity Drift: Identity drift is the gap between the access path originally approved and the behavior that exists later. For browser extensions, drift can appear through updates, remote configuration, publisher changes, or permission expansion, turning a trusted integration into a materially different risk.
- Relationship-Based Access: An access model where entitlements are justified by the current business relationship, such as employee, contractor, student, vendor, or service account status. In practice, the relationship defines scope, duration, ownership, and review requirements.
- Event-Driven Lifecycle Management: An operating pattern where identity changes such as joiners, movers, leavers, role updates, or entitlement drift trigger governance actions automatically. It reduces manual queueing and makes access changes auditable at the moment they occur, which is especially important in SaaS, cloud, and NHI-heavy environments.
What's in the full article
Fischer Identity's full blog covers the operational detail this post intentionally leaves for the source:
- Detailed examples of relationship-state transitions across workforce, student, contractor, vendor, service account, and AI agent populations.
- The article's full list of identity-state signals, including which systems should act as authoritative sources.
- Additional guidance on configuring identity workflows without custom code or brittle integration logic.
- Expanded examples of governance triggers tied to sponsorship changes, policy exceptions, and role drift.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org