By NHI Mgmt Group Editorial TeamBased on C1.ai: “December Product Wrap-Up” (December 30, 2025)

TL;DR: C1.ai says its December identity governance updates were aimed at making the platform easier to use, easier to understand, and easier to scale, with clearer access reviews, improved bulk actions, stronger automation support, and expanded connectors for real-world workflows. The underlying signal is that governance programmes fail when reviewer friction, context loss, and brittle integrations are treated as acceptable overhead.


At a glance

What this is: This is a December product wrap-up on identity governance UX, review visibility, scale, and integrations, with the key finding that small workflow and connector improvements were used to reduce friction across admin and reviewer tasks.

Why it matters: It matters because IAM and IGA teams do not fail only on policy design, but also on whether reviews, bulk administration, and system integrations are usable enough to sustain governance at scale.

👉 Read C1.ai's December identity governance update on UX, reviews, and integrations


Context

Identity governance often breaks down in the handoff between policy intent and daily execution. When reviewers need context scattered across tools, when admins have to force complex changes through brittle interfaces, and when scaling means more manual follow-up, the programme starts losing fidelity even if the policy model is sound.

This December wrap-up is about those operational frictions rather than a new governance model. The article focuses on UX refinements, clearer review visibility, bulk-action support, automation fit, and broader connector coverage, all of which affect how identity governance is actually run in production.


Key questions

Q: How should teams reduce friction in access review campaigns?

A: Treat campaign usability as part of the control design. Reviewers need the right context, clear status, and predictable workflows at the moment of decision. If they have to leave the review screen to gather basic facts, completion slows and the assurance value of the campaign drops.

Q: Why do identity governance programmes spiral into long, expensive projects?

A: They spiral when manual discovery, schema mapping, review handling, and connector maintenance are treated as normal work rather than implementation debt. That creates a programme that consumes time and people just to stay functional, which is especially problematic when access decisions are increasing across cloud, SaaS, and non-human identities.

Q: What breaks when identity reviews are too broad and infrequent?

A: Reviewers lose context, dormant access stays active, and the process turns into a completion exercise instead of a control. Broad reviews also hide the identities that matter most, especially high-risk service accounts and shared entitlements. When the review scope is too large, teams can satisfy the process without actually reducing exposure.

Q: How can teams tell if integrations are deep enough for governance?

A: Look for whether the connector supports the full access lifecycle, including provisioning, deprovisioning, and monitoring, rather than just data sync. If the platform can see access but cannot reliably change or retire it, governance remains partially manual and scale will stay constrained.


Technical breakdown

How UX changes affect identity governance throughput

Identity governance workflows depend on repeated human decisions, so small usability problems compound quickly. When policy authoring, table navigation, search, and notifications are awkward, reviewers spend more time interpreting the system than assessing access. That increases cognitive load and raises the chance that approvals become mechanical rather than informed. Better context inside the workflow matters because identity decisions are only as good as the information surfaced at the point of action. In practice, UX is not cosmetic in IGA. It changes how quickly teams can process reviews, how consistently admins can execute changes, and how much friction accumulates across routine governance tasks.

Practical implication: Design review and administration paths so the decision-maker sees enough context to act without switching tools.

Why campaign visibility is a control issue

Access review campaigns are not just reporting objects. They are control mechanisms that depend on momentum, completion, and follow-up. If admins cannot see where reviews are stuck, who is lagging, or how much work remains, the campaign can drift into delay without an obvious failure signal. Richer dashboards turn the campaign into an operational control surface rather than a static checklist. That matters because bottlenecks in certification workflows create stale access windows and reduce confidence in recertification outcomes. Visibility therefore becomes part of the control, not just a management convenience.

Practical implication: Track campaign status, reviewer performance, and outstanding work as governance signals, not as optional reporting.

How connectors and automation shape scale

As identity programmes grow, the question is not whether a tool can integrate, but whether the integration model supports real lifecycle operations. Provisioning, deprovisioning, infrastructure-as-code, and CLI-driven workflows all reduce manual touchpoints, but only if the connector ecosystem is deep enough to support the systems where access actually lives. Weak integrations create governance gaps because the platform can see the record of access without reliably changing it. Scale, in this context, depends on whether the governance layer can operate inside existing workflows rather than sit beside them as another queue of manual tasks.

Practical implication: Prioritise connector depth and lifecycle coverage over surface-level integration counts.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity governance usability is a control problem, not a cosmetic one. When policy authorship, review context, and navigation are hard to use, the governance process starts absorbing friction that should never exist in the first place. That friction does not just annoy admins and reviewers. It changes the quality and speed of decisions, which means the control itself becomes less dependable. The practitioner takeaway is that UX debt should be treated as governance debt.

Access review visibility is now a prerequisite for scale. Campaigns that hide bottlenecks or reviewer slowdown do not merely feel inefficient, they weaken the assurance value of recertification. A review process that cannot explain its own progress cannot inspire confidence in its outcomes. The practitioner implication is that dashboard design and workflow telemetry need to be evaluated as part of the access certification control, not added later as reporting chrome.

Integration depth matters more than connector count. The real test for identity governance is whether access can be governed end to end across provisioning, deprovisioning, and adjacent operational systems without manual stitching. Breadth without lifecycle depth leaves teams with visibility but not authority over the access state. Practitioners should judge connector strategy by whether it closes the loop on real-world access lifecycles.

Scale exposes brittle governance assumptions. Tools that work for a small team can fail when campaigns, reviewers, and integrations multiply across a larger estate. The assumption that humans can absorb extra coordination breaks quickly once governance becomes routine rather than exceptional. The implication is that maturity means designing for repeatability, not just control existence.

Lifecycle automation, not ad hoc administration, is what keeps governance sustainable. Bulk actions, exports, and infrastructure-as-code support reduce the manual overhead that otherwise grows with every new app and review cycle. That shifts identity governance from a maintenance burden to an operating model that can survive real organisational scale. The practitioner conclusion is simple: if the process cannot be repeated cleanly, it cannot be governed reliably.

What this signals

Governance UX debt accumulates quietly: when policy building, review navigation, and admin workflows stay cumbersome, teams pay the cost in slower decisions and lower-quality certifications. The practical signal is not just user annoyance, but reduced control reliability across the programme.

Connector depth is the real scale test: a governance platform that only records access relationships cannot support lifecycle management at enterprise pace. Practitioners should judge integrations by whether they can execute provisioning and deprovisioning cleanly in the systems where access actually lives.


For practitioners

  • Tighten review-context delivery Surface the minimum decision context inside certification and approval workflows so reviewers do not need to jump between tools to understand what they are authorising.
  • Measure campaign bottlenecks explicitly Track stalled reviews, reviewer lag, and unfinished work as governance signals so admins can intervene before recertification cycles lose credibility.
  • Test bulk operations at scale Validate whether bulk changes, exports, and similar high-volume tasks still behave predictably when the number of applications and reviewers increases.
  • Evaluate connector lifecycle depth Check that integrations support provisioning, deprovisioning, and configuration monitoring rather than only synchronising records into the platform.
  • Reduce governance friction in everyday administration Review navigation, search, and table behaviour in the admin experience and remove steps that slow repetitive identity work without adding value.

Key takeaways

  • Identity governance falters when reviewer and admin workflows create avoidable friction, because usability directly affects decision quality.
  • Campaign visibility, bulk operations, and connector depth are operational controls, not minor product conveniences.
  • Teams should judge scale by whether governance can run inside existing workflows without manual stitching or context switching.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing access reviews, approvals, and entitlement context.
Recommendation — Use PR.AA-05 to keep entitlement decisions visible, reviewable, and aligned to actual access state.
CIS Controls v8CIS-5 — Account ManagementDecember updates centre on account lifecycle governance, bulk administration, and access reviews.
Recommendation — Apply CIS-5 to keep account changes, reviews, and deprovisioning aligned to operational reality.
ISO/IEC 27001:2022A.5.15 — Access controlThe post focuses on how access governance is administered and reviewed in practice.
Recommendation — Use A.5.15 to structure access control processes that are understandable and repeatable at scale.
NIST SP 800-53 Rev 5AC-2 — Account ManagementThe updates affect lifecycle administration, review handling, and privileged workflow operations.
Recommendation — Apply AC-2 to govern account lifecycle tasks through consistent, auditable workflows.

Key terms

  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Access Review Campaign: An access review campaign is a scheduled process where application owners, managers, or delegates confirm whether existing permissions should remain in place. It is a control for removing excess access, but it only works when reviewers can understand the permissions and complete decisions reliably.
  • Connector Ecosystem: A connector ecosystem is the collection of tools, integrations, and reusable connection components that support system interoperability. In identity governance, the ecosystem becomes a control surface that must be visible, catalogued, and managed so teams can understand dependencies, limit risk, and maintain operational order.
  • Governance friction: The operational delay or complexity created by identity controls when users try to do legitimate work. Friction becomes a security issue when it encourages shadow access, informal approvals, or repeated exceptions. Good governance reduces unnecessary friction without weakening the control objective.

What's in the full article

C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:

  • Weekly release-note level detail on the December UX changes and where they apply in the platform
  • Expanded connector notes for PrismHR, HaloITSM, and the related provisioning and deprovisioning updates
  • More granular examples of bulk actions, exports, and infrastructure-as-code support in real workflows
  • The specific review and campaign visibility improvements behind the summary dashboard changes

👉 C1.ai's full post includes the weekly release-note detail behind the December governance changes

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org