By NHI Mgmt Group Editorial TeamBased on Zluri: “How to Implement Identity and Access Management?” (October 2, 2025)

TL;DR: IAM implementation is presented as a seven-step programme covering inventory, strategy, rollout, monitoring, compliance, and tool selection, with Zluri highlighting zero trust, least privilege, MFA, JIT access, and automated access reviews. The deeper issue is that IAM fails when organisations treat governance as a deployment task rather than an operating discipline.


At a glance

What this is: This is a how-to article on IAM implementation that finds programmes break when governance is handled as a project phase rather than an ongoing control discipline.

Why it matters: It matters because IAM teams cannot rely on initial rollout success if access reviews, monitoring, and policy enforcement are not built into day-to-day operations across human and non-human identities.


Context

IAM implementation is not just about standing up a tool or enabling a few access policies. The article’s core problem is that organisations often confuse deployment with governance, then discover that access control quality erodes once the rollout is complete.

For identity and access management teams, the issue is lifecycle discipline. Inventory, authentication, authorisation, access reviews, and monitoring all have to work together over time, or the programme becomes a static configuration that drifts away from real business access patterns.


Key questions

Q: What breaks when IAM governance is treated as a setup task?

A: IAM usually breaks at the point where access changes continue after launch but governance does not. Policies may look correct on day one, yet certifications, revocation, and monitoring drift as users, apps, and roles change. The result is a programme that appears implemented but no longer controls real access decisions.

Q: Should access reviews be tied to lifecycle events instead of fixed cycles?

A: Yes, when the goal is meaningful governance rather than simple compliance. Reviews tied to onboarding, role change, or exit preserve context and reduce repetition. Fixed cycles still have a place for oversight, but they should not be the only trigger for certification.

Q: How do teams know if IAM lifecycle controls are working?

A: They should be able to prove that accounts are provisioned and removed on schedule, that access changes are logged, and that stale entitlements are rare. If deprovisioning is incomplete or audit evidence is fragmented, lifecycle control is failing even when the front-end access experience looks smooth.

Q: When should organisations prioritise IAM automation over more manual controls?

A: Organisations should prioritise automation when request volume, stakeholder effort, or fulfilment delays are becoming routine rather than exceptional. If access handling requires repeated human coordination to move work forward, the process is already acting as a bottleneck. Automation is justified when governance depends on repeatability more than one-off judgment.


Technical breakdown

Why IAM implementation fails when governance is a one-time project

IAM implementation only works when policy, process, and enforcement remain active after rollout. If governance is treated as a setup task, teams may create clean initial access rules but never sustain them through joiner-mover-leaver changes, privilege changes, or application growth. That creates a gap between the intended access model and the live environment. The article repeatedly points to access reviews, monitoring, and maintenance as ongoing functions, which is the right framing: IAM is an operating discipline, not a deployment milestone.

Practical implication: design IAM ownership, review cadences, and exception handling as ongoing controls, not post-launch cleanup.

How MFA, JIT access, and access reviews fit into IAM control design

The article groups MFA, just-in-time access, and access certification automation as part of a broader IAM control stack. MFA strengthens authentication, JIT access shortens privilege exposure, and automated reviews help verify that permissions still match role needs. None of these controls works well in isolation if governance is weak. Their value depends on accurate role mapping, timely revocation, and sustained oversight after the initial rollout.

Practical implication: map each control to a lifecycle event, such as authentication, elevation, certification, or offboarding, so the programme does not rely on tooling alone.

Why monitoring and maintenance are part of identity governance

Monitoring and maintenance are not back-office tasks in IAM. They are the mechanisms that keep policy aligned with reality as applications, employees, and access paths change. The article stresses logging, alerting, patching, backups, and regular evaluation because stale configuration undermines both security and compliance. In practice, this means governance must include evidence generation, not just access assignment. A control that cannot be observed, tested, or reviewed is already drifting out of governance scope.

Practical implication: build continuous monitoring, maintenance, and evidence collection into the IAM operating model from day one.


NHI Mgmt Group analysis

IAM governance fails when teams mistake initial implementation for operational control. The article’s strongest lesson is that access policy only matters if it is enforced after deployment, across changes in people, apps, and permissions. That is the difference between an IAM project and an IAM programme. For practitioners, the governance model has to survive rollout.

Access reviews lose value when they are not tied to lifecycle events. The article’s emphasis on certification, provisioning, deprovisioning, and monitoring shows that review cycles alone do not create control. If the access model is not aligned to joiner-mover-leaver motion, teams end up certifying drift instead of correcting it. The practical conclusion is that access review design must follow identity change, not calendar rhythm.

Just-in-time access only reduces risk when revocation is operationally dependable. Zluri’s discussion of JIT access and auto-remediation reflects a wider truth: temporary privilege is useful only when expiry is enforced consistently. Without reliable revocation, time-limited access becomes a policy statement rather than a control. Practitioners should treat privilege expiry as a governance commitment, not a feature flag.

Identity programmes need evidence, not assumptions, to satisfy audit and compliance needs. The article connects IAM implementation to regulatory compliance, audit trails, and ongoing monitoring, which is where many programmes underperform. Control intent is not the same as control proof. Teams should expect auditors and internal assurance functions to ask whether access controls are observable, repeatable, and continuously maintained.

From our research library:

What this signals

Identity governance has to be treated as a recurring operating control, not a deployment phase. The programme fails when review, revocation, and monitoring are assumed to happen naturally after implementation. Teams should expect governance debt to accumulate unless ownership and evidence collection are built into the operating model.

Access certification only remains meaningful when it is coupled to identity change. A review process that is detached from joiner, mover, and leaver motion will certify old access rather than current need. That weakens both security assurance and audit defensibility.

JIT access and automation do not replace governance discipline. Temporary privilege only reduces exposure if expiry, remediation, and exception handling are reliable in production. Practitioners should judge IAM maturity by whether controls continue to work after rollout, not by how complete the implementation project looked at go-live.


For practitioners

  • Define IAM as an operating model Assign explicit owners for policy enforcement, access reviews, exception handling, and control evidence so the programme continues after deployment.
  • Tie reviews to identity lifecycle events Schedule access certification around joiner, mover, and leaver changes so teams review access when entitlement risk actually changes.
  • Make revocation operationally testable Validate that just-in-time access expiry, auto-remediation, and offboarding revocation actually remove access in the live environment.
  • Separate implementation from governance reporting Track monitoring, audit trails, and exception closure as standing operational metrics rather than one-off rollout deliverables.

Key takeaways

  • IAM implementation fails when governance is treated as a one-time setup activity instead of an ongoing operating discipline.
  • The article ties effective IAM to continuous access reviews, monitoring, and revocation rather than deployment alone.
  • Practitioners should judge IAM maturity by whether controls still work after rollout, across changes in people, applications, and privilege.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organisational ContextIAM implementation here is framed as an ongoing governance programme, not a one-time tool rollout.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on access control enforcement, reviews, and entitlement maintenance.
Recommendation — Establish IAM ownership, scope, and operating responsibilities as part of governance context. Review and maintain access permissions so they stay aligned to current business need.
CIS Controls v8CIS-5 — Account ManagementThe article repeatedly focuses on provisioning, deprovisioning, reviews, and account lifecycle.
Recommendation — Operationalise account management so onboarding, offboarding, and access changes stay controlled.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast privilege is one of the article’s explicit controls and depends on continuing governance.
Recommendation — Enforce least privilege through review and revocation, not just initial role assignment.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article’s emphasis on deprovisioning and revocation maps to offboarding failures when governance is weak.
Recommendation — Remove access promptly at offboarding and validate that revocation actually takes effect.

Key terms

  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org