TL;DR: IAM progress depends on three linked areas: interoperability, quantification, and access reviews, according to Nexis research, with findings on SCIM extensions, 43 IAM metrics, and usability-driven review improvements that make governance more measurable and operationally useful. Access reviews that still assume human-scale decision-making are already misaligned with distributed identity estates and emerging non-human identities.
At a glance
What this is: This is a research-to-practice IAM article showing that interoperability, metrics, and access review usability are the three levers that turn IAM from a theory-heavy discipline into an operational governance function.
Why it matters: It matters because IAM teams are being asked to govern human and non-human access with better evidence, better integration, and better decision quality, not just more policy.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
👉 Read Nexis' article on IAM interoperability, metrics, and access review research
Context
IAM is the discipline of deciding who or what can access which resources, but the article shows that the hardest problems are no longer limited to authentication. The real challenge is how to make distributed identity systems interoperable, measurable, and usable enough to support governance across human users, service accounts, and emerging non-human identities.
That framing fits modern enterprise reality. Access decisions are spread across products, logs, policy engines, and review workflows, so control quality depends on integration and evidence as much as on policy intent. For teams managing non-human identities, the article’s core message is that identity governance must be designed as a connected system, not a collection of isolated checks.
Key questions
Q: How should IAM teams govern access reviews across multiple systems?
A: They should define one accountable review owner, one evidence standard, and one remediation path that applies across every connected directory, SaaS platform, and on-prem system. If the review cannot trigger action in all downstream systems, it only measures governance. Consistency matters more than review volume.
Q: Why does interoperability matter so much in modern IAM?
A: Because governance fails when the same identity data means different things in different systems. Interoperability allows policy, logs, and lifecycle state to align across tools, which makes automation and audit evidence more trustworthy. Without that alignment, IAM becomes fragmented, and teams spend time reconciling inconsistencies instead of controlling access.
Q: What do IAM teams get wrong about metrics?
A: They often measure activity instead of control quality. A useful metric should connect to a business goal such as security, compliance, or efficiency, and it should tell leaders whether a process is improving. If the number does not affect a decision, it is usually reporting noise rather than governance signal.
Q: Why do non-human identities complicate IAM governance?
A: Non-human identities complicate IAM governance because they do not behave like people. They authenticate without interactive sessions, persist across deployments, and can be shared or embedded in code. That means the controls that work for users, such as MFA and periodic review cadences, often miss the real NHI risk, which is secret exposure and privilege drift.
Technical breakdown
Interoperability in distributed IAM systems
Modern IAM environments rarely live in one platform. They span directories, access management tools, policy engines, logs, and application-specific controls, which means interoperability is about shared identity semantics, not just data exchange. Extending standards such as SCIM and normalising transaction logs turns disparate systems into a governance fabric that can support RBAC decisions, auditability, and lifecycle consistency. Without that shared model, the same identity can look different across tools, which weakens automation and review quality.
Practical implication: standardise identity data models across systems before automating cross-platform governance decisions.
Quantification turns IAM governance into something steerable
The article treats quantification as a governance problem, not a reporting exercise. Measuring IAM quality means linking metrics to strategic goals such as security, compliance, operational efficiency, and service quality, then ensuring the numbers are meaningful to the right audience. That is why a metric without context can mislead, while a smaller set of aligned measures can expose whether access control policies are actually improving. This is especially important when governance teams need to compare inconsistent control environments over time.
Practical implication: define IAM metrics against business goals and review them in the same operating rhythm as risk and compliance decisions.
Access reviews fail when usability is treated as optional
Access reviews are often framed as a compliance task, but the article shows they are also a human decision problem. If reviewers face too many entitlements, vague context, or poor interface design, the result is predictable: low revocation rates and inconsistent outcomes. Digital nudges such as choice defaults and identity grids can improve decision quality, but they also raise cognitive load and review time. That trade-off matters because review design shapes whether governance produces real remediation or just procedural completion.
Practical implication: redesign review workflows so reviewers can make consistent decisions quickly without drowning in entitlement noise.
NHI Mgmt Group analysis
Interoperability is now a governance control, not just an integration problem. IAM programmes that treat system-to-system connectivity as plumbing miss the point. When access data is scattered across directories, logs, and application-specific policy stores, the organisation cannot maintain a consistent identity truth. That affects governance, auditability, and lifecycle accuracy at the same time. Practitioners should treat shared identity semantics as a control objective in its own right.
Quantification only has value when it is tied to decision-making. The article’s strongest insight is that IAM metrics must align with business outcomes, not merely report activity. A metric that cannot inform security, compliance, or operational priorities adds noise, not control. This is where many IAM programmes stall: they measure too much of the wrong thing and too little of the evidence that changes action.
Access review quality is a usability issue disguised as a compliance process. If reviewers cannot reach consistent decisions, recertification becomes ceremonial. The article shows that interface design, decision support, and bounded workload all influence whether reviews actually remove excessive access. Practitioners should stop treating review failure as reviewer negligence and start treating it as process design debt.
Non-human identity growth makes IAM research-to-practice translation more urgent. The article correctly points to AI agents, IoT devices, and machine identities as a reason to rethink IAM models. Those actor types do not fit neatly into human-centric governance assumptions, so interoperability, measurement, and review design all need to extend beyond traditional user access patterns. The implication is that future IAM architecture must govern multiple identity classes with one coherent operating model.
Identity Fabric thinking raises the bar for lifecycle governance. Orchestrated IAM ecosystems only work if provisioning, revocation, and review signals move consistently across platforms. The article’s architecture direction is sound, but it also increases dependency on accurate lifecycle state and shared policy interpretation. Practitioners should assume that poor interoperability will surface first as lifecycle drift and inconsistent access enforcement.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly remediation can lag behind exposure.
- For lifecycle depth, read NHI Lifecycle Management Guide and Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs.
What this signals
Identity Fabric: the more IAM services are orchestrated, the more governance depends on consistent identity semantics across platforms. Teams that cannot reconcile identity state across systems will struggle to automate reviews, revocation, or access evidence at scale.
With 96% of organisations storing secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, per the Ultimate Guide to NHIs, interoperability alone is not enough; lifecycle state has to be visible too.
The next IAM maturity step is not another dashboard. It is a control model that connects metrics, workflows, and lifecycle evidence so human access, service accounts, and machine identities can be governed under one operating rhythm.
For practitioners
- Map IAM data sources to a shared identity model Inventory directories, access tools, application logs, and review systems, then define one canonical model for identities, entitlements, and review outcomes so systems can exchange consistent meaning instead of just records.
- Tie IAM metrics to governance decisions Limit reporting to measures that can change prioritisation, remediation, or review outcomes, and review them against security, compliance, and operating goals rather than raw activity counts.
- Redesign access reviews around reviewer decision quality Use defaults, grouping, and entitlement context to reduce decision fatigue, then cap review scope so reviewers can complete accurate decisions without excessive cognitive load.
- Extend governance planning to non-human identities Separate human review patterns from service account, API key, and machine identity governance, because lifecycle, visibility, and offboarding requirements differ materially across those actor types.
Key takeaways
- IAM programmes fail when interoperability, measurement, and review design are treated as separate workstreams instead of one governance system.
- Access reviews are only as good as the human decision environment around them, which is why workflow design changes control outcomes.
- Non-human identities raise the stakes because lifecycle visibility and offboarding discipline are still too weak in most organisations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity governance, access reviews, and interoperability all support access control discipline. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege and access review improvement align directly with access enforcement. |
| NIST Zero Trust (SP 800-207) | 5.1 | Distributed IAM and identity fabric thinking align with zero trust identity and policy enforcement. |
| NIST SP 800-63 | SP 800-63C | Federated identity interoperability depends on standard identity assertions and trust relationships. |
Map IAM review and lifecycle workflows to PR.AC-1 and verify access decisions are consistently enforceable.
Key terms
- Identity Fabric: An identity fabric is a connected control model that shares context across governance, privileged access, and access management. It is not a product category. The aim is to make identity decisions coherent across the full lifecycle so ownership, privilege, and enforcement reinforce each other.
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Policy-Based Access Control: Policy-based access control grants or denies access using rules that evaluate context, signals, and identity state at decision time. It is more adaptive than static role assignment, but only if the policy engine receives accurate runtime inputs and can enforce them across systems.
- Identity Semantics: Identity semantics are the shared meanings attached to identity data such as accounts, roles, entitlements, and lifecycle state. When semantics differ across tools, integration may still move data, but governance breaks because systems no longer interpret access information the same way.
What's in the full article
Nexis' full article covers the research detail this post intentionally leaves for the source:
- The SCIM extension and API design principles behind the interoperability work, including where transaction logs fit as an analytical data source.
- The 43 IAM metrics mapped to goals and stakeholders, which is useful if you are building a measurement model.
- The access review experiments around identity grids, choice defaults, and threshold-based detection of low-quality reviews.
- The real-world case studies that validated the dissertation's design artifacts in practice.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org