TL;DR: Identity and access governance is moving from periodic certification toward continuous, intelligence-driven control, according to Nexis, as organisations contend with hybrid IT, SaaS sprawl, non-human identities, and rising regulatory pressure. The governance problem is no longer just access review cadence; it is keeping entitlement decisions aligned with live risk, ownership, and lifecycle change.
At a glance
What this is: This is Nexis’s analyst-inclusion post on identity and access governance, arguing that the discipline is becoming continuous, intelligence-driven, and tied to broader identity risk signals.
Why it matters: It matters because IAM, IGA, PAM, and NHI programmes now need governance that can keep pace with service accounts, workloads, bots, and AI agents without relying on stale review cycles.
By the numbers:
- In modern enterprises, NHIs outnumber human identities by 25x to 50x, which changes the scale of governance work.
- Only 5.7% of organisations have full visibility into their service accounts, leaving most NHI estates only partially governed.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
👉 Read Nexis's analysis of identity access governance in the 2026 Leadership Compass
Context
Identity and access governance is the discipline that decides who or what should have access, why that access exists, and whether it should still exist. In a modern IAM programme, that now extends well beyond employees to service accounts, APIs, workloads, bots, contractors, and AI agents.
Nexis is positioning this as a shift from periodic certification toward continuous, intelligence-driven governance. That framing reflects a real operational problem: access review processes designed for slow-moving human joiner-mover-leaver cycles do not keep up with identity sprawl, entitlement churn, or risk signals from adjacent security systems.
The underlying issue is not only volume. Governance teams now need to see relationships between identities, entitlements, ownership, and actual usage if they want reviews, SoD checks, and remediation to stay defensible. The most mature programmes are moving from static attestations to continuous decision support.
Key questions
Q: How should security teams run access reviews for non-human identities?
A: Security teams should scope reviews by risk pattern, assign every identity to an accountable owner, and require a documented decision for each item in scope. The workflow should allow direct remediation for obvious cases and owner follow-up for the rest. The goal is not just certification but a clean audit trail and a clear end state for each credential.
Q: Why do periodic certification campaigns fall short for modern identity governance?
A: Periodic campaigns assume access is stable long enough to be reviewed on a schedule, but modern environments change continuously across SaaS and machine identities. By the time a review closes, entitlement context may already be outdated. Continuous governance closes that gap by using live identity, usage, and risk signals instead of static snapshots.
Q: What do teams get wrong about data access governance?
A: They often treat access review as a directory exercise instead of a data-risk exercise. A permission can be approved and still be unsafe if it reaches sensitive data, persists after the task is complete, or belongs to a non-human identity that can move data outside human review rhythms.
Q: How should organisations decide whether to invest in IGA analytics or more review automation?
A: They should start with the review failure they need to fix. If the problem is weak visibility, prioritise identity and entitlement relationship data. If the problem is review fatigue, add contextual scoring and workflow automation. The best programmes use analytics to improve decisions and automation to reduce repeat manual effort.
Technical breakdown
Why identity access governance is moving beyond certification campaigns
Traditional identity access governance centres on periodic reviews, usually tied to quarterly or annual certification cycles. That model assumes entitlements are stable enough to be reviewed later, and that business ownership can be validated from a snapshot. In practice, SaaS adoption, hybrid infrastructure, and non-human identities create a moving target. Role mining, anomaly detection, and contextual risk scoring are responses to that change because they help teams infer whether access is still appropriate at the point of decision, not after the fact.
Practical implication: treat certification as one control in a continuous governance loop, not the control that defines the programme.
How identity graphs change access governance decisions
An identity access graph maps identities, roles, entitlements, policies, and relationships as connected data rather than isolated records. That matters because governance questions are relational, not just transactional: who approved an entitlement, what other access comes with it, and what downstream systems inherit the decision. When teams can simulate role changes or trace entitlement dependencies before production changes, they reduce toxic combinations and improve review quality.
Practical implication: prioritise platforms and processes that preserve relationship data, not just flattened user and role lists.
Where live security signals improve IGA and Zero Trust alignment
IGA becomes more effective when it consumes live signals from privileged access, SIEM, and threat detection tools. Those feeds add context that static HR or ticketing data cannot provide, such as whether an account is actively abused, whether privilege is unusually elevated, or whether a request aligns with recent risk indicators. That is also where governance begins to support Zero Trust and least privilege in a meaningful way, because decisions are informed by current conditions rather than historical entitlement states.
Practical implication: connect governance to operational telemetry so review and request decisions reflect real risk, not outdated ownership records.
NHI Mgmt Group analysis
Identity access governance is becoming a continuous control plane, not a periodic review activity. Quarterly certification cycles were designed for environments where access changed slowly and human approvers could validate context manually. That model breaks down when entitlements move across SaaS, workloads, service accounts, and AI-enabled workflows faster than review windows can capture. Practitioners should read this as a shift in control philosophy, not just tooling.
Access review quality now depends on relationship visibility, not just identity inventories. A list of users, accounts, and roles is not enough when the real governance question is how those objects relate to each other and to business ownership. Identity graphs and entitlement modelling matter because they expose toxic combinations, orphaned access, and privilege accumulation that flat records miss. The implication is that IGA maturity is increasingly a data architecture problem.
Governance scope now extends beyond the workforce to the full non-human identity estate. Service accounts, APIs, workloads, bots, and AI agents are not edge cases anymore. In programmes still built around employee-centric recertification, the real failure mode is scope blindness: the governance process does not see enough of the estate to govern it coherently. That is the point at which NHI lifecycle, access governance, and operational security start converging.
Identity visibility and intelligence platforms are best understood as governance accelerators, not replacements for IGA. Consolidating entitlement, account, and relationship data improves signal quality for review, SoD, and remediation, but the governance decision still belongs to the programme owner. The practical takeaway is that better visibility should tighten accountability, not create another silo of identity data detached from business ownership.
From our research:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- That is why Lifecycle Processes for Managing NHIs should be treated as a governance control, not an operational afterthought.
What this signals
Identity access governance is becoming a control plane for the full identity estate. As organisations absorb more non-human identities and delegated access paths, the old separation between IGA, PAM, and operational security starts to blur. Teams that still rely on periodic review cycles will need to add relationship data, live risk context, and workflow ownership before their governance process becomes too slow to matter.
Identity graph thinking will matter more than entitlement counting. Once governance depends on how access is connected across systems, the quality of the underlying relationship model becomes the differentiator. Programme leaders should expect more demand for access lineage, entitlement simulation, and cross-system visibility because those are the inputs that make review decisions defensible.
Governance scope will keep expanding toward machine identities and agentic workflows. Even when the immediate topic is workforce IGA, the same design pattern now applies to service accounts and AI-driven processes. Teams that build their operating model around lifecycle and accountability rather than around one identity type will adapt faster as the estate changes.
For practitioners
- Expand governance scope to non-human identities Map service accounts, APIs, workloads, bots, and AI agents into the same governance inventory as human users so recertification does not miss the majority of access-bearing identities. Use the Ultimate Guide to NHIs as a lifecycle reference point for provisioning, rotation, and offboarding logic.
- Move from snapshot reviews to relationship-based decisions Model identities, entitlements, roles, and ownership as connected relationships so reviewers can see toxic combinations, inherited access, and orphaned entitlements before approval. Identity graph analysis should inform each access review and SoD assessment.
- Fuse governance with live risk signals Feed privileged access, SIEM, and threat detection telemetry into governance workflows so elevated or suspicious access is reviewed in context. This helps access decisions reflect active exposure rather than stale certification records.
- Recheck Zero Trust assumptions in identity governance Use Zero Trust principles to test whether governance is actually limiting standing access and whether least privilege is enforced across connected systems. A governance process that cannot prove current access risk is not supporting Zero Trust in practice.
Key takeaways
- Identity access governance is moving from scheduled certification toward continuous, intelligence-driven control.
- The scale problem is now structural because non-human identities, not just employees, dominate access-bearing estates.
- Better governance depends on relationship visibility, live risk context, and lifecycle accountability across all identity types.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access governance and review alignment sit at the heart of this IGA topic. |
| OWASP Non-Human Identity Top 10 | NHI-03 | The post's NHI scope expansion raises credential lifecycle and visibility concerns. |
| NIST Zero Trust (SP 800-207) | The article explicitly links governance quality to Zero Trust and least privilege. | |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege and access scope management are central to governance review quality. |
Map entitlement review and approval workflows to PR.AC-4 and require ownership validation before certification.
Key terms
- Federated Identity Access Governance: A control model that separates policy setting from operational approval and evidence collection. Central teams define access rules and risk thresholds, while business owners make decisions within those guardrails and an independent platform records what happened for audit and review.
- Identity access flow graph: An identity access flow graph is a correlated view of identity activity, paths, and touched systems. It helps teams understand not just that something happened, but how access moved through the environment, which is essential when deciding whether to contain, revoke, or investigate further.
- Identity Visibility and Intelligence Platform: An Identity Visibility and Intelligence Platform is a layer that correlates identity data across multiple tools into one risk picture. It does not replace existing controls. It makes them more useful by connecting events, relationships, configuration, and posture so teams can prioritise what matters.
- Certification Campaign: A certification campaign is a structured access review in which owners confirm whether an identity still needs its permissions. For NHIs, the review must include purpose, actual usage, privilege scope, and ownership because role-based human review logic does not map cleanly to automation.
What's in the full article
Nexis's full article covers the operational detail this post intentionally leaves for the source:
- The specific capabilities of the NEXIS Platform across identity analytics, role mining, and authorization modelling.
- How the identity access graph supports impact analysis and governance simulation before production changes.
- What NICO does inside review, approval, and certification workflows to explain recommendations.
- How ISPM and segregation-of-duties checks are embedded into access request and certification processes.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org