TL;DR: As SaaS sprawl, remote work, and delayed revocation erode perimeter controls, identity governance and administration has become the mechanism for enforcing least privilege, continuous access review, and audit-ready accountability, according to Zluri. The governance problem is no longer authentication alone, but whether access is still justified across human and non-human identities.
At a glance
What this is: Zluri argues that identity-first security has moved IGA from a compliance function to the control plane for governing access across SaaS, service accounts and other non-human identities.
Why it matters: It matters because IAM can authenticate users, but IGA is what lets security and governance teams verify whether access is still justified, reviewable and revocable across human and non-human identity programmes.
By the numbers:
- Stolen or compromised credentials remain the leading cause of breaches, with an average cost of $4.9 million per incident, according to IBM’s 2024 Cost of Data Breach report cited by Zluri.
- The average breach cost cited in the article rose by 10% over the last year, according to IBM’s 2024 Cost of Data Breach report cited by Zluri.
Context
Identity-first security is the idea that identity becomes the control point for access decisions across SaaS, remote work, contractors and machine accounts. In this model, perimeter controls no longer provide enough visibility, so governance must follow the identity rather than the network.
The article’s core problem is governance drift: access is provisioned faster than it is reviewed, revoked or explained. For IAM and IGA teams, that means the real challenge is not just authentication at login, but whether every entitlement still has a current business justification and an auditable approval trail.
Key questions
Q: Where does IAM fail when organisations rely on it for access governance?
A: IAM fails when it is used as the only control for access governance, because it proves identity at login but does not show whether access is still needed, who approved it or whether it was ever reviewed. That gap leaves stale entitlements and delayed revocation in place across SaaS, contractors and service accounts.
Q: Why do delayed revocation and stale entitlements create so much risk?
A: They extend the lifetime of access beyond the business reason that justified it. When a former employee, contractor or service account still has active entitlements, an attacker or insider can use legitimate access paths that no longer have a valid owner, making abuse harder to detect and easier to escalate.
Q: What are the signs that user access reviews are not working well?
A: Common warning signs include long review cycles, heavy reliance on spreadsheets, inconsistent evidence collection, and app owners who delay or ignore assigned reviews. Another red flag is recurring orphaned accounts, especially in systems without automated provisioning. If access decisions are not documented or no next review date is set, the process is probably too fragmented to control privilege effectively.
Q: Why do service accounts and other non-human identities increase breach impact?
A: Service accounts and other non-human identities increase breach impact because they often carry broad, persistent access and bypass interactive controls like MFA. When those identities are not tightly scoped, rotated, and retired, attackers can reuse them to move quietly across systems, pipelines, and cloud environments. The issue is not the token alone, but the authority attached to it.
Technical breakdown
Why IAM authenticates, but does not govern access
IAM confirms that a user or service can log in, but it usually does not answer whether the entitlement should still exist. That distinction matters in SaaS-heavy environments, where access lives across an IdP, HRIS and dozens of applications. IGA adds the governance layer by correlating access, ownership, approval and review state so teams can see who has what, why they have it, and whether that access remains appropriate. Without that layer, authentication can be strong while authorization drift continues unchecked.
Practical implication: treat IAM as the entry control and IGA as the lifecycle control that validates whether access remains justified.
How continuous access reviews change the control model
The article describes a shift from periodic, checklist-style certifications to continuous access governance. In practice, that means access reviews are triggered by lifecycle changes, risk signals or policy rules rather than a quarterly calendar. This matters because stale entitlements, contractor overreach and former employee access are all symptoms of review cycles that arrive too late. Continuous governance also creates a better audit trail, because approvals and remediation actions are captured as access changes happen rather than reconstructed later from spreadsheets.
Practical implication: move review triggers closer to the event that changes risk, not the end of the quarter.
Why non-human identities widen the IGA problem
The article explicitly includes service accounts, bots and APIs in the identity surface, which means IGA must govern more than people. Non-human identities often accumulate standing access, are shared across workflows and are harder to validate through human-oriented review processes. That creates a larger blast radius when entitlements are stale or overbroad. Once machine identities enter the programme, governance has to cover ownership, intended use, access scope and revocation discipline as first-class controls rather than edge cases.
Practical implication: inventory non-human identities alongside users before access review and deprovisioning workflows are designed.
Threat narrative
Attacker objective: The attacker or insider seeks to use legitimate-looking access that still exists on paper, but no longer reflects current business need or trust.
- Entry occurs through credentials that are already valid but no longer appropriately governed, such as stale user, contractor or service access in SaaS environments.
- Privilege persists because delayed revocation and infrequent review allow entitlements to remain active after a role change, project end or employment exit.
- Impact follows when compromised or unnecessary access is used to reach sensitive data or administrative functions before governance catches up.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity-first security turns IGA into the programme’s control plane: The article is describing a governance shift, not a tooling preference. Once access decisions span SaaS, HRIS and machine identities, authentication alone no longer answers the operational question of whether access is still justified. The practitioner conclusion is that access governance now sits at the centre of cyber strategy, not beside it.
The core failure mode is access drift across review and revocation boundaries: The article repeatedly points to delayed revocation, stale contractor access and spreadsheet-driven certifications. That pattern matters because the control failure is not absence of identity data, but the inability to keep approval state aligned with current entitlement state. The practitioner takeaway is that governance has to follow lifecycle events continuously, not reconstruct them after the fact.
Non-human identities make IGA a universal governance discipline, not a human-only process: Once service accounts and APIs are part of the identity surface, the assumptions behind human-centric access review start to break. Ownership, business justification and revocation become harder to express, yet more important to enforce. The practitioner implication is that IGA maturity is now measured by whether it can govern people and non-human identities with the same lifecycle discipline.
Access review without remediation is a documentation exercise, not a security control: The article’s emphasis on automated remediation reflects a deeper truth. Review findings only reduce risk when they trigger timely deprovisioning, entitlement reduction or policy correction. The practitioner conclusion is that certification and remediation must be linked, or the control produces evidence without changing exposure.
Identity is now the practical perimeter, so auditability becomes a security outcome: The named concept here is identity control plane. It describes the shift from network-bound defence to entitlement-bound governance, where logs, approvals and change history are as important as login checks. The practitioner implication is that audit readiness and breach reduction now depend on the same access records.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
What this signals
Identity-first security exposes a governance gap that many programmes still underestimate: once access is spread across SaaS, HR systems and non-human identities, the issue is not login strength but entitlement drift. Teams should expect more pressure to prove current access justification, not just authentication assurance.
Identity control plane: the decisive shift is from checking whether someone or something can authenticate to checking whether it should still be entitled to act. For IAM and IGA programmes, that means lifecycle events, approval trails and revocation speed become core security metrics.
Access reviews need to move closer to the event that changes risk, because quarterly certification cannot keep pace with remote work, SaaS sprawl and contractor churn. The programme signal to watch is whether revocation and recertification are tied to actual lifecycle change, not calendar cadence.
For practitioners
- Inventory every access source Map entitlements across the IdP, HRIS and each SaaS application so access ownership is visible in one governance view.
- Automate lifecycle-based revocation Trigger deprovisioning when employment status, contractor scope or project assignment changes instead of waiting for periodic review cycles.
- Separate authentication from governance Use IAM for login control, but require IGA for approval history, access justification and entitlement recertification across the estate.
- Include non-human identities in reviews Treat service accounts, bots and APIs as governed identities with named owners, defined purpose and explicit review cadence.
- Tie access reviews to remediation Make every review outcome produce a change, whether that is removal, reduction or re-approval of the entitlement.
Key takeaways
- Identity-first security reframes IGA as the place where access justification, review and revocation are enforced across the estate.
- The article ties weak governance to delayed revocation, stale contractor access and missing approval trails, which are classic signs of entitlement drift.
- The control change that matters most is moving from periodic certification to continuous governance that covers people and non-human identities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Delayed revocation and contractor retention are central to the article's access risk theme. |
| NHI-05 — Overprivileged NHI | The article includes service accounts and bots that can accumulate unnecessary access. | |
| NHI-10 — Human Use of NHI | The article warns that human-centric governance breaks down when identities include bots and APIs. | |
| Recommendation — Enforce offboarding and entitlement removal when employment or contract scope ends. Review machine identities for excess access and reduce permissions to the minimum required. Separate human and non-human access governance so machine identities are reviewed on their own lifecycle. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle and revocation timing underpin the access governance problem described. |
| Recommendation — Apply authenticator management controls to remove or rotate access credentials when risk changes. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing entitlements, authorisations and access reviews. |
| Recommendation — Use entitlement governance to keep access approvals, reviews and revocations aligned with current need. | ||
Key terms
- Identity-first security: Identity-first security is an approach that treats identity as the primary control plane for managing risk. Instead of relying mainly on network or endpoint boundaries, it uses identity context to decide what can happen, when it can happen, and under what conditions. That model is especially relevant where privileges move across human, non-human, and agentic actors.
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Answer Drift: Answer drift is the gradual change in a model’s responses over time, often showing up as reduced consistency or increasing error rates. It can signal degraded grounding, shifting data quality, or prompt and retrieval issues. Monitoring drift helps teams catch reliability problems before they become widespread user-facing failures.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org