By NHI Mgmt Group Editorial TeamBased on Netwrix: “Révolutionner la gouvernance des identités à l'ère numérique : l'IGA 2.0” (May 26, 2026)

TL;DR: Identity governance and administration 2.0 is a maturity question for organisations that need broader visibility, stronger lifecycle control, and better governance across identities and access, according to Netwrix. The strategic issue is not tooling breadth alone, but whether governance can keep pace with expanding identity populations and modern access patterns.


At a glance

What this is: This is an identity governance benchmark piece arguing that governance maturity now hinges on visibility, lifecycle control, and access oversight across expanding identity populations.

Why it matters: It matters because IAM and IGA teams need governance models that work across human and non-human access, not just broader tooling or isolated reviews.


Context

Identity governance now has to cope with more identities, more access paths, and faster change than traditional programmes were built for. In practice, that means organisations can no longer treat visibility, provisioning, certification, and offboarding as separate control islands.

The benchmark question is whether identity governance can keep pace with modern access patterns across human users, privileged access, and non-human identities. The article positions IGA 2.0 as a maturity test for whether governance is operationally continuous rather than periodic.


Key questions

Q: How should enterprises modernize identity governance for SaaS, cloud, and AI-driven access models?

A: Enterprises should move from periodic, compliance-only governance to continuous, automated identity control. That means integrating across SaaS, cloud, and hybrid environments, covering employees, contractors, service accounts, and AI-driven agents, and using real-time policy enforcement instead of static reviews. The goal is to reduce friction while keeping least privilege current as access patterns change.

Q: Why does identity governance fail when it only covers employee accounts?

A: Because sensitive access is often held by service accounts, application credentials, and delegated entitlements that never pass through employee-centric review paths. If those identities are excluded, the organisation sees only part of the access graph and leaves the highest-risk privileges outside governance and offboarding controls.

Q: What are the signs that identity governance is not working in practice?

A: Common warning signs are repeated access workarounds, ignored approval workflows, super admins holding too much power, and teams bypassing the process because it is too slow or hard to use. If access reviews are always behind, permissions stay stale, and IT has to chase owners for answers, governance is operating more as paperwork than control.

Q: What should security teams do when governance and access ownership are split across teams?

A: They should define one accountable owner for each access class and require that owner to approve exceptions, review entitlements, and validate revocation. Split ownership creates gaps between policy, administration, and business accountability, which is where stale access usually persists.


Background and context

Why traditional IGA breaks under modern access sprawl

Identity governance and administration was designed for slower, more bounded identity estates. When access expands across cloud platforms, SaaS, privileged roles, and non-human identities, point-in-time certification no longer gives a reliable view of who can do what. The technical issue is not just volume, but the mismatch between static governance cycles and dynamic access creation, delegation, and reuse. That creates blind spots in entitlement accuracy, ownership, and revocation timing.

Practical implication: treat governance coverage as a live control problem, not a quarterly review exercise.

Lifecycle control is the real test of governance maturity

A mature identity programme does more than assign access. It tracks joiner, mover, and leaver states, aligns entitlement changes with role or job changes, and removes access when the relationship ends. In modern environments, lifecycle control also has to account for service accounts, tokens, and other non-human identities that persist after the business need changes. Without that lifecycle layer, governance becomes descriptive rather than preventive.

Practical implication: connect identity inventory, ownership, and revocation workflows so access changes follow the real lifecycle of each identity type.

Access visibility must extend beyond human accounts

Access governance fails when it only measures employee and contractor accounts while ignoring service identities, application credentials, and delegated access paths. Those identities often hold the most sensitive permissions and are least likely to be reviewed with the same discipline as human access. The result is an incomplete risk picture, especially where privileged actions are performed by accounts that do not map neatly to a person or team. Good governance depends on seeing the full access graph, not just the user directory.

Practical implication: include non-human and privileged identities in inventory, review, and ownership models before calling governance complete.


NHI Mgmt Group analysis

Identity governance 2.0 is less about more features and more about control coherence. The article points to a familiar pattern: organisations keep adding visibility and lifecycle tools, but the real benchmark is whether those controls work together across the full identity estate. That is why governance maturity is now measured by whether access can be explained, certified, and removed across human and non-human identities without relying on manual exception handling.

IGA maturity should be judged by lifecycle accuracy, not report volume. A programme can produce dashboards and still fail to revoke stale access, align ownership, or certify high-risk entitlements on time. The discipline shifts from documenting access to governing access states through joiner-mover-leaver processes, access reviews, and ownership clarity. Practitioners should treat incomplete lifecycle execution as a governance defect, not a reporting gap.

Non-human identity forces IGA to become a cross-actor discipline. Service accounts, application credentials, and automation identities do not fit neatly into employee-centric governance models, yet they often carry the broadest privileges and longest dwell times. That is where identity governance 2.0 becomes materially different from legacy IGA: the programme has to cover human IAM, privileged access, and NHI control in one operating model.

Access governance is moving from periodic assurance to continuous accountability. The benchmark implied by the article is not whether a review happened, but whether the organisation can answer who owns access, why it exists, and when it should disappear. That shift favours programmes that unify identity inventory, lifecycle events, and certification evidence into one governance spine. The practitioner conclusion is simple: if access cannot be tied to an owner and a live lifecycle state, governance is not finished.

From our research library:

What this signals

Identity governance 2.0 is best understood as a shift from periodic access administration to continuous access accountability. For IAM teams, that means inventory, ownership, lifecycle events, and certification evidence need to be tied together before governance can be called mature.

The practical signal for readers is that non-human identities now belong in the same governance conversation as employee access. If service accounts, tokens, and delegated permissions are outside the review model, the organisation is not governing digital access end to end.


For practitioners

  • Map all identity types to one governance model Inventory employees, contractors, service accounts, tokens, and application credentials in the same governance workflow so certification and ownership are not limited to human users.
  • Tie access reviews to lifecycle events Trigger recertification when a user changes role, a service account changes ownership, or a non-human credential is created, rotated, or retired.
  • Define clear owners for every entitlement Require business or technical ownership for privileged access, delegated access, and non-human identities so revocation and exception handling have an accountable decision maker.
  • Close offboarding gaps across human and non-human identities Align leaver processes with the removal of human access and the retirement or transfer of machine credentials so stale privileges do not persist after the business relationship ends.

Key takeaways

  • Identity governance maturity now depends on whether access can be explained, reviewed, and removed across the full identity estate.
  • Legacy, human-only governance leaves high-risk non-human access outside certification and offboarding workflows.
  • The immediate implication is to connect inventory, ownership, lifecycle triggers, and recertification into one operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on access governance, entitlement visibility, and lifecycle control.
ID.AM-01 — Physical devices and systems within the organization are inventoriedIGA 2.0 depends on complete identity and access inventory across human and non-human accounts.
GV.OC-01 — Organizational context is understood and informs cybersecurity risk managementThe piece frames governance maturity as a programme-wide benchmark, not a tool feature.
Recommendation — Apply PR.AA-05 to govern who and what has access, then validate entitlements continuously. Inventory all identity-bearing assets and keep the catalogue current before certification starts. Align governance scope to business context so access controls match real operational ownership.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article highlights lifecycle control and removal of access when relationships end.
NHI-05 — Overprivileged NHIBroad, unmanaged access is a core governance problem in mature identity programmes.
Recommendation — Retire non-human access when its business purpose ends and verify the credential is no longer usable. Reduce non-human privilege to the minimum required and revalidate high-risk entitlements regularly.

Key terms

  • Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Lifecycle Control: Lifecycle control is the set of processes that govern access from onboarding through change and removal. In identity programmes, it ensures that provisioning, review, and offboarding stay aligned as applications and permissions evolve. A connector that cannot support lifecycle control may sync data, but it does not fully govern access.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org