TL;DR: Legacy IGA often takes 18 months or longer to deploy, while 95% of multi-cloud permissions remain unused and 72% of organisations have experienced or suspect an NHI breach, according to Oleria Security and NHIMG research. The governance problem is no longer access approval at the door, but continuous proof that access still matches role, usage, and risk.
At a glance
What this is: This is an analysis of how identity governance and administration addresses access sprawl, review fatigue, and lifecycle control across human, privileged, and non-human identities.
Why it matters: It matters because IAM teams need a governance model that keeps pace with dormant access, service accounts, and AI-era identity growth without relying on manual reviews alone.
👉 Read Oleria Security's analysis of identity governance and administration in the AI era
Context
Identity governance and administration is the control layer that checks whether access remains appropriate after it has been granted. In practice, that means asking whether people, service accounts, and other non-human identities still need their permissions, whether those permissions still match current role or purpose, and whether dormant access is quietly expanding attack surface across the enterprise.
The article argues that legacy IGA often becomes expensive, slow, and operationally brittle, which is why many organisations settle for partial coverage or simplified "IGA Light" features. For IAM and IGA programmes, the real issue is not whether access can be granted, but whether access can be continuously reviewed, contextualised, and revoked across hybrid environments, SaaS, and machine identities.
That governance gap is familiar to teams trying to reconcile lifecycle management, privileged access, and compliance evidence across multiple systems. NHIMG’s broader guidance on the issue appears in the Ultimate Guide to NHIs and the Top 10 NHI Issues, both of which frame visibility, rotation, and offboarding as operational controls rather than abstract policy goals.
Key questions
Q: How should teams improve access reviews in complex hybrid environments?
A: Teams should start by improving entitlement visibility before trying to optimise review frequency. If reviewers cannot trace how access was granted, certifications become rubber stamps. The practical goal is to make every material entitlement explainable across legacy, cloud, and delegated systems so business owners can approve or revoke access with confidence.
Q: Why do service accounts and other NHIs complicate GRC implementation?
A: NHIs complicate GRC because they often outnumber human accounts, change outside normal HR-driven lifecycle processes, and carry access that is easy to overlook in reviews. If inventory, ownership, and expiry are incomplete, the GRC programme will miss the most material access risks. That makes NHI governance a core compliance issue, not a niche security task.
Q: What do teams get wrong about access certification?
A: Teams often treat certification as proof that access is safe, when it is really only a decision process. The quality of the outcome depends on the context given to reviewers, including role, activity, and ownership. Without that context, approvals can simply preserve inherited access and outdated entitlements.
Q: Who is accountable when dormant access or orphaned accounts remain active?
A: Accountability should sit with the business owner of the identity, the system owner that issues access, and the governance team that monitors recertification and offboarding. If those roles are not explicit, access drift becomes everyone’s problem and no one’s responsibility. Clear ownership is the difference between governance and paperwork.
Technical breakdown
Why identity governance is different from identity administration
Identity governance is the policy and oversight layer, while identity administration is the execution layer. Governance decides whether access should continue to exist, based on certifications, separation of duties, and compliance requirements. Administration handles the mechanics of provisioning, deprovisioning, entitlement assignment, and lifecycle updates. The distinction matters because many programmes automate grants but leave review and remediation weak, which creates a false sense of control. In mixed human and NHI environments, the administrative task may be fast while the governance decision remains unresolved.
Practical implication: map which parts of your programme automate access changes and which parts actually validate whether access is still justified.
Why access reviews fail when they lack usage context
Access certification only works when reviewers can see whether permissions are active, dormant, or unusually broad. Without usage telemetry, peer comparison, and recent role-change data, reviewers tend to rubber-stamp large lists and miss privilege creep. This is especially true in enterprises where permissions are spread across cloud platforms, SaaS applications, and custom systems. The technical failure is not the review itself, but the absence of decision-quality context inside the review workflow.
Practical implication: feed usage, recency, and role-change signals into access reviews before asking managers to certify anything.
How IGA, IAM, and PAM fit together in a layered model
IAM controls entry, IGA controls ongoing appropriateness, and PAM controls elevated access. That triad matters because modern identity security breaks when organisations treat these as interchangeable. IAM can authenticate a user or workload, but it does not answer whether access has outlived its purpose. PAM can isolate privileged credentials, but it does not solve enterprise-wide governance. IGA sits between them, connecting lifecycle events, entitlement oversight, and audit evidence across the identity stack.
Practical implication: align IAM, PAM, and IGA ownership so that entry control, privileged control, and governance are measured separately.
Threat narrative
Attacker objective: The attacker wants durable access that survives normal business changes, giving them a hidden path to data, systems, or privilege.
- Entry occurs when excessive access is granted through weak lifecycle controls, legacy provisioning, or incomplete offboarding.
- Escalation follows as unused entitlements, orphaned accounts, and privileged roles accumulate beyond current business need.
- Impact appears when dormant access or excessive permissions are used for fraud, lateral movement, audit failure, or data exposure.
Breaches seen in the wild
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity governance is becoming a control system for accumulated risk, not just a compliance layer. The article correctly frames IGA as the mechanism that asks whether access should still exist, not just whether it was approved once. That matters because privilege creep, dormant accounts, and rubber-stamped reviews are now structural enterprise problems, not edge cases. Teams that still treat IGA as audit support will keep missing the operational security value.
The IGA tax is really a governance-friction problem. When deployment takes 18 months or more, organisations do not simply delay tooling. They also delay cleanup of orphaned accounts, access recertification discipline, and lifecycle remediation. The practical consequence is a governance backlog that grows faster than the business can clear it. Practitioners should read long implementation cycles as an indicator of control decay, not just project complexity.
Access review without context is a weak control, especially in hybrid environments. The article is right to call out usage telemetry, role changes, and peer comparisons as reviewer inputs. Without that context, certification turns into a procedural approval exercise instead of a security decision. For IAM and IGA leads, the real issue is review quality, not review frequency.
NHI governance should be treated as part of the same lifecycle discipline as human access governance. Service accounts, API keys, and developer credentials do not age out by themselves, and they often outlive the teams that created them. That means JML, offboarding, and recertification must include non-human identities, not just employees and contractors. The implication is clear: access lifecycle governance must be identity-type aware, not human-only.
Identity security posture and IGA solve different questions, and conflating them weakens both. IGA answers whether access is still justified, while posture management asks whether controls are configured and operating effectively. Enterprises need both because a clean entitlement model can still be poorly monitored, and a well-monitored environment can still have excessive access. Security teams should separate governance decisions from configuration assurance in their operating model.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- Our 2024 ESG Report found that enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly one failure can repeat.
- That is why the 52 NHI Breaches Analysis remains useful for teams building lifecycle controls that outlast single incidents.
What this signals
Access review quality will matter more than access review volume. As enterprises spread permissions across SaaS, cloud, and machine identities, the real control signal is whether reviewers can see recent use, role movement, and ownership. That is where the gap sits between compliance completion and actual governance.
Identity programme owners should expect NHI oversight to become part of mainstream IGA design. Service accounts, API keys, and automation credentials are no longer a side topic, and they cannot be managed with human-only lifecycle assumptions. The organisations that separate human IAM, NHI governance, and privileged access cleanly will have a better chance of keeping review fatigue under control.
The governance backlog is already visible in the data: only 1.5 out of 10 organisations are highly confident in securing NHIs. That confidence gap should push teams toward tighter lifecycle ownership, better entitlement context, and more disciplined offboarding across the identity stack.
For practitioners
- Separate governance from administration in your operating model Define who approves access, who executes changes, and who validates recertification outcomes. If the same process owns all three, blind approvals and delayed remediation become harder to detect.
- Add usage context to every access review Require recent activity, peer comparison, and role-change signals before certification workflows can be completed. That reduces rubber-stamping and gives reviewers evidence they can actually judge.
- Extend JML coverage to non-human identities Treat service accounts, API keys, and other machine credentials as governed identities with owners, expiry expectations, and offboarding triggers. If they are not in the lifecycle process, they are already outside governance.
- Measure review quality, not just review completion Track the share of reviews with contextual data attached, the rate of approvals with no changes, and the number of dormant entitlements removed after certification. Those signals show whether governance is working.
- Reconcile IGA, PAM, and IAM ownership boundaries Document where baseline access ends, where privileged access begins, and where ongoing entitlement oversight sits. That separation makes control gaps easier to find across human and machine identities.
Key takeaways
- IGA is most useful when it continuously tests whether access still deserves to exist, not when it only records that access was granted.
- The strongest governance weakness in many programmes is not missing approvals, but reviews that lack the context needed for a real decision.
- Non-human identities must be brought into the same lifecycle discipline as human access or they will remain a persistent source of unused privilege.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity verification and access authority are central to governance reviews. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management directly governs provisioning, review, and deprovisioning. |
Map access reviews and lifecycle checks to identity assurance and entitlement validation in your governance cadence.
Key terms
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
- Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
What's in the full article
Oleria Security's full article covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of access certification, provisioning, deprovisioning, and entitlement management workflows across IGA and IAM
- Examples of how organisations structure Joiner, Mover, Leaver processes and audit reporting in regulated environments
- A comparison of IGA, IAM, and ISPM that goes deeper into programme design and operational ownership
- Implementation themes around legacy IGA deployment, review fatigue, and hybrid environment visibility
👉 Oleria Security's full post covers IGA, IAM, PAM, and lifecycle controls in more operational detail.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org