By NHI Mgmt Group Editorial TeamBased on Omada Identity: “Building a Sustainable Identity Governance Program with IdentityPROJECT+” (May 21, 2026)

TL;DR: Identity governance programmes often fail at scale because teams try to deliver too much at once, according to Omada Identity’s webinar on IdentityPROJECT+. A phased, business-driven operating model is now the practical way to reduce implementation risk, align stakeholders, and turn IGA into a durable business capability.


At a glance

What this is: A webinar on why identity governance programmes need phased delivery and a business-driven operating model to mature sustainably.

Why it matters: It matters because IAM and IGA teams need to sequence governance work in a way that improves adoption, reduces implementation risk, and embeds controls into operations rather than creating shelfware.


Context

Identity governance maturity is less about adding more controls and more about building a model that can absorb change, scale across the organisation, and keep producing value after the first rollout. When teams try to design the whole target state up front, they usually create complexity that slows adoption and makes governance harder to sustain.

Omada Identity frames the problem as an operating-model issue, not a tooling issue. The webinar argues for phased implementation, business alignment, and repeated delivery iterations so identity governance becomes part of normal operational and compliance work rather than a separate project.


Key questions

Q: How should organisations phase an identity governance programme to reduce risk?

A: Start with a limited business area, a clear set of access decisions, and a small number of systems where ownership is obvious. Then expand only after the operating model proves stable, stakeholders understand their roles, and the first governance outcomes are measurable. That approach reduces implementation risk and avoids overloading the programme before it has a repeatable rhythm.

Q: Why do identity governance projects struggle when they are treated as one-time deployments?

A: Because governance only works when the organisation can operate it repeatedly. One-time deployments often leave unclear ownership, poor adoption, and controls that do not fit operational reality. A durable programme needs phased delivery, business alignment, and repeatable processes that become part of normal identity operations.

Q: What are the signs that an IGA programme is too complex to sustain?

A: Common warning signs include stalled adoption, duplicated approvals, inconsistent review completion, and controls that require too much manual intervention to keep running. When the programme depends on constant project-style intervention, it is not yet operating as a sustainable governance capability.

Q: How should organisations stop identity governance from stalling in practice?

A: Treat IGA as an operating model problem first. Strengthen integration with core systems, reduce manual exception handling, and validate that the review and approval process still works at scale. If the programme cannot sustain daily operations, adding more controls will not improve governance because the control fabric itself is unstable.


Background and context

Why phased IGA delivery reduces implementation risk

A phased identity governance model breaks a large programme into smaller, measurable increments. That matters because IGA programmes usually fail when scope, process design, and stakeholder expectation all move at once. A phased model lets teams stabilise entitlement data, access request flows, and approval logic before expanding to broader governance processes. It also creates a clearer path for adoption because each phase can be validated against a business outcome rather than against an abstract maturity target.

Practical implication: sequence IGA rollouts around bounded governance outcomes instead of trying to implement the full operating model in one release.

How business-driven governance changes identity governance architecture

A business-driven IGA operating model starts with the processes the organisation actually needs to run, then maps identity controls to those processes. That shifts the design emphasis away from generic feature coverage and toward repeatable governance actions such as certification, role decisions, and exception handling. In practice, this means identity governance has to support operational cadence, compliance evidence, and business ownership at the same time. Without that alignment, the programme may exist technically but fail organisationally.

Practical implication: design governance around business processes and control ownership, not around the platform’s default implementation pattern.

What sustainable identity governance maturity looks like in practice

Sustainable maturity is not a destination state reached by completing a project plan. It is the ability to keep governance active as the identity estate, compliance demands, and business structure change. Identity governance matures when access reviews, policy enforcement, and stakeholder accountability become normal parts of operations rather than annual exercises. The webinar’s core message is that maturity depends on repeatability, adoption, and embedded governance, not on the number of features switched on.

Practical implication: measure maturity by whether governance is operating as a durable business capability, not by how many modules have been deployed.


NHI Mgmt Group analysis

Phased delivery is the only credible way to make IGA scale. Identity governance programmes fail when they are designed as single-gambit transformations, because the organisation has to absorb process change, data cleanup, policy design, and stakeholder adoption at the same time. A phased model reduces that load and gives each stage a measurable outcome. The implication for practitioners is that programme maturity should be built through controlled increments, not broad declarations of target state.

IGA maturity is an operating-model problem before it is a tooling problem. The webinar’s message is that technology does not create sustainable governance unless the surrounding process, ownership, and business alignment are already clear. That is the real maturity test: whether identity governance can survive normal operational pressure and still produce evidence, decisions, and adoption. Practitioners should therefore assess operating discipline before expanding platform scope.

Identity governance becomes durable only when it is embedded into business rhythm. Annual certification and isolated project milestones do not create lasting governance if they sit outside day-to-day operational and compliance processes. A phased model works because it turns governance into a recurring business function rather than a one-time implementation event. The implication is that teams should focus on repeatability and accountability, not just go-live.

Measured iteration is the named concept that separates maturity from ambition. In this context, measured iteration means delivering identity governance in bounded cycles that each prove value, reduce risk, and build stakeholder trust. That approach matters because IGA programmes often fail when they try to prove everything at once. Practitioners should use iteration as the governance mechanism for growth.

Stakeholder alignment is a control surface, not a communications task. The article treats adoption as a programme outcome, but in practice it is what determines whether governance decisions are followed, audited, and sustained. If business owners do not recognise the workflow as theirs, the model degrades into administrative overhead. The implication is that governance design must make ownership visible and operationally real.

From our research library:

What this signals

Measured iteration: identity governance maturity depends on proving value in bounded cycles, because broad target-state programmes often create more process friction than control value. For readers, the signal is to treat phased delivery as the mechanism that converts IGA from project work into operating discipline.

The programme question is no longer whether identity governance can be implemented, but whether it can be embedded into the cadence of approvals, reviews, and compliance evidence. Teams that cannot make governance repeatable will keep recreating the same adoption and ownership problems in every phase.


For practitioners

  • Define the first governance phase around a narrow business outcome Start with a bounded identity governance use case such as access requests, certifications, or high-risk role review, then prove value before expanding scope.
  • Map each phase to a named business owner and operational process Assign clear ownership for approvals, exceptions, and evidence so governance responsibilities align with how the organisation actually works.
  • Measure adoption and operational stability after each iteration Track whether users, reviewers, and process owners are completing governance tasks consistently before adding the next phase.
  • Embed governance into compliance and operational routines Use existing compliance checkpoints, access review cycles, and operational controls to make governance repeatable instead of project-specific.

Key takeaways

  • Identity governance maturity depends on operating discipline, not on how much of the platform has been switched on.
  • Phased delivery reduces implementation risk by limiting the number of moving parts each iteration has to absorb.
  • Sustainable IGA programmes are the ones that become part of daily business and compliance routines.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-03 — Understanding roles and responsibilitiesThe article centres on governance ownership and operating-model alignment for IGA.
GV.RM-02 — Risk appetite and tolerance are established and communicatedThe phased model is about reducing implementation risk and sequencing change safely.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity governance implementation ultimately controls entitlements, reviews, and authorization decisions.
Recommendation — Clarify governance roles and responsibilities before expanding IGA scope or delivery phases. Set delivery risk thresholds that define when an IGA phase is ready to expand. Use access entitlement governance as the measurable output of each delivery phase.
NIST SP 800-53 Rev 5AC-2 — Account ManagementIGA programs operationalize account and entitlement lifecycle controls across the enterprise.
Recommendation — Tie phased governance delivery to account and entitlement lifecycle control outcomes.
CIS Controls v8CIS-5 — Account ManagementThe article addresses scalable management of identities and governance processes.
Recommendation — Use account management outcomes to validate whether the phased model is operationally working.

Key terms

  • Identity Governance Maturity Model: A framework for assessing how consistently an organisation controls access, enforces policy, and proves compliance across its identity estate. In practice, maturity is measured by operational reliability, remediation speed, and the ability to scale governance across human and non-human identities.
  • Phased Operating Model: A delivery approach that breaks identity governance into smaller, sequenced stages with clear outcomes and feedback loops. It reduces implementation risk by letting teams validate process, data, and adoption before expanding scope or complexity.
  • Business-Driven Governance: An identity governance approach that starts from operational and compliance needs, then maps controls and workflows to those needs. It keeps the programme aligned to how the organisation actually makes decisions, assigns ownership, and proves control effectiveness.
  • Stakeholder Alignment: Stakeholder alignment is the deliberate coordination of security, operations, compliance, HR, and business leaders around identity goals. It matters because identity security succeeds only when different groups agree on risk, ownership, and the outcomes the programme is meant to deliver.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 3, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org