TL;DR: Identity security does not become simpler just because tools promise automation; SailPoint argues that large enterprises still face millions of entitlements, thousands of applications, and the need for autonomous decision-making to keep pace with business change. The governance lesson is that complexity must be managed, not hidden, because identity programmes fail when they are simplified beyond what the environment actually requires.
At a glance
What this is: This is a blog post arguing that identity security for complex enterprises cannot be reduced to a simple button because scale, application sprawl, and access nuance require sophisticated governance.
Why it matters: IAM, PAM, and NHI practitioners should treat identity security as a core operating discipline, because oversimplified programmes fail when entitlement volume and business change outpace manual control.
Context
Identity security becomes a governance problem when enterprise scale turns every access decision into an ongoing control choice. The article argues that there is no traditional easy button for identity because large organisations carry too many identities, applications, and entitlement relationships for simplified approaches to hold.
The underlying issue is not whether identity security can be automated, but whether automation is being asked to operate over a programme that still lacks strategy, ownership, and operating discipline. For identity, access, and NHI teams, the question is how to keep pace with change without reducing controls to the lowest common denominator.
Key questions
Q: What breaks when identity security is simplified too far?
A: When identity security is oversimplified, the programme loses the governance depth needed to handle large entitlement sets, application sprawl, and changing access patterns. Controls may still exist, but they no longer match the scale or nuance of the enterprise, so stale access and unowned exceptions keep accumulating.
Q: Why does autonomous identity decision-making increase governance pressure?
A: Autonomous decision-making speeds access decisions to match business change, but that also means policy quality and exception handling matter more than manual review volume. The control model shifts from periodic human checking to governed, fast-moving decision logic that must stay aligned with risk.
Q: How should security teams evaluate whether their identity program is actually mature?
A: Focus on operating resilience, not deployment status. Mature identity programs keep entitlement data current, support reliable lifecycle changes, and sustain reviews without heavy manual intervention. If connector failures, exception handling, and backlog cleanup dominate day-to-day work, the program is still in an immature state even if the platform is already live.
Q: What is the difference between simplifying identity management and governing identity complexity?
A: Simplifying identity management removes steps, but governing identity complexity preserves the control depth needed for enterprise scale. The first can hide risk by stripping capability, while the second makes risk manageable by standardising decisions, clarifying ownership, and keeping exceptions visible.
Technical breakdown
Why enterprise identity complexity defeats simplified governance
Identity security complexity is not just a tooling problem. In large enterprises, identities span employees, service accounts, applications, and access exceptions across many systems, which creates a moving control surface. If a programme is built around static assumptions, it cannot keep up when entitlements accumulate faster than reviews, removals, or policy changes. That is why the article frames identity security as a hard problem rather than a task to automate away. The issue is not the absence of controls, but the need to govern them at enterprise scale without losing fidelity.
Practical implication: design identity governance for scale and change, not for a narrow demo environment.
How autonomous identity decision-making changes the control model
Autonomous identity decision-making means the programme is not waiting for a human to manually approve every access action. Instead, decisions about risk, entitlement relevance, and access change happen quickly enough to track business movement. That does not remove governance requirements. It shifts the control point toward policy, decision quality, and exception handling. In this model, the programme has to distinguish low-risk from high-risk access patterns and act fast enough to prevent stale or excessive access from becoming normal.
Practical implication: move repetitive access decisions into governed automation while retaining policy oversight and escalation paths.
Why identity strategy and ownership matter before technology choices
The article’s most practical message is that identity security cannot be treated as a one-off project. Without a clearly defined strategy and an owner for the programme, enterprises end up buying tools that reduce friction without fixing the underlying governance gap. Strategy answers what identity must protect, who is accountable, and which access decisions must be standardised versus exception-based. Ownership gives the programme the authority to act across application, workforce, and non-human identity domains.
Practical implication: establish explicit programme ownership before expanding controls, automation, or AI-driven decision support.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Complexity is the control condition, not the obstacle. Identity security in large enterprises fails when teams try to compress a genuinely complex access estate into a simplified operating model. That usually strips away the very governance depth needed to manage millions of entitlements, diverse applications, and uneven access usage. The practitioner lesson is that the programme must be built to govern complexity directly, not pretend it does not exist.
Autonomous identity decision-making changes the governance assumption. Human-paced review cycles were designed for access that changes slowly enough to be observed, reviewed, and certified. That assumption weakens when identity programmes rely on autonomous decisions to keep pace with business change, because the control model shifts from periodic review to policy-directed action. The implication is that identity governance must be measured by decision quality and policy fit, not by manual intervention volume.
Identity strategy is a business control, not an IT project. The article is right to push for clear ownership because identity security touches application access, workforce productivity, and operational risk at the same time. When strategy is undefined, organisations buy point fixes and call it progress, while entitlement sprawl keeps growing. The practitioner conclusion is that identity needs a named owner, a business mandate, and a programme charter before scale can be controlled.
Complex enterprises need sophistication with discipline, not simplicity with blind spots. The named concept here is the identity complexity gap: the distance between what a simplified programme can govern and what the enterprise actually exposes. That gap widens as more identities, applications, and entitlements accumulate. The implication for practitioners is to optimise for governed simplification, where controls are streamlined only after the underlying decision model is explicit.
AI belongs in identity only when it accelerates governed decisions. The article’s use of autonomous identity decision-making is meaningful because it points to speed, not marketing automation. In practice, AI is useful only where it helps separate routine access decisions from exceptions that need human review. The practitioner takeaway is to treat AI as a control amplifier inside a defined governance model, not as a substitute for one.
What this signals
Identity complexity becomes a programme design issue once application and entitlement scale outrun manual control. For most enterprises, the next step is not more point tooling but a clearer operating model for how identity decisions are made, reviewed, and escalated. That is especially true when the same programme must cover human access, non-human identities, and delegated automation.
Identity complexity gap: the distance between the access model an organisation can realistically govern and the access model its business now exposes. Practitioners should close that gap by defining ownership, standardising common decisions, and keeping exceptions visible to the control owners.
For practitioners
- Define a named identity strategy Document what the identity programme must protect, which access decisions are standard, and who owns the outcomes across workforce and non-human identities.
- Map the true access estate Inventory identities, applications, and entitlement density so the programme can see where simplification would remove needed control depth.
- Use autonomy where decisions repeat Automate routine access decisions only where policy can be expressed clearly and exceptions still route to human oversight.
- Set governance before tooling expansion Require programme ownership, approval boundaries, and review cadences before adding more automation or AI-driven decision support.
Key takeaways
- Identity security in complex enterprises fails when teams confuse simplicity with governance.
- The article’s own example shows the scale problem clearly: one customer has well over 140,000 identities, more than 8,500 applications, and millions of entitlements.
- The practical answer is not to remove sophistication, but to make identity strategy, ownership, and autonomous decision-making part of the operating model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on access sprawl and too much access across a large enterprise estate. |
| NHI-10 — Human Use of NHI | The post touches autonomous identity decision-making as identity operations become machine-assisted. | |
| Recommendation — Review entitlement scope and remove standing overprivilege where access exceeds business need. Separate human approval from machine-driven identity decisions so governance remains explicit. | ||
| NIST CSF 2.0 | GV.OC-01 — Organisational Context | The article argues identity must align to business strategy and ownership before automation choices. |
| Recommendation — Define identity programme ownership and operating context before expanding controls or automation. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Excess access and unused access are explicit problems in the article's enterprise example. |
| Recommendation — Apply least privilege to reduce unused access and constrain entitlement growth across applications. | ||
| MITRE ATT&CK | TA0004;TA0006 — Privilege Escalation; Credential Access | The article's over-access conditions map to common paths attackers exploit when identity governance is weak. |
| Recommendation — Hunt for entitlement paths that enable privilege escalation and credential abuse in sprawling environments. | ||
Key terms
- Identity Complexity Gap: The gap between the identity controls an organisation can realistically govern and the access estate it actually exposes. In large enterprises, that gap grows when application sprawl, entitlement volume, and business change outpace the operating model.
- Autonomous Identity: An access governance model where identity decisions are made continuously with policy and automation rather than only through periodic human review. It is meant to keep pace with dynamic apps, machine identities, and fast-changing permissions while still preserving auditability and accountability.
- Entitlement Sprawl: The gradual accumulation of too many discrete permissions, often with overlapping access and unclear ownership. It makes access review noisy and offboarding fragile. Grouping entitlements into profiles is one way to reduce that sprawl, provided the groups are designed around real work patterns.
- Identity Governance Operating Model: An identity governance operating model is the way an organization designs, runs, and measures decisions about who gets access, why they get it, and how that access is reviewed. It defines roles, workflows, controls, ownership, and evidence across joiner, mover, leaver, and privileged access processes.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org