By NHI Mgmt Group Editorial TeamBased on Cerbos: “Overcoming IAM blind spots and fragmentation for continuous governance” (March 2, 2026)

TL;DR: Fragmented identity tooling creates blind spots, weak audit evidence, and delayed incident response because access data, approvals, and logs live in separate systems, according to Cerbos’s discussion with 1Kosmos advisor Giao Nguyen. Continuous governance matters because IAM maturity is no longer about how many tools you have, but whether you can prove and enforce access decisions in real time.


At a glance

What this is: This blog argues that identity sprawl undermines IAM governance by scattering access data across too many systems to support reliable control or auditability.

Why it matters: For IAM, IGA, and PAM teams, the issue is not tool count but whether access decisions can be proven, enforced, and corrected in real time across the full identity estate.


Context

Identity sprawl is the accumulation of identity directories, IAM consoles, governance tools, and approval records that do not share a single operational truth. In this article, Cerbos argues that the result is not just administrative friction but a governance gap in which access cannot be reliably traced, reviewed, or enforced across systems.

That matters because continuous governance depends on seeing entitlement changes as they happen, not reconstructing them after an audit or incident. The article frames this as a maturity problem for IAM programmes: if approvals, logs, and policy outcomes are fragmented, the organisation can look controlled while remaining operationally blind.


Key questions

Q: What breaks when IAM data is spread across too many systems?

A: The control chain breaks because no one can reliably connect approvals, entitlements, and logs into one auditable access decision. That creates blind spots, slows investigations, and makes compliance evidence expensive to assemble. The practical fix is not more reporting after the fact, but a governance model that preserves traceability at the point of change.

Q: Why does fragmented IAM increase operational and security risk?

A: Fragmented IAM increases risk because access data, review states, and revocation actions diverge across tools. That creates blind spots, slows response, and makes it harder to prove that access was removed correctly. In practice, the organisation inherits multiple partial truths instead of one defensible record of entitlement.

Q: What are the signs that governance controls are not working as intended?

A: Common signs include slow remediation of governance deficiencies, inconsistent policy enforcement, weak communication between business and IT, and controls that do not surface non-compliance early enough. When boards cannot quickly access reliable data or certification evidence, governance is likely too fragmented. Those gaps usually show up as delayed reviews, unclear ownership, and poor visibility into risk.

Q: How can teams move from periodic IAM reviews to continuous control?

A: By combining contextual enforcement, automated revocation, and runtime detection instead of relying on annual or quarterly certification alone. The goal is to make access decisions responsive to behaviour, device state, and current risk, so that high-risk access can be challenged or removed before it is abused.


Technical breakdown

Why identity silos break governance evidence

Identity silos appear when HR systems, directories, cloud IAM consoles, and governance platforms each hold part of the access picture. A team may know who the user is but still lack a reliable way to prove what that user can do, who approved it, or whether the access is still justified. The technical problem is not only inventory drift. It is that evidence becomes distributed across systems with different policy states, timestamps, and ownership boundaries, so the organisation cannot answer basic authorisation questions with confidence.

Practical implication: centralise identity data enough to reconstruct who has access, why they have it, and whether that access is still valid.

How fragmented approvals weaken traceability

Traceability fails when access decisions are separated from the policy or ticket that justified them. In a fragmented IAM environment, a privilege may be granted in one console, approved in another, and logged somewhere else entirely. That breaks the chain of custody for identity decisions. Without a durable link between request, approval, enforcement, and logging, audit evidence becomes manual reconstruction rather than machine-verifiable control. The system may still provision access, but it cannot reliably explain itself later.

Practical implication: bind each entitlement change to a recorded policy decision so approvals and enforcement stay auditable as one event.

Why policy-as-code changes the control model

Policy-as-code externalises access rules from individual applications and consoles into a central decision layer. Instead of each tool interpreting approval logic differently, applications consult the same policy engine and receive consistent decisions. This is technically important because it reduces drift between directories, cloud platforms, and custom apps. It also creates a repeatable decision record that can be logged, reviewed, and monitored. In practice, continuous governance becomes less about periodic reconciliation and more about enforcing one rule set at the point of decision.

Practical implication: move recurring access rules into a central policy layer so enforcement and logging happen at the same decision point.


Threat narrative

Attacker objective: The attacker wants to exploit governance blind spots to move through access paths that the organisation cannot easily detect, prove, or unwind.

  1. Entry occurs through identity fragmentation, where access is granted or changed in one system while other systems remain unaware of the full state.
  2. Escalation happens when stale entitlements, orphaned accounts, or inconsistent policy engines leave excessive access in place across separate platforms.
  3. Impact follows when auditors or responders cannot quickly prove who approved access, what was used, or where the compromise spread across the identity estate.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity sprawl is a governance failure before it is a tooling problem. When approvals, entitlements, and logs sit in separate systems, the organisation loses the ability to prove access decisions end to end. That breaks continuous governance because control depends on a single operational view, not a stack of disconnected products. The practitioner conclusion is that governance maturity starts with identity data coherence, not more console coverage.

Continuous governance is the point where IAM becomes evidence-driven rather than calendar-driven. Quarterly reviews and annual audits only tell you whether a process existed, not whether it prevented risk between checkpoints. If access can change without immediate traceability, then the programme is still reactive. The implication is that identity controls must be measured by live decision integrity, not by whether the last audit passed.

Policy-as-code gives identity teams a way to remove interpretation from access control. In sprawl-heavy environments, each system can apply access logic differently, which creates policy variance and audit arguments. A central policy layer makes the decision rule explicit and repeatable, so the same entitlement is treated the same way across applications. The practitioner conclusion is to externalise access logic wherever possible and stop relying on local interpretations of governance.

Operational chaos is the hidden cost of fragmented IAM, and attackers benefit from that delay. When teams have to reconcile spreadsheets, ticketing records, and directory logs by hand, response time stretches and accountability blurs. That delay does not just hurt audits. It expands the window in which risky access remains active and unverifiable. The conclusion is that IAM programmes must be built for immediate explanation, not post-event archaeology.

Identity visibility now defines whether governance is real or performative. The article captures a broader market truth: organisations can own many IAM tools and still lack control if no one can connect the decisions those tools produce. That is the central flaw continuous governance addresses, and it is why identity programme maturity now depends on traceable enforcement, not tool accumulation. Practitioners should treat visibility as a control objective in its own right.

From our research library:

What this signals

Identity data fragmentation is now a governance control problem, not just a reporting nuisance. When directories, cloud consoles, and governance tools each carry a partial view, the programme cannot reliably prove who has access or why. Teams should treat identity data integration as a prerequisite for audit-ready control, not a back-office cleanup task.

Continuous governance is the practical answer to access decisions that age out between audits. Quarterly reviews cannot compensate for a control model that only checks state after the fact. The operational shift is to enforce and log decisions at issuance time, then measure whether those decisions stay explainable across the identity lifecycle.

According to the State of Secrets in AppSec, organisations maintain an average of 6 distinct secrets manager instances, creating fragmentation that undermines centralised control. That same pattern appears in IAM sprawl: multiple systems may each be functional, yet the programme still lacks a coherent operating picture.


For practitioners

  • Inventory every identity source Catalog HR systems, directories, cloud consoles, governance tools, and any shadow identity stores so you know where access truth currently lives.
  • Unify access evidence Create a single reporting layer that can answer who approved access, when it changed, and why the entitlement still exists.
  • Externalise policy decisions Move recurring access rules into policy-as-code so applications enforce the same approval logic instead of maintaining local exceptions.
  • Automate high-risk remediation Start with orphaned accounts, inactive users, and unauthorised privilege changes, then remove or flag them as soon as they are detected.
  • Measure governance as a live control Track time to deprovision, number of orphaned accounts, and the percentage of access changes with complete approval trails.

Key takeaways

  • Identity sprawl weakens IAM because the organisation can no longer prove access decisions from request to enforcement to audit evidence.
  • The article shows that fragmented identity tooling creates blind spots, slower response, and manual evidence collection when audits or incidents occur.
  • Continuous governance shifts identity security from periodic review to live traceability, policy consistency, and faster remediation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing entitlements across fragmented identity systems.
DE.CM-09 — Network Monitoring for Identity EventsContinuous governance depends on monitoring identity changes as they happen.
Recommendation — Centralise entitlement governance so access decisions remain traceable and consistent across tools. Monitor identity events continuously so access changes are visible before audits or incidents expose them.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article highlights orphaned accounts and lingering access created by fragmented lifecycle control.
NHI-05 — Overprivileged NHIThe post discusses excess access that accumulates when governance is not continuous.
Recommendation — Track and revoke stale identity access so departed or inactive accounts do not persist in the estate. Reduce standing privilege by reviewing and removing excess entitlements before they become routine.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeContinuous governance is needed to keep access aligned to least-privilege intent over time.
Recommendation — Apply least-privilege enforcement to keep granted access aligned with current business need.

Key terms

  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
  • Continuous governance: An identity governance model that checks and enforces policy as activity happens rather than on a schedule. It is designed to catch drift, misuse, and orphaned access while the identity is still active, which matters when risk unfolds in minutes instead of review cycles.
  • Policy as Code: Policy as code stores authorization logic in version control and evaluates it through testable, reviewable rules. For agent governance, it makes runtime decisions reproducible and measurable, which is critical when actions can be triggered by untrusted content and executed at machine speed.
  • Identity data fabric: An identity data fabric is a consolidated layer that aggregates identity and access information from multiple sources into a more coherent view. It does not erase the source systems, but it makes entitlements, approvals, and account state easier to query, reconcile, and govern across the programme.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org