By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Oleria SecurityPublished March 2, 2026

TL;DR: 451 Research says enterprises name classic IGA and PAM problems as top identity pain points, yet only 42% have deployed standard IGA tools, with legacy implementations often taking 12 to 24 months and carrying seven-figure services costs. The adoption gap shows governance still fails when deployment and operating models do not match real enterprise complexity.


At a glance

What this is: The article argues that IGA adoption lags because legacy deployments are slow, expensive, and too rigid for how enterprises actually operate.

Why it matters: That matters because IAM teams still need governance over privileged access, access reviews, and offboarding, but they cannot rely on tools that are too heavy to deploy or too narrow to cover hybrid identity sprawl.

By the numbers:

👉 Read Oleria Security's analysis of the IGA adoption gap and governance trade-offs


Context

Identity governance and administration is meant to solve recurring access problems such as privileged access, access reviews, and offboarding. The article’s central point is that many organisations know the pain well, but legacy IGA delivery has made the cure feel worse than the disease.

That gap is especially relevant for hybrid identity programmes, where user accounts, service accounts, API keys, and AI-adjacent access patterns all need different governance treatment. When visibility, connector depth, and reviewer context are weak, teams fall back to partial controls and checkbox reviews instead of durable governance.

For practitioners, the question is not whether governance is needed, but which operating model can deliver it without months of consulting and a brittle integration footprint. That is the practical tension this article surfaces, and it is typical rather than unusual across large enterprise environments.


Key questions

Q: How should teams reduce IGA implementation time without weakening governance?

A: Teams should reduce implementation time by standardising the access model, using flexible workflows, and limiting custom code that must be maintained over time. Speed is only useful if approvals, recertification, and audit trails remain intact after rollout. The goal is not faster administration alone, but governance that can still adapt as systems and roles change.

Q: Why do access reviews fail when organisations expand into hybrid environments?

A: They fail when reviewers lack enough context to distinguish legitimate access from dormant or excessive access. Hybrid estates fragment identity data across cloud, SaaS, and on-prem systems, so the review process becomes a checklist instead of a decision. The problem is not review cadence alone. It is the absence of a unified entitlement picture.

Q: What do security teams get wrong about simplified IGA tools?

A: They often assume lower deployment friction automatically means sufficient governance. In practice, shallow integrations, limited analytics, and ecosystem boundaries can preserve the same blind spots that made legacy IGA painful. A simplified tool is only useful if it still supports real decisions about provisioning, review, and offboarding.

Q: Why do automated ITDR programs need different rules for service accounts and human users?

A: Service accounts and human users fail in different ways. Human identities often show interactive anomalies, while service accounts may signal compromise through unusual token use, privilege drift, or unexpected calling patterns. A single response policy creates noise or overreaction, so teams need identity-specific thresholds and containment paths.


Technical breakdown

Why legacy IGA becomes a deployment and operating burden

Legacy IGA platforms often depend on bespoke connectors, long implementation projects, and specialist tuning before they deliver usable value. That architecture creates a cost curve that starts with integration work and continues with ongoing maintenance, making the system hard to justify outside the largest programmes. The problem is not governance as a function, but governance delivered through a delivery model that assumes abundant time, budget, and specialist staff. In practice, that leaves many teams with delayed value and incomplete coverage.

Practical implication: assess whether your current governance stack can be operated by the team you actually have, not the specialist services team you wish you had.

How hybrid identity visibility breaks access review quality

Access reviews only work when reviewers can see enough context to make a decision. In hybrid environments, shallow integrations and ecosystem boundaries create blind spots across SaaS, cloud, and on-prem systems, so reviewers approve access without understanding usage, dormancy, or peer context. That turns certification into a procedural exercise rather than a control. The article’s point is that poor visibility is not just an observability issue. It directly degrades the quality of governance decisions.

Practical implication: measure review quality by context completeness, not by how many campaigns you close.

What modern IGA must do differently for NHI governance

The article correctly extends the governance problem beyond people. Service accounts, API keys, machine identities, and AI-adjacent access all create machine-speed governance demands that legacy IGA was not designed to handle. The challenge is less about adding more workflows and more about building richer identity context, better automation, and lifecycle handling that fits non-human access patterns. For IAM teams, this is where human-centric governance assumptions start to fail.

Practical implication: separate human access certification workflows from NHI lifecycle controls instead of forcing both into one generic process.


Threat narrative

Attacker objective: The objective is to keep excessive or unreviewed access in place long enough for misuse, privilege abuse, or compliance failure to become operationally inevitable.

  1. Entry begins with governance sprawl, where identity access is spread across multiple systems and the organisation lacks a complete view of accounts, entitlements, and review context.
  2. Escalation occurs when incomplete integrations and rigid provisioning paths leave orphaned accounts, stale access, and weak reviewer decisions in place for long periods.
  3. Impact is persistent access risk, because critical accounts remain overprivileged or unreviewed while the organisation believes governance is functioning.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Legacy IGA is failing as an operating model, not as a security idea. The article shows that organisations still care about the same core governance problems, but they reject delivery models that require long projects, heavy consulting, and brittle custom integration. That distinction matters because adoption failures are often read as apathy when they are actually a rejection of implementation friction. The practitioner conclusion is that governance design now competes on deployability as much as on control depth.

Hybrid visibility is the real precondition for meaningful access review. If reviewers cannot see usage, dormancy, peer context, and connected entitlements across environments, certification degrades into rubber-stamping. That failure mode is structural, not procedural. It means many IGA programmes are measuring completion, not decision quality. The practitioner conclusion is that visibility breadth should be treated as a control dependency, not a reporting nice-to-have.

Modern governance has to split human IAM from NHI lifecycle mechanics. The article is most useful when it acknowledges that service accounts, API keys, machine identities, and AI-adjacent access behave differently from human users. Human review cadences do not map cleanly to machine-speed credentials, and the same workflow cannot cover both without losing precision. The practitioner conclusion is that NHI governance needs lifecycle-specific controls, not just recycled access review language.

IGA Lite helps only if it preserves decision quality, not just lower friction. Simplified platforms can reduce deployment pain, but shallow analytics and pre-built connector limits can leave the same governance blind spots in place. That creates a false economy: lower implementation burden, but weaker accountability and residual risk. The practitioner conclusion is to evaluate whether simplified governance actually changes decisions or merely changes packaging.

Identity governance should be judged by residual risk reduction per unit of operational effort. That is the named concept this article points to: the governance tax is no longer acceptable when the control outcomes remain partial. Organisations do not need less governance, they need governance that scales without collapsing into a services project. The practitioner conclusion is to compare platforms on measurable control coverage, not implementation theatre.

From our research:

  • Only 42% have deployed standard IGA tools, according to Ultimate Guide to NHIs.
  • Only 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
  • The governance gap becomes clearer when you compare adoption with lifecycle hygiene in the NHI Lifecycle Management Guide.

What this signals

Residual risk reduction per unit of effort is becoming the right way to judge identity governance investment. When implementation consumes quarters of consulting time but still leaves review quality weak, security leaders should assume the operating model is the real constraint, not the absence of policy.

The practical next step is to align IGA, PAM, and NHI lifecycle work around the same visibility model. That means using contextual identity data, not just entitlement lists, and comparing programmes against the operating reality described in the Ultimate Guide to NHIs , Key Challenges and Risks.

With 96% of organisations storing secrets outside secrets managers in vulnerable locations including code, config files, and CI/CD tools, the governance problem is already broader than human access reviews, according to the Ultimate Guide to NHIs. Teams should prepare for a combined human and machine identity operating model rather than treating IGA as a standalone project.


For practitioners

  • Map governance pain points to control outcomes Start by separating privileged access, access reviews, developer/admin accounts, and offboarding into distinct control outcomes so you can see which failures are genuine governance gaps and which are tooling constraints.
  • Score implementation effort against control quality Measure time to value, integration burden, and ongoing maintenance alongside review context quality and lifecycle coverage, then retire any IGA approach that only looks efficient on paper.
  • Treat visibility as a control prerequisite Require cross-environment visibility for SaaS, cloud, and on-prem identities before certifying access, because shallow connectors create review decisions that are functionally blind.
  • Separate NHI lifecycle governance from human review workflows Build different control paths for service accounts, API keys, machine identities, and human users so that machine-speed access does not get forced into human-paced certification cycles.

Key takeaways

  • Legacy IGA adoption is constrained less by demand than by deployment models that are too slow, expensive, and hard to operate.
  • Hybrid visibility and context-rich review data determine whether governance produces decisions or just compliance theatre.
  • IAM teams need separate control paths for human access and NHI lifecycle governance if they want coverage that scales.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Access governance and least privilege are central to the article's IGA discussion.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control objective behind the governance gap discussed here.
OWASP Non-Human Identity Top 10NHI-03The article's NHI and lifecycle discussion aligns with credential and identity governance gaps.
NIST Zero Trust (SP 800-207)The article links identity governance to broader zero-trust implementation requirements.

Use zero trust principles to ensure access decisions are continuously validated across environments.


Key terms

  • Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
  • IGA Tax: IGA tax is the operational burden created when identity governance requires long implementations, custom integrations, specialist maintenance, and heavy consulting before it becomes useful. It is not a formal control term, but it accurately describes the cost structure that slows adoption and weakens governance outcomes.
  • Hybrid Identity: Hybrid identity is an architecture that connects on-premises directories with cloud identity providers and SaaS applications. It creates operational flexibility, but it also expands the blast radius of identity compromise across multiple systems that share trust and authentication dependencies.
  • NHI Lifecycle Management: The end-to-end governance of a non-human identity from creation and onboarding through active management, monitoring, credential rotation, and secure decommissioning.

What's in the full article

Oleria Security's full post covers the operational detail this analysis intentionally leaves for the source:

  • The article’s full 451 Research context and the exact survey framing behind the 42% IGA adoption figure.
  • The five-point checklist for modern IGA design, including deployment speed, context-rich reviews, and hybrid visibility.
  • The vendor’s discussion of how platform-native governance features try to bridge classic IGA use cases.
  • The article’s explanation of why machine identities and AI agents force a broader governance model than human-only IGA.

👉 Oleria Security's full post covers the 451 Research findings, the IGA tax, and the case for modern governance design.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org