By NHI Mgmt Group Editorial TeamBased on C1.ai: “10 IGA Metrics Every Security Team Should Use to Measure Success” (January 16, 2026)

TL;DR: C1.ai argues that identity governance should be measured by risk reduction, operational speed, and automation coverage, not just completed reviews or passed audits, because those activity metrics say little about whether identity exposure is actually falling across humans, non-human identities, and AI agents. Completion proves process motion; risk reduction proves the programme is governing access effectively.


At a glance

What this is: This is a metrics guide arguing that IGA success should be judged by reduced risk, faster access change, and more automation, not by whether reviews were merely completed.

Why it matters: For IAM, IGA, PAM, NHI, and AI governance teams, the article matters because it reframes measurement around whether access decisions actually shrink exposure across all identity types.

👉 Read C1.ai's guide to IGA metrics that prove risk reduction, not completion


Context

Identity governance often stops at activity tracking, where teams can prove a review ran or an auditor signed off, but not whether access risk dropped. That gap becomes more serious as identity estates expand beyond employees into non-human identities and AI agents, because completion metrics do not show whether access is still too broad, too slow to change, or too manual to sustain.

The practical problem is not a lack of process, but a lack of outcome-based measurement. Mature programmes need signals that expose whether onboarding, offboarding, requests, privilege, and reviews are reducing exposure in real time instead of producing periodic evidence for compliance.


Key questions

Q: What should teams do first when access reviews are completed but identity risk is still high?

A: Start by separating process completion from security outcome. If reviews close on time but orphaned accounts, standing privilege, or slow revocation remain high, the review model is not reducing exposure. Prioritise the controls that change access state automatically, then use review cycles to handle exceptions and ambiguous cases.

Q: Why do completed identity workflows not always mean the programme is effective?

A: Because completion only proves that a task ran, not that access changed safely. A successful workflow can still leave excessive permissions, manual bottlenecks, or delayed offboarding in place. Effectiveness shows up in lower risk, faster access change, and less human effort, not in ticket closure alone.

Q: What are the signs that an IGA programme is relying too much on manual effort?

A: Long campaign preparation, slow revocation, heavy reviewer load, and large numbers of tickets for routine access changes are all signs that manual work is doing the job automation should handle. When those signals rise, the programme usually becomes slower, more error-prone, and less scalable.

Q: How should organisations measure whether identity governance is reducing blast radius?

A: Use measures that show whether risky access is shrinking over time, including standing privilege, orphaned accounts, and high-risk entitlements. If those numbers stay flat after campaigns and remediation, the programme is maintaining records rather than reducing exposure.


Technical breakdown

Why activity metrics hide identity risk

Identity governance metrics can be misleading when they measure work performed instead of security changed. A review can be completed, a request can be approved, and a ticket can be closed while excessive access remains in place. That is especially true in environments where humans, service accounts, workloads, and AI agents all move at different speeds. The real question is whether access decisions are timely, justified, and reversible. Outcome metrics convert identity governance from evidence collection into control verification.

Practical implication: Measure whether access changed safely, not whether the workflow finished.

Why standing privilege and manual review are weak signals

Standing privilege creates exposure because elevated access persists after the task that required it is over. Manual review only weakens that exposure if reviewers have enough context, time, and signal quality to make consistent decisions. When review preparation is slow and decisions are manual, teams usually get either late campaigns or rubber-stamped approvals. That is why automation coverage, privileged-access duration, and decision quality are better indicators than completion percentages alone.

Practical implication: Track how much privileged access is temporary versus persistent, and how many decisions still depend on human effort.

How identity programmes should measure scale across humans, NHIs, and AI agents

The same governance logic now spans people, service accounts, and AI agents, but the operating tempo differs. Humans are governed through onboarding, offboarding, and access certification. NHIs require lifecycle and secret control. AI agents introduce runtime decision pressure that can outpace periodic review cadences. A useful metric set therefore has to reveal how quickly access adapts to change, how much work is automated, and whether risk is falling across all identity classes rather than one at a time.

Practical implication: Use a common measurement model, but compare each actor type on the controls that actually govern its access pattern.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Outcome metrics are now the only credible proof of identity governance maturity. Completion data can show that a process ran, but it cannot prove that access risk fell or that the programme became easier to operate. In mature identity governance, the meaningful question is whether risk trends, remediation speed, and automation coverage are improving together. Practitioners should treat activity as evidence of motion, not evidence of control.

Standing privilege remains the clearest example of a governance signal that can look healthy while exposure stays high. A team can complete every review cycle and still leave privileged access sitting in place for too long. That is why duration of privilege, not just review completion, is the stronger indicator of whether the programme is actually constraining blast radius. The practical conclusion is that temporary privilege should be measured as a default state, not an exception.

Identity governance now has to be measured across human, non-human, and autonomous actors without collapsing them into one cadence. Humans can be reviewed on periodic cycles, NHIs are controlled through lifecycle and secret discipline, and AI agents may require shorter issuance and tighter runtime guardrails. The implication is not that one metric fits all, but that one programme has to prove control effectiveness across all three identity classes.

Risk reduction is the named concept that matters most here. The article’s real contribution is the shift from audit-style completion reporting to a control model where falling orphaned accounts, lower overprivilege, and faster revocation are the proof points. That is the measurement language practitioners need if identity governance is to operate as a security control rather than an administrative record.

From our research library:

What this signals

Identity programmes should be judged by state change, not workflow completion. If access remains excessive after onboarding, review, or termination events, the governance model is producing administrative output without materially changing exposure. That is the wrong success criterion for a programme that exists to control who can do what.

One metric that deserves more weight is how quickly privilege returns to baseline. Standing access is easy to count, but difficult to justify once a task ends. Practitioners should watch whether elevated access is temporary by default, because duration is often the clearest signal of whether identity governance is influencing actual risk.

What changes for readers is the measurement culture around humans, NHIs, and agents. A single dashboard can cover them all, but not with the same timing assumptions. Human workflows may tolerate periodic certification, while NHIs and AI agents demand tighter issuance, revocation, and automation measures.


For practitioners

  • Track time to remove access after change events Measure the time from termination, role change, or contract end to full access removal, and treat long tail cleanup as a governance failure, not a workflow delay.
  • Separate review completion from review quality Measure how many access decisions are automated, how many are exception-based, and how much reviewer effort is spent preparing campaigns versus making decisions.
  • Baseline privileged access duration Record how long elevated access stays active by system and entitlement, then compare standing privilege against temporary access granted only when needed.
  • Quantify automation coverage by identity type Track what percentage of access requests, revocations, onboarding steps, and NHI lifecycle events are handled automatically rather than by ticketed manual work.
  • Report identity risk as a trend, not a point-in-time Use a recurring risk baseline that follows orphaned accounts, overprivileged access, and revocation lag across users, applications, and environments.

Key takeaways

  • The core problem is not whether identity work gets done, but whether it reduces exposure in a measurable way.
  • Risk reduction, revocation speed, and automation coverage are better indicators of programme health than review completion alone.
  • A mature identity governance model needs separate measurement logic for humans, non-human identities, and AI agents.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Oversight of the cybersecurity risk management strategyThe article is about how to measure whether identity governance is actually reducing risk.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe metrics focus on entitlement reduction, revocation speed, and privileged access duration.
Recommendation — Tie IGA reporting to oversight measures that show whether access risk is falling, not just whether tasks completed. Track entitlement state, revocation latency, and privileged access duration as core governance measures.
CIS Controls v8CIS-5 — Account ManagementThe post centres on onboarding, offboarding, and access revocation as measurable account-management outcomes.
Recommendation — Measure account lifecycle speed and cleanup completeness to show whether account management is reducing exposure.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingSlow offboarding is one of the article's clearest examples of measurable identity risk.
Recommendation — Use offboarding latency to spot improper offboarding and tighten revocation after termination events.

Key terms

  • Identity governance KPI: A measurable indicator used to show whether identity controls are reducing risk, improving compliance, or improving operational efficiency. In practice, the best KPIs link a governance activity to a change in access state or audit outcome, rather than only counting workflow volume.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Access review timeliness: The speed at which review campaigns are completed and decisions are finalised. Timeliness matters because late reviews lose security value and often become checkbox exercises, especially when reviewer context is weak and the number of entitlements is large.
  • Automation coverage: The share of identity work handled without manual tickets or repeated human intervention. For modern programmes, automation coverage is not just an efficiency measure, but a sign that identity operations can scale across humans, NHIs, and AI agents without depending on endless manual processing.

What's in the full article

C1.ai's full blog post covers the operational measurement detail this post intentionally leaves for the source:

  • The ten-metric breakdown for onboarding, offboarding, access requests, privileged access, and review execution
  • Specific examples of what to measure for automation coverage, reviewer workload, and remediation speed
  • The article's framing for turning identity metrics into risk and productivity evidence
  • How the vendor recommends thinking about access governance across humans, non-human identities, and AI agents

👉 The full C1.ai post breaks down the ten metrics and what each one is meant to reveal about programme effectiveness.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org