TL;DR: C1.ai says modern IGA selection in 2026 hinges on lifecycle management, access certification, just-in-time access, policy-based controls, and NHI governance, with API-first SaaS delivery and automation now part of the baseline rather than a differentiator. The real test is whether governance can keep pace with hybrid identity sprawl without becoming manual review theatre.
At a glance
What this is: This guide frames modern IGA RFP selection around lifecycle automation, access review quality, just-in-time access, and NHI governance, while warning that legacy approaches struggle in hybrid environments.
Why it matters: It matters because IAM teams need an RFP that tests governance outcomes, not feature lists, across human, non-human, and emerging autonomous identity estates.
👉 Read C1.ai's guide to selecting a modern IGA platform in 2026
Context
Choosing an IGA platform now means deciding how the organisation will govern access across human users, service accounts, and increasingly automated workflows. The article argues that the wrong choice creates security and productivity drag because governance becomes a manual reconciliation exercise instead of a lifecycle control.
The selection problem is not just tooling. It is whether the programme can support access reviews, just-in-time privilege, policy-based access, and audit evidence across cloud and on-prem environments without relying on spreadsheets, bespoke services, or long implementation cycles.
Key questions
Q: What breaks when IGA selection ignores lifecycle automation?
A: Governance breaks down when onboarding, mover events, and offboarding still depend on manual intervention. Access drifts, certifications become stale, and audit evidence no longer reflects current entitlements. The result is a programme that looks controlled on paper but cannot keep pace with actual identity change across cloud, SaaS, and on-prem systems.
Q: Why do standing privileges create a higher access management risk?
A: Standing privileges increase risk because they remain available outside the task that justified them. That widens the window for misuse, makes review less meaningful, and increases the chance that access survives organisational change. The longer privilege persists, the more likely it is to outlive the decision that created it.
Q: How do IAM teams know whether access governance is working?
A: IAM teams should look for fast revocation after role change or departure, accurate entitlement data, and low numbers of orphaned or over-provisioned accounts. If access creation is easy but removal is slow, governance is incomplete. The strongest signal is whether access still matches business need after the identity changes.
Q: How should organisations govern non-human identities inside IGA programmes?
A: Treat non-human identities as governed identities with owners, purposes, expiry paths, and review cycles. Service accounts, API keys, and tokens should enter the same lifecycle discipline as human accounts, with explicit onboarding, certification, rotation, and offboarding steps. If an identity cannot be assigned to a business owner, it should not remain privileged.
Technical breakdown
Identity lifecycle management as the anchor control
Identity lifecycle management is the operational backbone of IGA because it governs onboarding, role changes, and offboarding across the access estate. In practice, the control has to connect provisioning, deprovisioning, and review workflows so access changes follow identity state changes rather than manual tickets. If lifecycle management is fragmented, every other governance function inherits stale entitlements and slower response times. Modern IGA RFPs should therefore test whether lifecycle events can be handled end to end across HR, IT, and cloud systems without creating separate exceptions for each application class.
Practical implication: Require lifecycle workflows that remove access immediately at departure and keep entitlements aligned as roles change.
Just-in-time access and access certification reduce standing privilege
Just-in-time access and access certification solve different parts of the same governance problem. JIT access reduces how long elevated access exists, while certification checks whether any remaining access still matches business need and policy. Together they shrink standing privilege and reduce the amount of persistent access that reviewers must inspect. The article is right to put both in the RFP because a programme that relies only on periodic review can still leave high-risk access sitting idle between campaigns. The control question is whether privileged access exists only when needed and whether review processes can verify that reality.
Practical implication: Test whether the platform can grant temporary access and certify permissions without leaving persistent privilege in place.
API-first architecture for hybrid identity governance
API-first, SaaS-delivered IGA matters because identity data is now distributed across directories, SaaS applications, cloud infrastructure, and workflow tools. A modern governance layer has to ingest, normalise, and act on that data quickly enough to support access decisions and audit evidence. This is less about deployment fashion than about integration depth and automation reach. If the platform cannot extend cleanly into cloud and on-prem systems, governance will fragment into partial visibility and manual reconciliation. The RFP should therefore probe connector coverage, workflow extensibility, and whether AI features actually improve decision quality rather than just speeding up the interface.
Practical implication: Validate that the platform can integrate across your real identity stack and automate decisions without heavy professional services dependence.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Modern IGA RFPs now have to govern hybrid identity, not just human user access: The article correctly centres lifecycle management, access certification, JIT, and NHI governance because those are the controls that actually determine governance reach. Legacy IGA assumptions break when identities span cloud, SaaS, infrastructure, and service accounts. The implication is that selection must be anchored in cross-domain lifecycle control, not feature completeness.
Access review quality is now a governance outcome, not a checkbox: Automated certification is only useful if it reduces reviewer fatigue and exposes meaningful entitlements, not if it reproduces the same spreadsheet logic at scale. The article’s emphasis on audit trails, reminders, and decision accuracy points to a broader shift: the value is in trustworthy governance evidence. Practitioners should judge platforms on decision quality and review signal, not campaign volume.
JIT access changes the governance baseline for privileged access: Temporary, scoped access should be treated as a core control in modern IGA because it reduces standing privilege before review ever starts. That shifts the programme away from retrospective cleanup and toward issuance-time control. For practitioners, the RFP question is whether the platform can enforce least privilege dynamically enough to make persistent elevation the exception.
Non-human identity governance belongs in the same RFP as human lifecycle control: The guide is right to include NHI governance as a core use case because service accounts, tokens, and machine access now shape governance risk as much as employees do. The old assumption that IGA is mostly about people is no longer sufficient. IAM teams should treat machine identity governance as a first-class evaluation criterion, not a side requirement.
Future-proof IGA is really a question of operational extensibility: API-first architecture, no-code workflows, and transparent pricing matter because governance programmes fail when every change requires specialist intervention. The market is moving toward systems that can adapt with the identity estate rather than lock teams into slow implementation cycles. Practitioners should prioritise platforms that reduce dependence on bespoke services and preserve governance agility over time.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: IGA Buyer's Guide
What this signals
Governance programmes fail first at the handoff points: when lifecycle ownership is split across IT, HR, security, and compliance, review quality becomes inconsistent and offboarding slows down. Modern IGA selection should therefore be judged on whether it can preserve accountability across the full identity lifecycle, not just automate a single control.
Non-human identity governance is now part of the baseline IGA conversation: service accounts, tokens, and other machine identities create the same governance burden as employees when they outlive their purpose. Teams that leave NHI outside the selection criteria end up with blind spots in ownership, certification, and revocation.
Future-proofing means reducing dependence on manual services: if every connector, workflow, or policy change needs specialists, the platform will struggle as the identity estate changes. A usable IGA programme should be able to extend into cloud and SaaS environments without turning governance into a custom integration project.
For practitioners
- Align IGA scope to the broader IAM strategy Map ownership across IT, security, HR, and compliance before issuing the RFP so lifecycle responsibilities and success measures are explicit.
- Prioritise lifecycle and offboarding controls Verify that the platform can remove access immediately when people leave and can handle onboarding, mover events, and exception handling without manual cleanup.
- Test certification quality, not campaign volume Ask how the platform reduces review fatigue, exposes meaningful entitlements, and maintains auditable evidence for decisions.
- Validate JIT and policy-based privilege control Check that temporary access can be granted only when needed and that policy or attribute logic can reduce standing privilege across sensitive systems.
- Demand NHI governance coverage in the core use cases Include service accounts, tokens, and other non-human identities in the same evaluation set as human access so machine privileges are not left outside governance.
Key takeaways
- The article treats modern IGA as a lifecycle governance problem that spans human users and non-human identities, not as a narrow access review tool.
- Its selection criteria emphasise evidence quality, temporary privilege, and integration depth because those are the controls that matter in hybrid estates.
- Practitioners should use the RFP to test whether a platform can enforce governance continuously without relying on manual spreadsheets or heavy service dependencies.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article stresses immediate access removal when identities leave or change roles. |
| NHI-05 — Overprivileged NHI | The guide prioritises least privilege and just-in-time access to reduce standing machine access. | |
| NHI-10 — Human Use of NHI | RFP questions explicitly include non-human identity governance as a first-class use case. | |
| Recommendation — Map offboarding workflows to NHI-01 and verify access is removed as part of every identity departure. Use NHI-05 to identify persistent machine privileges that should be replaced with task-scoped access. Apply NHI-10 to ensure humans are not creating or reusing machine credentials outside governed workflows. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article focuses on how access permissions and entitlements are governed across the environment. |
| Recommendation — Align access governance to PR.AA-05 so entitlements stay current across users, apps, and infrastructure. | ||
| CIS Controls v8 | CIS-5 — Account Management | IGA selection is fundamentally about account lifecycle and entitlement governance. |
| Recommendation — Use CIS-5 to enforce account creation, review, and removal processes that match identity lifecycle events. | ||
Key terms
- Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
- Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials, ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.
What's in the full article
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- Sample RFP questions grouped by deployment, architecture, automation, compliance, cost, and customer success
- Criteria for evaluating speed to value, scalability, and customer experience during vendor comparison
- Detailed feature breakdowns for lifecycle management, access certification, JIT access, and segregation of duties
- Examples of how C1 positions its own deployment model, pricing, and AI-assisted review workflow
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org